Domain name data monitoring method, device, server and storage medium

By using blockchain technology to cache monitoring results in domain name monitoring, the problems of low accuracy and low reuse rate of DNS traffic anomaly monitoring are solved, and more efficient domain name security monitoring and result updates are achieved.

CN113746778BActive Publication Date: 2025-08-19HEZE FUXI TECH CO LTD +1
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202010460758.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-05-27
Publication Date
2025-08-19
Estimated Expiration
2040-05-27

AI Technical Summary

Technical Problem

In the prior art, DNS traffic abnormality monitoring has low accuracy and lacks targeting, and the monitoring results are not stored and updated, resulting in low monitoring multiplexing.

Method used

Blockchain technology is used to cache domain name monitoring results, and security monitoring of the domain names to be monitored through preset monitoring algorithms, and the monitoring results and user information are stored on the domain name monitoring blockchain to achieve update and reuse of monitoring results.

Benefits of technology

It improves the reuse rate and efficiency of domain name monitoring results, ensures that users obtain the latest monitoring results, and enhances the scope of application and accuracy of monitoring.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113746778B_ABST
    Figure CN113746778B_ABST
Patent Text Reader

Abstract

An embodiment of the present application provides a domain name data monitoring method, device, server, and storage medium. The method includes: obtaining a domain name to be monitored input by a target user and user information of the target user, wherein the user information includes user identity information; performing security monitoring on the domain name to be monitored based on a preset monitoring algorithm to obtain a current monitoring result; sending the current monitoring result to the target user based on the user identity information; caching the domain name to be monitored, the current monitoring result, and the user information of the target user in a domain name monitoring blockchain. By performing security monitoring on the domain name input by the user and storing the monitoring result and user information in the blockchain, security monitoring of the domain name and storage of the monitoring result are achieved, while improving the reuse rate and efficiency of the monitoring.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the technical field of domain name security monitoring, and in particular to a method, device, server, and storage medium for monitoring domain name data. Background Art

[0002] The Domain Name System (DNS), a database that maps domain names to IP addresses, is a crucial Internet infrastructure resource. As the Internet continues to develop and the network environment becomes increasingly complex, monitoring unusual domain names has become increasingly important.

[0003] When DNS services are attacked by a network, they typically manifest as abnormal traffic in the DNS domain name direction. By monitoring abnormal domain names in DNS traffic, abnormal behavior can be detected promptly, allowing effective measures to mitigate losses. However, traffic-based anomaly monitoring is inaccurate and untargeted. Furthermore, the monitoring results are not stored or updated, resulting in a low reuse rate. Summary of the Invention

[0004] The embodiments of the present application provide a domain name data monitoring method, device, server, and storage medium, which cache domain name monitoring results based on blockchain, improve the reuse rate of domain name monitoring results, and thus improve the efficiency of monitoring.

[0005] In a first aspect, an embodiment of the present application provides a method for monitoring domain name data, the method comprising:

[0006] Obtaining the domain name to be monitored input by the target user and the user information of the target user, wherein the user information includes user identity information;

[0007] Perform security monitoring on the domain name to be monitored based on a preset monitoring algorithm to obtain a current monitoring result;

[0008] Sending the current monitoring result to the target user according to the user identity information;

[0009] The domain name to be monitored, the current monitoring results and the user information of the target user are cached in the domain name monitoring blockchain.

[0010] Optionally, the user information includes a user security level. Before performing security monitoring on the domain name to be monitored based on a preset monitoring algorithm, the method further includes:

[0011] Obtaining a monitoring algorithm list, wherein the monitoring algorithm list includes at least two preset monitoring algorithms;

[0012] A preset monitoring algorithm is determined according to the user security level and the monitoring algorithm list.

[0013] Optionally, the monitoring algorithm list includes any one of a monitoring algorithm based on network traffic, a monitoring algorithm based on web page content, a monitoring algorithm based on black and white lists, a monitoring algorithm based on domain name data, and a monitoring algorithm based on a bipartite graph, or a fusion algorithm consisting of multiple algorithms.

[0014] Optionally, after caching the domain name to be monitored, the current monitoring result, and the user information of the target user in the domain name monitoring blockchain, the method further includes:

[0015] Obtaining historical monitoring results of the domain name to be monitored in the domain name monitoring blockchain;

[0016] When the historical monitoring result is inconsistent with the current monitoring result, obtaining user information of the historical user corresponding to the historical monitoring result;

[0017] The current monitoring result is sent to the historical user according to the user information of the historical user.

[0018] Optionally, after sending the monitoring result to the historical user according to the user information of the historical user, the method further includes:

[0019] The historical monitoring results are updated as current monitoring results.

[0020] Optionally, the domain name monitoring blockchain includes at least two domain name monitoring nodes, and caching the domain name to be monitored, the current monitoring result, and the user information of the target user to the blockchain includes:

[0021] When the current domain name monitoring node initiates monitoring data caching, it obtains verification results of each domain name monitoring node for the monitoring data cache, wherein the monitoring data includes the domain name to be monitored, the current monitoring result, and the user information of the target user;

[0022] The current domain name monitoring node determines whether the monitoring data cache is qualified according to the verification results of the monitoring data cache by each domain name monitoring node;

[0023] If qualified, the monitoring data will be cached in the domain name monitoring blockchain.

[0024] Optionally, the current domain name monitoring node determines whether the monitoring data cache is qualified according to verification results of the monitoring data cache by each domain name monitoring node, including:

[0025] The current domain name monitoring node receives verification results of the monitoring data cache from each domain name monitoring node, wherein the verification results include two types: verification passed and verification failed;

[0026] Whether the monitoring data cache is qualified is determined based on a comparison result of the ratio of verification passes in the verification result and a preset threshold.

[0027] In a second aspect, the present application further provides a domain name data monitoring device, the device comprising:

[0028] A domain name acquisition module to be monitored is used to obtain the domain name to be monitored input by the target user and the user information of the target user, wherein the user information includes user identity information;

[0029] A domain name monitoring module, configured to perform security monitoring on the domain name to be monitored based on a preset monitoring algorithm to obtain a current monitoring result;

[0030] A monitoring result sending module, configured to send the current monitoring result to the target user according to the user identity information;

[0031] The monitoring result storage module is used to cache the domain name to be monitored, the current monitoring result and the user information of the target user to the domain name monitoring blockchain.

[0032] Optionally, the user information includes a user security level, and the domain name data monitoring device further includes:

[0033] Before performing security monitoring on the domain name to be monitored based on a preset monitoring algorithm, obtaining a monitoring algorithm list, wherein the monitoring algorithm list includes at least two preset monitoring algorithms;

[0034] A preset monitoring algorithm is determined according to the user security level and the monitoring algorithm list.

[0035] Optionally, the monitoring algorithm list includes any one of a monitoring algorithm based on network traffic, a monitoring algorithm based on web page content, a monitoring algorithm based on black and white lists, a monitoring algorithm based on domain name data, and a monitoring algorithm based on a bipartite graph, or a fusion algorithm consisting of multiple algorithms.

[0036] Optionally, the domain name data monitoring device further includes:

[0037] A historical monitoring result acquisition module is used to obtain the historical monitoring results of the domain name to be monitored in the domain name monitoring blockchain after caching the domain name to be monitored, the current monitoring results and the user information of the target user in the domain name monitoring blockchain;

[0038] A historical user information acquisition module, configured to acquire user information of historical users corresponding to the historical monitoring results when the historical monitoring results are inconsistent with the current monitoring results;

[0039] The second monitoring result sending module is used to send the current monitoring result to the historical user according to the user information of the historical user.

[0040] Optionally, the domain name data monitoring device further includes:

[0041] The monitoring result updating module is configured to update the historical monitoring result to the current monitoring result after sending the monitoring result to the historical user according to the user information of the historical user.

[0042] Optionally, the monitoring result storage module includes:

[0043] A node verification result acquisition unit is used to obtain the verification results of each domain name monitoring node for the monitoring data cache when the current domain name monitoring node initiates the monitoring data cache, wherein the monitoring data includes the domain name to be monitored, the current monitoring result and the user information of the target user;

[0044] a cache qualification determination unit, configured for the current domain name monitoring node to determine whether the monitoring data cache is qualified according to the verification results of the monitoring data cache by each domain name monitoring node;

[0045] The monitoring result storage unit is used to cache the monitoring data in the domain name monitoring blockchain if the monitoring data cache is qualified.

[0046] Optionally, the cache eligibility determination unit is specifically configured to:

[0047] The current domain name monitoring node receives verification results of the monitoring data cache from each domain name monitoring node, wherein the verification results include two types: verification passed and verification failed;

[0048] Whether the monitoring data cache is qualified is determined based on a comparison result of the ratio of verification passes in the verification result and a preset threshold.

[0049] In a third aspect, the present application provides a domain name monitoring server, comprising: a memory, a processor, and a computer program;

[0050] The computer program is stored in the memory and is configured to cause the processor to execute the domain name data monitoring method provided in any embodiment of the present application.

[0051] In a fourth aspect, the present application provides a computer-readable storage medium, in which computer-executable instructions are stored. When the computer-executable instructions are executed by a processor, they are used to implement a method for monitoring domain name data as provided in any embodiment of the present application.

[0052] The domain name data monitoring method, device, server, and storage medium provided in the embodiments of the present application perform security monitoring on the domain name input by the user based on a preset monitoring algorithm, send the monitoring results to the user, and store the monitoring results and user information in the blockchain to facilitate the updating of the monitoring results of the domain name, thereby achieving security monitoring of the domain name and storage of the monitoring results, while improving the reuse rate and efficiency of the monitoring. BRIEF DESCRIPTION OF THE DRAWINGS

[0053] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present application and, together with the description, serve to explain the principles of the present application.

[0054] Figure 1 A diagram of an application scenario of the domain name data monitoring method provided in an embodiment of the present application;

[0055] Figure 2 A flowchart of a method for monitoring domain name data provided in one embodiment of the present application;

[0056] Figure 3 This application Figure 2 A schematic diagram of a preset monitoring algorithm in the illustrated embodiment;

[0057] Figure 4 A flowchart of a method for monitoring domain name data provided in another embodiment of the present application;

[0058] Figure 5 For this application Figure 3 Flowchart of step S206 in the illustrated embodiment;

[0059] Figure 6 A schematic diagram of the structure of a domain name data monitoring device provided in one embodiment of the present application;

[0060] Figure 7 A schematic diagram of the structure of a domain name data monitoring device provided in another embodiment of the present application;

[0061] Figure 8 A schematic diagram of the structure of a domain name monitoring server provided in one embodiment of the present application.

[0062] The above drawings illustrate specific embodiments of the present application, which will be described in more detail below. These drawings and the textual description are not intended to limit the scope of the present application in any way, but rather to illustrate the concepts of the present application to those skilled in the art by reference to specific embodiments. DETAILED DESCRIPTION

[0063] Exemplary embodiments will be described in detail herein, with examples illustrated in the accompanying drawings. In the following description, when referring to the drawings, identical numerals in different figures represent identical or similar elements, unless otherwise indicated. The embodiments described in the following exemplary embodiments are not intended to represent all embodiments consistent with the present application. Rather, they are merely examples of apparatus and methods consistent with certain aspects of the present application, as detailed in the appended claims.

[0064] The following specific embodiments describe in detail the technical solution of the present application and how the technical solution of the present application solves the above-mentioned technical problems. The following specific embodiments can be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments. The embodiments of the present application will be described below in conjunction with the accompanying drawings.

[0065] The following explains the application scenarios of the embodiments of the present application:

[0066] Figure 1 An application scenario diagram of the domain name data monitoring method provided in the embodiment of the present application, such as Figure 1 As shown, the domain name data monitoring method provided in the embodiment of the present application runs on an electronic device, specifically, the electronic device can be a server. The target user enters a domain name (Domain Name) through the relevant application or web page of the user terminal. The DNS server or domain name server performs domain name resolution based on the domain name entered by the user, obtains its corresponding IP address, and returns the IP address to the user terminal. The user can then access the relevant web page according to the IP address. Domain name monitoring refers to the monitoring of abnormal domain names or even malicious domain names. It occurs after the user enters the domain name and before accessing the web page according to the IP address. It is executed by the domain name monitoring server to ensure the security of the user's access to the web page.

[0067] The technical solution of the domain name data monitoring method provided in this application mainly includes: performing security monitoring on the domain name entered by the user, storing the monitoring results of the domain name after security monitoring and user information in the blockchain, and then feeding back the latest monitoring results of the domain name to other users who have monitored the same domain name based on the user information stored in the blockchain, so as to ensure that all users are aware of the latest monitoring results, thereby improving the scope of application and reuse rate of monitoring.

[0068] Blockchain is a distributed database with three main characteristics: first, it uses hash algorithms to save data structures, improving data traceability; second, multiple nodes participate in the operation of the system, reflecting the characteristics of distribution and achieving decentralization or weak centralization; third, through certain protocols or algorithms, consensus is reached on the consistency of saved data, which is called a consensus algorithm, effectively preventing the data in the blockchain from being maliciously tampered with.

[0069] Figure 2 A flowchart of a method for monitoring domain name data provided in one embodiment of the present application is shown as follows: Figure 2 As shown, the domain name data monitoring method provided in this embodiment includes the following steps:

[0070] Step S101: obtaining the domain name to be monitored input by the target user and the user information of the target user.

[0071] The target user can be any user. User information includes user identity information, which is information used to identify the user. This information can be a user's registered account or other information. User information can also include information such as the user's network environment and network security level. The domain name to be monitored refers to the domain name that needs to be monitored.

[0072] A domain name is usually the name of a computer or computer group on the Internet, consisting of a string of names separated by dots. Due to the shortcomings of IP addresses, such as being difficult to remember and unable to display the name and nature of the address organization, people designed domain names and used the Domain Name System (DNS) to map domain names and IP addresses to each other, making it easier for people to access the Internet without having to remember the IP address string that can be directly read by machines.

[0073] Step S102: Perform security monitoring on the domain name to be monitored based on a preset monitoring algorithm to obtain a current monitoring result.

[0074] The preset monitoring algorithm may be an algorithm selected by the user from a provided monitoring algorithm list, or may be a user-defined monitoring algorithm. The current monitoring result may include a determination result of whether the domain name to be monitored is safe, and may also include the domain name to be monitored.

[0075] Exemplarily, the preset monitoring algorithm can be an algorithm for analyzing network traffic. By monitoring the network traffic of the domain name to be monitored in real time, the algorithm analyzes its dynamic changes in units of a set step size, sets corresponding traffic increase thresholds for different domain names, and when the increase in network traffic or the rate of increase within the current step size is detected to be greater than the traffic increase threshold, the domain name to be monitored is determined to be an abnormal domain name, that is, its monitoring result (the current monitoring result) is unsafe. The preset monitoring algorithm can also be a monitoring algorithm based on web page content. By running a script associated with the web page of the domain name to be monitored in a preset browser and monitoring various activities during the script execution process, it can be determined whether there is malicious activity. If so, the monitoring result of the domain name to be monitored is determined to be unsafe. The preset monitoring algorithm can also be a monitoring algorithm based on blacklists and whitelists, that is, it determines whether the domain name to be monitored is on a blacklist or whitelist. If it is on the blacklist, its monitoring result is unsafe; if it is on the whitelist, its monitoring result is safe.

[0076] For example, Figure 3 This application Figure 2 A schematic diagram of a preset monitoring algorithm in the embodiment provided is shown in FIG. Figure 3 As shown, the preset monitoring algorithm can also be a monitoring algorithm based on a bipartite graph, including: establishing an unweighted bipartite graph of domain names and IP addresses including the domain name to be monitored; if there is an association between the domain name (such as D1, D2 or D3) and the IP address, connecting the domain name and the IP address with a straight line; and obtaining an unweighted bipartite graph of domain names and IP addresses by counting a large number of domain names and IP addresses; determining the weight values between each domain name in the unweighted bipartite graph based on a weight calculation formula ( Figure 3 The number on the line connecting the two domain names in the figure); define the known abnormal domain names as seeds, and calculate the abnormal coefficient of each domain name based on the seed node (D3); when the abnormal coefficient of the domain name to be monitored is greater than the abnormal threshold, the domain name to be monitored is considered to be an abnormal domain name, and its monitoring result is unsafe. For example, the abnormal threshold can be 0.7,

[0077] Step S103: sending the current monitoring result to the target user according to the user identity information.

[0078] Specifically, after the current monitoring result of the domain name to be monitored is determined, the current monitoring result is returned to the target user or the user terminal of the target user according to the user identity information in the user information, so that the target user can view the monitoring result.

[0079] Step S104: Cache the domain name to be monitored, the current monitoring result, and the user information of the target user into the domain name monitoring blockchain.

[0080] Among them, the domain name monitoring blockchain refers to the blockchain used to store the domain name to be monitored, the current monitoring results and the user information of the target user.

[0081] Specifically, the domain name monitoring blockchain uses a hash algorithm to store the domain name to be monitored, the current monitoring results, and the user information of the target user. Based on the distributed characteristics of the blockchain, decentralization is achieved, the efficiency of data access is improved, and the security and tamper-proofness of data storage are improved.

[0082] The domain name data monitoring method provided in this embodiment performs security monitoring on the domain name entered by the user based on a preset monitoring algorithm, sends the monitoring results to the user, and stores the monitoring results and user information in the blockchain to facilitate the updating of the monitoring results of the domain name. This achieves security monitoring of the domain name and storage of monitoring results, while improving the reuse rate and efficiency of monitoring.

[0083] Figure 4A flowchart of a method for monitoring domain name data provided in another embodiment of the present application is shown as follows: Figure 4 As shown, the domain name data monitoring method provided by this embodiment is Figure 2 Based on the domain name data monitoring method provided in the illustrated embodiment, a step of determining a preset monitoring algorithm is added before step S102, and a step of sending monitoring results of historical users is added after step S104. The domain name data monitoring method provided in this embodiment includes the following steps:

[0084] Step S201: obtaining the domain name to be monitored input by the target user and the user information of the target user.

[0085] The user information includes user identity information and user security level.

[0086] Specifically, the user security level may be set by the user himself or determined based on the domain name to be monitored input by the user and the network environment in which the user is located.

[0087] Step S202: Obtain a monitoring algorithm list, wherein the monitoring algorithm list includes at least two preset monitoring algorithms.

[0088] Optionally, the monitoring algorithm list includes any one of a monitoring algorithm based on network traffic, a monitoring algorithm based on web page content, a monitoring algorithm based on black and white lists, a monitoring algorithm based on domain name data, and a monitoring algorithm based on a bipartite graph, or a fusion algorithm consisting of multiple algorithms.

[0089] Specifically, the fusion algorithm composed of two or more algorithms can be a fusion of the monitoring results of each monitoring algorithm in a weighted manner, or can be a fusion of the algorithms themselves.

[0090] For example, taking a fusion algorithm consisting of a network traffic monitoring algorithm and a bipartite graph monitoring algorithm as an example, when the growth of the network traffic of the domain to be monitored within a set time period meets the network traffic condition, and the abnormal coefficient of the domain to be monitored meets the abnormal coefficient condition, the domain to be monitored is determined to be an abnormal domain, and the current monitoring result is that the domain to be monitored is unsafe. The network traffic condition and the abnormal coefficient condition correspond to each other. For example, when the growth of the network traffic is between a first traffic threshold and a second traffic threshold, and the abnormal coefficient is greater than the first abnormal coefficient threshold, the domain to be monitored is determined to be an abnormal domain, and the current monitoring result is that the domain to be monitored is unsafe; when the growth of the network traffic is between a second traffic threshold and a third traffic threshold, and the abnormal coefficient is between the first abnormal coefficient threshold and the second abnormal coefficient threshold, the domain to be monitored is determined to be an abnormal domain, and the current monitoring result is that the domain to be monitored is unsafe. The first traffic threshold is less than the second traffic threshold, the second traffic threshold is less than the third traffic threshold, and the first abnormal coefficient is greater than the second abnormal coefficient. Of course, the network traffic condition and the abnormal coefficient condition can also take other forms.

[0091] Step S203: determining a preset monitoring algorithm according to the user security level and the monitoring algorithm list.

[0092] Specifically, different user security levels may correspond to different preset monitoring algorithms. The higher the user security level, the higher the accuracy of the corresponding preset monitoring algorithm.

[0093] Furthermore, a correspondence between the user security level and each preset monitoring algorithm in the monitoring algorithm list can be pre-designed, and then a preset monitoring algorithm that meets the user security level can be determined based on the correspondence and the user security level.

[0094] In the steps of this embodiment, by setting multiple monitoring algorithms for users to choose from and determining the corresponding preset monitoring algorithm according to the user's security level, the adaptability of security monitoring is improved, and at the same time, the monitoring results are more in line with user needs.

[0095] Step S204: Perform security monitoring on the domain name to be monitored based on a preset monitoring algorithm to obtain a current monitoring result.

[0096] Step S205: Send the current monitoring result to the target user according to the user identity information.

[0097] Step S206: Cache the domain name to be monitored, the current monitoring result, and the user information of the target user into the blockchain.

[0098] Figure 5 For this application Figure 4 The flowchart of step S206 in the embodiment shown is as follows: Figure 5 As shown, step S206 specifically includes the following steps:

[0099] Step S2061: When the current domain name monitoring node initiates monitoring data caching, the verification results of each domain name monitoring node for the monitoring data cache are obtained.

[0100] The monitoring data includes the domain name to be monitored, the current monitoring result and the user information of the target user.

[0101] Specifically, for the domain name monitoring blockchain, when the current domain name monitoring node needs to cache monitoring data, each node of the domain name monitoring blockchain needs to verify the data caching action, including verifying the monitoring data and verifying whether the current domain name monitoring node has data caching authority.

[0102] Step S2062: The current domain name monitoring node determines whether the monitoring data cache is qualified according to the verification results of the monitoring data cache by each domain name monitoring node.

[0103] Optionally, the current domain name monitoring node determines whether the monitoring data cache is qualified according to verification results of the monitoring data cache by each domain name monitoring node, including:

[0104] The current domain name monitoring node receives the verification results of the monitoring data cache from each domain name monitoring node, wherein the verification results include two types: verification passed and verification failed; and determines whether the monitoring data cache is qualified based on the comparison result of the ratio of verification passed in the verification results and the preset threshold.

[0105] Specifically, the preset threshold may be 0.5, 0.6, 0.7 or other values.

[0106] Step S2063: If qualified, the monitoring data is cached in the domain name monitoring blockchain.

[0107] Among them, the domain name monitoring blockchain includes at least two domain name monitoring nodes, and the above-mentioned current domain name monitoring node is a node in the domain name monitoring blockchain.

[0108] Specifically, caching monitoring data into the domain name monitoring blockchain mainly includes: creating data shards, dividing the monitoring data into smaller fragments to obtain individual data shards; encrypting each data shard; generating a hash value for each data shard; copying each data shard and distributing the copied data shards.

[0109] Step S207: Obtain historical monitoring results of the domain name to be monitored in the domain name monitoring blockchain.

[0110] The historical monitoring results refer to the monitoring results of the domain name to be monitored at historical time nodes.

[0111] Specifically, for the same domain name to be monitored, different users will perform security monitoring at different time nodes, and then obtain monitoring results corresponding to each time node. The historical monitoring results are the monitoring results corresponding to the historical time nodes.

[0112] Step S208: When the historical monitoring result is inconsistent with the current monitoring result, user information of the historical user corresponding to the historical monitoring result is obtained.

[0113] The historical user is a user who performed security monitoring on the domain name to be monitored at a historical node, and the monitoring result at that time is a historical monitoring result.

[0114] Specifically, as time goes by, a domain name that was historically monitored as safe may become an unsafe domain name or an abnormal domain name in the current security monitoring. Therefore, after determining the current monitoring result, it is necessary to obtain the user information or identity information of the historical user who performed security monitoring on the monitored domain name at the historical time node, so as to feedback the latest security monitoring results to the user.

[0115] Step S209: Send the current monitoring result to the historical user according to the user information of the historical user.

[0116] In the steps of this embodiment, by storing the user information of each user and the corresponding monitoring results in the blockchain, and sending the latest monitoring results of the same domain name to be monitored to historical users, so that historical users can also obtain the latest monitoring results of the domain name to be monitored, the reuse rate of the monitoring results and the application scope of monitoring are improved.

[0117] Optionally, after sending the monitoring result to the historical user according to the user information of the historical user, the method further includes:

[0118] The historical monitoring results are updated as current monitoring results.

[0119] In order to avoid repeatedly sending domain name monitoring results to historical users, after the latest monitoring result (current monitoring result) is sent to the historical user, the historical monitoring results of the historical user in the blockchain are updated to the current monitoring result.

[0120] In this embodiment, a preset monitoring algorithm that matches the user's security level is determined, and security monitoring is performed on the domain name to be monitored input by the user based on the preset monitoring algorithm, thereby improving the adaptability and diversity of security monitoring, while also improving the efficiency and accuracy of security monitoring; the monitoring results and user information are stored in the blockchain, laying the foundation for the reuse of subsequent monitoring results; and the latest monitoring results are sent to users who have historically queried the domain name to be monitored to ensure that historical users can also continue to obtain the latest monitoring results, thereby improving the reuse rate and applicability of the monitoring results.

[0121] Figure 6 A schematic diagram of the structure of a domain name data monitoring device provided in one embodiment of the present application is shown as follows: Figure 6 As shown, the domain name data monitoring device provided by this embodiment includes: a domain name acquisition module 610 to be monitored, a domain name monitoring module 620, a monitoring result sending module 630 and a monitoring result storage module 640.

[0122] Among them, the domain name acquisition module 610 to be monitored is used to obtain the domain name to be monitored input by the target user and the user information of the target user, wherein the user information includes user identity information; the domain name monitoring module 620 is used to perform security monitoring on the domain name to be monitored based on a preset monitoring algorithm to obtain the current monitoring result; the monitoring result sending module 630 is used to send the current monitoring result to the target user according to the user identity information; the monitoring result storage module 640 is used to cache the domain name to be monitored, the current monitoring result and the user information of the target user to the domain name monitoring blockchain.

[0123] Optionally, the user information includes a user security level, and the domain name data monitoring device further includes:

[0124] Before performing security monitoring on the domain name to be monitored based on a preset monitoring algorithm, a monitoring algorithm list is obtained, wherein the monitoring algorithm list includes at least two preset monitoring algorithms; and a preset monitoring algorithm is determined according to the user security level and the monitoring algorithm list.

[0125] Optionally, the monitoring algorithm list includes any one of a monitoring algorithm based on network traffic, a monitoring algorithm based on web page content, a monitoring algorithm based on black and white lists, a monitoring algorithm based on domain name data, and a monitoring algorithm based on a bipartite graph, or a fusion algorithm consisting of multiple algorithms.

[0126] Optionally, the domain name data monitoring device further includes:

[0127] A historical monitoring result acquisition module is used to obtain the historical monitoring results of the domain name to be monitored in the domain name monitoring blockchain after caching the domain name to be monitored, the current monitoring results and the user information of the target user in the domain name monitoring blockchain; a historical user information acquisition module is used to obtain the user information of the historical user corresponding to the historical monitoring result when the historical monitoring result is inconsistent with the current monitoring result; a second monitoring result sending module is used to send the current monitoring result to the historical user according to the user information of the historical user.

[0128] Optionally, the domain name data monitoring device further includes:

[0129] The monitoring result updating module is configured to update the historical monitoring result to the current monitoring result after sending the monitoring result to the historical user according to the user information of the historical user.

[0130] Optionally, the monitoring result storage module 640 includes:

[0131] The node verification result acquisition unit is used to obtain the verification results of each domain name monitoring node for the monitoring data cache when the current domain name monitoring node initiates the monitoring data cache, wherein the monitoring data includes the domain name to be monitored, the current monitoring result and the user information of the target user; the cache qualification determination unit is used to determine whether the monitoring data cache is qualified based on the verification results of the monitoring data cache by each domain name monitoring node; the monitoring result storage unit is used to cache the monitoring data into the domain name monitoring blockchain if the monitoring data cache is qualified.

[0132] Optionally, the cache eligibility determination unit is specifically configured to:

[0133] The current domain name monitoring node receives the verification results of the monitoring data cache from each domain name monitoring node, wherein the verification results include two types: verification passed and verification failed; and determines whether the monitoring data cache is qualified based on the comparison result of the ratio of verification passed in the verification results and the preset threshold.

[0134] Figure 7 A schematic diagram of the structure of a domain name data monitoring device provided in another embodiment of the present application is shown as follows: Figure 7 As shown, the domain name data monitoring device includes a domain name security monitoring platform 710, a data exchange platform 720 and a domain name monitoring blockchain 730.

[0135] The user queries data through the domain name security monitoring platform 710, which monitors malicious domain names for the URL (Uniform Resource Locator) or DNS-related information provided by the user. Security monitoring is performed using one or more specific malicious domain name basic monitoring algorithms. The secure query data is encrypted and written to a node on the domain name monitoring blockchain 730 via the data exchange platform 720, where it is stored. Furthermore, user information needs to be saved to facilitate subsequent feedback.

[0136] The data exchange platform 720 is an intermediate "springboard" that facilitates the interaction between the domain name security monitoring platform 710 and the domain name monitoring blockchain 730, thereby writing and querying data. Its functions include analyzing the security of data, writing security monitoring results and user information into the domain name monitoring blockchain 730 as a block through the API (Application Programming Interface), etc.

[0137] Domain Name Monitoring Blockchain 730 maintains the original characteristics and advantages of blockchain, such as the original regulatory mechanism of blockchain to ensure security, and encrypts and decrypts data through smart contracts and consensus algorithms. At the same time, blockchain retains its original data structure for data storage and also supports other applications of ordinary blockchain.

[0138] Specifically, the domain name monitoring blockchain 730 is a storage system composed of multiple technologies such as distributed data storage, smart contracts, peer-to-peer transmission, consensus mechanism, and encryption algorithm.

[0139] The domain name data monitoring device provided in this embodiment can perform the following operations: Figure 2-Figure 5 The technical solution of the method embodiment shown has similar implementation principles and technical effects, which will not be repeated here.

[0140] Figure 8 A schematic diagram of a domain name monitoring server provided in one embodiment of the present application is shown as follows: Figure 8 As shown, the domain name monitoring server provided in this embodiment includes: a memory 810, a processor 820 and a computer program.

[0141] The computer program is stored in the memory 810 and is configured to be executed by the processor 820 to implement the present application. Figure 2-Figure 5 The domain name data monitoring method provided in any one of the corresponding embodiments.

[0142] The memory 810 and the processor 820 are connected via a bus 830 .

[0143] For related instructions, please refer to Figure 2-Figure 5 You can understand the relevant descriptions and effects corresponding to the steps, and will not go into details here.

[0144] One embodiment of the present application provides a computer-readable storage medium having a computer program stored thereon, which is executed by a processor to implement the present application. Figure 2-Figure 5 The domain name data monitoring method provided in any one of the corresponding embodiments.

[0145] The computer-readable storage medium may be a ROM, a random access memory (RAM), a CD-ROM, a magnetic tape, a floppy disk, an optical data storage device, or the like.

[0146] In the several embodiments provided in this application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of modules is only a logical function division. In actual implementation, there may be other division methods, such as multiple modules or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or modules, which can be electrical, mechanical or other forms.

[0147] Those skilled in the art will readily appreciate other embodiments of the present application after considering the specification and practicing the application herein. This application is intended to cover any variations, uses, or adaptations of the present application that follow the general principles of this application and include common knowledge or customary techniques in the art that are not claimed herein. The description and examples are to be considered as exemplary only, and the true scope and spirit of the present application are indicated by the following claims.

[0148] It should be understood that the present application is not limited to the exact structure described above and shown in the drawings, and that various modifications and changes may be made without departing from the scope thereof. The scope of the present application is limited only by the appended claims.

Claims

1. A method for monitoring domain name data, characterized in that: The method comprises: Obtaining the domain name to be monitored input by the target user and the user information of the target user, wherein the user information includes user identity information; Perform security monitoring on the domain name to be monitored based on a preset monitoring algorithm to obtain a current monitoring result; Sending the current monitoring result to the target user according to the user identity information; Cache the domain name to be monitored, the current monitoring results, and the user information of the target user in the domain name monitoring blockchain; Obtaining historical monitoring results of the domain name to be monitored in the domain name monitoring blockchain; When the historical monitoring result is inconsistent with the current monitoring result, obtaining user information of the historical user corresponding to the historical monitoring result; Sending the current monitoring result to the historical user according to the user information of the historical user; Updating the historical monitoring results to current monitoring results; The domain name monitoring blockchain includes at least two domain name monitoring nodes, and caching the domain name to be monitored, the current monitoring result, and the user information of the target user into the domain name monitoring blockchain includes: When the current domain name monitoring node initiates monitoring data caching, it obtains verification results of each domain name monitoring node for the monitoring data cache, wherein the monitoring data includes the domain name to be monitored, the current monitoring result, and the user information of the target user; The current domain name monitoring node determines whether the monitoring data cache is qualified according to the verification results of the monitoring data cache by each domain name monitoring node; If qualified, the monitoring data will be cached in the domain name monitoring blockchain.

2. The method according to claim 1, characterized in that The user information includes a user security level. Before performing security monitoring on the domain name to be monitored based on a preset monitoring algorithm, the method further includes: Obtaining a monitoring algorithm list, wherein the monitoring algorithm list includes at least two preset monitoring algorithms; A preset monitoring algorithm is determined according to the user security level and the monitoring algorithm list.

3. The method according to claim 2, characterized in that The monitoring algorithm list includes any one of the monitoring algorithms based on network traffic, the monitoring algorithm based on web page content, the monitoring algorithm based on blacklist and whitelist, the monitoring algorithm based on domain name data and the monitoring algorithm based on bipartite graph, or a fusion algorithm composed of multiple algorithms.

4. The method according to claim 1, wherein The current domain name monitoring node determines whether the monitoring data cache is qualified according to the verification results of the monitoring data cache by each domain name monitoring node, including: The current domain name monitoring node receives verification results of the monitoring data cache from each domain name monitoring node, wherein the verification results include two types: verification passed and verification failed; Whether the monitoring data cache is qualified is determined based on a comparison result of the ratio of verification passes in the verification result and a preset threshold.

5. A domain name data monitoring device, characterized in that: The device comprises: A domain name acquisition module to be monitored is used to obtain the domain name to be monitored input by the target user and the user information of the target user, wherein the user information includes user identity information; A domain name monitoring module, configured to perform security monitoring on the domain name to be monitored based on a preset monitoring algorithm to obtain a current monitoring result; A monitoring result sending module, configured to send the current monitoring result to the target user according to the user identity information; A monitoring result storage module is used to cache the domain name to be monitored, the current monitoring result, and the user information of the target user to the domain name monitoring blockchain; A historical monitoring result acquisition module is used to obtain the historical monitoring results of the domain name to be monitored in the domain name monitoring blockchain after caching the domain name to be monitored, the current monitoring results and the user information of the target user in the domain name monitoring blockchain; A historical user information acquisition module, configured to acquire user information of historical users corresponding to the historical monitoring results when the historical monitoring results are inconsistent with the current monitoring results; A second monitoring result sending module, configured to send the current monitoring result to the historical user according to the user information of the historical user; A monitoring result updating module, configured to update the historical monitoring result to the current monitoring result after sending the current monitoring result to the historical user according to the user information of the historical user; The domain name monitoring blockchain includes at least two domain name monitoring nodes, and the monitoring result storage module includes: A node verification result acquisition unit is used to obtain the verification results of each domain name monitoring node for the monitoring data cache when the current domain name monitoring node initiates the monitoring data cache, wherein the monitoring data includes the domain name to be monitored, the current monitoring result and the user information of the target user; a cache qualification determination unit, configured for the current domain name monitoring node to determine whether the monitoring data cache is qualified according to the verification results of the monitoring data cache by each domain name monitoring node; The monitoring result storage unit is used to cache the monitoring data in the domain name monitoring blockchain if it is qualified.

6. A domain name monitoring server, characterized in that: include: memory, processors and computer programs; The computer program is stored in the memory and is configured to be executed by the processor to implement the domain name data monitoring method according to any one of claims 1 to 4.

7. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer-executable instructions, which, when executed by a processor, are used to implement the domain name data monitoring method according to any one of claims 1 to 4.

Citation Information

Patent Citations

  • Abnormal domain name monitoring method and device based on block chain

    CN109889619A