Domain name detection methods, devices, equipment and storage media

By collecting and analyzing feature data from the Domain Name System logs, and combining IP address lifecycle, domain name quantity, and anomaly ratio, rapidly changing domain names can be accurately identified, solving the problem of low identification accuracy in existing technologies and improving network security.

CN116389112BActive Publication Date: 2026-07-17INDUSTRIAL AND COMMERCIAL BANK OF CHINA

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
INDUSTRIAL AND COMMERCIAL BANK OF CHINA
Filing Date
2023-04-04
Publication Date
2026-07-17

AI Technical Summary

Technical Problem

Existing technologies cannot accurately identify rapidly changing domain names, leading to attacks on user networks and resulting in low identification accuracy.

Method used

By collecting characteristic data from the Domain Name System logs, including the lifecycle of IP addresses, domain name sets, and IP address sets, the proportion of abnormal domain names and abnormal IP addresses is analyzed, and the rapidly changing domain names are identified by combining characteristic data from multiple dimensions.

Benefits of technology

It improves the accuracy of identifying rapidly changing domain names, effectively defends against attacks, and enhances network security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116389112B_ABST
    Figure CN116389112B_ABST
Patent Text Reader

Abstract

This disclosure provides a domain name detection method, apparatus, device, and storage medium, which can be applied to the fields of information security technology or fintech. The method includes: collecting Domain Name System (DNS) logs from a DNS router, wherein the DNS logs are used to store domain names and IP addresses; extracting feature data from the DNS logs, wherein the feature data includes at least the lifecycle of IP addresses, a set of domain names to be analyzed, and a set of IP addresses corresponding to the set of domain names, and all domain names in the set are correlated; processing the feature data to obtain the proportion of abnormal domain names in the set of domain names and the proportion of abnormal IP addresses in the set of IP addresses; and identifying all domain names in the set of domain names as rapidly changing domain names if the lifecycle of IP addresses, the number of domain names in the set of domain names, the proportion of abnormal domain names, and the proportion of abnormal IP addresses all match the abnormal domain name conditions.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to the fields of information security technology or financial technology, and in particular to a domain name detection method, apparatus, device, medium, and program product. Background Technology

[0002] Fast-Flux Service Network (FFSN) attacks are a type of attack. In developing the present invention, the inventors discovered that related technologies generally suffer from the following problems: Fast-Flux domains, by frequently changing their IP addresses, can confuse the user's network, and existing technologies cannot accurately identify them, thus allowing the user's network to be attacked and implanted with malicious programs. Therefore, existing technologies suffer from low accuracy in identifying fast-Flux domains. Summary of the Invention

[0003] In view of the above issues, this disclosure provides domain name methods, apparatus, devices, storage media, and program products.

[0004] One aspect of this disclosure provides a domain name detection method, comprising: collecting domain name system logs from a domain name system router, wherein the domain name system logs are used to store domain names and IP addresses; extracting feature data from the domain name system logs, wherein the feature data includes at least the lifecycle of the IP address, a set of domain names to be analyzed, and a set of IP addresses corresponding to the set of domain names, wherein each domain name in the set of domain names is correlated; processing the feature data to obtain the proportion of abnormal domain names in the set of domain names and the proportion of abnormal IP addresses in the set of IP addresses; and, if the lifecycle of the IP address, the number of domain names in the set of domain names, the proportion of abnormal domain names, and the proportion of abnormal IP addresses all match the domain name abnormality condition, identifying all domain names in the set of domain names as rapidly changing domain names.

[0005] According to an embodiment of this disclosure, the abnormal domain name is determined as follows: for each domain name in the domain name set: the domain name is split into multiple subdomains with location identifiers; in the domain name set, all subdomains with the same location identifier are searched to obtain a subdomain list; an abnormal subdomain is found from the subdomain list, wherein the name of the abnormal subdomain is different from the names of the other subdomains in the subdomain list; based on the abnormal subdomain, the abnormal domain name is determined from the domain name set.

[0006] According to an embodiment of this disclosure, the abnormal IP address is determined as follows: each IP address in the IP address set is converted to a different number system; a preset number of digit strings are extracted from the multiple addresses obtained by the number system conversion to obtain a list of digit strings; an abnormal digit string is found from the list of digit strings, wherein the digits contained in the abnormal digit string are different from the digits contained in the other digit strings in the list of digit strings; and the abnormal IP address is located from the IP address set based on the abnormal digit string.

[0007] According to embodiments of this disclosure, the domain name anomaly conditions are constructed from multiple anomaly thresholds; determining all domain names in the domain name set as fast-changing domain names when the lifecycle of the IP address, the number of domain names in the domain name set, the proportion of abnormal domain names, and the proportion of abnormal IP addresses all match the domain name anomaly conditions includes: comparing the lifecycle of the IP address, the number of domain names, the proportion of abnormal domain names, and the proportion of abnormal IP addresses with the anomaly thresholds respectively; and determining all domain names in the domain name set as fast-changing domain names when the lifecycle of the IP address, the number of domain names, the proportion of abnormal domain names, and the proportion of abnormal IP addresses are all within the range of the anomaly thresholds.

[0008] According to embodiments of this disclosure, the method further includes: blocking the aforementioned fast-changing domain name; and recording the blocked fast-changing domain name and its abnormal characteristic data into a blocking database.

[0009] According to embodiments of this disclosure, the method further includes: comparing the feature data with the abnormal feature data in the blocking database before processing the feature data; and directly blocking all domains in the domain set if the feature data matches the abnormal feature data.

[0010] According to embodiments of this disclosure, the above-mentioned abnormal threshold includes at least one of the following: lifecycle threshold, related domain name quantity threshold, abnormal domain name ratio threshold, and abnormal IP address ratio threshold.

[0011] Another aspect of this disclosure provides a domain name detection device, comprising: a collection module for collecting domain name system logs from a domain name system router, wherein the domain name system logs are used to store domain names and IP addresses; an extraction module for extracting feature data from the domain name system logs, wherein the feature data includes at least the lifecycle of the IP address, a set of domain names to be analyzed, and a set of IP addresses corresponding to the set of domain names, wherein each domain name in the set of domain names is correlated; a processing module for processing the feature data to obtain the proportion of abnormal domain names in the set of domain names and the proportion of abnormal IP addresses in the set of IP addresses; and a first determination module for determining all domain names in the set of domain names as rapidly changing domain names when the lifecycle of the IP address, the number of domain names in the set of domain names, the proportion of abnormal domain names, and the proportion of abnormal IP addresses all meet the domain name abnormality condition.

[0012] Another aspect of this disclosure provides an electronic device, including: one or more processors; and a storage device for storing one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors perform the domain name detection method described above.

[0013] Another aspect of this disclosure provides a computer-readable storage medium having executable instructions stored thereon, which, when executed by a processor, cause the processor to perform the aforementioned domain name detection method.

[0014] Another aspect of this disclosure provides a computer program product, including a computer program that, when executed by a processor, implements the aforementioned domain name detection method.

[0015] According to the domain name detection method provided in this disclosure, domain name system logs are collected; feature data is extracted from the domain name system logs and analyzed to obtain the lifecycle of IP addresses, the number of related domain names, the proportion of abnormal domain names, and the proportion of abnormal IP addresses; when all of the above data meet the abnormal conditions, all related domain names in the domain name set are identified as fast-changing domain names. Because the domain detection process combines multiple dimensions of features such as the lifecycle of IP addresses, the number of related domain names, the proportion of abnormal domain names, and the proportion of abnormal IP addresses, and determines fast-changing domain names only when these features simultaneously meet the abnormal conditions, it at least partially overcomes the problem of inaccurate identification of fast-changing domain names in related technologies, thereby achieving the technical effect of improving the accuracy of fast-changing domain name identification. Attached Figure Description

[0016] The foregoing contents, as well as other objects, features, and advantages of this disclosure, will become clearer from the following description of embodiments with reference to the accompanying drawings, in which:

[0017] Figure 1 This diagram illustrates an application scenario of the domain name detection method and apparatus according to embodiments of the present disclosure.

[0018] Figure 2 A flowchart illustrating a domain name detection method according to an embodiment of the present disclosure is shown schematically.

[0019] Figure 3 This diagram schematically illustrates the relationship between domain names and IP addresses according to embodiments of the present disclosure.

[0020] Figure 4 A flowchart illustrating a domain name detection method according to another embodiment of this disclosure is shown schematically;

[0021] Figure 5 A schematic block diagram of a domain name detection apparatus according to an embodiment of the present disclosure is shown; and

[0022] Figure 6 A block diagram schematically illustrates an electronic device suitable for implementing a domain name detection method according to an embodiment of the present disclosure. Detailed Implementation

[0023] The embodiments of the present disclosure will now be described with reference to the accompanying drawings. However, it should be understood that these descriptions are exemplary only and are not intended to limit the scope of the disclosure. In the following detailed description, numerous specific details are set forth to provide a thorough understanding of the embodiments of the present disclosure for ease of explanation. However, it will be apparent that one or more embodiments may be practiced without these specific details. Furthermore, descriptions of well-known structures and techniques are omitted in the following description to avoid unnecessarily obscuring the concepts of the present disclosure.

[0024] The terminology used herein is for the purpose of describing particular embodiments only and is not intended to limit this disclosure. The terms “comprising,” “including,” etc., as used herein indicate the presence of the stated features, steps, operations, and / or components, but do not exclude the presence or addition of one or more other features, steps, operations, or components.

[0025] All terms used herein (including technical and scientific terms) have the meanings commonly understood by those skilled in the art, unless otherwise defined. It should be noted that the terms used herein are to be interpreted in a manner consistent with the context of this specification, and not in an idealized or overly rigid way.

[0026] When using expressions such as "at least one of A, B, and C", they should generally be interpreted in accordance with the meaning that is commonly understood by a person skilled in the art (e.g., "a system having at least one of A, B, and C" should include, but is not limited to, a system having A alone, a system having B alone, a system having C alone, a system having A and B, a system having A and C, a system having B and C, and / or a system having A, B, and C, etc.).

[0027] The working principle of a rapid domain name change attack is to continuously update the IP address corresponding to the domain name at regular time intervals. By repeatedly and rapidly changing the IP address, malicious servers can be hidden. The typical attack process of a rapidly changing domain name is as follows: A user visits the domain name "www.abc.com" and sends an IP address query request to the DNS server. The DNS server recursively and iteratively obtains the IP address of the domain name www.abc.com as 1.1.1.1 and returns this IP address to the user. The user obtains the IP address 1.1.1.1 and directly accesses it. Since the domain name can be created by the attacker, the attacker will set the time-to-live (TTL) of caching this IP address on the user's computer to a very short time, such as 1 second. When the user needs to access the domain name www.abc.com again, because the TTL of the IP address cached on the user's computer is very short, the IP address has expired, forcing the user to send another IP address query request to the DNS server. When the user sends another IP address query request, the IP address corresponding to the domain name www.abc.com has been changed by the attacker to an IP address 2.2.2.2 containing malicious programs. When the user accesses IP address 2.2.2.2, the user's computer will be infected with Trojans, worms, or other malicious programs, allowing the attacker to achieve their attack objectives.

[0028] In view of this, embodiments of this disclosure provide a domain name detection method, apparatus, device, storage medium, and program product for accurately identifying attacks involving rapidly changing domain names. Specifically, the method may include collecting Domain Name System (DNS) logs from a DNS router, wherein the DNS logs are used to store domain names and IP addresses; extracting feature data from the DNS logs, wherein the feature data includes at least the lifecycle of IP addresses, a set of domain names to be analyzed, and a set of IP addresses corresponding to the set of domain names, and all domain names in the set are correlated; processing the feature data to obtain the proportion of abnormal domain names in the set of domain names and the proportion of abnormal IP addresses in the set of IP addresses; and determining all domain names in the set of domain names as rapidly changing domain names if the lifecycle of IP addresses, the number of domain names in the set of domain names, the proportion of abnormal domain names, and the proportion of abnormal IP addresses all match the abnormal domain name conditions.

[0029] It should be noted that the domain name detection method and apparatus determined in this disclosure can be used in the field of information security technology or fintech, or in any field other than information security technology or fintech. This disclosure does not limit the application field of the determined domain name detection method and apparatus.

[0030] In the technical solutions disclosed herein, the collection, storage, use, processing, transmission, provision, disclosure, and application of data (including but not limited to user personal information) comply with the provisions of relevant laws and regulations, necessary confidentiality measures have been taken, and they do not violate public order and good morals.

[0031] Figure 1 The illustration shows an application scenario of the domain name detection method and apparatus according to embodiments of the present disclosure.

[0032] like Figure 1 As shown, application scenario 100 according to this embodiment may include a first detection device 101, a second detection device 102, a third detection device 103, a domain name system 104, a server 105, and a network 106. The network 106 serves as a medium for providing communication links between the first terminal device 101, the second terminal device 102, the third terminal device 103, and the domain name system 104, as well as between the domain name system 104 and the server 105. The network 104 may include various connection types, such as wired or wireless communication links, or fiber optic cables, etc.

[0033] Users can use at least one of the first terminal device 101, the second terminal device 102, and the third terminal device 103 to interact with the Domain Name System 104 via the network 106 to receive or send IP address query requests, etc. Various communication client applications requiring information security protection can be installed on the first terminal device 101, the second terminal device 102, and the third terminal device 103, such as financial applications, shopping applications, web browser applications, search applications, instant messaging tools, email clients, social media platform software, etc. (this is just an example).

[0034] The first terminal device 101, the second terminal device 102, and the third terminal device 103 can be various electronic devices with displays and support web browsing, including but not limited to smartphones, tablets, laptops, and desktop computers.

[0035] Domain Name System 104 is used to transmit the IP address query request sent by the terminal device to the server 105, and to return the IP address queried by the server 105 to the terminal device.

[0036] Server 105 can be a server providing various services, utilizing a backend management server (for example only) that supports IP address query requests. The backend management server can analyze and process received requests and other data, and feed back the processing results (such as IP addresses, web pages, information, or data obtained or generated based on the request) to the terminal device. Specifically, server 105 can collect Domain Name System (DNS) logs from a DNS router, where the DNS logs store domain names and IP addresses; extract feature data from the DNS logs, where the feature data includes at least the lifecycle of IP addresses, the set of domain names to be analyzed, and the set of IP addresses corresponding to the set of domain names, with each domain name in the set being correlated; process the feature data to obtain the proportion of abnormal domain names in the domain name set and the proportion of abnormal IP addresses in the IP address set; if the lifecycle of IP addresses, the number of domain names in the domain name set, the proportion of abnormal domain names, and the proportion of abnormal IP addresses all match the abnormal domain name conditions, then all domain names in the domain name set are identified as fast-changing domain names.

[0037] It should be noted that the domain name detection method provided in this disclosure embodiment can generally be executed by server 105. Correspondingly, the domain name detection device provided in this disclosure embodiment can generally be located in server 105. The domain name detection method provided in this disclosure embodiment can also be executed by a server or server cluster that is different from server 105 and capable of communicating with the first terminal device 101, the second terminal device 102, the third terminal device 103, and / or server 105. Correspondingly, the domain name detection device provided in this disclosure embodiment can also be located in a server or server cluster that is different from server 105 and capable of communicating with the first terminal device 101, the second terminal device 102, the third terminal device 103, and / or server 105.

[0038] It should be understood that Figure 1 The number of terminal devices, domain name systems, networks, and servers shown is merely illustrative. Depending on implementation needs, any number of terminal devices, domain name systems, networks, and servers can be included.

[0039] The following will be based on Figure 1 The described scene, through Figures 2-4 The domain name detection method of the disclosed embodiments is described in detail.

[0040] Figure 2 A flowchart illustrating a domain name detection method according to an embodiment of the present disclosure is shown schematically.

[0041] like Figure 2 As shown, the domain name detection method in this embodiment includes operations S201 to S204.

[0042] In operation S201, Domain Name System (DNS) logs are collected from the DNS router. The DNS logs are used to store domain names and IP addresses.

[0043] In operation S202, feature data is extracted from the Domain Name System log. The feature data includes at least the lifecycle of the IP address, the set of domain names to be analyzed, and the set of IP addresses corresponding to the set of domain names. All domain names in the set of domain names are related to each other.

[0044] In operation S203, the feature data is processed to obtain the proportion of abnormal domain names in the domain name set and the proportion of abnormal IP addresses in the IP address set.

[0045] In operation S204, if the IP address's lifecycle, the number of domains in the domain name set, the proportion of abnormal domain names, and the proportion of abnormal IP addresses all meet the abnormal domain name conditions, all domain names in the domain name set will be identified as fast-changing domain names.

[0046] According to embodiments of this disclosure, the Domain Name System (DNS) can serve as a distributed database that maps domain names to IP addresses, enabling users to access the Internet more conveniently. DNS logs collected from DNS routers can be stored in a database for subsequent processing and analysis. DNS logs can be retrieved from the database to reduce the workload associated with retrieving them from the DNS router.

[0047] According to embodiments of this disclosure, the feature data can be used by users to subsequently determine whether a domain name is a fast-changing domain. In the feature data, the IP address lifetime can be understood as the cache duration of the IP address corresponding to the domain name on the user's computer. A short TTL (Time To Live) for an IP address suggests that the domain name corresponding to that IP address may be a fast-changing domain.

[0048] According to embodiments of this disclosure, the set of domain names to be analyzed refers to a set of related domain names. Correspondingly, the IP addresses corresponding to these domain names can form a set of IP addresses. Since rapidly changing domain names are characterized by frequent changes, the set of domain names contains a large number of domain names, meaning there are many related domain names; therefore, the current set of domain names may be rapidly changing domain names.

[0049] According to embodiments of this disclosure, the processing of feature data can be understood as converting this feature data into several numerical values ​​that can represent the characteristics of the domain name set and IP address set. Examples include the proportion of abnormal domain names and the proportion of abnormal IP addresses.

[0050] According to embodiments of this disclosure, by comparing the lifecycle of an IP address, the number of domains in the domain name set, the proportion of abnormal domain names, and the proportion of abnormal IP addresses with multiple threshold ranges in the domain name abnormality conditions, when all are within the average threshold range of these data, it can be considered that the domain names in the current domain name set have the characteristics of rapidly changing domain names, thereby blocking these domain names.

[0051] According to the domain name detection method provided in this disclosure, domain name system logs are collected; feature data is extracted from the domain name system logs and analyzed to obtain the lifecycle of IP addresses, the number of related domain names, the proportion of abnormal domain names, and the proportion of abnormal IP addresses; when all of the above data meet the abnormal conditions, all related domain names in the domain name set are identified as fast-changing domain names. Because the domain detection process combines multiple dimensions of features such as the lifecycle of IP addresses, the number of related domain names, the proportion of abnormal domain names, and the proportion of abnormal IP addresses, and determines fast-changing domain names only when these features simultaneously meet the abnormal conditions, it at least partially overcomes the problem of inaccurate identification of fast-changing domain names in related technologies, thereby achieving the technical effect of improving the accuracy of fast-changing domain name identification.

[0052] Figure 3 A schematic diagram illustrating the relationship between domain names and IP addresses according to embodiments of the present disclosure is provided.

[0053] like Figure 3 As shown, multiple IP addresses resolved to the same domain name can be related; similarly, if multiple domain names resolve to the same IP address, then these domain names are also related. Therefore, the number of related domain names can be used as a basis to determine whether a domain name is a rapidly changing domain. Figure 3 For example, domains d1 through d9 are all related, so the total number of domains in the set is 9. It should also be noted that... Figure 3 The relationship between domain names and IP addresses shown is merely exemplary, and the embodiments disclosed herein are not limited thereto.

[0054] According to embodiments of this disclosure, the abnormal domain name ratio in operation S203 is obtained based on the ratio of the number of abnormal domain names to the total number of domain names in the domain name set. Abnormal domain names can be determined as follows: For each domain name in the domain name set: the domain name is split into multiple subdomains with location identifiers; in the domain name set, all subdomains with the same location identifier are searched to obtain a subdomain list; abnormal subdomains are found from the subdomain list, wherein the names of the abnormal subdomains are different from the names of the other subdomains in the subdomain list; based on the abnormal subdomains, abnormal domain names are determined from the domain name set.

[0055] According to embodiments of this disclosure, taking the domain name www.abc.com as an example, the domain name is split into subdomains with a location table, namely, split into "first part www." and "second part abc.com", where the second part can serve as the main content of the domain name. Each domain name in the domain name set can be split. Based on the splitting results, a keyword search method is used to filter out all subdomains with the same location identifier, such as searching using keywords like "second part" and ".com", thereby obtaining all subdomains of the second part. The search results are then recombined to generate a subdomain list. In the subdomain list, subdomains whose names differ from most names in the list are identified as abnormal subdomains. Based on the abnormal subdomains, a search is performed in the domain name set to find abnormal domains containing abnormal subdomains. The ratio of the number of abnormal domains to the total number of domains in the domain name set can be used to obtain the abnormal domain ratio. If no abnormal subdomains are found, the abnormal domain ratio can be zero.

[0056] According to embodiments of this disclosure, the abnormal IP address ratio in operation S203 is obtained as the ratio of the number of abnormal IP addresses to the total number of IP addresses in the IP address set. The abnormal IP address ratio can also be understood as the ratio of non-public IP addresses among related domain names. An abnormal IP address can be understood as a non-public IP address; among the IP addresses corresponding to related domain names, those that are not public IP addresses, and whose form or name differs from the other IP addresses, can be considered abnormal IP addresses. Abnormal IP addresses can be obtained by directly comparing their names. For example, refer to... Figure 3 Assume IP address 1 is 123.456.7.1, IP address 2 is 123.456.7.2, IP address 3 is 987.123.5.6, and IP address 4 is 123.456.7.3. If 123.456.7 can represent a public address, then in the above embodiment, IP address 3 is a non-public IP address, and the proportion of abnormal IP addresses can be 25% (1 / 4 = 25%).

[0057] According to embodiments of this disclosure, the proportion of abnormal IP addresses can also refer to the percentage of the different first 16 bits of an IP address after number system conversion. Abnormal IP addresses can also be determined as follows: Each IP address in the IP address set is converted to a different number system; a preset number of numeric strings are extracted from the multiple addresses obtained after number system conversion to obtain a list of numeric strings; abnormal numeric strings are found in the list of numeric strings, wherein the numbers contained in the abnormal numeric strings are different from the numbers contained in the other numeric strings in the list; and abnormal IP addresses are located from the IP address set based on the abnormal numeric strings.

[0058] According to embodiments of this disclosure, number system conversion can be understood as binary conversion, etc. By performing binary conversion on each IP address and extracting the first 16 bits of the resulting string, a list of number strings is generated. A string in this list that differs from the strings containing the specified digits is identified as an abnormal string.

[0059] For example, suppose IP address 1 is 1.1.1.1, IP address 2 is 1.1.1.2, IP address 3 is 2.1.1.2, and IP address 4 is 1.1.1.4. After binary conversion, we can obtain:

[0060] The first 16 bits of IP address 1 are: 00000001 00000001;

[0061] The first 16 bits of IP address 2 are: 00000001 00000001;

[0062] The first 16 bits of IP address 3 are: 00000010 00000001;

[0063] The first 16 bits of IP address 4 are: 00000001 00000001;

[0064] In the conversion result, the abnormal number string is "00000010 00000001", and the IP address corresponding to this abnormal number string is "IP address 3". The proportion of abnormal IP addresses or the proportion of different first 16 bits can be 0.25 (1 / 4 = 0.25).

[0065] According to embodiments of this disclosure, the domain name anomaly condition can be constructed from multiple anomaly thresholds; operation S204 may include the following operations: comparing the lifespan of the IP address, the number of domain names, the proportion of abnormal domain names, and the proportion of abnormal IP addresses with the anomaly thresholds respectively; and when the lifespan of the IP address, the number of domain names, the proportion of abnormal domain names, and the proportion of abnormal IP addresses are all within the range of the anomaly thresholds, determining all domain names in the domain name set as fast-changing domain names.

[0066] According to embodiments of this disclosure, the abnormal threshold may include at least one of the following: a lifecycle threshold, a related domain name quantity threshold, an abnormal domain name ratio threshold, and an abnormal IP address ratio threshold.

[0067] According to embodiments of this disclosure, the lifecycle threshold can be 200 seconds, and the domain name anomaly condition corresponding to the lifecycle threshold can be "whether the lifecycle value of the smallest IP address is less than or equal to 200 seconds".

[0068] According to embodiments of this disclosure, the threshold for the number of relevant domain names can be 3 to 17, and the domain name anomaly condition corresponding to the threshold can be "whether the number of domain names is within the range of 3 to 17". Rapidly changing domain names require multiple domain names to change frequently, so a large number of domain names can meet the characteristics of rapidly changing domain names.

[0069] According to embodiments of this disclosure, the abnormal domain name ratio threshold can be 20% to 33%, and the abnormal domain name condition corresponding to the abnormal domain name ratio threshold can be "whether the abnormal domain name ratio is within the range of 20% to 33%".

[0070] According to embodiments of this disclosure, the abnormal IP address ratio threshold can be 0.72, and the domain name abnormality condition corresponding to the abnormal IP address ratio threshold can be "whether the abnormal IP address ratio is greater than or equal to 0.72".

[0071] According to embodiments of this disclosure, the lifecycle threshold, the related domain name quantity threshold, the abnormal domain name ratio threshold, and the abnormal IP address ratio threshold can be adaptively adjusted according to actual needs.

[0072] According to the embodiments of this disclosure, in the execution of operation S204, the lifespan of the IP address, the number of domain names, the proportion of abnormal domain names, the proportion of abnormal IP addresses, and the abnormal threshold can be compared respectively. If the comparison results simultaneously satisfy "the lifespan of the smallest IP address is less than or equal to 200 seconds", "the number of domain names is in the range of 3 to 17", "the proportion of abnormal domain names is in the range of 20% to 33%", and "the proportion of abnormal IP addresses is greater than or equal to 0.72", then all the domain names in the domain name set are fast-changing domain names.

[0073] According to embodiments of this disclosure, after detecting a rapidly changing domain name, the rapidly changing domain name can be blocked; and the blocked rapidly changing domain name and its abnormal characteristic data can be recorded in a blocking database.

[0074] According to embodiments of this disclosure, the above method may further include the following operations: comparing the feature data with abnormal feature data in the blocking database before processing the feature data; and directly blocking all domains in the domain name set if the feature data matches the abnormal feature data.

[0075] According to embodiments of this disclosure, the blocking database can be a small database used to store historical abnormal characteristic data of rapidly changing domain names, including historical lifecycles, the number of domain names in the historical domain name set, the proportion of historically abnormal domain names, and the proportion of historically abnormal IP addresses. When the processed characteristic data is consistent with the historical abnormal characteristic data, the domain name can be directly blocked without performing subsequent judgment operations, thereby improving the processing efficiency of rapidly changing domain names.

[0076] Figure 4 A flowchart illustrating a domain name detection method according to another embodiment of the present disclosure is shown.

[0077] like Figure 4 As shown, the domain name detection method in this embodiment includes operations S401 to S405.

[0078] When operating S401, DNS logs are collected from the DNS router.

[0079] During operation of S402, the collected DNS logs are stored.

[0080] In operation S403, feature values ​​are extracted from the stored DNS logs.

[0081] In operation S404, the extracted feature values ​​are analyzed using algorithms.

[0082] When operating S405, the fast-changing domain name is identified based on the algorithm analysis results.

[0083] According to the embodiments of this disclosure, the contents of operations S401 to S405 can be referred to the relevant contents of operations S201 to S204, and will not be repeated here.

[0084] According to embodiments of this disclosure, by combining multiple dimensions of features such as the lifecycle of IP addresses, the number of related domain names, the proportion of abnormal domain names, and the proportion of abnormal IP addresses during the domain detection process, rapidly changing domain names can be judged from multiple perspectives. When these features simultaneously meet abnormal conditions, the rapidly changing domain names can be identified, thereby improving the accuracy of identifying rapidly changing domain names, effectively defending against attacks, and improving network security.

[0085] It should be noted that, unless it is explicitly stated that there is a sequential order of execution between different operations, or that there is a sequential order of execution between different operations in terms of technical implementation, the execution order between multiple operations may not be significant, and multiple operations may be executed simultaneously.

[0086] Based on the above-described domain name detection method, this disclosure also provides a domain name detection device. The following will combine... Figure 5 The device is described in detail.

[0087] Figure 5 A schematic block diagram of a domain name detection apparatus according to an embodiment of the present disclosure is shown.

[0088] like Figure 5 As shown, the domain name detection device 500 of this embodiment includes a collection module 510, an extraction module 520, a processing module 530, and a first determination module 540.

[0089] The acquisition module 510 is used to collect Domain Name System (DNS) logs from the DNS router, where the DNS logs are used to store domain names and IP addresses.

[0090] The extraction module 520 is used to extract feature data from the Domain Name System logs. The feature data includes at least the lifecycle of the IP address, the set of domain names to be analyzed, and the set of IP addresses corresponding to the set of domain names. All domain names in the set of domain names are related to each other.

[0091] The processing module 530 is used to process the feature data to obtain the proportion of abnormal domain names in the domain name set and the proportion of abnormal IP addresses in the IP address set.

[0092] The first determination module 540 is used to determine all domain names in the domain name set as fast-changing domain names when the life cycle of the IP address, the number of domain names in the domain name set, the proportion of abnormal domain names, and the proportion of abnormal IP addresses all meet the abnormal domain name conditions.

[0093] According to the domain name detection method provided in this disclosure, domain name system logs are collected; feature data is extracted from the domain name system logs and analyzed to obtain the lifecycle of IP addresses, the number of related domain names, the proportion of abnormal domain names, and the proportion of abnormal IP addresses; when all of the above data meet the abnormal conditions, all related domain names in the domain name set are identified as fast-changing domain names. Because the domain detection process combines multiple dimensions of features such as the lifecycle of IP addresses, the number of related domain names, the proportion of abnormal domain names, and the proportion of abnormal IP addresses, and determines fast-changing domain names only when these features simultaneously meet the abnormal conditions, it at least partially overcomes the problem of inaccurate identification of fast-changing domain names in related technologies, thereby achieving the technical effect of improving the accuracy of fast-changing domain name identification.

[0094] According to embodiments of this disclosure, the domain name detection device may further include a splitting module, a first search module, a second search module, and a second determination module.

[0095] The splitting module is used to split a domain name into multiple subdomains with location identifiers.

[0096] The first search module is used to find all subdomains in the domain set that have the same location identifier, and obtain a list of subdomains.

[0097] The second search module is used to find abnormal subdomains from the subdomain list, wherein the name of the abnormal subdomain is different from the names of the other subdomains in the subdomain list.

[0098] The second determination module is used to determine the abnormal domain name from the domain name set based on the abnormal subdomain name.

[0099] According to embodiments of this disclosure, the domain name detection device may further include a conversion module, an extraction module, a third search module, and a positioning module.

[0100] The conversion module is used to perform number system conversion for each IP address in the IP address set.

[0101] The extraction module is used to extract a preset number of digit strings from multiple addresses obtained by number system conversion, and obtain a list of digit strings.

[0102] The third search module is used to find abnormal number strings from the list of number strings, wherein the numbers contained in the abnormal number strings are different from the numbers contained in the other number strings in the list of number strings.

[0103] The location module is used to locate abnormal IP addresses from the set of IP addresses based on abnormal numeric strings.

[0104] According to embodiments of this disclosure, the first determining module may further include a comparison unit and a determining unit.

[0105] The comparison unit is used to compare the lifecycle of an IP address, the number of domain names, the proportion of abnormal domain names, the proportion of abnormal IP addresses, and the abnormal threshold.

[0106] The determination unit is used to identify all domain names in the domain name set as fast-changing domain names when the lifecycle of the IP address, the number of domain names, the proportion of abnormal domain names, and the proportion of abnormal IP addresses are all within the abnormal threshold range.

[0107] According to embodiments of this disclosure, the domain name detection device may further include a first blocking module and a recording module.

[0108] The first blocking module is used to block rapidly changing domain names.

[0109] The recording module is used to record the blocked instant-change domain name and its abnormal characteristics into the blocking database.

[0110] According to embodiments of this disclosure, the domain name detection device may further include a comparison module and a second blocking module.

[0111] The comparison module is used to compare the feature data with the abnormal feature data in the ban database before processing the feature data.

[0112] The second blocking module is used to directly block all domains in the domain set when the feature data matches the abnormal feature data.

[0113] According to embodiments of this disclosure, any plurality of modules among the acquisition module 510, extraction module 520, processing module 530, and first determination module 540 may be combined into one module, or any one of these modules may be split into multiple modules. Alternatively, at least some of the functions of one or more of these modules may be combined with at least some of the functions of other modules and implemented in one module. According to embodiments of this disclosure, at least one of the acquisition module 510, extraction module 520, processing module 530, and first determination module 540 may be at least partially implemented as hardware circuitry, such as a field-programmable gate array (FPGA), a programmable logic array (PLA), a system-on-a-chip, a system-on-a-substrate, a system-on-package, an application-specific integrated circuit (ASIC), or implemented in hardware or firmware by any other reasonable means of integrating or packaging the circuitry, or implemented in any one of software, hardware, and firmware methods, or in a suitable combination of any of these methods. Alternatively, at least one of the acquisition module 510, extraction module 520, processing module 530 and first determination module 540 may be at least partially implemented as a computer program module, which can perform corresponding functions when the computer program module is run.

[0114] It should be noted that the domain name detection device part in the embodiments of this disclosure corresponds to the domain name detection method part in the embodiments of this disclosure. For a detailed description of the domain name detection device part, please refer to the domain name detection method part, which will not be repeated here.

[0115] Figure 6 A block diagram schematically illustrates an electronic device suitable for implementing a domain name detection method according to an embodiment of the present disclosure.

[0116] like Figure 6 As shown, an electronic device 600 according to an embodiment of this disclosure includes a processor 601, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 602 or a program loaded from a storage portion 608 into a random access memory (RAM) 603. The processor 601 may include, for example, a general-purpose microprocessor (e.g., a CPU), an instruction set processor and / or an associated chipset and / or a special-purpose microprocessor (e.g., an application-specific integrated circuit (ASIC)), etc. The processor 601 may also include onboard memory for caching purposes. The processor 601 may include a single processing unit or multiple processing units for performing different actions of the method flow according to an embodiment of this disclosure.

[0117] RAM 603 stores various programs and data required for the operation of electronic device 600. Processor 601, ROM 602, and RAM 603 are interconnected via bus 604. Processor 601 performs various operations of the method flow according to embodiments of the present disclosure by executing programs in ROM 602 and / or RAM 603. It should be noted that the programs may also be stored in one or more memories other than ROM 602 and RAM 603. Processor 601 may also perform various operations of the method flow according to embodiments of the present disclosure by executing programs stored in said one or more memories.

[0118] According to embodiments of this disclosure, the electronic device 600 may further include an input / output (I / O) interface 605, which is also connected to a bus 604. The electronic device 600 may also include one or more of the following components connected to the input / output (I / O) interface 605: an input section 606 including a keyboard, mouse, etc.; an output section 607 including a cathode ray tube (CRT), liquid crystal display (LCD), etc., and a speaker, etc.; a storage section 608 including a hard disk, etc.; and a communication section 609 including a network interface card such as a LAN card, modem, etc. The communication section 609 performs communication processing via a network such as the Internet. A drive 610 is also connected to the input / output (I / O) interface 605 as needed. A removable medium 611, such as a disk, optical disk, magneto-optical disk, semiconductor memory, etc., is installed on the drive 610 as needed so that computer programs read from it can be installed into the storage section 608 as needed.

[0119] This disclosure also provides a computer-readable storage medium, which may be included in the device / apparatus / system described in the above embodiments; or it may exist independently and not assembled into the device / apparatus / system. The computer-readable storage medium carries one or more programs that, when executed, implement the method according to the embodiments of this disclosure.

[0120] According to embodiments of this disclosure, the computer-readable storage medium may be a non-volatile computer-readable storage medium, such as including, but not limited to: portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof. In this disclosure, the computer-readable storage medium may be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. For example, according to embodiments of this disclosure, the computer-readable storage medium may include ROM 602 and / or RAM 603 and / or one or more memories other than ROM 602 and RAM 603 described above.

[0121] Embodiments of this disclosure also include a computer program product comprising a computer program containing program code for performing the methods shown in the flowchart. When the computer program product is run on a computer system, the program code is used to enable the computer system to implement the domain name detection method provided in the embodiments of this disclosure.

[0122] When the computer program is executed by the processor 601, it performs the functions defined in the system / apparatus of this disclosure embodiments. According to embodiments of this disclosure, the systems, apparatuses, modules, units, etc., described above can be implemented by computer program modules.

[0123] In one embodiment, the computer program may rely on a tangible storage medium such as an optical storage device or a magnetic storage device. In another embodiment, the computer program may also be transmitted and distributed in the form of signals over a network medium, and downloaded and installed via the communication section 609, and / or installed from the removable medium 611. The program code contained in the computer program can be transmitted using any suitable network medium, including but not limited to: wireless, wired, etc., or any suitable combination thereof.

[0124] In such an embodiment, the computer program can be downloaded and installed from a network via the communication section 609, and / or installed from the removable medium 611. When the computer program is executed by the processor 601, it performs the functions defined in the system of this disclosure embodiment. According to embodiments of this disclosure, the systems, devices, apparatuses, modules, units, etc., described above can be implemented by computer program modules.

[0125] According to embodiments of this disclosure, program code for executing the computer programs provided in embodiments of this disclosure can be written in any combination of one or more programming languages. Specifically, these computational programs can be implemented using high-level procedural and / or object-oriented programming languages, and / or assembly / machine languages. Programming languages ​​include, but are not limited to, languages ​​such as Java, C++, Python, "C", or similar programming languages. The program code can execute entirely on the user's computing device, partially on the user's device, partially on a remote computing device, or entirely on a remote computing device or server. In cases involving remote computing devices, the remote computing device can be connected to the user's computing device via any type of network, including a local area network (LAN) or a wide area network (WAN), or it can be connected to an external computing device (e.g., via the Internet using an Internet service provider).

[0126] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this disclosure. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in a block diagram or flowchart, and combinations of blocks in a block diagram or flowchart, may be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.

[0127] Those skilled in the art will understand that the features described in the various embodiments and / or claims of this disclosure can be combined or combined in various ways, even if such combinations or combinations are not explicitly described in this disclosure. In particular, the features described in the various embodiments and / or claims of this disclosure can be combined or combined in various ways without departing from the spirit and teachings of this disclosure. All such combinations and / or combinations fall within the scope of this disclosure.

[0128] The embodiments of this disclosure have been described above. However, these embodiments are for illustrative purposes only and are not intended to limit the scope of this disclosure. Although various embodiments have been described above, this does not mean that the measures in the various embodiments cannot be used advantageously in combination. The scope of this disclosure is defined by the appended claims and their equivalents. Various substitutions and modifications can be made by those skilled in the art without departing from the scope of this disclosure, and all such substitutions and modifications should fall within the scope of this disclosure.

Claims

1. A domain name detection method, comprising: Domain Name System (DNS) logs are collected from the DNS router, wherein the DNS logs are used to store domain names and IP addresses; Feature data is extracted from the Domain Name System logs, wherein the feature data includes at least the lifecycle of the IP address, the set of domain names to be analyzed, and the set of IP addresses corresponding to the set of domain names, and the domain names in the set of domain names are all correlated; The feature data is processed to obtain the proportion of abnormal domain names in the domain name set and the proportion of abnormal IP addresses in the IP address set. If the lifecycle of the IP address, the number of domains in the domain name set, the proportion of abnormal domain names, and the proportion of abnormal IP addresses all meet the abnormal domain name conditions, then all domain names in the domain name set will be identified as fast-changing domain names. The abnormal IP address is determined as follows: each IP address in the IP address set is converted to a different number system; a preset number of digit strings are extracted from the multiple addresses obtained after the number system conversion to obtain a list of digit strings; an abnormal digit string is found from the list of digit strings, wherein the digits contained in the abnormal digit string are different from the digits contained in the other digit strings in the list of digit strings; and the abnormal IP address is located from the IP address set based on the abnormal digit string.

2. The method according to claim 1, wherein, The abnormal domain name was determined in the following way: For each domain in the aforementioned domain set: The domain name is split into multiple subdomains with location identifiers; Within the domain name set, find all subdomains that share the same identifier at the specified location to obtain a list of subdomains; Find the abnormal subdomain from the subdomain list, wherein the name of the abnormal subdomain is different from the names of the other subdomains in the subdomain list; The abnormal domain name is determined from the domain name set based on the abnormal subdomain name.

3. The method according to claim 1, wherein, The domain name anomaly conditions are constructed from multiple anomaly thresholds; When the lifecycle of the IP address, the number of domains in the domain name set, the proportion of abnormal domain names, and the proportion of abnormal IP addresses all meet the domain name abnormality condition, identifying all domain names in the domain name set as rapidly changing domain names includes: The lifetime of the IP address, the number of domain names, the proportion of abnormal domain names, and the proportion of abnormal IP addresses are compared with the abnormal threshold, respectively; and If the lifecycle of the IP address, the number of domain names, the proportion of abnormal domain names, and the proportion of abnormal IP addresses are all within the abnormal threshold, then all domain names in the domain name set are identified as the rapidly changing domain names.

4. The method according to claim 1, further comprising: The aforementioned rapidly changing domain names will be blocked; as well as The blocked instant domain name and its abnormal characteristics are recorded in the blocking database.

5. The method according to claim 4, further comprising: Before processing the feature data, the feature data is compared with the abnormal feature data in the ban database; as well as If the characteristic data matches the abnormal characteristic data, all domains in the domain set are directly blocked.

6. The method according to claim 3, wherein, The abnormal threshold includes at least one of the following: lifecycle threshold, related domain name number threshold, abnormal domain name ratio threshold, and abnormal IP address ratio threshold.

7. A domain name detection device, comprising: The acquisition module is used to acquire Domain Name System (DNS) logs from the DNS router, wherein the DNS logs are used to store domain names and IP addresses; An extraction module is used to extract feature data from the Domain Name System logs, wherein the feature data includes at least the lifecycle of the IP address, the set of domain names to be analyzed, and the set of IP addresses corresponding to the set of domain names, and the domain names in the set of domain names are all correlated; The processing module is used to process the feature data to obtain the proportion of abnormal domain names in the domain name set and the proportion of abnormal IP addresses in the IP address set. The first determining module is used to determine all domain names in the domain name set as fast-changing domain names when the life cycle of the IP address, the number of domain names in the domain name set, the proportion of abnormal domain names, and the proportion of abnormal IP addresses all meet the domain name abnormality condition. The conversion module is used to perform number system conversion on each IP address in the IP address set; The extraction module is used to extract a preset number of digit strings from multiple addresses obtained by number system conversion, and obtain a list of digit strings; The third search module is used to find abnormal number strings from the list of number strings, wherein the abnormal number strings contain numbers that are different from the numbers contained in the other number strings in the list of number strings; The location module is used to locate the abnormal IP address from the IP address set based on the abnormal number string.

8. An electronic device, comprising: One or more processors; Storage device for storing one or more programs. Wherein, when the one or more programs are executed by the one or more processors, the one or more processors perform the method according to any one of claims 1 to 6.

9. A computer-readable storage medium having stored thereon executable instructions that, when executed by a processor, cause the processor to perform the method according to any one of claims 1 to 6.

10. A computer program product comprising a computer program that, when executed by a processor, implements the method according to any one of claims 1 to 6.