A method, device, chip, medium and system for obtaining abnormal device information

By simplifying the method of obtaining abnormal device information through DNS resolution and detection modules, this technology solves the problem of identifying abnormal devices through complex DNS traffic feature comparison in existing technologies, and realizes a network security solution that can quickly locate and simplify the process.

CN116684159BActive Publication Date: 2026-05-15CHINA UNITED NETWORK COMM GRP CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
CHINA UNITED NETWORK COMM GRP CO LTD
Filing Date
2023-06-13
Publication Date
2026-05-15

AI Technical Summary

Technical Problem

Existing technologies for identifying abnormal devices by monitoring DNS traffic characteristics are complex and difficult to implement, making it hard to detect network attack devices in a timely manner.

Method used

By employing a DNS resolution module and a detection module, device access information is obtained by receiving domain name requests and matching them in a domain name blacklist, thus determining the device's ownership information and simplifying the process to one that does not require traffic feature comparison.

Benefits of technology

It simplifies the process of obtaining information about abnormal devices, enables rapid location of abnormal devices, avoids network security issues such as information leakage, and the process is simple and easy to implement.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116684159B_ABST
    Figure CN116684159B_ABST
Patent Text Reader

Abstract

The application provides a method, device, chip, medium and system for obtaining abnormal device information, relates to the technical field of network security, and can simplify the process of obtaining abnormal device information and is easy to implement. The system comprises a domain name system (DNS) resolution module and a detection module. The DNS resolution module is configured to receive a first domain name request from a first device, wherein the first domain name request comprises a first domain name requested by the first device to access; and the DNS resolution module is further configured to send an address of a first module to the first device in the case that the first domain name is included in a domain name blacklist, wherein the first module can resolve access information of the first device; and the detection module is configured to obtain the access information of the first device and determine home information of the first device according to the access information, wherein the access information comprises an address of the first device.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network security technology, and in particular to a method, apparatus, chip, medium and system for obtaining information about abnormal devices. Background Technology

[0002] With the development of the internet, the network environment has become increasingly complex, and cyberattacks have become more industrialized and organized, with increasingly diversified attack methods. Furthermore, if attacked devices (hereinafter referred to as abnormal devices) within the network are not detected in a timely manner, it can seriously impact network security. Therefore, obtaining information about abnormal devices within the network is crucial.

[0003] Currently, the main method is to monitor Domain Name System (DNS) traffic, extract traffic characteristics, and compare these characteristics to identify network attacks and obtain information about abnormal devices. However, this method is complex and difficult to implement. Summary of the Invention

[0004] This application provides a method, apparatus, chip, medium, and system for obtaining abnormal device information, which simplifies the process of obtaining abnormal device information and is easy to implement.

[0005] To achieve the above objectives, this application adopts the following technical solution:

[0006] In a first aspect, this application provides a system for obtaining abnormal device information, the system comprising: a DNS resolution module and a detection module; the DNS resolution module is configured to receive a first domain name request from a first device, the first domain name request including a first domain name requested by the first device; the DNS resolution module is further configured to send the address of a first module to the first device if the first domain name is included in a domain name blacklist, the first module being able to resolve the access information of the first device; the detection module is configured to obtain the access information of the first device and determine the ownership information of the first device based on the access information, wherein the access information includes the address of the first device.

[0007] Based on the system provided in the first aspect above, the DNS resolution module can receive a first domain name request from the first device and, if the first domain name is included in the domain name blacklist, send the address of the first module to the first device. The detection module can obtain the access information of the first device and determine the ownership information of the first device based on the access information, thereby obtaining information about the first device, such as its address, and thus locating abnormal devices to prevent network security problems such as information leakage caused by abnormal devices. This method of determining the ownership information of the first device does not require traffic feature comparison, so the process is relatively simple and easy to implement.

[0008] In one possible implementation, the first module is a redirection module, and the system further includes: the redirection module; the redirection module is configured to receive a second domain name request from the first device through a first port, the first port being one of a plurality of input ports of the redirection module, the second domain name request including the access information; the redirection module is further configured to redirect the access information to a second port associated with the plurality of input ports, the second port being an output port of the redirection module, the second port being configured to forward the received information to the detection module.

[0009] Based on the above method, the redirection module can redirect the access information included in the second domain name request to a second port associated with multiple input ports, and then forward the received information to the detection module through the second port. In this way, the detection module only needs to set a port corresponding to the second port to receive information, reducing the number of ports used by the detection module.

[0010] One possible implementation is that the first module is a detection module; the detection module is used to obtain access information of the first device, including: the detection module receives a second domain name request from the first device, the second domain name request including the access information.

[0011] Based on the above method, the detection module can receive the second domain name request from the first device, obtain the access information of the first device, and thus determine the address of the first device included in the access information.

[0012] One possible implementation is that the detection module determines the ownership information of the first device based on the access information, including: the detection module searches for the address range corresponding to the address of the first device in the address analysis table, and determines the ownership information of the first device based on the address range, wherein the ownership information of the first device includes the location information of the first device and the information of the administrator of the first device.

[0013] Based on the above method, the detection module can find the address range corresponding to the address of the first device in the address analysis table, and determine the ownership information of the first device based on the address range, that is, obtain the information of abnormal devices in the network.

[0014] In one possible implementation, the access information further includes the time when the first device accessed the first domain name, and the system further includes: a report module; the report module is used to output an abnormal device report, the abnormal device report including the location information of the first device, the information of the administrator of the first device, and the time when the first device accessed the first domain name.

[0015] Based on the above method, the reporting module can output abnormal device reports, enabling security personnel to locate abnormal devices in a timely manner and avoid network security problems such as information leakage caused by abnormal devices.

[0016] Secondly, this application provides a method for obtaining abnormal device information. The method includes: receiving a first domain name request from a first device, the first domain name request including a first domain name that the first device requests to access; if the first domain name is included in a domain name blacklist, sending the address of a first module to the first device, the first module being able to resolve and obtain the access information of the first device; obtaining the access information of the first device, the access information including the address of the first device; and determining the ownership information of the first device based on the access information.

[0017] One possible implementation is that determining the ownership information of the first device based on the access information includes: searching for the address range corresponding to the address of the first device in the address analysis table; determining the ownership information of the first device based on the address range, wherein the ownership information of the first device includes the location information of the first device and the information of the administrator of the first device.

[0018] In one possible implementation, the access information further includes the time when the first device accessed the first domain name, and the method further includes: outputting an abnormal device report, the abnormal device report including the location information of the first device, the information of the administrator of the first device, and the time when the first device accessed the first domain name.

[0019] Thirdly, this application provides an apparatus for acquiring abnormal device information to implement the above-described method. The apparatus for acquiring abnormal device information includes modules, units, or means corresponding to the above-described method. These modules, units, or means can be implemented in hardware, software, or by hardware executing corresponding software. The hardware or software includes one or more modules or units corresponding to the above-described functions.

[0020] Fourthly, this application provides an apparatus for obtaining abnormal device information, the apparatus comprising: a processor; the processor being coupled to a memory, and after reading instructions from the memory, executing the method described in the second aspect above according to the instructions.

[0021] Fifthly, this application provides a computer-readable storage medium storing instructions that, when executed on a computer, cause the computer to perform the methods described in the second aspect or any possible implementation thereof.

[0022] In a sixth aspect, embodiments of this application provide a computer program product containing instructions that, when run on a computer, cause the computer to perform the methods described in the second aspect or any possible implementation thereof.

[0023] In a seventh aspect, embodiments of this application provide a chip including a processor for running computer programs or instructions to implement the methods described in the second aspect or any possible implementation thereof.

[0024] In one possible implementation, the chip provided in this application embodiment further includes a memory for storing computer programs or instructions.

[0025] The technical effects of any possible implementation of aspects two through seven can be found in the first aspect or the technical effects of different possible implementations of aspect one, and will not be repeated here. Attached Figure Description

[0026] Figure 1 This application provides a schematic diagram of the system architecture for an abnormal device.

[0027] Figure 2 A flowchart illustrating a method for obtaining abnormal device information provided in this application embodiment;

[0028] Figure 3 This is a schematic diagram of a device structure for obtaining abnormal device information provided in an embodiment of this application;

[0029] Figure 4 This application provides a schematic diagram of the hardware structure of a device for obtaining abnormal device information.

[0030] Figure 5 This is a schematic diagram of the structure of a chip provided in an embodiment of this application. Detailed Implementation

[0031] The method and apparatus for obtaining abnormal device information provided in the embodiments of this application will be described in detail below with reference to the accompanying drawings.

[0032] In this article, the term "and / or" is merely a description of the relationship between related objects, indicating that there can be three relationships. For example, A and / or B can represent three situations: A exists alone, A and B exist simultaneously, and B exists alone.

[0033] The terms "first" and "second," etc., used in the specification and drawings of this application are used to distinguish different objects or to distinguish different treatments of the same object, rather than to describe a specific order of objects.

[0034] Furthermore, the terms "comprising" and "having," and any variations thereof, used in the description of this application are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or apparatus that includes a series of steps or units is not limited to the steps or units listed, but may optionally include other steps or units not listed, or may optionally include other steps or units inherent to such process, method, product, or apparatus.

[0035] It should be noted that in the embodiments of this application, the words "exemplary" or "for example" are used to indicate examples, illustrations, or explanations. Any embodiment or design scheme described as "exemplary" or "for example" in the embodiments of this application should not be construed as being more preferred or advantageous than other embodiments or design schemes. Specifically, the use of the words "exemplary" or "for example" is intended to present the relevant concepts in a specific manner.

[0036] In the description of this application, unless otherwise stated, "a plurality of" means two or more.

[0037] The following is based on Figure 1 Taking the system 10 of the abnormal device shown as an example, the method provided in the embodiments of this application will be described.

[0038] like Figure 1 The diagram shown is a schematic representation of the architecture of a system 10 for an abnormal device provided in an embodiment of this application. Figure 1 In the system 10 for abnormal devices, there are a first device 101 and a system 102 for acquiring abnormal device information. Optionally, the system 10 for abnormal devices also includes an uplink domain name server 103.

[0039] The first device in this application embodiment, such as first device 101, is a device with wireless transceiver capabilities. The first device can also be referred to as a terminal. Exemplarily, a terminal can be a computer used by developers, a personal computer, a desktop computer, a laptop computer, a handheld computer, a notebook computer, or an ultra-mobile personal computer (UMPC). A terminal can also be referred to as a host. Exemplarily, a host can be a computer host, an internet host, a mini-computer host, a virtual host, a dual-line virtual host, a communication host, etc.

[0040] In this application embodiment, the uplink domain name server, for example, uplink domain name server 103, can be any root domain name server, used to query whether the first domain name requested by the first device is included in the domain name blacklist.

[0041] The system for obtaining abnormal device information in this embodiment, for example, system 102, can receive a first domain name request from a first device 101. If the first domain name is included in the domain name blacklist, system 102 sends the address of a first module to the first device 101, wherein the first module can resolve to obtain the access information of the first device. System 102 obtains the access information of the first device 101 and determines the ownership information of the first device 101 based on the access information. Optionally, after receiving the first domain name request from the first device 101, system 102 can continue to send the first domain name request to the upstream domain name server 103, recursively querying whether the first domain name is included in the domain name blacklist. The upstream domain name server 103 receives the first domain name request, queries whether the first domain name is included in the domain name blacklist, and sends the query result to system 102.

[0042] The system 102 for obtaining abnormal device information in this embodiment includes a DNS resolution module 1021 and a detection module 1022. Optionally, the system 102 for obtaining abnormal device information may also include a redirection module 1023 and a reporting module 1024.

[0043] The DNS resolution module 1021, detection module 1022, redirection module 1023, and reporting module 1024 in this embodiment can each be any single server. These include, but are not limited to, tower servers, blade servers, rack servers, physical servers, virtual hosts, Virtual Private Servers (VPS), cloud servers, home servers, and enterprise servers. Optionally, some or all of the modules in the DNS resolution module 1021, detection module 1022, redirection module 1023, and reporting module 1024 can be integrated into a single device. Optionally, the DNS resolution module 1021, detection module 1022, redirection module 1023, and reporting module 1024 can each be configured with different addresses, such as Internet Protocol (IP) addresses.

[0044] Figure 1 The system 10 for the abnormal device shown is for illustrative purposes only and is not intended to limit the technical solutions of this application. Those skilled in the art should understand that in specific implementations, the system 10 for the abnormal device may also include other devices, and the number of the first devices may be determined according to specific needs without limitation.

[0045] The methods provided in the embodiments of this application will be described in detail below.

[0046] like Figure 2 The image shows a method for obtaining abnormal device information provided in an embodiment of this application. The method for obtaining abnormal device information includes the following steps:

[0047] S201: The device for obtaining abnormal device information receives a first domain name request from the first device.

[0048] In this embodiment of the application, the device for obtaining abnormal device information may be: Figure 1 The system 102 for obtaining abnormal device information in the system 10 of the abnormal device shown. The first device may be... Figure 1 The first device 101 in system 10 of the abnormal device shown.

[0049] In this embodiment, the first domain name request includes a first domain name that the first device requests to access. The DNS resolution module can be a separate domain name server. The first device is used to send a first domain name request containing the first domain name to the DNS resolution module.

[0050] For example, taking the system 10 with abnormal devices as an example, the first device 101 sends a first domain name request to the DNS resolution module 1021 of the system 102 that obtains abnormal device information, and the DNS resolution module 1021 receives the first domain name request from the first device 101.

[0051] Optionally, after receiving the first domain name request, the device for obtaining abnormal device information can determine whether the first domain name is included in the domain name blacklist.

[0052] The domain blacklist includes multiple illegal domains. Illegal domains can be replaced with obscene domains. The domain blacklist can be pre-configured; for example, multiple illegal domains could be illegal domains extracted from the browser engine directory of the first device's Software Development Kit (SDK); or, multiple illegal domains could be illegal domains recorded on the network using a web crawler; or, multiple illegal domains could be reported by other devices.

[0053] Understandably, a domain blacklist can be stored in the DNS resolution module. When the DNS resolution module receives a request for the first domain name, it searches its local domain blacklist to determine if the first domain is included. Alternatively, the domain blacklist can be stored on an upstream domain name server, such as... Figure 1 In the upstream domain name server 103, after the DNS resolution module receives the first domain name request, it can send a query request to the upstream domain name server to determine whether the first domain name is included in the domain name blacklist.

[0054] Understandably, if the device that obtains abnormal device information determines that the first domain name is included in the domain name blacklist, then S202 will continue to be executed.

[0055] S202: If the device for obtaining abnormal device information includes the first domain name in the domain name blacklist, it sends the address of the first module to the first device.

[0056] For example, taking system 10 with an abnormal device as an example, if the DNS resolution module 1021 of system 102, which obtains abnormal device information, includes the first domain name in the domain name blacklist, it sends the address of the first module to the first device 101. The first module can resolve the access information of the first device. The access information includes the address of the first device. Optionally, the access information also includes the time when the first device accessed the first domain name.

[0057] One possible design is that the first module could be a detection module, such as... Figure 1 The detection module 1022 in system 10 of the abnormal device shown.

[0058] One possible implementation is that the DNS resolution module sends the address of the detection module to the first device. The first device then sends a second domain name request to the detection module based on that address. The detection module receives the second domain name request from the first device. The second domain name request includes access information. Another possible design is that the first module can be a redirection module, such as... Figure 1 The redirection module 1023 in system 10 of the abnormal device shown.

[0059] One possible implementation is that the DNS resolution module sends the address of the redirection module to the first device, the first device sends a second domain name request to the redirection module based on the address of the redirection module, the redirection module receives the second domain name request from the first device, and sends access information to the detection module.

[0060] For example, the redirection module receives a second domain name request from the first device through a first port, where the first port is one of multiple input ports of the redirection module, and the second domain name request includes access information. The redirection module is also configured to redirect the access information to a second port associated with the multiple input ports, where the second port is an output port of the redirection module, and the second port is used to forward the received information to the detection module.

[0061] Understandably, information received by the redirection module through any one of the multiple input ports can be considered as information received through the preset port. The second port is the output port corresponding to this preset port. For example, if the multiple input ports are ports 0 to 65535, and the preset port is port 12345, then the output port corresponding to port 12345 is the second port. That is, the redirection module can forward information received from any one of the ports from 0 to 65535 to the detection module through the second port. In this way, the detection module only needs to set one port corresponding to the second port to receive information, reducing the number of ports required for the detection module.

[0062] S203: The device for obtaining abnormal device information obtains access information of the first device.

[0063] For example, taking the abnormal device system 10 as an example, the detection module 1022 of the abnormal device information system 102 obtains the access information of the first device.

[0064] One possible design is that the first module is a detection module, which receives a second domain name request from the first device, that is, the detection module obtains the access information of the first device.

[0065] One possible design is that the first module is a redirection module, and the detection module receives the access information included in the second domain name request forwarded to the detection module by the redirection module, that is, the detection module obtains the access information of the first device.

[0066] Optionally, the detection module can store the access information of the first device in a database according to a standard format.

[0067] S204: The device for obtaining abnormal device information determines the ownership information of the first device based on the access information.

[0068] The ownership information of the first device includes the device's location information and the information of the device's administrator. Optionally, the ownership information of the first device may also include the time when the first device accessed the first domain name.

[0069] One possible implementation is that the device for obtaining abnormal device information searches for the address range corresponding to the address of the first device in the address analysis table, and determines the ownership information of the first device based on the address range.

[0070] For example, taking the system 10 with abnormal equipment as an example, the detection module 1022 searches for the address segment corresponding to the address of the first device 101 in the address analysis table, and determines the home location information and management personnel information corresponding to the address segment as the home location information and management personnel information of the first device.

[0071] Optionally, after the device acquiring abnormal device information determines the ownership information of the first device based on the access information, it may also output an abnormal device report. The abnormal device report includes the ownership information of the first device, the information of the administrator of the first device, and the time when the first device accessed the first domain name.

[0072] For example, taking system 10 with abnormal devices as an example, the detection module 1022 sends the ownership information of the first device 101 to the report module 1024. The report module 1024 receives the ownership information of the first device 101 and outputs an abnormal device report. It can be understood that the abnormal device report is used by security personnel who manage abnormal device reports to locate abnormal devices and notify the management personnel of the first device to handle the device.

[0073] Based on the above method, the device for obtaining abnormal device information can receive a request from the first device for the first domain name, and if the first domain name is included in the blacklist, send the address of the first module to the first device. The device can also obtain the access information of the first device, determine the ownership information of the first device based on the access information, and output an abnormal device report. This abnormal device report includes the address of the first device, the information of the administrator of the first device, and the time the first device accessed the first domain name. This allows security personnel managing abnormal device reports to promptly locate abnormal devices based on the reports, preventing network security issues such as information leakage caused by abnormal devices. This method of determining the ownership information of the first device does not require traffic feature comparison, therefore the process is relatively simple and easy to implement.

[0074] This application embodiment can divide the device for obtaining abnormal device information into functional modules or functional units according to the above method example. For example, each function can be divided into a separate functional module or functional unit, or two or more functions can be integrated into one module. The integrated module can be implemented in hardware or in software functional modules or functional units. The module or unit division in this application embodiment is illustrative and only represents one logical functional division; other division methods may be used in actual implementation.

[0075] like Figure 3 The diagram shown is a structural schematic of a device 30 for obtaining abnormal device information provided in an embodiment of this application. The device for obtaining abnormal device information includes a transceiver module 301 and a processing module 302.

[0076] The transceiver module 301 is used to receive a first domain name request from the first device, the first domain name request including the first domain name that the first device requests to access. For example, the transceiver module 301 is used to execute the above-described S201.

[0077] Processing module 302 is used to send the address of the first module to the first device when the first domain name is included in the domain name blacklist, and the first module can resolve to obtain the access information of the first device. For example, processing module 302 is used to execute the above-described S202.

[0078] The processing module 302 is also configured to obtain access information of the first device, including the address of the first device. For example, the processing module 302 is configured to execute the above-described S203.

[0079] The processing module 302 is further configured to determine the ownership information of the first device based on the access information. For example, the processing module 302 is configured to execute the above-described S204.

[0080] One possible implementation involves processing module 302, which is specifically used to look up the address range corresponding to the address of the first device in the address analysis and matching table. Processing module 302 is also specifically used to determine the ownership information of the first device based on the address range. The ownership information of the first device includes the device's location information and the information of the device's administrator.

[0081] In one possible implementation, the processing module 302 is also used to output an abnormal device report, which includes the location information of the first device, the information of the administrator of the first device, and the time when the first device accessed the first domain name.

[0082] It is understandable that the aforementioned device for determining and obtaining abnormal device information can also be implemented in hardware. For example, in hardware implementation, the sending module 302 in this embodiment can be integrated on the communication interface, and the processing module 302 can be integrated on the processor. As another example, in hardware implementation, both the transceiver module 301 and the processing module 302 in this embodiment are integrated on the processor. The hardware structure can be as follows... Figure 4 As shown.

[0083] Figure 4 A schematic diagram of a possible hardware structure of the apparatus for acquiring abnormal device information involved in the above embodiments is shown. The apparatus for acquiring abnormal device information includes a processor 402. Optionally, the apparatus for identifying obscured cells further includes a communication interface 403, a memory 401, and a bus 404.

[0084] Processor 402 is used to control and manage the actions of the device acquiring abnormal device information, for example, executing the steps performed by processing module 302, and / or other processes for performing the techniques described herein. Optionally, processor 402 may also execute the steps performed by processing module 302. The processor 402 may implement or execute various exemplary logic blocks, modules, and circuits described in conjunction with the disclosure of this application. The processor may be a central processing unit, a general-purpose processor, a digital signal processor, an application-specific integrated circuit, a field-programmable gate array, or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. It may implement or execute various exemplary logic blocks, modules, and circuits described in conjunction with the disclosure of this application. The processor may also be a combination that implements computing functions, such as including one or more microprocessor combinations, a combination of a DSP and a microprocessor, etc.

[0085] The communication interface 403 is used to support communication between the device for obtaining abnormal device information and other network entities, for example, to perform the steps performed by the transceiver module 301 described above.

[0086] The memory 401 is used to store program code and data of the device for obtaining abnormal device information. For example, the memory 401 may be the memory in the device for obtaining abnormal device information, and the memory may include volatile memory, such as random access memory; the memory may also include non-volatile memory, such as read-only memory, flash memory, hard disk or solid-state drive; the memory may also include a combination of the above types of memory.

[0087] Bus 404 can be an Extended Industry Standard Architecture (EISA) bus, etc. Bus 404 can be divided into address bus, data bus, control bus, etc. For ease of representation, Figure 4 The bus is represented by a single thick line, but this does not mean that there is only one bus or one type of bus.

[0088] Figure 5 This is a schematic diagram of the structure of chip 50 provided in an embodiment of this application. Chip 50 includes one or more processors 501. Optionally, chip 50 also includes a communication interface 503, a bus 502, and a memory 504.

[0089] The processor 501 described above can implement or execute various exemplary logic blocks, units, and circuits described in conjunction with the disclosure of this application. The processor can be a central processing unit, a general-purpose processor, a digital signal processor, an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. It can implement or execute various exemplary logic blocks, units, and circuits described in conjunction with the disclosure of this application. The processor can also be a combination that implements computing functions, such as a combination of one or more microprocessors, a combination of a DSP and a microprocessor, etc.

[0090] Memory 504 may include read-only memory and random access memory, and provides operation instructions and data to processor 501. A portion of memory 504 may also include non-volatile random access memory (NVRAM).

[0091] In some implementations, memory 504 stores elements such as execution modules or data structures, or subsets thereof, or extended sets thereof.

[0092] In this embodiment of the application, the corresponding operation is executed by calling the operation instructions stored in memory 504 (which may be stored in the operating system).

[0093] The memory 504 may include volatile memory, such as random access memory; the memory may also include non-volatile memory, such as read-only memory, flash memory, hard disk or solid-state drive; the memory may also include combinations of the above types of memory.

[0094] Bus 502 can be an Extended Industry Standard Architecture (EISA) bus, etc. Bus 502 can be divided into address bus, data bus, control bus, etc. For ease of representation, Figure 5 The symbol is represented by only one line, but this does not mean that there is only one bus or one type of bus.

[0095] Through the above description of the embodiments, those skilled in the art will clearly understand that, for the sake of convenience and brevity, only the division of the above functional modules is used as an example. In practical applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above. The specific working process of the system, device, and unit described above can be referred to the corresponding process in the foregoing method embodiments, and will not be repeated here.

[0096] This application provides a system for obtaining abnormal device information. The system includes a system DNS resolution module, a detection module, a redirection module, and a reporting module. The system is used to execute the methods described in the above method embodiments.

[0097] This application provides a computer program product containing instructions that, when run on a computer, cause the computer to perform the methods described in the above method embodiments.

[0098] This application also provides a computer-readable storage medium storing instructions that, when executed on a computer, cause the computer to perform the method in the method flow shown in the above method embodiments.

[0099] The computer-readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of computer-readable storage media (a non-exhaustive list) include: an electrical connection having one or more wires; a portable computer disk drive; a hard disk drive; a random access memory (RAM); a read-only memory (ROM); an erasable programmable read-only memory (EPROM); a register; a hard disk drive; an optical fiber; a portable compact disc read-only memory (CD-ROM); an optical storage device; a magnetic storage device; or any suitable combination thereof; or any other form of computer-readable storage medium known in the art. An exemplary storage medium is coupled to a processor, enabling the processor to read information from and write information to the storage medium. Of course, the storage medium may also be a component of the processor. The processor and the storage medium may reside in an application-specific integrated circuit (ASIC). In the embodiments of this application, the computer-readable storage medium can be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, apparatus, or device.

[0100] Since the apparatus, computer-readable storage medium, and computer program product in the embodiments of this application can be applied to the above methods, the technical effects that can be obtained can also be referred to the above method embodiments. The embodiments of this application will not be repeated here.

[0101] In the several embodiments provided in this application, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the mutual coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between devices or units may be electrical, mechanical, or other forms.

[0102] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0103] In addition, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.

[0104] The above are merely specific embodiments of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions within the technical scope disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. A system for acquiring abnormal device information, characterized in that, The system includes: a Domain Name System (DNS) resolution module, a redirection module, and a detection module; The DNS resolution module is used to receive a first domain name request from the first device, wherein the first domain name request includes a first domain name that the first device requests to access; The DNS resolution module is also used to send the address of the first module to the first device when the first domain name is included in the domain name blacklist, and the first module can resolve to obtain the access information of the first device; The first module is the redirection module; The redirection module is configured to receive a second domain name request from the first device through a first port, wherein the first port is one of a plurality of input ports of the redirection module, and the second domain name request includes the access information; The redirection module is further configured to redirect the access information to a second port associated with the plurality of input ports, the second port being the output port of the redirection module, and the second port being configured to forward the received information to the detection module; the detection module is configured to obtain the access information of the first device and determine the ownership information of the first device based on the access information, wherein the access information includes the address of the first device; Some or all of the DNS resolution module, the detection module, and the redirection module are integrated into one device.

2. The system according to claim 1, characterized in that, The detection module determines the ownership information of the first device based on the access information, including: The detection module searches for the address range corresponding to the address of the first device in the address analysis table, and determines the ownership information of the first device based on the address range. The ownership information of the first device includes the location information of the first device and the information of the administrator of the first device.

3. The system according to claim 2, characterized in that, The access information also includes the time when the first device accessed the first domain name, and the system also includes: a reporting module; The reporting module is used to output an abnormal device report, which includes the location information of the first device, the information of the administrator of the first device, and the time when the first device accessed the first domain name.

4. A method for obtaining abnormal device information, characterized in that, The method includes: Receive a first domain name request from a first device, wherein the first domain name request includes a first domain name that the first device requests to access; If the first domain name is included in the domain name blacklist, the address of the first module is sent to the first device, and the first module can resolve to obtain the access information of the first device; the first module is a redirection module. The second domain name request is received from the first device through the first port of the redirection module, where the first port is one of multiple input ports of the redirection module, and the second domain name request includes the access information; The redirection module redirects the access information to a second port associated with the plurality of input ports. The second port is the output port of the redirection module and is used to forward the received information to the detection module. The detection module is used to obtain the access information of the first device and determine the ownership information of the first device based on the access information. The access information includes the address of the first device. The ownership information of the first device is determined based on the access information.

5. The method according to claim 4, characterized in that, Determining the ownership information of the first device based on the access information includes: Find the address range corresponding to the address of the first device in the address analysis table; The ownership information of the first device is determined based on the address range. The ownership information of the first device includes the location information of the first device and the information of the administrator of the first device.

6. The method according to claim 5, characterized in that, The access information also includes the time when the first device accessed the first domain name, and the method further includes: Output an abnormal device report, which includes the location information of the first device, the information of the administrator of the first device, and the time when the first device accessed the first domain name.

7. A device for acquiring abnormal equipment information, characterized in that, include: A processor coupled to a memory for storing programs or instructions that, when executed by the processor, cause the apparatus to perform the method as described in any one of claims 4 to 6.

8. A chip, characterized in that, include: A processor coupled to a memory for storing programs or instructions that, when executed by the processor, cause the chip to perform the method as described in any one of claims 4 to 6.

9. A computer-readable storage medium storing instructions, characterized in that, When the computer executes the instruction, the computer performs the method described in any one of claims 4 to 6.