Root server resolution anomaly detection method and system based on multi-dimensional attribute statistics

By acquiring diverse heterogeneous data through multidimensional attribute statistics and combining it with SOA information and routing information for anomaly analysis, the accuracy problem of DNS root anomaly resolution detection in existing technologies is solved, and efficient anomaly detection and resolution optimization are achieved.

CN116366307BActive Publication Date: 2025-11-25HARBIN INST OF TECH AT WEIHAI +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310224004.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-03-10
Publication Date
2025-11-25
Estimated Expiration
2043-03-10

AI Technical Summary

Technical Problem

Existing technologies for detecting abnormal DNS root resolutions are limited in method and inaccurate, making it difficult to effectively identify anomalies, especially when logs are incomplete or unreliable, which complicates detection.

Method used

Multidimensional attribute statistics are used to obtain diverse and heterogeneous data, including downloading root zone files, WHOIS data, AXFR queries, and active probing. Combined with SOA information and routing information, anomaly analysis is performed to identify abnormal situations such as deletion, tampering, denial of service, and path hijacking.

Benefits of technology

It achieves accurate detection of abnormal DNS root resolution, obtains correct and complete root-side data, optimizes DNS resolution efficiency, and improves the accuracy and reliability of detection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116366307B_ABST
    Figure CN116366307B_ABST
Patent Text Reader

Abstract

The application provides a root server abnormality detection method and system based on multi-dimensional attribute statistics, and specifically comprises the following contents: S1. A method for acquiring multi-element heterogeneous data; S2. A root side abnormality analysis method, S2.1. Judging whether there is a deletion, tampering, or denial of service event; S2.2. Judging whether there is a root area file synchronization convergence abnormality analysis; S2.3. Judging whether there is path hijacking, and comprehensively realizing path hijacking determination by combining response content features and route hop number comparison. First, the corresponding root side data is acquired, multi-element heterogeneous root domain data is acquired through various means; the collected data is sorted and calculated to identify root server abnormality; and then the detection of DNS root abnormality resolution is accurately completed.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The application belongs to the technical field of DNS root abnormal resolution detection, and particularly relates to a root server abnormal resolution detection method and system based on multi-dimensional attribute statistics. BACKGROUND

[0002] In recent years, the DNS system is constantly updated and improved, and as the top domain in the DNS system, the root domain is particularly important in the DNS resolution process, but at the same time, it is also the first to be exposed to various network attacks. Therefore, how to detect DNS root abnormal resolution has become an important problem for maintaining the DNS system.

[0003] In the past, for the detection of DNS root abnormal resolution, the method of checking DNS query logs is usually used to reveal malicious or abnormal situations. This method needs to access detailed logs, and it takes a long time to analyze. In addition, the logs may be incomplete or unreliable, making it difficult to accurately detect abnormalities. Therefore, it has important research value and practical significance to study a method that can effectively detect root abnormal resolution. SUMMARY

[0004] The application provides a root server abnormal resolution detection method and system based on multi-dimensional attribute statistics to solve the technical problem of single and inaccurate existing DNS root side abnormal detection methods. First, the corresponding root side data is obtained, and multi-dimensional heterogeneous root domain data is obtained through various means. The collected data is sorted and calculated to identify root server abnormal conditions, and then the detection of DNS root abnormal resolution is accurately completed.

[0005] Therefore, the technical scheme of the application is a root server abnormal resolution detection method based on multi-dimensional attribute statistics, which specifically includes the following contents.

[0006] S1. A method for obtaining multi-dimensional heterogeneous data, specifically comprising the following steps:

[0007] S1.1. Requesting to download root zone file data from the WEB server and FTP server provided by the IANA institution;

[0008] S1.2. Requesting to the WHOIS server of IANA to obtain WHOIS data of the top-level domain name, and extracting and collecting NS records and their corresponding A / AAAA records therefrom;

[0009] S1.3. Sending AXFR query requests to the seven root servers with full zone transfer function and the two servers provided by ICANN to obtain root zone file data;

[0010] S1.4, based on the records of all top-level domain names NS obtained in steps S1.1-S1.3, verifying by proportion, taking the majority record value as the reference root area data;

[0011] S1.5, starting from several different geographic locations of detection points, actively requesting NS record data of all top-level domain names from 13 root servers, and recording the answers in the returned content, NSID mirror identification information, TTL information, and return status code information of the root servers; requesting root domain SOA information from the 13 root servers and recording;

[0012] S1.6, starting from several different geographic locations of detection points, and using the method of traceroute to obtain the corresponding routing information from the detection points to the 13 root servers, for path hijacking anomaly verification;

[0013] S2. The method for root side anomaly analysis, the specific steps are as follows:

[0014] S2.1, according to the SOA information in S1.5, judging whether there is a deletion, tampering, or denial of service event;

[0015] S2.2, according to the SOA information in S1.5, judging whether there is a root area file synchronization convergence anomaly analysis;

[0016] S2.3, according to the NS record data in S1.5 and the routing information in S1.6, judging whether there is path hijacking, combining the response content characteristics and the number of routing hops for comprehensive path hijacking determination.

[0017] Preferably, the method for judging whether there is a deletion, tampering, or denial of service event is to compare each top-level domain name data actively detected in step S1.5 of the multi-element heterogeneous data acquisition method with the information of the reference root area file data obtained in step S1.4, and combine the return status code of each data to analyze whether the NS and A, AAAA of the top-level domain name have denial of service, tampering, or deletion anomaly events.

[0018] Preferably, the method for judging whether there is a root area file synchronization convergence anomaly analysis is to first take the latest root area file dynamically acquired in real time as the reference root area data; then use the SOA record requested by each detection point to the 13 root servers in step S1.5 of the multi-element heterogeneous data acquisition method to obtain the root area file information maintained by the current root mirror server; by comparing whether the serial numbers of the two root area files are consistent, to judge whether the root area file currently operated by the root mirror exists synchronization convergence anomaly.

[0019] Preferably, the determination rule for determining whether there is a root zone file synchronization convergence anomaly analysis is that when the return result is NOERROR, and not empty, and not completely consistent with the root zone file content, it is determined that tampering has occurred; when the return result is NOERROR, and empty or the return result is NXDOMAIN, it is determined that deletion has occurred, and when the return time or other status code is returned, it is determined that access is denied.

[0020] Preferably, the method for determining whether there is path hijacking is to parse the NS record data of each root server obtained in step S1.5 of the multi-heterogeneous data acquisition method as follows:

[0021] S2.3.1 determine whether the NSID value of each record is empty and the TTL value is 172800, if the NSID mirror identifier is not empty and the TTL value in the NS record is 172800, the root server is normally parsed;

[0022] S2.3.2 if the NSID mirror identifier is empty and the TTL value in the NS record is not 172800, continue to determine whether the current hop count is less than the actual routing hop count (obtained in step S1.6 of the multi-heterogeneous data acquisition method), if it is less, path hijacking has occurred, otherwise it belongs to normal root server parsing.

[0023] A root server parsing anomaly detection system based on multi-dimensional attribute statistics, comprising a multi-heterogeneous data acquisition module, an IANA Root Zone Database module, an AXFR data transmission module, a multi-source top-level domain name resolution record active detection module, a parsing path acquisition module, a root-side anomaly analysis module, a deletion, tampering, denial of service event determination module, a root zone file synchronization convergence anomaly analysis module, a path hijacking determination module, and a root-side anomaly parsing classification data module.

[0024] Preferably, the multi-heterogeneous data acquisition module establishes a high-confidence data set and integrates data from different sources; it includes the IANA Root Zone Database module, the AXFR data transmission module, the multi-source top-level domain name resolution record active detection module, and the parsing path acquisition module;

[0025] The IANA Root Zone Database module collects root zone file data provided by the IANA organization, and obtains WHOIS information of top-level domain names provided by the IANA organization;

[0026] The AXFR data transmission module collects root zone files of servers supporting root full zone transfer function through AXFR request;

[0027] The multi-source top-level domain name resolution record active detection module collects NS records, root domain SOA records and root server attributes and the like data of each top-level domain name obtained by actively requesting the root server from a plurality of detection points in different geographical positions, and simultaneously opens the NSID option in the EDNS in the request message to obtain the root server mirror identification;

[0028] The resolution path acquisition module collects resolution path information data of the detection points in different geographical positions to the 13 root servers;

[0029] The root-side anomaly analysis module analyzes the data obtained by the multi-element heterogeneous data acquisition module to determine whether a root-side anomaly occurs, including a deletion, tampering and denial of service event determination module, a root zone file synchronization convergence anomaly analysis module and a path hijacking determination module;

[0030] The deletion, tampering and denial of service event determination module analyzes whether abnormal events such as tampering, deletion and denial of service occur in the request and answer of each root server to the top-level domain name;

[0031] The root zone file synchronization convergence anomaly analysis module determines whether there is a synchronization convergence anomaly in the root zone file currently operated by the root mirror;

[0032] The path hijacking determination module determines whether there is path hijacking in the communication process of the detection point and the root server;

[0033] The root-side anomaly resolution classification data module collects various abnormal resolution data verified by the anomaly determination module.

[0034] The method and system first acquire corresponding root-side data, acquire multi-element heterogeneous root domain data through a plurality of means, such as downloading the IANA root zone database, full area transmission (AXFR) of the root domain zone file and active detection and the like; through arrangement and calculation of the collected data, root server abnormal conditions such as deletion, tampering, denial, root domain file synchronization anomaly and path hijacking are recognized; and then accurate detection of DNS root abnormal resolution is completed.

[0035] The method and system can be used to acquire correct and complete root-side data, and can also accurately complete root-side resolution anomaly detection, and in addition, help to optimize the efficiency of related DNS resolution. BRIEF DESCRIPTION OF DRAWINGS

[0036] Fig. 1 is a schematic diagram of root-side data acquisition and anomaly analysis of the application;

[0037] Fig. 2 is a path hijacking determination flowchart. DETAILED DESCRIPTION

[0038] The application will be further described in connection with the embodiments.

[0039] Figs. 1-2 is an embodiment of a root server abnormality detection method and system based on multi-dimensional attribute statistics. First, the corresponding root side data is obtained, and multi-dimensional heterogeneous root domain data is obtained through various means, such as downloading the IANA root zone database, the full zone transfer (AXFR) of the root domain zone file, and active detection; through the arrangement and calculation of the collected data, the root server abnormality conditions are identified, such as deletion, tampering, rejection, root domain file synchronization abnormality, and path hijacking; and then the detection of the DNS root abnormality resolution is accurately completed.

[0040] A root server abnormality detection method based on multi-dimensional attribute statistics, specifically including the following contents:

[0041] S1. A method for obtaining multi-dimensional heterogeneous data, specifically including the following steps:

[0042] S1.1. Requesting to download root zone file data through the WEB server and FTP server provided by the IANA institution. Request address: https: / / www.internic.net / domain / root.zone, ftp: / / rs.internic.net / domain / root.zone.

[0043] S1.2. Requesting to the WHOIS server (whois.iana.org) of the IANA to obtain the WHOIS data of the top-level domain name, extracting and collecting the NS record and the corresponding A / AAAA record therefrom;

[0044] S1.3. Sending AXFR query requests to the seven root servers (root servers: B / C / D / E / F / G / K) with full zone transfer function and the two servers (lax.xfr.dns.icann.org, iad.xfr.dns.icann.org) provided by the ICANN to obtain root zone file data;

[0045] S1.4. Based on all the NS records of the top-level domain name obtained in steps S1.1-S1.3, taking the majority record value as the reference root zone data through proportion verification.

[0046] S1.5. Starting from several different geographical positions of detection points, actively requesting the NS record data of all top-level domain names from the thirteen root servers, and recording the answer in the returned content of the root server, the NSID mirror identification information, TTL information, and returned status code of the root server; in addition, the root domain SOA information is requested from the thirteen root servers and recorded;

[0047] S1.6 Starting from several different geographical locations of the detection points, and using the method of traceroute to obtain the routing information from the detection points to the corresponding 13 root servers, for path hijacking anomaly verification.

[0048] S2. The method for root-side anomaly analysis, the specific steps are as follows:

[0049] S2.1 Determine whether there is a deletion, tampering, denial of service event. Compare each top-level domain name data obtained by active detection in step S1.5 of the method for obtaining multi-element heterogeneous data with the information of the reference root zone file data obtained in step S1.4, and combine the return status code of each piece of data to analyze whether the NS and A, AAAA of the top-level domain name have denial of service, tampering, deletion anomaly events.

[0050] The determination rules are shown in Table 1, wherein when the return result is NOERROR, and not empty, and not completely consistent with the root zone file content, it is judged that tampering has occurred; when the return result is NOERROR, and empty or the return result is NXDOMAIN, it is judged that deletion has occurred, and when the return time or other status code is returned, it is judged that access is denied.

[0051] Table 1 Root anomaly event determination rule table

[0052]

[0053] S2.2 Determine whether there is a root zone file synchronization convergence anomaly analysis. First, obtain the latest root zone file as reference data (IANA Root Zone Database) in real time; then obtain the SOA record requested by each detection point to the 13 root servers in step S1.5 of the method for obtaining multi-element heterogeneous data to obtain the root zone file information maintained by the current root mirror server. By comparing whether the serial numbers of the two root zone files are consistent, it is determined whether the root zone file currently operated by the root mirror exists synchronization convergence anomaly.

[0054] S2.3 Determine whether there is path hijacking, and combine the response content characteristics and the number of routing hops to comprehensively realize path hijacking determination.

[0055] As shown in Fig. 2 , the method for determining whether there is path hijacking is to judge the NS record data of each root server obtained in step S1.5 of the method for obtaining multi-element heterogeneous data according to the following flow:

[0056] S2.3.1 judging whether the NSID value of each record is empty and the TTL value is 172800, if the NSID mirror identifier is not empty and the TTL value in the NS record is 172800, the root server is normally resolved;

[0057] S2.3.2 if the NSID mirror identifier is empty and the TTL value in the NS record is not 172800, continue to judge whether the current hop count is less than the actual routing hop count (obtained in step S1.6 of the method for acquiring multi-element heterogeneous data), if less, path hijacking occurs, otherwise it belongs to normal resolution of the root server.

[0058] A root server abnormal resolution detection system based on multi-dimensional attribute statistics, comprising a multi-element heterogeneous data acquisition module, an IANA Root Zone Database module, an AXFR data transmission module, a multi-source top-level domain name resolution record active detection module, a resolution path acquisition module, a root-side anomaly analysis module, a deletion, tampering and denial of service event judgment module, a root zone file synchronization convergence anomaly analysis module, a path hijacking judgment module, and a root-side anomaly resolution classification data module.

[0059] The multi-element heterogeneous data acquisition module establishes a high-credibility data set and integrates data from different sources. It includes the IANA Root Zone Database module, the AXFR data transmission module, the multi-source top-level domain name resolution record active detection module, and the resolution path acquisition module;

[0060] The IANA Root Zone Database module collects root zone file data provided by the IANA institution and obtains WHOIS information of top-level domain names provided by the IANA institution;

[0061] The AXFR data transmission module collects root zone files of servers supporting root full zone transfer function through AXFR request;

[0062] The multi-source top-level domain name resolution record active detection module collects NS records, root domain SOA records, and root server attributes of each top-level domain name obtained by actively requesting root servers from several detection points in different geographic locations. At the same time, the NSID option in the EDNS is enabled in the request message to obtain the root server mirror identifier;

[0063] The resolution path acquisition module collects resolution path information data of the detection points in different geographic locations to the 13 root servers;

[0064] The root side anomaly analysis module analyzes the data obtained by the multi-element heterogeneous data acquisition module to determine whether a root side anomaly occurs, and includes a deletion, tampering, denial of service event determination module, a root area file synchronization convergence anomaly analysis module, and a path hijacking determination module.

[0065] The deletion, tampering, denial of service event determination module analyzes whether the request and response of each root server to the top-level domain name has an abnormal event of tampering, deletion, or denial of service.

[0066] The root area file synchronization convergence anomaly analysis module determines whether the root mirror currently operating the root area file has a synchronization convergence anomaly.

[0067] The path hijacking determination module determines whether there is path hijacking in the communication process between the detection point and the root server.

[0068] The root side anomaly analysis module analyzes the data obtained by the multi-element heterogeneous data acquisition module to determine whether a root side anomaly occurs, and includes a deletion, tampering, denial of service event determination module, a root area file synchronization convergence anomaly analysis module, and a path hijacking determination module.

[0069] The above is only a specific embodiment of the present application, which cannot limit the scope of the present application. Therefore, the replacement of equivalent components or equivalent changes and modifications made within the scope of the present application should still fall within the scope of the present application.

Claims

1. A root server parsing anomaly detection method based on multidimensional attribute statistics, characterized in that, Specifically, it includes the following: S1. The method for obtaining multivariate heterogeneous data, the specific steps are as follows: S1.1 requests the download of root zone file data from the web server and FTP server provided by IANA. S1.2 requests WHOIS data of the top-level domain from IANA's WHOIS server, and extracts and collects NS records and their corresponding A / AAAA records from them. S1.3 Sends AXFR query requests to the seven root servers with full zone transfer capabilities and two servers provided by ICANN to obtain root zone file data; S1.4 Based on all the records of the top-level domain NS obtained in steps S1.1-S1.3, the majority of the record values ​​are taken as the baseline root zone data through proportional verification. S1.5 starts from several probe points in different geographical locations, actively requests NS record data for all top-level domains from 13 root servers, and records the responses in the content returned by the root servers, as well as the NSID mirror identifier information, TTL information, and return status code information of the root servers; it also requests and records the root domain SOA information from the 13 root servers. S1.6 starts from several probe points in different geographical locations and uses the traceroute method to obtain the corresponding routing information from the probe points to 13 root servers for path hijacking anomaly verification. S2. The method for root lateral anomaly analysis, the specific steps are as follows: S2.1 Based on the SOA information in S1.5, determine whether there are any deletion, tampering, or denial-of-service events; S2.2 Based on the SOA information in S1.5, determine whether there is an anomaly analysis for root region file synchronization convergence; S2.3 determines whether path hijacking exists based on the NS record data in S1.5 and the routing information in S1.

6. It combines the characteristics of the response content with the comparison of the route hop count to comprehensively determine path hijacking.

2. The root server parsing anomaly detection method based on multidimensional attribute statistics according to claim 1, characterized in that, The method for determining whether deletion, tampering, or denial-of-service events exist in step S2.1 is to compare each top-level domain data actively probed in step S1.5 of the method for obtaining multi-dimensional heterogeneous data with the information of the baseline root zone file data obtained in step S1.4, and combine the return status code of each data to analyze whether denial-of-service, tampering, or deletion anomaly events have occurred in the NS, A, and AAAA of the top-level domain.

3. The root server parsing anomaly detection method based on multidimensional attribute statistics according to claim 1, characterized in that, The method for determining whether there is a synchronization convergence anomaly in the root zone file in step S2.2 is as follows: First, the latest root zone file obtained dynamically in real time is used as the baseline root zone data; then, the SOA records requested by each probe point from the 13 root servers in step S1.5 of the method for obtaining multivariate heterogeneous data are used to obtain the root zone file information maintained by the current root image server; by comparing whether the sequence numbers of the two root zone files are consistent, it is determined whether there is a synchronization convergence anomaly in the root zone file currently maintained by the root image.

4. The root server parsing anomaly detection method based on multidimensional attribute statistics according to claim 1, characterized in that, The judgment rule for determining whether there is a root zone file synchronization convergence anomaly analysis in step S2.2 is as follows: when the returned result is NOERROR, and is not empty, and is not completely consistent with the content of the root zone file, it is judged that tampering has occurred; when the returned result is NOERROR, and is empty, or the returned result is NXDOMAIN, it is judged that deletion has occurred; when a timeout or other status code is returned, it is judged that access is denied.

5. The root server parsing anomaly detection method based on multidimensional attribute statistics according to claim 1, characterized in that, The method for determining whether path hijacking exists in step S2.3 is to perform the following process on each root server parsed NS record data obtained in step S1.5 of the method for obtaining heterogeneous data: S2.3.1 Determine whether the NSID value of each record is empty and whether the TTL value is 172800. If the NSID mirror identifier is not empty and the TTL value in the NS record is 172800, then the root server resolves normally. S2.3.2 If the NSID mirror identifier is empty and the TTL value in the NS record is not 172800, then continue to determine whether the current hop count is less than the actual route hop count (obtained in step S1.6 of the method for obtaining multi-variable heterogeneous data). If it is less, then path hijacking has occurred; otherwise, it is normal resolution by the root server.

6. A root server parsing anomaly detection system based on multidimensional attribute statistics, characterized in that, The method for detecting root server resolution anomalies based on multidimensional attribute statistics as described in any one of claims 1-5 includes a multi-dimensional heterogeneous data acquisition module, an IANA Root Zone Database module, an AXFR data transmission module, a multi-source top-level domain name resolution record active detection module, a resolution path acquisition module, a root-side anomaly analysis module, a deletion, tampering, and denial-of-service event determination module, a root zone file synchronization convergence anomaly analysis module, a path hijacking determination module, and a root-side anomaly resolution classification data module.

7. A root server parsing anomaly detection system based on multidimensional attribute statistics according to claim 6, characterized in that, The multi-source heterogeneous data acquisition module establishes a highly reliable dataset and integrates data from different sources; it comprises four parts: an IANA Root Zone Database module, an AXFR data transmission module, a multi-source top-level domain name resolution record active detection module, and a resolution path acquisition module. The IANA Root Zone Database module collects root zone file data provided by IANA and obtains WHOIS information of top-level domains provided by IANA. The AXFR data transmission module collects the root zone files of servers that support the root full zone transfer function through AXFR requests; The multi-source top-level domain name resolution record active detection module collects data such as NS records, root domain SOA records and root server attributes of each top-level domain name obtained by actively requesting the root server from several detection points in different geographical locations. At the same time, it enables the NSID option in EDNS in the request message to obtain the root server mirror identifier. The path resolution acquisition module collects path resolution information data from probe points in different geographical locations to 13 root servers; The root-side anomaly analysis module analyzes the data acquired by the multi-dimensional heterogeneous data acquisition module to determine whether a root-side anomaly has occurred. It includes three parts: a deletion, tampering, and denial-of-service event determination module, a root zone file synchronization convergence anomaly analysis module, and a path hijacking determination module. The deletion, tampering, and denial-of-service event determination module analyzes whether any abnormal events such as tampering, deletion, or denial-of-service occur in the requests and responses of each root server to the top-level domain. The root zone file synchronization convergence anomaly analysis module determines whether there is a synchronization convergence anomaly in the root zone file currently being maintained by the root image. The path hijacking determination module determines whether path hijacking occurs during the communication process between the probe point and the root server. The root-side anomaly analysis and classification data module collects various anomaly analysis data verified by the anomaly determination module.

Citation Information

Patent Citations

  • Top level domain name configuration and security analysis method based on domain resource record

    CN107819895A

  • Root zone record monitoring method, system and device and readable storage medium

    CN115695275A