A network security analysis method and system based on a domain name monitoring mechanism
The network security analysis system based on domain name monitoring mechanism enables real-time monitoring and anomaly analysis of domain names, solving the problem of unpredictable network attacks in existing technologies and improving network security protection capabilities and data protection effectiveness.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- 江西金德铅业股份有限公司
- Filing Date
- 2024-09-09
- Publication Date
- 2026-05-05
AI Technical Summary
Existing domain-based network security detection methods cannot analyze patterns based on network status, attack type, and attack time, resulting in an inability to predict network attacks and thus an inability to provide early protection. Furthermore, data protection is poor, making data loss or leakage more likely.
Design a network security analysis system based on a domain name monitoring mechanism, including information monitoring, information processing, emergency response, and inspection systems. Through units such as alerts, data locking, and DNS changes, it can achieve real-time monitoring and anomaly analysis of domain names and provide timely protection.
It enables intelligent analysis and early warning of domain names, which can promptly detect abnormal behavior, prevent data loss or theft, improve network security, and reduce human resource requirements.
Smart Images

Figure CN118944970B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network security technology, specifically to a network security analysis method and system based on a domain name monitoring mechanism. Background Technology
[0002] Network security situational awareness utilizes technologies such as multi-element data fusion, massive data mining, AI-based data analysis, and data visualization. Referring to Chinese patent publication number "CN114844722B" for "A Network Security Detection Method Based on Domain Names," this patent points out that existing domain name-based network security detection methods lack the ability to analyze attack patterns based on network status, attack types, and attack times. Therefore, existing domain name-based network security detection methods cannot predict network attacks and thus cannot provide early protection. Furthermore, the aforementioned monitoring methods and devices still suffer from poor data protection, leading to data loss or leakage when domain names are attacked. To address these issues, we propose a network security analysis method and system based on a domain name monitoring mechanism. Summary of the Invention
[0003] To address the shortcomings of existing technologies, this invention provides a network security analysis method and system based on a domain name monitoring mechanism, which solves the problems mentioned in the background section.
[0004] To achieve the above objectives, the present invention provides the following technical solution: a network security analysis system based on a domain name monitoring mechanism, comprising an information monitoring system, an information processing system, an emergency response system, and an inspection system;
[0005] The output of the information monitoring system is connected to the input of the information processing system, the output of the information processing system is connected to the input of the emergency response system, and the output of the emergency response system is connected to the input of the inspection system.
[0006] The emergency response system includes an alert unit, a data recording unit, a locking unit, a control recovery unit, a DNS change unit, and a security review unit;
[0007] The output of the warning unit is connected to the input of the data recording unit, the output of the data recording unit is connected to the input of the locking unit, the output of the locking unit is connected to the input of the control recovery unit, the output of the control recovery unit is connected to the input of the DNS change unit, and the output of the DNS change unit is connected to the input of the security review unit.
[0008] Preferably, the locking unit includes a server detection unit, a data locking unit, and a permission locking unit.
[0009] Preferably, the output of the server detection unit is connected to the input of the data locking unit, and the output of the data locking unit is connected to the input of the permission locking unit.
[0010] Preferably, the information monitoring system includes a detection unit, an information extraction unit, an information judgment unit, and a preprocessing unit.
[0011] Preferably, the output end of the detection unit is connected to the input end of the information extraction unit, the output end of the information extraction unit is connected to the input end of the information determination unit, and the output end of the information determination unit is connected to the input end of the preprocessing unit.
[0012] Preferably, the information processing system includes a parsing unit, a judgment unit, a data processing unit, a blocking unit, and a data storage unit.
[0013] Preferably, the output of the parsing unit is connected to the input of the determination unit, the output of the determination unit is connected to the input of the data processing unit, the output of the data processing unit is connected to the input of the blocking unit, and the output of the blocking unit is connected to the input of the data storage unit.
[0014] Preferably, the inspection system includes a DNS extension unit, a DNS monitoring unit, and an update unit.
[0015] Preferably, the output of the DNS extension unit is connected to the input of the DNS monitoring unit, and the output of the DNS monitoring unit is connected to the input of the update unit.
[0016] This invention also discloses a network security analysis method, based on the aforementioned network security analysis system, specifically including the following steps:
[0017] S1. Continuously monitor the domain name based on the information monitoring system, and judge the extracted information to see if there are any abnormal redirects or content changes, so as to discover any possible security issues or illegal use in a timely manner.
[0018] S2. Through the information processing system, resolve the obtained domain name information, promptly restore the normal resolution of the domain name and prevent illegal use when the domain name is hijacked or misused, and store the operation data to prevent loss;
[0019] S3. Based on the emergency response system, it can promptly issue a warning when a domain hijacking incident occurs and lock the stored data values and control permissions to prevent data loss or theft. At the same time, it can automatically log in to the control panel through the DNS change unit to change the DNS records and point them to the correct server IP address.
[0020] S4. Based on the inspection system, the DNS extension unit provides an additional security layer for DNS queries, ensuring that the returned information has not been tampered with, and regularly monitors DNS queries and responses to detect abnormal behavior in a timely manner.
[0021] This invention provides a network security analysis method and system based on a domain name monitoring mechanism. Compared with existing technologies, it has the following advantages:
[0022] (1) The network security analysis method and system based on the domain name monitoring mechanism can provide timely warnings when a domain name is hijacked or misused through the setting of the emergency handling system, and lock the stored data values and control permissions in a timely manner, thereby effectively preventing data loss or theft. At the same time, it can automatically log in to the control panel through the DNS change unit to change the DNS records and point to the correct server IP address, further improving network security.
[0023] (2) The network security analysis method and system based on the domain name monitoring mechanism can provide an additional security layer for DNS queries through the setting of the inspection system and the cooperation of the DNS extension unit, ensuring that the returned information has not been tampered with, and regularly monitor DNS queries and responses in order to detect abnormal behavior in a timely manner.
[0024] (3) This network security analysis method and system based on domain name monitoring mechanism can collect and organize relevant data on domain names, including their source, type, and access frequency. This information can be obtained from public data sources or captured by its own program. It can then build and train a domain name monitoring model. This model can automatically monitor and analyze changes in domain names according to preset rules. When anomalies are detected, such as a significant increase or decrease in the number of domain name visits or large fluctuations in access time, the model will automatically trigger an alarm. By combining the model with a real-time monitoring mechanism, it continuously monitors the dynamic changes of domain names and immediately issues an alarm when anomalies are detected. This allows users to understand potential security risks at the first opportunity, thereby achieving intelligent analysis and early warning of domain name changes and improving network security protection capabilities. The combination of a domain name monitoring model and a real-time monitoring mechanism makes the monitoring and early warning of domain name changes more intelligent and accurate, improving the actual effectiveness of network security protection capabilities. Furthermore, because the model is adaptive, it can automatically identify anomalies without human intervention, saving human resources and reducing system maintenance costs. In addition, since the model monitors and warns based on changes in domain names, it can also promptly detect and defend against newly emerging unknown attack patterns. Attached Figure Description
[0025] Figure 1 This is a schematic diagram of the system of the present invention;
[0026] Figure 2 This is a schematic diagram of the information monitoring system of the present invention;
[0027] Figure 3 This is a schematic diagram of the information processing system of the present invention;
[0028] Figure 4 This is a schematic diagram of the emergency response system of the present invention;
[0029] Figure 5 This is a schematic diagram of the locking unit of the present invention;
[0030] Figure 6 This is a schematic diagram of the inspection system of the present invention.
[0031] In the diagram: 11. Information monitoring system; 111. Detection unit; 112. Information extraction unit; 113. Information judgment unit; 114. Preprocessing unit;
[0032] 22. Information processing system; 221. Parsing unit; 222. Decision unit; 223. Data processing unit; 224. Blocking unit; 225. Data storage unit;
[0033] 33. Emergency Response System; 331. Alert Unit; 332. Data Recording Unit; 333. Locking Unit; 3330. Server Detection Unit; 3331. Data Locking Unit; 3332. Access Control Locking Unit; 334. Control Recovery Unit; 335. DNS Change Unit; 336. Security Review Unit;
[0034] 44. Inspection system; 441. DNS extension unit; 442. DNS monitoring unit; 443. Update unit. Detailed Implementation
[0035] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0036] Please see Figures 1-6 The present invention provides two technical solutions, specifically including the following embodiments:
[0037] Example 1: A network security analysis system based on a domain name monitoring mechanism, comprising an information monitoring system 11, an information processing system 22, and an inspection system 44;
[0038] The output of the information monitoring system 11 is connected to the input of the information processing system 22, and the output of the information processing system 22 is connected to the input of the inspection system 44.
[0039] The information monitoring system 11 includes a detection unit 111, an information extraction unit 112, an information judgment unit 113, and a preprocessing unit 114;
[0040] The output of the detection unit 111 is connected to the input of the information extraction unit 112, the output of the information extraction unit 112 is connected to the input of the information determination unit 113, and the output of the information determination unit 113 is connected to the input of the preprocessing unit 114.
[0041] The information processing system 22 includes a parsing unit 221, a judgment unit 222, a data processing unit 223, a blocking unit 224, and a data storage unit 225;
[0042] The output of the parsing unit 221 is connected to the input of the judgment unit 222, the output of the judgment unit 222 is connected to the input of the data processing unit 223, the output of the data processing unit 223 is connected to the input of the blocking unit 224, and the output of the blocking unit 224 is connected to the input of the data storage unit 225.
[0043] The inspection system 44 includes a DNS extension unit 441, a DNS monitoring unit 442, and an update unit 443;
[0044] The output of DNS extension unit 441 is connected to the input of DNS monitoring unit 442, and the output of DNS monitoring unit 442 is connected to the input of update unit 443.
[0045] This invention also discloses a network security analysis method, which, based on the aforementioned network security analysis system, specifically includes the following steps:
[0046] S1. Based on the information monitoring system 11, the domain name is continuously monitored, and the extracted information is judged to determine whether there are any abnormal redirects or content changes, so as to promptly detect any possible security issues or illegal use.
[0047] S2. Through the information processing system 22, the obtained domain name information is resolved. When the domain name is hijacked or misused, the normal resolution of the domain name is restored in a timely manner, illegal use is prevented, and the operation data is stored to prevent loss.
[0048] S3. Based on the inspection system 44, the DNS extension unit 441 provides an additional security layer for DNS queries, ensuring that the returned information has not been tampered with, and regularly monitors DNS queries and responses in order to detect abnormal behavior in a timely manner.
[0049] Example 2: Based on Example 1, a network security analysis system based on a domain name monitoring mechanism includes an information monitoring system 11, an information processing system 22, an emergency response system 33, and an inspection system 44;
[0050] The output of the information monitoring system 11 is connected to the input of the information processing system 22, the output of the information processing system 22 is connected to the input of the emergency response system 33, and the output of the emergency response system 33 is connected to the input of the inspection system 44.
[0051] The emergency response system 33 includes an alert unit 331, a data recording unit 332, a locking unit 333, a control recovery unit 334, a DNS change unit 335, and a security review unit 336;
[0052] The output of the warning unit 331 is connected to the input of the data recording unit 332, the output of the data recording unit 332 is connected to the input of the locking unit 333, the output of the locking unit 333 is connected to the input of the control recovery unit 334, the output of the control recovery unit 334 is connected to the input of the DNS change unit 335, and the output of the DNS change unit 335 is connected to the input of the security review unit 336.
[0053] The locking unit 333 includes a server detection unit 3330, a data locking unit 3331, and an access control unit 3332;
[0054] The output of the server detection unit 3330 is connected to the input of the data locking unit 3331, and the output of the data locking unit 3331 is connected to the input of the permission locking unit 3332.
[0055] The information monitoring system 11 includes a detection unit 111, an information extraction unit 112, an information judgment unit 113, and a preprocessing unit 114;
[0056] The output of the detection unit 111 is connected to the input of the information extraction unit 112, the output of the information extraction unit 112 is connected to the input of the information determination unit 113, and the output of the information determination unit 113 is connected to the input of the preprocessing unit 114.
[0057] The information processing system 22 includes a parsing unit 221, a judgment unit 222, a data processing unit 223, a blocking unit 224, and a data storage unit 225;
[0058] The output of the parsing unit 221 is connected to the input of the judgment unit 222, the output of the judgment unit 222 is connected to the input of the data processing unit 223, the output of the data processing unit 223 is connected to the input of the blocking unit 224, and the output of the blocking unit 224 is connected to the input of the data storage unit 225.
[0059] The inspection system 44 includes a DNS extension unit 441, a DNS monitoring unit 442, and an update unit 443;
[0060] The output of DNS extension unit 441 is connected to the input of DNS monitoring unit 442, and the output of DNS monitoring unit 442 is connected to the input of update unit 443.
[0061] This invention also discloses a network security analysis method, which, based on the aforementioned network security analysis system, specifically includes the following steps:
[0062] S1. Based on the information monitoring system 11, the domain name is continuously monitored, and the extracted information is judged to determine whether there are any abnormal redirects or content changes, so as to promptly detect any possible security issues or illegal use.
[0063] S2. Through the information processing system 22, the obtained domain name information is resolved. When the domain name is hijacked or misused, the normal resolution of the domain name is restored in a timely manner, illegal use is prevented, and the operation data is stored to prevent loss.
[0064] S3, based on the emergency handling system 33, can promptly alert when a domain hijacking event occurs, and lock the stored data values and control permissions to prevent data loss or theft. At the same time, it can automatically log in to the control panel through the DNS change unit 335 to change the DNS records and point them to the correct server IP address.
[0065] S4. Based on the inspection system 44, the DNS extension unit 441 provides an additional security layer for DNS queries, ensuring that the returned information has not been tampered with, and regularly monitors DNS queries and responses in order to detect abnormal behavior in a timely manner.
[0066] Furthermore, any content not described in detail in this specification is existing technology known to those skilled in the art.
[0067] The foregoing has provided a detailed description of one embodiment of the present invention, but this description is merely a preferred embodiment and should not be construed as limiting the scope of the invention. All equivalent variations and modifications made within the scope of the present invention should still fall within the scope of the present invention.
Claims
1. A network security analysis system based on a domain name monitoring mechanism, characterized in that: It includes an information monitoring system (11), an information processing system (22), an emergency response system (33), and an inspection system (44). The output of the information monitoring system (11) is connected to the input of the information processing system (22), the output of the information processing system (22) is connected to the input of the emergency response system (33), and the output of the emergency response system (33) is connected to the input of the inspection system (44). The emergency response system (33) includes an alert unit (331), a data recording unit (332), a locking unit (333), a control recovery unit (334), a DNS change unit (335), and a security review unit (336). The output of the warning unit (331) is connected to the input of the data recording unit (332), the output of the data recording unit (332) is connected to the input of the locking unit (333), the output of the locking unit (333) is connected to the input of the control recovery unit (334), the output of the control recovery unit (334) is connected to the input of the DNS change unit (335), and the output of the DNS change unit (335) is connected to the input of the security review unit (336). The locking unit (333) includes a server detection unit (3330), a data locking unit (3331), and a permission locking unit (3332). The output of the server detection unit (3330) is connected to the input of the data locking unit (3331), and the output of the data locking unit (3331) is connected to the input of the permission locking unit (3332). The emergency response system (33) can provide timely warnings when a domain hijacking incident occurs and lock the stored data values and control permissions to prevent data loss or theft. At the same time, it can automatically log in to the control panel through the DNS change unit (335) to change the DNS records and point to the correct server IP address. The information monitoring system (11) includes a detection unit (111), an information extraction unit (112), an information determination unit (113), and a preprocessing unit (114). The output of the detection unit (111) is connected to the input of the information extraction unit (112), the output of the information extraction unit (112) is connected to the input of the information determination unit (113), and the output of the information determination unit (113) is connected to the input of the preprocessing unit (114). The information processing system (22) includes a parsing unit (221), a judgment unit (222), a data processing unit (223), a blocking unit (224), and a data storage unit (225). The output of the parsing unit (221) is connected to the input of the judgment unit (222), the output of the judgment unit (222) is connected to the input of the data processing unit (223), the output of the data processing unit (223) is connected to the input of the blocking unit (224), and the output of the blocking unit (224) is connected to the input of the data storage unit (225).
2. The network security analysis system based on a domain name monitoring mechanism according to claim 1, characterized in that: The inspection system (44) includes a DNS extension unit (441), a DNS monitoring unit (442), and an update unit (443).
3. The network security analysis system based on a domain name monitoring mechanism according to claim 2, characterized in that: The output of the DNS extension unit (441) is connected to the input of the DNS monitoring unit (442), and the output of the DNS monitoring unit (442) is connected to the input of the update unit (443).
4. A network security analysis method, based on the network security analysis system according to any one of claims 1-3, characterized in that, Specifically, the following steps are included: S1. Based on the information monitoring system (11), the domain name is continuously monitored, and the extracted information is judged to determine whether there is any abnormal redirection or content change, so as to discover any possible security problems or illegal use in a timely manner. S2. The information processing system (22) resolves the obtained domain name information. When the domain name is hijacked or misused, the system restores the normal resolution of the domain name in a timely manner, prevents illegal use, and stores the operation data to prevent loss. S3. Based on the emergency handling system (33), it can promptly warn when a domain hijacking event occurs and lock the stored data values and control permissions to prevent data loss or theft. At the same time, it can automatically log in to the control panel through the DNS change unit (335) to change the DNS record and point to the correct server IP address. S4. Based on the inspection system (44), the DNS extension unit (441) provides an additional security layer for DNS queries, ensuring that the returned information is not tampered with, and regularly monitors DNS queries and responses in order to detect abnormal behavior in a timely manner.
Citation Information
Patent Citations
Domain-based network security detection methods
CN114844722B
Method and system for realizing website falsification-proof
CN101605068A
Authoritative name emergency resolution system and method based on recursive server
CN105391818A
Information transmission method and device, computer equipment and storage medium
CN116633701A