A domain name processing method and device, electronic equipment and storage medium
Patent Information
- Application Number
- CN202211119565.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-09-14
- Publication Date
- 2026-10-09
- Estimated Expiration
- 2042-09-14
AI Technical Summary
[0035] In a sixth aspect, embodiments of this application provide a computer storage medium storing executable instructions, which, when executed by a processor, implement the domain name processing method as described in the above embodiments.
Smart Images

Figure CN116962347B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communications, and more particularly to a domain name processing method, apparatus, electronic device, and storage medium. Background Technology
[0002] With the development of internet technology, harmful websites and online information have proliferated, highlighting the increasing importance of cybersecurity. Effectively managing website and application domains to create a healthy and clean online environment for users, and filtering out potentially harmful information, data leaks, and online scams during website and application browsing, has become a key focus. Summary of the Invention
[0003] To address the aforementioned technical problems, embodiments of this application provide a domain name processing method, apparatus, electronic device, and storage medium.
[0004] In a first aspect, embodiments of this application provide a domain name processing method, the method being applied to a domain name configuration platform, the method comprising:
[0005] Obtain domain name rules, and generate a first domain name configuration file based on the domain name information contained in the domain name rules; the first domain name configuration file includes a first address filtering rule;
[0006] A notification signal is sent to the domain name server, which is used to notify the domain name server to obtain the first domain name configuration file. The first domain name configuration file is used by the domain name server to match the first address information included in the domain name access message received by the user with the first address filtering rule in the first domain name configuration file when the domain name server receives the domain name access message triggered by the user and performs real-time parsing of the domain name access message to obtain the first address information included in the domain name access message. If the first address information matches the first address filtering rule, the first address information is written into the first domain name configuration file to obtain the second domain name configuration file. The second domain name configuration file includes a second address filtering rule. The second domain name configuration file is used by the target device to filter the access traffic corresponding to the second address information included in the second address filtering rule.
[0007] In an optional embodiment of this application, the first address filtering rule includes: a first address filtering sub-rule, a second address filtering sub-rule, and a matching relationship between the first address filtering sub-rule and the second address filtering sub-rule; the first address filtering sub-rule is a single address filtering rule, and the second address filtering sub-rule is an address set filtering rule; the step of generating a first domain name configuration file based on the domain name information contained in the domain name rule includes:
[0008] Based on at least one physical address contained in the domain name rule, a first address filtering sub-rule and a second address filtering sub-rule corresponding to each physical address in the at least one physical address are created, and the matching relationship between the first address filtering sub-rule and the second address filtering sub-rule is set;
[0009] The domain name rules are pre-resolved using a domain name resolution function to obtain the second address information included in the domain name rules;
[0010] The second address information is written into the target address set in the second address filtering sub-rule to obtain the updated second address filtering sub-rule;
[0011] A first domain name configuration file is generated based on the first address filtering sub-rule, the updated second address filtering sub-rule, and the matching relationship between the two.
[0012] In an optional embodiment of this application, the step of pre-resolving the domain name rule using a domain name resolution function to obtain the second address information included in the domain name rule includes:
[0013] For each domain name information included in the domain name rule, the domain name information is parsed within a specified time range. If the address information corresponding to the domain name information is parsed within the specified time range, the address information corresponding to the domain name information is written into the target address set, and the target address set is at least a portion of the address set in the second address filtering sub-rule.
[0014] If the address information corresponding to the domain name is not resolved within the specified time range, the domain name information is skipped, and the next domain name information after the domain name information in the domain name rule is resolved.
[0015] The address information corresponding to at least a portion of the domain name information that was successfully resolved within a specified time range in the domain name rules is determined as the second address information.
[0016] In one optional embodiment of this application, the second address filtering sub-rule includes at least one address set; the step of writing the second address information into the target address set in the second address filtering sub-rule includes:
[0017] Based on the physical address corresponding to the second address information, the second address information is written into one or more address sets in the at least one address set; wherein, each physical address corresponds to one address set.
[0018] Secondly, embodiments of this application provide a domain name processing method, which is applied to a domain name server, and the method includes:
[0019] The first domain name configuration file is obtained based on the notification signal sent by the domain name configuration platform; the first domain name configuration file is generated by the domain name configuration platform after obtaining the domain name rules, based on the domain name information contained in the domain name rules; the first domain name configuration file includes a first address filtering rule;
[0020] Upon receiving a domain access message triggered by a user and performing real-time parsing of the domain access message to obtain the first address information included in the domain access message, the first address information is matched with the first address filtering rule in the first domain configuration file. If the first address information matches the first address filtering rule, the first address information is written into the first domain configuration file to obtain a second domain configuration file. The second domain configuration file includes a second address filtering rule. The second domain configuration file is used by the target device to filter the access traffic corresponding to the second address information included in the second address filtering rule.
[0021] In an optional embodiment of this application, the first address filtering rule includes a first address filtering sub-rule, a second address filtering sub-rule, and a matching relationship between the first address filtering sub-rule and the second address filtering sub-rule; the first address filtering sub-rule is a single address filtering rule, the second address filtering sub-rule is an address set filtering rule, and the second address filtering sub-rule includes at least one address set; the step of writing the first address information into the first domain name configuration file includes:
[0022] Based on the physical address corresponding to the first address information, the first address information is written into one or more address sets in the at least one address set; wherein, each physical address corresponds to one address set.
[0023] Thirdly, embodiments of this application provide a domain name processing apparatus, which is applied to a domain name configuration platform, and the apparatus includes:
[0024] The first acquisition unit is used to acquire domain name rules and generate a first domain name configuration file based on the domain name information contained in the domain name rules; the first domain name configuration file includes a first address filtering rule;
[0025] A sending unit is configured to send a notification signal to a domain name server, the notification signal being used to notify the domain name server to obtain the first domain name configuration file; the first domain name configuration file is used by the domain name server to match the first address information included in the domain name access message received by the user and after real-time parsing of the domain name access message to obtain the first address information, and if the first address information matches the first address filtering rule, write the first address information into the first domain name configuration file to obtain a second domain name configuration file; wherein, the second domain name configuration file includes a second address filtering rule; the second domain name configuration file is used by the target device to filter the access traffic corresponding to the second address information included in the second address filtering rule.
[0026] In one optional embodiment of this application, the first address filtering rule includes: a first address filtering sub-rule, a second address filtering sub-rule, and a matching relationship between the first address filtering sub-rule and the second address filtering sub-rule; the first address filtering sub-rule is a single address filtering rule, and the second address filtering sub-rule is an address set filtering rule.
[0027] The first acquisition unit is specifically configured to: create a first address filtering sub-rule and a second address filtering sub-rule corresponding to each physical address among the at least one physical address contained in the domain name rule, and set a matching relationship between the first address filtering sub-rule and the second address filtering sub-rule; pre-parse the domain name rule using a domain name resolution function to obtain the second address information included in the domain name rule; write the second address information into the target address set in the second address filtering sub-rule to obtain the updated second address filtering sub-rule; and generate a first domain name configuration file based on the first address filtering sub-rule, the updated second address filtering sub-rule, and the matching relationship between them.
[0028] In an optional embodiment of this application, the first acquisition unit is specifically configured to: parse each domain name information included in the domain name rule within a specified time period; if the address information corresponding to the domain name information is parsed within the specified time period, then write the address information corresponding to the domain name information into a target address set, wherein the target address set is at least a portion of the address set in the second address filtering sub-rule; if the address information corresponding to the domain name information is not parsed within the specified time period, then skip the domain name information and parse the next domain name information following the domain name information in the domain name rule; and determine the address information corresponding to the at least a portion of the domain name information successfully parsed within the specified time period in the domain name rule as the second address information.
[0029] In one optional embodiment of this application, the second address filtering sub-rule includes at least one address set; the first acquisition unit is specifically used to: write the second address information into one or more address sets in the at least one address set based on the physical address corresponding to the second address information; wherein, each physical address corresponds to one address set.
[0030] Fourthly, embodiments of this application provide a domain name processing apparatus, which is applied to a domain name server, and the apparatus includes:
[0031] The second acquisition unit is used to acquire a first domain name configuration file based on a notification signal sent by the domain name configuration platform; the first domain name configuration file is a domain name configuration file generated by the domain name configuration platform after acquiring the domain name rules, based on the domain name information contained in the domain name rules; the first domain name configuration file includes a first address filtering rule;
[0032] The parsing unit is configured to, upon receiving a domain name access message triggered by a user and performing real-time parsing on the domain name access message to obtain first address information included in the domain name access message, match the first address information with the first address filtering rule in the first domain name configuration file, and, if the first address information matches the first address filtering rule, write the first address information into the first domain name configuration file to obtain a second domain name configuration file; wherein, the second domain name configuration file includes a second address filtering rule; the second domain name configuration file is used by the target device to filter the access traffic corresponding to the second address information included in the second address filtering rule.
[0033] In an optional embodiment of this application, the first address filtering rule includes a first address filtering sub-rule, a second address filtering sub-rule, and a matching relationship between the first address filtering sub-rule and the second address filtering sub-rule; the first address filtering sub-rule is a single address filtering rule, and the second address filtering sub-rule is an address set filtering rule, wherein the second address filtering sub-rule includes at least one address set; the parsing unit is specifically used to: write the first address information into one or more address sets in the at least one address set based on the physical address corresponding to the first address information; wherein each physical address corresponds to one address set.
[0034] Fifthly, embodiments of this application provide an electronic device, the electronic device comprising: a memory and a processor, wherein the memory stores computer-executable instructions, and the processor, when executing the computer-executable instructions in the memory, can implement the domain name processing method as described in the above embodiments.
[0035] In a sixth aspect, embodiments of this application provide a computer storage medium storing executable instructions, which, when executed by a processor, implement the domain name processing method as described in the above embodiments.
[0036] The technical solution of this application combines two domain name resolution methods: domain name resolution through a domain name configuration platform and real-time domain name resolution through a domain name server. This can effectively control domain names containing harmful information on the network and improve the non-real-time nature of domain name resolution and control caused by browser caching, thereby enhancing the real-time performance and effectiveness of domain name control. Attached Figure Description
[0037] Figure 1 This is a schematic diagram of the architecture of an internet behavior management project.
[0038] Figure 2 This is a schematic diagram illustrating the working process of SmartDNS.
[0039] Figure 3 A flowchart illustrating the domain name processing method provided in this application embodiment. Figure 1 ;
[0040] Figure 4 A flowchart illustrating the domain name processing method provided in this application embodiment. Figure 2 ;
[0041] Figure 5 A schematic diagram illustrating the generation and transmission process of the domain name configuration file provided in this application embodiment;
[0042] Figure 6A flowchart illustrating the domain name control method provided in this application embodiment;
[0043] Figure 7 Schematic diagram of the structural composition of the domain name processing device provided in the embodiments of this application Figure 1 ;
[0044] Figure 8 Schematic diagram of the structural composition of the domain name processing device provided in the embodiments of this application Figure 2 ;
[0045] Figure 9 This is a schematic diagram of the structural composition of the electronic device provided in the embodiments of this application. Detailed Implementation
[0046] In order to gain a more detailed understanding of the features and technical content of the embodiments of this application, the implementation of the embodiments of this application will be described in detail below with reference to the accompanying drawings. The accompanying drawings are for reference and illustration only and are not intended to limit the embodiments of this application.
[0047] The technical solution of this application mainly focuses on how to control the domain names of specified websites and APP applications on specific downstream devices (i.e., devices connected to the gateway or router via wireless or wired network connection) on mobile gateways (i.e., optical modems) and routers, so as to achieve effective management of Internet access behavior. Figure 1 The internet behavior management project shown involves the function of controlling the domain names of specified websites and mobile applications.
[0048] Figure 1 The internet access management project shown primarily provides users with functions such as internet security detection, internet behavior management, and security protection. It mainly consists of a user mini-program page, a business management platform, router plugins, a router plugin management platform, gateway plugins, a gateway plugin management platform, and a security analysis platform. When a user activates application control on the mini-program page, the business management platform notifies the plugin to obtain the corresponding control rules. The plugin then uses the iptables / ip6tables or ipset tools in the operating system (such as Linux) to write the obtained domain name control rules into the operating system's (such as Linux) kernel system, thus achieving the purpose of application control.
[0049] Here, the main function of iptables / ip6tables is to control the entry and exit of network packets and their forwarding. When packets need to enter a device, flow out of a device, or be forwarded or routed through that device, iptables / ip6tables can be used for control. ipset is an extension of iptables; it allows the creation of rules that match entire address sets. Internet Protocol version 4 (IPv4) and Internet Protocol version 6 (IPv6) address sets are stored in indexed data structures. This structure allows for efficient address information lookup even when the address sets are large.
[0050] Below, we will introduce several domain name control solutions.
[0051] Option 1: Use a bypass method to call the third-party libPcap library (a network packet capture function library) to capture the Domain Name System (DNS) packets of the domains that need to be controlled, and drop the resolved IPv4 and IPv6 addresses to achieve the control effect. The plugin saves the MAC (Media Access Control) domain name mapping table for specified devices issued by the business management platform (hereinafter referred to as "the platform"), creates iptables / ip6tables rules (example: iptables / ip6tables-N self_control; iptables / ip6tables-I FORWARD-j self_control, i.e., creating a custom chain on the FORWARD forwarding chain of the iptables / ip6tables filter table) and ipset sets (example: ipset create block_list hash: net maxelem 1000000, i.e., creating an ipset set named block_list to store network Internet Protocol (IP) addresses, with a maximum element capacity of 1,000,000) and sets the matching relationship between the two (example: iptables / ip6tables-I self_control-m set--match-set block_list src-j DROP; iptables / ip6tables-I self_control-m set--match-setblock_list dst-j) (DROP); When a user visits a website or app with domain control rules set, the `ipset add block_list 36.152.44.90` command calls the third-party libPcap library (with pre-set DNS capture rules: src port 53) to capture the IPv4 and IPv6 addresses resolved to the corresponding domain name on the Mac and write them to the `ipset` set named `block_list`. Because the IPv4 and IPv6 addresses in the `block_list` set have already been DROP'd and discarded, the user cannot access the controlled domain website or app. The disadvantage of this solution is that it passively captures and resolves DNS packets only when the user visits the controlled domain website or app, resulting in low real-time control and a poor user experience.
[0052] Option 2: A combination of calling the third-party libPcap library and the system function getaddrinfo(). The getaddrinfo() function can handle both name-to-address and service-to-port conversions. Calling getaddrinfo() (which supports both IPv4 and IPv6) performs DNS pre-resolution on the platform-issued controlled domain name. The resolved IP address is then configured in the same way as in Option 1 (i.e., creating iptables rules, ipset sets, and matching relationships between them, and dropping IP addresses in the ipset set). When a user accesses the controlled website or app, the third-party libPcap library is called again to capture and resolve DNS packets, writing the newly resolved IPv4 and IPv6 addresses into the ipset set to achieve the expected control over the domain website or app. The disadvantage of this option is that, due to differences in network device processing performance and DNS configuration, as well as the working principle of the getaddrinfo() function itself, it also suffers from low real-time control and a poor user experience.
[0053] Of the two solutions mentioned above, Solution 1 passively triggers DNS domain name resolution. However, since browsers may have caches at the second or minute level, they may not make DNS requests every time. Therefore, Solution 1 suffers from control failure or low real-time control, failing to meet the requirements. Solution 2 suffers from differences in the processing performance of gateways or routers, different DNS configurations, and the working principle of the getaddrinfo() function (strace tracing reveals that getaddrinfo needs to communicate with the DNS server 10 times, and it is blocking, so it cannot meet the needs of concurrent processing scenarios). According to actual test results, the getaddrinfo() function call usually takes tens of milliseconds to succeed and often takes more than 30 seconds to fail. This leads to different rule effective times on different network devices (gateways or routers) (sometimes at the second level, and sometimes at the minute level in some scenarios), making it impossible to guarantee the approximate consistency of domain name control time and resulting in a poor user experience.
[0054] Based on the analysis of the shortcomings of the above two schemes, the domain name control scheme provided in this application embodiment needs to meet the following requirements:
[0055] 1. When users access websites or apps with controlled domains, DNS domain name resolution can be performed in real time, and the real-time control should be highly effective.
[0056] 2. Supports dynamic updates of the domain blacklist database and corresponding configuration files;
[0057] 3. Because the FLASH (flash memory) and RAM (random access memory) resources of embedded devices are relatively limited, the domain name management method should be simple to implement, have a small memory footprint, and have few third-party dependencies.
[0058] The technical solution of this application embodiment is mainly based on the technical principle of SmartDNS domain name server to quickly and efficiently resolve domain name IP addresses and automatically write IP addresses into the ipset set, thereby achieving effective control over domain name websites or APPs. The following is a collection of... Figure 2 The working process of native SmartDNS is described below:
[0059] like Figure 2 As shown, SmartDNS receives DNS query requests from local network devices, such as computers and mobile phones. SmartDNS sends these requests to multiple upstream DNS servers, using standard UDP queries, non-standard port UDP queries, and TCP queries. The upstream DNS servers return a list of server IP addresses corresponding to the domain names. SmartDNS detects the server IP with the fastest access speed from the local network and returns this fastest server IP to the local client, improving network access speed. SmartDNS also supports specifying both IPv4 and IPv6 addresses for specific domain names, achieving efficient IP address matching and filtering information from websites with specified domain names.
[0060] The native SmartDNS has the following problems:
[0061] 1. After adding domain rules to the domain configuration file, SmartDNS cannot dynamically obtain the latest domain configuration file. The process must be restarted to obtain the updated domain configuration file. Because actual business needs and user scenarios may involve frequent updates to domain rules (i.e., frequently updating the domain configuration file with new domains), frequent restarts of the SmartDNS process may affect normal access to other user services.
[0062] 2. If you set different ipset set names for the same domain name rule in the domain name configuration file, SmartDNS will only write the IPv4 and IPv6 addresses resolved by the domain name to the ipset set that is sorted last in the domain name configuration file. That is, it will only write to the same set and cannot manage the same domain name on different home devices.
[0063] In order to effectively manage website domains and applications using SmartDNS, it is necessary to overcome the aforementioned problems of native SmartDNS. The technical solution of the embodiments of this application will be introduced below.
[0064] Figure 3 A flowchart illustrating the domain name processing method provided in this application embodiment. Figure 1 The domain name processing method is applied to a domain name configuration platform, and the method includes the following steps:
[0065] Step 301: Obtain domain name rules and generate a first domain name configuration file based on the domain name information contained in the domain name rules; the first domain name configuration file includes a first address filtering rule.
[0066] In this embodiment of the application, the domain name configuration platform is a platform that generates domain name configuration files based on domain name rules. Specifically, it can be a domain name configuration plugin in the domain name configuration platform, which generates domain name configuration files based on domain name rules.
[0067] In this embodiment, the domain name rules are domain name management rules set by the user. These rules include domain names that need to be managed, such as websites containing inappropriate information or inappropriate advertisements. In this embodiment, the domain names to be managed can be set according to the user's needs. Different types of users may require different domain names to be managed; for example, the domain names to be managed may differ between children and adults.
[0068] In this embodiment of the application, the first domain name configuration file includes a first address filtering rule.
[0069] In one optional embodiment of this application, the first address filtering rule includes: a first address filtering sub-rule, a second address filtering sub-rule, and a matching relationship between the first address filtering sub-rule and the second address filtering sub-rule; the first address filtering sub-rule is a single address filtering rule, and the second address filtering sub-rule is an address set filtering rule.
[0070] For example, the first address filtering sub-rule can be an iptables / ip6tables rule, and the second filtering sub-rule can be an ipset set rule.
[0071] In an optional implementation, the step of generating the first domain name configuration file based on the domain name information contained in the domain name rules in step 301 above can be specifically implemented through the following steps:
[0072] 3.1) Based on at least one physical address contained in the domain name rule, create a first address filtering sub-rule and a second address filtering sub-rule corresponding to each physical address in the at least one physical address, and set the matching relationship between the first address filtering sub-rule and the second address filtering sub-rule;
[0073] 3.2) Use the domain name resolution function to pre-resolve the domain name rule to obtain the second address information included in the domain name rule;
[0074] 3.3) Write the second address information into the target address set in the second address filtering sub-rule to obtain the updated second address filtering sub-rule;
[0075] 3.4) Generate a first domain name configuration file based on the first address filtering sub-rule, the updated second address filtering sub-rule, and the matching relationship between the two.
[0076] In this embodiment of the application, the domain name rules include the physical address information of the network device. For step 3.1 above, after obtaining the domain name rules, the domain name configuration platform can create iptables / ip6tables rules corresponding to each physical address information (example: iptables / ip6tables-N self_control; iptables / ip6tables-I FORWARD-j self_control) and ipset sets (example: ipsetcreate block_list hash:net maxelem 1000000) and set the matching relationship between the two (example: iptables / ip6tables-I self_control-m set--match-set block_list src-j DROP; iptables / ip6tables-I self_control-m set--match-set block_list dst-j DROP).
[0077] In an optional embodiment of this application, step 3.2) specifically includes the following steps:
[0078] Step 3.2.1) For each domain name information included in the domain name rule, parse the domain name information within a specified time range. If the address information corresponding to the domain name information is parsed within the specified time range, write the address information corresponding to the domain name information into the target address set. The target address set is at least a portion of the address set in the second address filtering sub-rule.
[0079] Step 3.2.2) If the address information corresponding to the domain name information is not resolved within the specified time range, skip the domain name information and resolve the next domain name information after the domain name information in the domain name rule;
[0080] Step 3.2.3) Determine the address information corresponding to at least a portion of the domain name information that was successfully resolved within the specified time range in the domain name rule as the second address information.
[0081] Specifically, to ensure the timeliness of domain name control, the domain name configuration platform will first pre-resolve the obtained domain name rules. During the pre-resolution of domain name rules, the getaddrinfo() function is called and a timeout mechanism is set. When the set timeout period is reached (set in the range of N ms to 1 second), if the IPv4 and IPv6 addresses of the corresponding domain name are not resolved, the next domain name in the domain name rule will be skipped (domain names that are not resolved successfully will be supplemented by SmartDNS for resolution later). The resolved IPv4 and IPv6 addresses are written to the ipset set corresponding to the physical address information of the corresponding device (example: ipset add block_list 36.152.44.90).
[0082] The technical solution of this application embodiment sets a timeout mechanism (specifically, a timeout at the millisecond level) while calling the getaddrinfo() system function to perform domain name resolution. When performing pre-resolution of domain name rules, domain names that have timed out in the domain name rules are discarded. When the user triggers access, SmartDNS performs real-time update resolution and writes IPv4 and IPv6 addresses. The combination of pre-resolution and real-time resolution methods achieves the effect of no latency perceived by the user.
[0083] In an optional embodiment of this application, the second address filtering sub-rule includes at least one set of addresses, and step 3.3) above specifically includes the following steps:
[0084] Based on the physical address corresponding to the second address information, the second address information is written into one or more address sets in the at least one address set; wherein, each physical address corresponds to one address set.
[0085] In this embodiment of the application, the data structure and code related to domain name resolution and ipset set writing in SmartDNS are modified. For example, according to the configuration parameters in the domain name configuration file, the original one-to-one storage of the correspondence between "domain name -> IPv4 and IPv6 address -> single ipset set" is transformed into a one-to-many storage of the correspondence between "domain name -> IPv4 and IPv6 address -> multiple ipset sets", so that the same domain name can be managed under different network devices when performing domain name management.
[0086] #specific ipset to domain
[0087] #ipset / domain / [ipset|-)
[0088] #ipset / www.example.com / block,set ipset with ipset name of block
[0089] #ipset / www.example.com / -,ignore this domain
[0090] ipset / www.example.com / block
[0091] ipset / www.example.com / block1
[0092] Step 302: Send a notification signal to the domain name server, the notification signal being used to notify the domain name server to obtain the first domain name configuration file.
[0093] In this embodiment, the first domain name configuration file is used by the domain name server to match the first address information with the first address filtering rule in the first domain name configuration file when it receives a domain name access message triggered by a user and performs real-time parsing of the domain name access message to obtain the first address information included in the domain name access message. If the first address information matches the first address filtering rule, the first address information is written into the first domain name configuration file to obtain a second domain name configuration file. The second domain name configuration file includes a second address filtering rule. The second domain name configuration file is used by the target device to filter the access traffic corresponding to the second address information included in the second address filtering rule.
[0094] In this embodiment of the application, the domain name configuration platform sends a notification signal to the domain name server. The notification signal is used to notify the domain name server that the domain name configuration platform has generated a first domain name configuration file. After receiving the notification signal, the domain name server performs the operation of obtaining the first domain name configuration file.
[0095] It should be noted that in this embodiment of the application, the domain name configuration platform and the domain name server can be in the same system environment or in different system environments. For example, the domain name configuration platform and the domain name server can be deployed on different devices, or deployed in different unit modules of the same device, or deployed in the same unit module of the same device.
[0096] In this embodiment of the application, while the domain name configuration platform is pre-resolving the domain name rules, it will update the SmartDNS configuration file, that is, update the first domain name configuration file. It will send a signal to notify SmartDNS to obtain and resolve the latest domain name configuration file in a timely manner, that is, to notify SmartDNS to obtain and resolve the first domain name configuration file.
[0097] In this embodiment, when a user accesses a controlled website or APP application, i.e., when accessing a controlled domain name website, SmartDNS filters the domain names in the DNS messages triggered when the user accesses the website. If the domain name information in the DNS message is found to match the set domain name rules, the IPv4 and IPv6 addresses resolved by the DNS message will be updated and written to the ipset set specified in the first domain name configuration file. The gateway / router underlying system will drop all IPv4 and IPv6 address access packet traffic in the ipset set according to the set iptables / ip6tables rules, so as to achieve effective domain name control and filtering.
[0098] The technical solution of this application combines two domain name resolution methods: domain name resolution through a domain name configuration platform and real-time domain name resolution through a domain name server. This can effectively control domain names containing harmful information on the network and improve the non-real-time nature of domain name resolution and control caused by browser caching, thereby enhancing the real-time performance and effectiveness of domain name control.
[0099] Figure 4 A flowchart illustrating the domain name processing method provided in this application embodiment. Figure 2 The domain name processing method is applied to a domain name server, and the method includes the following steps:
[0100] Step 401: Obtain the first domain name configuration file based on the notification signal sent by the domain name configuration platform.
[0101] In this embodiment, the first domain name configuration file is generated by the domain name configuration platform after obtaining the domain name rules, based on the domain name information contained in the domain name rules; the first domain name configuration file includes a first address filtering rule. The specific process by which the domain name configuration platform parses the domain name rules to generate the first domain name configuration file can be referred to the description of step 301 above, and will not be repeated here.
[0102] In this embodiment of the application, when the domain name configuration platform obtains the domain name rules, it will pre-parse the domain name rules and update the SmartDNS configuration file, that is, update the first domain name configuration file. It will also send a signal to notify SmartDNS to obtain and parse the latest domain name configuration file in a timely manner, that is, to notify SmartDNS to obtain and parse the first domain name configuration file.
[0103] Step 402: Upon receiving a domain name access message triggered by a user and performing real-time parsing of the domain name access message to obtain the first address information included in the domain name access message, the first address information is matched with the first address filtering rule in the first domain name configuration file. If the first address information matches the first address filtering rule, the first address information is written into the first domain name configuration file to obtain the second domain name configuration file.
[0104] In this embodiment of the application, the second domain name configuration file includes a second address filtering rule; the second domain name configuration file is used by the target device to filter the access traffic corresponding to the second address information included in the second address filtering rule.
[0105] In one optional embodiment of this application, the first address filtering rule includes a first address filtering sub-rule, a second address filtering sub-rule, and a matching relationship between the first address filtering sub-rule and the second address filtering sub-rule; the first address filtering sub-rule is a single address filtering rule, the second address filtering sub-rule is an address set filtering rule, and the second address filtering sub-rule includes at least one address set.
[0106] For example, the first address filtering sub-rule can be an iptables / ip6tables rule, and the second filtering sub-rule can be an ipset set rule.
[0107] In this embodiment, when a user accesses a controlled website or APP application, i.e., when accessing a controlled domain name website, SmartDNS filters the domain names in the DNS messages triggered when the user accesses the website. If the domain name information in the DNS message is found to match the set domain name rules, the IPv4 and IPv6 addresses resolved by the DNS message will be updated and written to the ipset set specified in the first domain name configuration file (the set name is the same as in point 2). According to the set iptables / ip6tables rules, the gateway / router underlying system will drop all IPv4 and IPv6 address access packet traffic in the ipset set, so as to achieve effective domain name control and filtering.
[0108] In an optional embodiment of this application, the step of writing the first address information into the first domain name configuration file in step 402 above can be specifically implemented through the following steps:
[0109] Based on the physical address corresponding to the first address information, the first address information is written into one or more address sets in the at least one address set; wherein, each physical address corresponds to one address set.
[0110] In this embodiment of the application, the data structure and code related to domain name resolution and ipset set writing in SmartDNS are modified. According to the configuration items of the first domain name configuration file, the original one-to-one storage of the correspondence between "domain name -> IPv4 and IPv6 address -> single ipset set" is transformed into a one-to-many storage of the correspondence between "domain name -> IPv4 and IPv6 address -> multiple ipset sets", so that the same domain name can be managed under different network devices when performing domain name management.
[0111] The technical solution of this application combines two domain name resolution methods: domain name resolution through a domain name configuration platform and real-time domain name resolution through a domain name server. This can effectively control domain names containing harmful information on the network and improve the non-real-time nature of domain name resolution and control caused by browser caching, thereby enhancing the real-time performance and effectiveness of domain name control.
[0112] Figure 5 This is a schematic diagram illustrating the generation and transmission process of the domain name configuration file provided in an embodiment of this application, as shown below. Figure 5 As shown, a signal notification mechanism is established between the plugin and SmartDNS. After the plugin receives the domain name rules issued by the platform and updates the SmartDNS domain name configuration file, it sends a signal to notify SmartDNS to promptly obtain the updated domain name configuration file. This allows SmartDNS to dynamically obtain the latest domain name configuration file without restarting the process, thus meeting management requirements without affecting users' access to other normal services.
[0113] Figure 6 This is a flowchart illustrating the domain name control method provided in this application embodiment. Before domain name website / APP application control, we assume that the plugin has completed registration with the business management platform (gateway / router MAC, SN information (i.e., serial number information) and the domain name corresponding to the website / APP application have been entered into the business management platform database), the downstream device information (MAC, IPv4 address, and device name, etc.) has been reported to the business management platform, and the user has completed the process of binding the mini-program to the gateway / router device. Below, we will combine... Figure 6 This section introduces the working principle of domain name management based on SmartDNS.
[0114] 1. Users enable domain name rule control for websites / app applications via mini-programs. The business management platform pushes messages to the plugin via MQTT (a message transmission protocol) to inform the plugin that there are updated control rules. The plugin immediately sends a request to the business management platform to obtain the new domain name rules, creates corresponding iptables / ip6tables rules based on the MAC address (example: iptables / ip6tables-N self_control; iptables / ip6tables-I FORWARD-j self_control) and ipset sets (example: ipset create block_list hash:net maxelem 1000000) and sets the matching relationship between the two (example: iptables / ip6tables-I self_control-m set--match-set block_list src-j DROP; iptables / ip6tables-I self_control-m set--match-setblock_list dst-j DROP).
[0115] 2. To meet the high timeliness requirements of domain name control and improve user experience, the plugin will first pre-resolve and set the domain name rules issued by the business management platform. During domain name pre-resolution, the getaddrinfo() function is called to set a resolution timeout mechanism. When the set timeout period is reached (set in the range of N ms to 1 second), if the IPv4 and IPv6 addresses of the corresponding domain name in the domain name rule are not resolved, the next domain name will be skipped (domain names that are not resolved successfully will be supplemented by SmartDNS for resolution later). The resolved IPv4 and IPv6 addresses are written to the ipset set related to the corresponding device MAC (example: ipset add block_list 36.152.44.90).
[0116] 3. While pre-resolving domain name rules, the plugin will update the SmartDNS domain name configuration file and send a signal to notify SmartDNS to obtain and resolve the latest SmartDNS domain name configuration file in a timely manner.
[0117] 4. When a user accesses a controlled website or app, SmartDNS filters the domain name information in the DNS access packets triggered by the user. If the IP address information in the domain name information is found to match the set domain name rules, the resolved IPv4 and IPv6 addresses are updated and written to the ipset set specified in the domain name configuration file. The gateway / router underlying system will drop all IPv4 and IPv6 address access packet traffic in the ipset set according to the set iptables / ip6tables rules, so as to achieve effective domain name control and filtering.
[0118] The technical solution of this application is based on the SmartDNS framework, which has been modified and optimized. Since SmartDNS has been integrated into gateways / routers by most manufacturers as a DNS packet forwarding tool to improve webpage access speed, our solution has universality. Furthermore, in modifying and optimizing the SmartDNS framework, this application specifically modifies SmartDNS to support dynamic configuration files, the mapping relationship of "domain name -> IPv4 and IPv6 address -> multiple ipset sets," and combines this with the pre-resolution of domain name rules by the domain name configuration platform. By establishing rules on the forward chain of the iptables / ip6tables filter table and setting the matching relationship between iptables / ip6tables and ipsets, the IPv4 and IPv6 addresses in the ipset set are filtered, thereby achieving effective control over the domain names accessed by the device.
[0119] Figure 7 Schematic diagram of the structural composition of the domain name processing device provided in the embodiments of this application Figure 1 ,like Figure 7 As shown, the domain name processing device is applied to a domain name configuration platform, and the domain name processing device includes:
[0120] The first acquisition unit 701 is used to acquire domain name rules and generate a first domain name configuration file based on the domain name information contained in the domain name rules; the first domain name configuration file includes a first address filtering rule;
[0121] The sending unit 702 is used to send a notification signal to the domain name server, the notification signal being used to notify the domain name server to obtain the first domain name configuration file; the first domain name configuration file is used by the domain name server to match the first address information included in the domain name access message received by the user and after real-time parsing of the domain name access message to obtain the first address information, and if the first address information matches the first address filtering rule, write the first address information into the first domain name configuration file to obtain a second domain name configuration file; wherein, the second domain name configuration file includes a second address filtering rule; the second domain name configuration file is used by the target device to filter the access traffic corresponding to the second address information included in the second address filtering rule.
[0122] In one optional embodiment of this application, the first address filtering rule includes: a first address filtering sub-rule, a second address filtering sub-rule, and a matching relationship between the first address filtering sub-rule and the second address filtering sub-rule; the first address filtering sub-rule is a single address filtering rule, and the second address filtering sub-rule is an address set filtering rule.
[0123] The first acquisition unit 701 is specifically configured to: create a first address filtering sub-rule and a second address filtering sub-rule corresponding to each physical address among the at least one physical address contained in the domain name rule, and set a matching relationship between the first address filtering sub-rule and the second address filtering sub-rule; pre-parse the domain name rule using a domain name resolution function to obtain the second address information included in the domain name rule; write the second address information into the target address set in the second address filtering sub-rule to obtain the updated second address filtering sub-rule; and generate a first domain name configuration file based on the first address filtering sub-rule, the updated second address filtering sub-rule, and the matching relationship between them.
[0124] In an optional embodiment of this application, the first acquisition unit 701 is specifically configured to: parse each domain name information included in the domain name rule within a specified time range; if the address information corresponding to the domain name information is parsed within the specified time range, then write the address information corresponding to the domain name information into a target address set, wherein the target address set is at least a portion of the address set in the second address filtering sub-rule; if the address information corresponding to the domain name information is not parsed within the specified time range, then skip the domain name information and parse the next domain name information following the domain name information in the domain name rule; and determine the address information corresponding to the at least a portion of the domain name information successfully parsed within the specified time range in the domain name rule as the second address information.
[0125] In one optional embodiment of this application, the second address filtering sub-rule includes at least one address set; the first acquisition unit 701 is specifically used to: write the second address information into one or more address sets in the at least one address set based on the physical address corresponding to the second address information; wherein, each physical address corresponds to one address set.
[0126] Those skilled in the art should understand that Figure 7 The functions of each unit in the domain name processing device shown can be understood by referring to the relevant description of the aforementioned domain name processing method. Figure 7 The functions of each unit in the domain name processing device shown can be implemented by a program running on a processor or by specific logic circuits.
[0127] Figure 8 Schematic diagram of the structural composition of the domain name processing device provided in the embodiments of this application Figure 2 ,like Figure 8 As shown, the domain name processing device is applied to a domain name server; the domain name processing device includes:
[0128] The second acquisition unit 801 is used to acquire a first domain name configuration file based on a notification signal sent by the domain name configuration platform; the first domain name configuration file is a domain name configuration file generated by the domain name configuration platform after acquiring the domain name rules, based on the domain name information contained in the domain name rules; the first domain name configuration file includes a first address filtering rule;
[0129] The parsing unit 802 is configured to, upon receiving a domain name access message triggered by a user and performing real-time parsing on the domain name access message to obtain first address information included in the domain name access message, match the first address information with the first address filtering rule in the first domain name configuration file, and, if the first address information matches the first address filtering rule, write the first address information into the first domain name configuration file to obtain a second domain name configuration file; wherein, the second domain name configuration file includes a second address filtering rule; the second domain name configuration file is used by the target device to filter the access traffic corresponding to the second address information included in the second address filtering rule.
[0130] In an optional embodiment of this application, the first address filtering rule includes a first address filtering sub-rule, a second address filtering sub-rule, and a matching relationship between the first address filtering sub-rule and the second address filtering sub-rule; the first address filtering sub-rule is a single address filtering rule, and the second address filtering sub-rule is an address set filtering rule, wherein the second address filtering sub-rule includes at least one address set; the parsing unit 802 is specifically used to: write the first address information into one or more address sets in the at least one address set based on the physical address corresponding to the first address information; wherein each physical address corresponds to one address set.
[0131] Those skilled in the art should understand that Figure 8 The functions of each unit in the domain name processing device shown can be understood by referring to the relevant description of the aforementioned domain name processing method. Figure 8 The functions of each unit in the domain name processing device shown can be implemented by a program running on a processor or by specific logic circuits.
[0132] This application also provides an electronic device. Figure 9 This is a schematic diagram of the hardware structure of the electronic device according to an embodiment of this application, such as... Figure 9 As shown, the electronic device includes: a communication component 903 for data transmission, at least one processor 901, and a memory 902 for storing computer programs capable of running on the processor 901. The various components in the terminal are coupled together via a bus system 904. It is understood that the bus system 904 is used to implement communication between these components. In addition to a data bus, the bus system 904 also includes a power bus, a control bus, and a status signal bus. However, for clarity, in… Figure 9 The general labeled all buses as Bus System 904.
[0133] Wherein, when the processor 901 executes the computer program, it performs at least the following: Figure 3 or Figure 4 The steps of the method shown.
[0134] It is understood that memory 902 can be volatile memory or non-volatile memory, or both. Non-volatile memory can be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), ferromagnetic random access memory (FRAM), flash memory, magnetic surface memory, optical disc, or compact disc read-only memory (CD-ROM); magnetic surface memory can be disk storage or magnetic tape storage. Volatile memory can be random access memory (RAM), which is used as an external cache. By way of example, but not limitation, many forms of RAM are available, such as Static Random Access Memory (SRAM), Synchronous Static Random Access Memory (SSRAM), Dynamic Random Access Memory (DRAM), Synchronous Dynamic Random Access Memory (SDRAM), Double Data Rate Synchronous Dynamic Random Access Memory (DDRSDRAM), Enhanced Synchronous Dynamic Random Access Memory (ESDRAM), SyncLink Dynamic Random Access Memory (SLDRAM), and Direct Rambus Random Access Memory (DRRAM).The memory 902 described in the embodiments of this application is intended to include, but is not limited to, these and any other suitable types of memory.
[0135] The methods disclosed in the embodiments of this application can be applied to or implemented by the processor 901. The processor 901 may be an integrated circuit chip with signal processing capabilities. In the implementation process, each step of the above method can be completed by the integrated logic circuit of the hardware in the processor 901 or by instructions in the form of software. The processor 901 may be a general-purpose processor, a DSP, or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The processor 901 can implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of this application. The general-purpose processor may be a microprocessor or any conventional processor, etc. The steps of the methods disclosed in the embodiments of this application can be directly manifested as being executed by a hardware decoding processor, or being executed by a combination of hardware and software modules in the decoding processor. The software modules may be located in a storage medium, which is located in the memory 902. The processor 901 reads the information in the memory 902 and combines it with its hardware to complete the steps of the aforementioned method.
[0136] In an exemplary embodiment, the electronic device may be implemented by one or more application-specific integrated circuits (ASICs), DSPs, programmable logic devices (PLDs), complex programmable logic devices (CPLDs), FPGAs, general-purpose processors, controllers, MCUs, microprocessors, or other electronic components to perform the aforementioned call recording method.
[0137] This application also provides a computer-readable storage medium storing a computer program thereon, characterized in that the program, when executed by a processor, is at least used to perform... Figure 3 or Figure 4 The steps of the method are shown. The computer-readable storage medium may specifically be a memory. The memory may be, for example... Figure 9 The memory 902 shown.
[0138] The technical solutions described in the embodiments of this application can be combined arbitrarily without conflict.
[0139] In the several embodiments provided in this application, it should be understood that the disclosed methods and smart devices can be implemented in other ways. The device embodiments described above are merely illustrative. For example, the division of units is only a logical functional division, and in actual implementation, there may be other division methods, such as: multiple units or components can be combined, or integrated into another system, or some features can be ignored or not executed. In addition, the coupling, direct coupling, or communication connection between the various components shown or discussed can be through some interfaces, and the indirect coupling or communication connection between devices or units can be electrical, mechanical, or other forms.
[0140] The units described above as separate components may or may not be physically separate. The components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of the units may be selected to achieve the purpose of this embodiment according to actual needs.
[0141] In addition, each functional unit in the various embodiments of this application can be integrated into a second processing unit, or each unit can be a separate unit, or two or more units can be integrated into a unit; the integrated unit can be implemented in hardware or in the form of hardware plus software functional units.
[0142] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any changes or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application.
Claims
1. A domain name processing method, characterized in that, The method is applied to a domain name configuration platform, and the method includes: Obtain domain name rules, and generate a first domain name configuration file based on the domain name information contained in the domain name rules. The domain name rules include the domain names that need to be managed. The first domain name configuration file includes a first address filtering rule. A notification signal is sent to the domain name server, which is used to notify the domain name server to obtain the first domain name configuration file. The first domain name configuration file is used by the domain name server to match the first address information included in the domain name access message received by the user with the first address filtering rule in the first domain name configuration file when the domain name server receives the domain name access message triggered by the user and performs real-time parsing of the domain name access message to obtain the first address information included in the domain name access message. If the first address information matches the first address filtering rule, the first address information is written into the first domain name configuration file to obtain the second domain name configuration file. The second domain name configuration file includes a second address filtering rule. The second domain name configuration file is used by the target device to filter the access traffic corresponding to the second address information included in the second address filtering rule. The first address filtering rule includes: a first address filtering sub-rule, a second address filtering sub-rule, and a matching relationship between the first address filtering sub-rule and the second address filtering sub-rule; the first address filtering sub-rule is a single address filtering rule, and the second address filtering sub-rule is an address set filtering rule; the step of generating a first domain name configuration file based on the domain name information contained in the domain name rule includes: Based on at least one physical address contained in the domain name rule, a first address filtering sub-rule and a second address filtering sub-rule corresponding to each physical address in the at least one physical address are created, and the matching relationship between the first address filtering sub-rule and the second address filtering sub-rule is set; The domain name rules are pre-resolved using a domain name resolution function to obtain the third address information included in the domain name rules; The third address information is written into the target address set in the second address filtering sub-rule to obtain the updated second address filtering sub-rule; A first domain name configuration file is generated based on the first address filtering sub-rule, the updated second address filtering sub-rule, and the matching relationship between the two.
2. The method according to claim 1, characterized in that, The process of pre-resolving the domain name rules using a domain name resolution function to obtain the third address information included in the domain name rules includes: For each domain name information included in the domain name rule, the domain name information is parsed within a specified time range. If the address information corresponding to the domain name information is parsed within the specified time range, the address information corresponding to the domain name information is written into the target address set, and the target address set is at least a portion of the address set in the second address filtering sub-rule. If the address information corresponding to the domain name is not resolved within the specified time range, the domain name information is skipped, and the next domain name information after the domain name information in the domain name rule is resolved. The address information corresponding to at least a portion of the domain name information that was successfully resolved within a specified time range in the domain name rules is determined as the third address information.
3. The method according to claim 1, characterized in that, The second address filtering sub-rule includes at least one address set; the step of writing the third address information into the target address set in the second address filtering sub-rule includes: Based on the physical address corresponding to the third address information, the third address information is written into one or more address sets in the at least one address set; wherein, each physical address corresponds to one address set.
4. A domain name processing method, characterized in that, The method is applied to a domain name server, and the method includes: The first domain name configuration file is obtained based on the notification signal sent by the domain name configuration platform. The first domain name configuration file is generated by the domain name configuration platform after obtaining the domain name rules, based on the domain name information contained in the domain name rules. The domain name rules include the domain names that need to be managed. The first domain name configuration file includes the first address filtering rules. Upon receiving a domain access message triggered by a user and performing real-time parsing of the domain access message to obtain the first address information included in the domain access message, the first address information is matched with the first address filtering rule in the first domain configuration file. If the first address information matches the first address filtering rule, the first address information is written into the first domain configuration file to obtain a second domain configuration file. The second domain configuration file includes a second address filtering rule. The second domain configuration file is used by the target device to filter the access traffic corresponding to the second address information included in the second address filtering rule. The first address filtering rule includes a first address filtering sub-rule, a second address filtering sub-rule, and a matching relationship between the first address filtering sub-rule and the second address filtering sub-rule; the first address filtering sub-rule is a single address filtering rule, and the second address filtering sub-rule is an address set filtering rule; the first domain name configuration file is generated based on the first address filtering sub-rule, the updated second address filtering sub-rule, and the matching relationship between the two; the first address filtering sub-rule and the second address filtering sub-rule are created based on each physical address in at least one physical address contained in the domain name rule; the updated second address filtering sub-rule is obtained by writing the third address information included in the domain name rule into the target address set in the second address filtering sub-rule; the third address information is obtained by pre-resolving the domain name rule using a domain name resolution function.
5. The method according to claim 4, characterized in that, The second address filtering sub-rule includes at least one set of addresses; the step of writing the first address information into the first domain name configuration file includes: Based on the physical address corresponding to the first address information, the first address information is written into one or more address sets in the at least one address set; wherein, each physical address corresponds to one address set.
6. A domain name processing device, characterized in that, The device is used in a domain name configuration platform, and the device includes: The first acquisition unit is used to acquire domain name rules and generate a first domain name configuration file based on the domain name information contained in the domain name rules. The domain name rules include domain names that need to be controlled. The first domain name configuration file includes a first address filtering rule. The first address filtering rule includes a first address filtering sub-rule, a second address filtering sub-rule, and a matching relationship between the first address filtering sub-rule and the second address filtering sub-rule. The first address filtering sub-rule is a single address filtering rule, and the second address filtering sub-rule is an address set filtering rule. The first acquisition unit is specifically configured to: create a first address filtering sub-rule and a second address filtering sub-rule corresponding to each physical address in the at least one physical address contained in the domain name rule, and set a matching relationship between the first address filtering sub-rule and the second address filtering sub-rule; pre-parse the domain name rule using a domain name resolution function to obtain third address information included in the domain name rule; write the third address information into the target address set in the second address filtering sub-rule to obtain an updated second address filtering sub-rule; and generate a first domain name configuration file based on the first address filtering sub-rule, the updated second address filtering rule, and the matching relationship between them. A sending unit is configured to send a notification signal to a domain name server, the notification signal being used to notify the domain name server to obtain the first domain name configuration file; the first domain name configuration file is used by the domain name server to match the first address information included in the domain name access message received by the user and after real-time parsing of the domain name access message to obtain the first address information, and if the first address information matches the first address filtering rule, write the first address information into the first domain name configuration file to obtain a second domain name configuration file; wherein, the second domain name configuration file includes a second address filtering rule; the second domain name configuration file is used by the target device to filter the access traffic corresponding to the second address information included in the second address filtering rule.
7. A domain name processing device, characterized in that, The apparatus is used in a domain name server, and the apparatus includes: The second acquisition unit is used to acquire a first domain name configuration file based on a notification signal sent by a domain name configuration platform. The first domain name configuration file is generated by the domain name configuration platform after acquiring domain name rules, based on the domain name information contained in the domain name rules. The domain name rules include domain names that need to be managed. The first domain name configuration file includes a first address filtering rule. The first address filtering rule includes a first address filtering sub-rule, a second address filtering sub-rule, and a matching relationship between the first address filtering sub-rule and the second address filtering sub-rule. The first address filtering sub-rule is a single address filtering rule, and the second address filtering sub-rule is an address set filtering rule. The first domain name configuration file is generated based on the first address filtering sub-rule, the updated second address filtering sub-rule, and the matching relationship between them. The first address filtering sub-rule and the second address filtering rule are created based on each physical address in at least one physical address contained in the domain name rules. The updated second address filtering sub-rule is obtained by writing the third address information included in the domain name rules into the target address set in the second address filtering sub-rule. The third address information is obtained by pre-resolving the domain name rules using a domain name resolution function. The parsing unit is configured to, upon receiving a domain name access message triggered by a user and performing real-time parsing on the domain name access message to obtain first address information included in the domain name access message, match the first address information with the first address filtering rule in the first domain name configuration file, and, if the first address information matches the first address filtering rule, write the first address information into the first domain name configuration file to obtain a second domain name configuration file; wherein, the second domain name configuration file includes a second address filtering rule; the second domain name configuration file is used by the target device to filter the access traffic corresponding to the second address information included in the second address filtering rule.
8. An electronic device, characterized in that, The electronic device includes a memory and a processor, wherein the memory stores computer-executable instructions, and the processor, when executing the computer-executable instructions in the memory, can implement the method of any one of claims 1 to 3, or claims 4 to 5.
9. A computer storage medium, characterized in that, The storage medium stores executable instructions that, when executed by a processor, implement the method of any one of claims 1 to 3, or claims 4 to 5.
Citation Information
Patent Citations
Domain name filtering system and method
CN101488965A