Methods, devices, electronic equipment, and storage media for handling DDoS attacks

By building a highly secure backup link between recursive DNS and top-level DNS and switching over it during DDoS attacks, the problem of top-level DNS service interruption under attack is solved, ensuring the normal operation of DNS.

CN119155097BActive Publication Date: 2025-11-14CHINA TELECOM CORP LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411435033.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-10-14
Publication Date
2025-11-14
Estimated Expiration
2044-10-14

AI Technical Summary

Technical Problem

In existing technologies, DDoS attacks cause top-level DNS to be unable to provide services normally. Existing network security measures cannot effectively distinguish between legitimate and malicious traffic, resulting in legitimate access being blocked incorrectly, and performance is limited under high-traffic attacks.

Method used

A highly secure and reliable backup link is established between the recursive DNS and the top-level DNS, and the system quickly switches to the backup link during DDoS attacks to ensure that the service resources of the top-level DNS are not consumed.

Benefits of technology

It enables top-level DNS to continue providing services normally under DDoS attacks, avoiding service interruption and enhancing the ability to respond to complex DDoS attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119155097B_ABST
    Figure CN119155097B_ABST
Patent Text Reader

Abstract

This application discloses a method, apparatus, electronic device, and storage medium for handling DDoS attacks, belonging to the field of network security technology. In this method, after a DDoS attack occurs on the top-level DNS (TLD), the control terminal receives a link switching request. Then, it queries the first agent for the link used by the recursive DNS to the TLD. If it is determined that the link used by the recursive DNS is a regular link, a link switching instruction is sent to the first agent to switch the regular link used by the recursive DNS to a backup link to the TLD. The service resources of the TLD corresponding to the backup link and the regular link are different. Thus, when the TLD encounters a DDoS attack, only the service resources corresponding to the regular link are consumed, without affecting the service resources corresponding to the backup link. Therefore, after switching the link used by the recursive DNS from a regular link to a backup link, the TLD can still provide normal service to the recursive DNS.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network security technology, and in particular to a method, apparatus, electronic device and storage medium for handling DDoS attacks. Background Technology

[0002] In recent years, attackers have been increasing the scale and intensity of their attacks on top-level domains. Taking the top-level domain ".cn" as an example, its outbound bandwidth is usually within 1Gbps, which means that the top-level domain name system (DNS) can handle a maximum of about 1Gbps of data traffic.

[0003] In related technologies, network security measures against domain name resolution systems are mainly edge-based anti-DDoS attack methods, such as firewalls and intrusion detection systems (IDS). These methods often rely on preset rules to block unauthorized access, but they cannot effectively distinguish between legitimate and malicious network traffic. If the rules are not set properly, legitimate access may be blocked incorrectly, which is insufficient to defend against large-scale DDoS attacks. At the same time, their performance limitations make them vulnerable to high-volume attacks. Summary of the Invention

[0004] This application provides a method, apparatus, electronic device, and storage medium for handling DDoS attacks, in order to solve the problem in the related art that DDoS attacks can prevent top-level DNS from providing normal services.

[0005] In a first aspect, embodiments of this application provide a method for handling DDoS attacks, including:

[0006] The control terminal receives a link switching request, which is triggered after a DDoS attack occurs in the top-level DNS.

[0007] Send a first link query request to the first agent, the first link query request being used to query the links between the recursive DNS and the top-level DNS, the first agent being deployed on the recursive DNS;

[0008] Receive the first link information sent by the first agent;

[0009] If, based on the first link information, it is determined that the recursive DNS is using a regular link, a link switching instruction is sent to the first agent to switch the regular link used by the recursive DNS to a backup link between the top-level DNS and the backup link. The service resources of the top-level DNS corresponding to the regular link are different.

[0010] Secondly, embodiments of this application provide a method for handling DDoS attacks, including:

[0011] The first agent receives a first link query request, which is used to query the links between the recursive DNS and the top-level DNS. The first link query request is sent by the control terminal after receiving a link switching request. The link switching request is triggered after a DDoS attack occurs on the top-level DNS. The first agent is deployed on the recursive DNS.

[0012] Send the first link information to the control terminal;

[0013] The control terminal receives a link switching request, which is sent by the control terminal after determining, based on the first link information, that the recursive DNS is using a regular link.

[0014] The regular link used by the recursive DNS is switched to an alternative link between the top-level DNS and the recursive DNS. The service resources of the top-level DNS corresponding to the alternative link and the regular link are different.

[0015] Thirdly, embodiments of this application provide a DDoS attack processing apparatus, comprising:

[0016] The first receiving module is used to receive a link switching request, which is triggered after a DDoS attack occurs in the top-level DNS.

[0017] The first sending module is used to send a first link query request to the first agent. The first link query request is used to query the links between the recursive DNS and the top-level DNS. The first agent is deployed on the recursive DNS.

[0018] The second receiving module is used to receive the first link information sent by the first agent;

[0019] The second sending module is configured to send a link switching instruction to the first agent if it is determined based on the first link information that the recursive DNS is using a regular link, so as to switch the regular link used by the recursive DNS to a backup link between the top-level DNS and the backup link and the regular link, wherein the service resources of the top-level DNS corresponding to the backup link and the regular link are different.

[0020] Fourthly, embodiments of this application provide a DDoS attack processing apparatus, comprising:

[0021] The first receiving module is used to receive a first link query request. The first link query request is used to query the links between the recursive DNS and the top-level DNS. The first link query request is sent by the control terminal after receiving the link switching request. The link switching request is triggered after a DDoS attack occurs in the top-level DNS. The first proxy is deployed on the recursive DNS.

[0022] The first sending module is used to send the first link information to the control terminal;

[0023] The second receiving module is used to receive the link switching request sent by the control terminal. The link switching request is sent by the control terminal after determining, based on the first link information, that the recursive DNS is using a regular link.

[0024] The second sending module is used to switch the regular link used by the recursive DNS to an alternative link between the top-level DNS and the regular link, wherein the service resources of the top-level DNS corresponding to the alternative link and the regular link are different.

[0025] Fifthly, embodiments of this application provide an electronic device, including: at least one processor, and a memory communicatively connected to the at least one processor, wherein:

[0026] The memory stores a computer program that can be executed by at least one processor, which enables the at least one processor to perform any of the above-described methods for handling DDoS attacks.

[0027] Sixthly, embodiments of this application provide a storage medium in which, when a computer program in the storage medium is executed by a processor of an electronic device, the electronic device is capable of executing any of the above-described methods for handling DDoS attacks.

[0028] In a seventh aspect, embodiments of this application provide a computer program product, including a computer program, which, when executed by a processor, implements a method for processing any of the aforementioned DDoS attacks.

[0029] In this embodiment, after a DDoS attack occurs on the top-level DNS, the control terminal receives a link switching request. It then queries the first proxy for the link used by the recursive DNS to the top-level DNS. If it determines that the link used by the recursive DNS is a regular link, it sends a link switching instruction to the first proxy to switch the regular link used by the recursive DNS to a backup link to the top-level DNS. The service resources of the top-level DNS corresponding to the backup link and the regular link are different. This effectively divides the service resources of the top-level DNS into two parts: one corresponding to the regular link and the other to the backup link. When the top-level DNS encounters a DDoS attack, only the service resources corresponding to the regular link are consumed, without affecting the service resources corresponding to the backup link. Therefore, after switching the link used by the recursive DNS from the regular link to the backup link, the top-level DNS can still provide normal service to the recursive DNS. Attached Figure Description

[0030] The accompanying drawings, which are included to provide a further understanding of this application and form part of this application, illustrate exemplary embodiments and are used to explain this application, but do not constitute an undue limitation of this application. In the drawings:

[0031] Figure 1 A schematic diagram illustrating a DDoS attack scenario provided in an embodiment of this application;

[0032] Figure 2 A flowchart illustrating a method for handling DDoS attacks provided in this application embodiment;

[0033] Figure 3 A flowchart illustrating yet another method for handling DDoS attacks provided in this application embodiment;

[0034] Figure 4 A schematic diagram illustrating a scenario for a DDoS attack handling method provided in an embodiment of this application;

[0035] Figure 5 A schematic diagram of a DDoS attack processing device provided in an embodiment of this application;

[0036] Figure 6 A schematic diagram of the structure of another DDoS attack processing device provided in the embodiments of this application;

[0037] Figure 7 This is a schematic diagram of the hardware structure of an electronic device for implementing a DDoS attack processing method, as provided in an embodiment of this application. Detailed Implementation

[0038] To address the problem that DDoS attacks can prevent top-level DNS from providing normal services in related technologies, embodiments of this application provide a method, apparatus, electronic device, and storage medium for handling DDoS attacks.

[0039] The preferred embodiments of this application are described below with reference to the accompanying drawings. It should be understood that the preferred embodiments described herein are for illustration and explanation only and are not intended to limit this application. Furthermore, the embodiments and features in the embodiments of this application can be combined with each other without conflict.

[0040] For ease of understanding, the technical terms used in this application are as follows:

[0041] Backbone network: refers to the high-speed, high-capacity network connecting the major nodes in the Internet. It is usually built and maintained by operators. The backbone network is the main transmission channel of the Internet and is responsible for carrying a large amount of data exchange on the Internet.

[0042] Intrusion Detection System (IDS): A network security system that monitors network transmissions and issues alerts or takes proactive measures when suspicious transmissions are detected.

[0043] Domain Name System (DNS): A distributed database system used to manage the mapping relationship between domain names and IP addresses. A DNS server is a host that provides domain name resolution services to users.

[0044] Top-Level DNS: This refers to the DNS servers responsible for managing top-level domains (TLDs) on the Internet, such as .com, .org, and .net. Each TLD has one or more authoritative DNS servers responsible for responding to domain name query requests under that TLD.

[0045] Authoritative DNS: The ultimate authoritative source for a domain name. It stores the DNS records for a specific domain name, including the IP address corresponding to the domain name, and other DNS record types that may be needed. When a recursive DNS server finds the authoritative DNS server responsible for a specific domain name through the TLD server, it queries that authoritative DNS server for the specific information of the required domain name.

[0046] Recursive DNS acts as a proxy between clients and other DNS servers, helping to resolve domain name requests. When a client sends a query to a recursive DNS server, the server begins recursively querying upwards, seeking the authoritative or top-level DNS server until it obtains the answer, which it then returns to the client.

[0047] Distributed Denial of Service (DDoS) is a type of cyberattack where attackers use a large number of compromised "bottom hosts" to send a barrage of requests to a target system, such as a top-level DNS server. This causes the target system to run out of resources, making it unable to provide services to legitimate users. This type of attack is characterized by its distributed nature, high degree of stealth, and difficulty in tracing.

[0048] With the rapid development of the Internet, DNS has become an important part of network infrastructure services. However, DNS faces a variety of security threats, such as DDoS attacks. DDoS attacks can easily spread across different networks around the world, making it difficult to quickly identify and block the attack source. Furthermore, attack requests not only consume server processing power but may also fill up the bandwidth of the entire network, making it impossible for legitimate DNS query requests to be responded to, thus causing service interruption.

[0049] In recent years, attackers have been increasing the scale and intensity of their attacks on top-level domains. Taking the top-level domain ".cn" as an example, its outbound bandwidth is usually within 1Gbps, which means that the top-level domain name system (DNS) can handle a maximum of about 1Gbps of data traffic.

[0050] In related technologies, network security measures against domain name resolution systems are mainly edge-based anti-DDoS attack methods, such as firewalls and intrusion detection systems (IDS). These methods often rely on preset rules to block unauthorized access, but they cannot effectively distinguish between legitimate and malicious network traffic. If the rules are not set properly, legitimate access may be blocked incorrectly, which is insufficient to defend against large-scale DDoS attacks. At the same time, their performance limitations make them vulnerable to high-volume attacks.

[0051] See Figure 1 , Figure 1 The present application provides a scenario diagram of a DDoS attack, including a recursive DNS, a backbone network, and a top-level DNS. The backbone network is used to provide network transmission services for multiple user terminals. Each user terminal can send a domain name resolution request to the recursive DNS. The recursive DNS interacts with the top-level DNS through the backbone network to obtain the domain name resolution result and sends the domain name resolution result to the user terminal. Then, the user terminal accesses the top-level DNS through the backbone network based on the domain name resolution result.

[0052] When a top-level DNS (TLD) is subjected to a DDoS attack, a large number of packets will arrive at the TLD, exhausting its service resources such as network interface cards (NICs). This prevents the TLD from providing normal services to the recursive DNS. In addition, there may also be a large number of attack packets on the backbone network.

[0053] Therefore, in this embodiment of the application, a dedicated and covert backup link with high security and high reliability is constructed between the recursive DNS and the top-level DNS. Since the service resources of the top-level DNS corresponding to the backup link and the regular link are different, the DDoS attack will only consume the service resources corresponding to the regular link, without affecting the service resources corresponding to the backup link. Therefore, when the top-level domain DNS faces a DDoS attack, the link between the recursive DNS and the top-level DNS is quickly switched to the backup link, and the top-level DNS can still provide normal services to the recursive DNS. This solution is not limited by the scale and size of the attack and can ensure that the domain name resolution service is not interrupted from the source.

[0054] After introducing the application scenarios of the embodiments of this application, the processing of DDoS attacks proposed in this application will be described below with specific embodiments.

[0055] Figure 2 A flowchart of a DDoS attack handling method provided in this application embodiment, the method including the following steps.

[0056] In step 201, a link switching request is received, which is triggered after a DDoS attack occurs in the top-level DNS.

[0057] In practice, detection nodes for DDoS attacks can be deployed at both the top-level DNS and backbone network ends. The detection nodes at the top-level DNS end can react quickly when the link performance fails, and can also avoid situations where the response is not timely due to the excessive detection time overhead on the backbone network side in some cases. The detection nodes at the backbone network end can start detecting before the DDoS attack paralyzes the top-level DNS, and can also detect DDoS attacks that do not affect the top-level domain device itself (which is difficult to detect on the top-level DNS side) but will cause link failure. In this way, the linkage between the two sides can identify DDoS attacks as accurately as possible, thereby providing more accurate link switching decisions.

[0058] Therefore, a link switching request can be sent by a second proxy deployed on the top-level DNS after determining that the packet processing load of the top-level DNS matches the load characteristics when a DDoS attack occurs, or it can be sent by a third proxy deployed on the corresponding network device on the backbone network after determining that the network traffic transmitted on the backbone network matches the traffic characteristics when a DDoS attack occurs on the top-level DNS.

[0059] In step 202, a first link query request is sent to the first agent. The first link query request is used to query the links between the recursive DNS and the top-level DNS. The first agent is deployed on the recursive DNS.

[0060] To avoid accidental switching, you can first check the links between the current recursive DNS and the top-level DNS.

[0061] In step 203, the first link information sent by the first agent is received.

[0062] The first link information includes link identifier and link number.

[0063] In step 204, if it is determined based on the first link information that the recursive DNS is using a regular link, a link switching instruction is sent to the first agent to switch the regular link used by the recursive DNS to a backup link between the top-level DNS and the backup link. The service resources of the top-level DNS corresponding to the regular link are different.

[0064] Among them, the regular link can also be called the first link, the backup link can also be called the second link, and the top-level DNS service resources are such as network cards.

[0065] In step 205, a link recovery request is received, which is triggered after the DDoS attack on the top-level DNS is resolved.

[0066] The link recovery request may include a first link recovery request and a second link recovery request. The first link recovery request may be a load alarm cancellation message sent by a second agent, and the second link recovery request may be a network alarm cancellation message sent by a third agent.

[0067] In other words, link restoration can only proceed once both the top-level DNS server and the backbone network have confirmed that the DDoS attack has been resolved. This ensures the legitimacy of the link restoration process.

[0068] In step 206, a second link query request is sent to the first agent. The second link query request is used to query the links between the recursive DNS and the top-level DNS.

[0069] To avoid accidental recovery, you can first check the links between the current recursive DNS and the top-level DNS.

[0070] In step 207, the second link information sent by the first agent is received.

[0071] The second link information includes link identifier and link number.

[0072] In step 208, if it is determined based on the second link information that the recursive DNS is using a backup link, a link recovery instruction is sent to the first agent to restore the backup link used by the recursive DNS to a regular link.

[0073] See Figure 3 , Figure 3 A flowchart of another DDoS attack handling method provided in this application embodiment, the method including the following steps.

[0074] In step 301, a first link query request is received. The first link query request is used to query the link between the recursive DNS and the top-level DNS. The first link query request is sent by the control terminal after receiving the link switching request. The link switching request is triggered after a DDoS attack occurs on the top-level DNS. The first proxy is deployed on the recursive DNS.

[0075] In step 302, the first link information is sent to the control terminal.

[0076] Here, the first link information of the currently used inter-top-level DNS link is sent to the control end.

[0077] In step 303, a link switching request is received from the control terminal. The link switching request is sent by the control terminal after determining, based on the first link information, that the recursive DNS is using a regular link.

[0078] In step 304, the regular link used by the recursive DNS is switched to an alternative link to the top-level DNS. The service resources of the top-level DNS corresponding to the alternative link and the regular link are different.

[0079] In step 305, a second link query request is received. The second link query request is used to query the link between the recursive DNS and the top-level DNS. The second link query request is sent by the control end after receiving the link recovery request. The link recovery request is triggered after the DDoS attack on the top-level DNS is resolved.

[0080] In step 306, the second link information is sent to the control terminal.

[0081] Here, the control end sends the second link information of the currently used inter-top-level DNS link.

[0082] In step 307, a link recovery instruction is received. The link recovery instruction is sent by the control terminal after determining, based on the second link information, that the recursive DNS is using a regular link.

[0083] In step 308, the backup link used by the recursive DNS is restored to a regular link.

[0084] This application provides a recursive top-level domain name service protection scheme with end-to-end network collaboration. Specifically, by deploying detection nodes for DDoS attack detection at both the top-level DNS and backbone network ends, accurate link switching decisions based on multi-source information are achieved. This is because the top-level DNS can react quickly to link performance failures, avoiding delays caused by excessive detection time on the backbone network in some cases. The backbone network can begin detection before a DDoS attack paralyzes the top-level DNS, and can also detect DDoS attacks that do not affect the top-level DNS itself (which the top-level DNS may find difficult to detect) but still cause link failures. Simultaneously, a backup link is constructed between the recursive DNS and the top-level DNS to create a covert, secure, and highly reliable emergency backup channel for the top-level domain, serving as a transfer channel when the top-level domain suffers a DDoS attack.

[0085] See Figure 4 , Figure 4 This is a schematic diagram illustrating a DDoS attack handling method provided in an embodiment of this application. The components in this solution include a recursive DNS, a top-level DNS, a control terminal (which can be a link control program), a backbone network traffic detection program (Traffic-Agent), a recursive server control program (DNS-Agent), a recursive server monitoring program (Load-Agent), and a regular link and a backup link running between the recursive DNS and the top-level DNS, each requiring initial configuration. The Load-Agent, as an end-side detection agent, can take various forms, including but not limited to programs running on the device, IDS, etc.

[0086] The following is combined with Figure 4 The solutions of the embodiments of this application will be described.

[0087] Step 1. Environment setup and module initialization.

[0088] Step 1.1 Communication Link Construction. Establish a communication link between the recursive DNS and the top-level DNS to be protected. The communication link includes a regular link and a backup link.

[0089] The regular link provides standard DNS query and response services, while the backup link needs to be specially designed to have higher security and stealth. For example, it can use Multiprotocol Label Switching (MPLS), Segment Routing IPv6 (SRv6) based on the IPv6 forwarding plane, GPRS Tunnelling Protocol (GTP), or other Virtual Private Network (VPN) technologies to provide dedicated line services that are isolated from the network traffic of the regular link. This ensures that the backup link has sufficient bandwidth and low latency to serve as an alternative link during high-traffic attacks.

[0090] Step 1.2 Initialize Traffic-Agent, configure traffic collection information, and monitor network traffic of the top-level DNS in order to detect abnormal traffic in a timely manner.

[0091] Step 1.3 Initialize DNS-Agent and start listening for link switching control commands from the control terminal; initialize the control terminal, start listening for link switching requests from Load-Agent, and run Load-Agent.

[0092] Step 2. When a DDoS attack occurs, a link switching request is generated, including the following two situations.

[0093] Step 2.1 Network Alarm: Traffic Alarm from Traffic-Agent. Leveraging the operator's advantage in acquiring network traffic on the backbone network, the network traffic of the top-level DNS is analyzed from a network perspective. Using either a static or dynamic baseline method, combined with a pre-trained anomaly detection model, abnormal traffic matching the characteristics of a DDoS attack is identified. If Traffic-Agent determines that the network traffic is abnormal DDoS attack traffic, a traffic alarm is generated, and a link switching request is sent to the control terminal.

[0094] Step 2.2 Load Alarm: Load alarm from Load-Agent. Load-Agent runs as a program on the top-level DNS server, acquiring real-time network interface card (NIC) information for regular links of the top-level DNS, including but not limited to NIC load, number of active connections, number of new connections, and NIC throughput increment. It uses machine learning models (including but not limited to time-series-based anomaly detection models or clustering algorithms) to comprehensively analyze multi-dimensional data. When the machine learning model shows that the current load matches the load characteristics during a DDoS attack, it determines that the top-level DNS server is under DDoS attack, thereby generating a load alarm and sending a link switching request to the link control program.

[0095] Step 3. Link switching.

[0096] Step 3.1 Status Query. The control terminal first queries the DNS-Agent for the link currently used by the recursive DNS. If it is already operating on the backup link, then Step 3 is completed. Here, the control terminal can listen for and process link switching and recovery requests from Traffic-Agent and Load-Agent according to their status. It can also use a specified protocol (such as OpenFlow, netconf, or a custom control protocol) to complete link status queries and issue session link switching operation commands to the DNS-Agent session.

[0097] Step 3.2 If the current recursive DNS is using a regular link, then notify the DNS-Agent to switch to an alternative link.

[0098] Step 3.3 The DNS-Agent responds to the switching instruction, updates the enabled link in the recursive DNS configuration file to the standby link, and restarts the DNS service program, thereby switching the link to the standby link to provide service for ongoing legitimate DNS queries.

[0099] Step 4. After switching to the backup link, Traffic-Agent and Load-Agent continue to run to detect whether the regular link has been restored.

[0100] Step 4.1 Since Load-Agent is closer to the top-level DNS, Load-Agent is the first to detect whether the link has been restored. Therefore, Load-Agent will usually send a first link restoration request to the control end. After Traffic-Agent detects that the DDoS attack has been resolved, it will send a second link restoration request to the control end.

[0101] Step 4.2 After receiving the first link recovery request and the second link recovery request, the control terminal queries the DNS-Agent for the link currently used by the recursive DNS. If the link has been restored to a normal link, then step 4 is completed.

[0102] Step 4.3 If the backup link is still in use, the DNS-Agent will be notified to switch back to the regular link. The DNS-Agent will then perform the corresponding configuration changes, restart the service, and complete the link recovery.

[0103] This application provides a method for ensuring domain name service through recursive top-level linkage between endpoints and networks, which can achieve the following beneficial effects:

[0104] 1. By implementing collaborative detection between the top-level domain device end-side and the backbone network side, a global perspective and multi-point monitoring are achieved during DDoS attacks, ensuring that the top-level domain DNS service can quickly switch to the backup link under attack, avoiding service interruption caused by DDoS attacks;

[0105] 2. By linking recursive DNS and top-level DNS, a highly secure and reliable dedicated and covert backup link is built, enabling a rapid switch to a preset secure link when the top-level domain DNS faces a DDoS attack, without being limited by the scale or size of the attack, thus ensuring domain name resolution services from the source.

[0106] 3. By making precise link switching decisions based on multi-source information, the efficiency and accuracy of attack detection have been greatly improved. Automated monitoring and rapid response have been achieved throughout the entire process from attack occurrence and duration to resolution and recovery, significantly enhancing the top-level domain DNS's ability to cope with increasingly complex DDoS attacks.

[0107] Based on the same technical concept, this application also provides a DDoS attack processing device. The principle of the DDoS attack processing device in solving the problem is similar to the above-mentioned DDoS attack processing method. Therefore, the implementation of the DDoS attack processing device can refer to the implementation of the DDoS attack processing method, and the repeated parts will not be described again.

[0108] Figure 5 A schematic diagram of a DDoS attack processing device provided in this application embodiment includes:

[0109] The first receiving module 501 is used to receive a link switching request, which is triggered after a DDoS attack occurs in the top-level DNS.

[0110] The first sending module 502 is used to send a first link query request to the first agent. The first link query request is used to query the links between the recursive DNS and the top-level DNS. The first agent is deployed on the recursive DNS.

[0111] The second receiving module 503 is used to receive the first link information sent by the first agent;

[0112] The second sending module 504 is configured to send a link switching instruction to the first agent if it is determined based on the first link information that the recursive DNS is using a regular link, so as to switch the regular link used by the recursive DNS to a backup link between the top-level DNS and the backup link and the regular link. The service resources of the top-level DNS corresponding to the backup link and the regular link are different.

[0113] In some embodiments, the link switching request is sent by a second agent after determining that the packet processing load of the top-level DNS matches the load characteristics during a DDoS attack, and the second agent is deployed on the top-level DNS; or, the link switching request is sent by a third agent after determining that the network traffic transmitted on the backbone matches the traffic characteristics during a DDoS attack, and the third agent is deployed on the network device corresponding to the backbone.

[0114] In some embodiments, the first receiving module 501 is further configured to receive a link recovery request, which is triggered after the DDoS attack on the top-level DNS is resolved.

[0115] The first sending module 502 is further configured to send a second link query request to the first agent, the second link query request being used to query the links between the recursive DNS and the top-level DNS;

[0116] The second receiving module 503 is also used to receive the second link information sent by the first agent;

[0117] The second sending module 504 is further configured to, if based on the second link information, determine that the recursive DNS is using the backup link, then send a link recovery instruction to the first agent to restore the backup link used by the recursive DNS to the regular link.

[0118] In some embodiments, the link recovery request includes a first link recovery request and a second link recovery request. The first link recovery request is sent by the second agent after determining that the packet processing load of the top-level DNS does not match the load characteristics during the DDoS attack. The second link recovery request is sent by the third agent after determining that the network traffic transmitted on the backbone does not match the traffic characteristics during the DDoS attack.

[0119] Figure 6 A schematic diagram of another DDoS attack processing device provided in this application embodiment includes:

[0120] The first receiving module 601 is used to receive a first link query request. The first link query request is used to query the links between the recursive DNS and the top-level DNS. The first link query request is sent by the control terminal after receiving the link switching request. The link switching request is triggered after a DDoS attack occurs in the top-level DNS. The first proxy is deployed on the recursive DNS.

[0121] The first sending module 602 is used to send first link information to the control terminal;

[0122] The second receiving module 603 is used to receive a link switching request sent by the control terminal. The link switching request is sent by the control terminal after determining, based on the first link information, that the recursive DNS is using a regular link.

[0123] The second sending module 604 is used to switch the regular link used by the recursive DNS to an alternative link between the top-level DNS and the regular link, wherein the service resources of the top-level DNS corresponding to the alternative link and the regular link are different.

[0124] In some embodiments, the first receiving module 601 is further configured to receive a second link query request, the second link query request being used to query the links between the recursive DNS and the top-level DNS, the second link query request being sent by the control terminal after receiving a link recovery request, the link recovery request being triggered after the DDoS attack on the top-level DNS is resolved;

[0125] The first sending module 602 is also used to send second link information to the control terminal;

[0126] The second receiving module 603 is also used to receive a link recovery instruction, which is sent by the control terminal after determining, based on the second link information, that the recursive DNS is using the regular link;

[0127] The second sending module 604 is further configured to restore the backup link used by the recursive DNS to the regular link.

[0128] The module division in this application embodiment is illustrative and only represents one logical functional division. In actual implementation, other division methods are possible. Furthermore, the functional modules in each embodiment of this application can be integrated into a single processor, exist as separate physical entities, or be integrated into a single module. Coupling between modules can be achieved through interfaces, typically electrical communication interfaces, but mechanical interfaces or other types of interfaces are also possible. Therefore, modules described as separate components may or may not be physically separate; they can be located in one place or distributed across different locations on the same or different devices. The integrated modules described above can be implemented in hardware or as software functional modules.

[0129] Having introduced the DDoS attack processing method and apparatus according to exemplary embodiments of this application, we will now introduce an electronic device according to another exemplary embodiment of this application.

[0130] The following reference Figure 7 To describe an electronic device 130 implemented according to this embodiment of the present application. Figure 7 The electronic device 130 shown is merely an example and should not impose any limitations on the functionality and scope of use of the embodiments of this application.

[0131] like Figure 7 As shown, the electronic device 130 is presented in the form of a general-purpose electronic device. The components of the electronic device 130 may include, but are not limited to: at least one processor 131, at least one memory 132, and a bus 133 connecting different system components (including memory 132 and processor 131).

[0132] Bus 133 represents one or more of several bus structures, including a memory bus or memory controller, peripheral bus, processor, or local bus using any of the various bus structures.

[0133] The memory 132 may include a readable medium in the form of volatile memory, such as random access memory (RAM) 1321 and / or cache memory 1322, and may further include read-only memory (ROM) 1323.

[0134] The memory 132 may also include a program / utility 1325 having a set (at least one) of program modules 1324, including but not limited to: an operating system, one or more application programs, other program modules, and program data, each or some combination of these examples may include an implementation of a network environment.

[0135] Electronic device 130 can also communicate with one or more external devices 134 (e.g., keyboard, pointing device, etc.), and with one or more devices that enable a user to interact with electronic device 130, and / or with any device that enables electronic device 130 to communicate with one or more other electronic devices (e.g., router, modem, etc.). This communication can be performed via input / output (I / O) interface 135. Furthermore, electronic device 130 can also communicate with one or more networks (e.g., local area network (LAN), wide area network (WAN), and / or public networks, such as the Internet) via network adapter 136. As shown, network adapter 136 communicates with other modules used in electronic device 130 via bus 133. It should be understood that, although not shown in the figures, other hardware and / or software modules can be used in conjunction with electronic device 130, including but not limited to: microcode, device drivers, redundant processors, external disk drive arrays, RAID systems, tape drives, and data backup storage systems.

[0136] In an exemplary embodiment, a storage medium is also provided, which, when executed by a processor of an electronic device, enables the electronic device to perform the aforementioned DDoS attack handling method. Optionally, the storage medium may be a non-transitory computer-readable storage medium, such as a ROM, random access memory (RAM), CD-ROM, magnetic tape, floppy disk, and optical data storage device.

[0137] In an exemplary embodiment, the electronic device of this application may include at least one processor and a memory communicatively connected to the at least one processor, wherein the memory stores a computer program that can be executed by the at least one processor, and when the computer program is executed by the at least one processor, it can cause the at least one processor to perform the steps of any DDoS attack handling method provided in the embodiments of this application.

[0138] In an exemplary embodiment, a computer program product is also provided, which, when executed by an electronic device, enables the electronic device to implement any of the exemplary methods provided in this application.

[0139] Furthermore, computer program products may employ any combination of one or more readable media. A readable medium may be a readable signal medium or a readable storage medium. A readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of readable storage media (a non-exhaustive list) include: electrical connections having one or more wires, portable disks, hard disks, RAM, ROM, erasable programmable read-only memory (EPROM), flash memory, optical fiber, compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof.

[0140] The program product for handling DDoS attacks in the embodiments of this application may be a CD-ROM and include program code, and may run on a computing device. However, the program product of this application is not limited thereto. In this document, the readable storage medium may be any tangible medium that contains or stores a program, which may be used by or in conjunction with an instruction execution system, apparatus, or device.

[0141] A readable signal medium may include a data signal propagated in baseband or as part of a carrier wave, carrying readable program code. This propagated data signal may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. A readable signal medium may also be any readable medium other than a readable storage medium, capable of sending, propagating, or transmitting a program for use by or in conjunction with an instruction execution system, apparatus, or device.

[0142] The program code contained on the readable medium may be transmitted using any suitable medium, including but not limited to wireless, wired, optical fiber, radio frequency (RF), or any suitable combination thereof.

[0143] Program code for performing the operations of this application can be written in any combination of one or more programming languages, including object-oriented programming languages ​​such as Java and C++, as well as conventional procedural programming languages ​​such as C or similar languages. The program code can execute entirely on the user's computing device, partially on the user's computing device, as a standalone software package, partially on the user's computing device and partially on a remote computing device, or entirely on a remote computing device or server. In cases involving remote computing devices, the remote computing device can be connected to the user's computing device via any type of network, such as a Local Area Network (LAN) or a Wide Area Network (WAN), or it can be connected to an external computing device (e.g., via the Internet using an Internet service provider).

[0144] It should be noted that although several units or sub-units of the device have been mentioned in the detailed description above, this division is merely exemplary and not mandatory. In fact, according to embodiments of this application, the features and functions of two or more units described above can be embodied in one unit. Conversely, the features and functions of one unit described above can be further divided and embodied by multiple units.

[0145] Furthermore, although the operations of the method of this application are described in a specific order in the accompanying drawings, this does not require or imply that these operations must be performed in that specific order, or that all the operations shown must be performed to achieve the desired result. Additionally or alternatively, certain steps may be omitted, multiple steps may be combined into one step, and / or one step may be broken down into multiple steps.

[0146] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0147] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart... Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0148] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0149] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0150] Although preferred embodiments of this application have been described, those skilled in the art, upon learning the basic inventive concept, can make other changes and modifications to these embodiments. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments as well as all changes and modifications falling within the scope of this application.

[0151] Obviously, those skilled in the art can make various modifications and variations to this application without departing from the spirit and scope of this application. Therefore, if such modifications and variations fall within the scope of the claims of this application and their equivalents, then this application also includes such modifications and variations.

Claims

1. A method for handling DDoS attacks, characterized in that, include: The control terminal receives a link switching request, which is triggered after a DDoS attack occurs in the top-level DNS. Send a first link query request to the first agent, the first link query request being used to query the links between the recursive DNS and the top-level DNS, the first agent being deployed on the recursive DNS; Receive the first link information sent by the first agent; If, based on the first link information, it is determined that the recursive DNS is using a regular link, a link switching instruction is sent to the first agent to switch the regular link used by the recursive DNS to a backup link between the top-level DNS and the backup link. The service resources of the top-level DNS corresponding to the regular link are different.

2. The method as described in claim 1, characterized in that, The link switching request is sent by the second agent after determining that the packet processing load of the top-level DNS matches the load characteristics during a DDoS attack. The second agent is deployed on the top-level DNS. Alternatively, the link switching request is sent by the third agent after determining that the network traffic transmitted on the backbone matches the traffic characteristics during a DDoS attack. The third agent is deployed on the network device corresponding to the backbone.

3. The method as described in claim 2, characterized in that, Also includes: Receive a link recovery request, which is triggered after the DDoS attack on the top-level DNS is resolved; Send a second link query request to the first agent, the second link query request being used to query the links between the recursive DNS and the top-level DNS; Receive the second link information sent by the first agent; If, based on the second link information, it is determined that the recursive DNS is using the backup link, then a link recovery instruction is sent to the first agent to restore the backup link used by the recursive DNS to the regular link.

4. The method as described in claim 3, characterized in that, The link recovery request includes a first link recovery request and a second link recovery request. The first link recovery request is sent by the second agent after determining that the packet processing load of the top-level DNS does not match the load characteristics during the DDoS attack. The second link recovery request is sent by the third agent after determining that the network traffic transmitted on the backbone does not match the traffic characteristics during the DDoS attack.

5. A method for handling DDoS attacks, characterized in that, include: The first agent receives a first link query request, which is used to query the links between the recursive DNS and the top-level DNS. The first link query request is sent by the control terminal after receiving a link switching request. The link switching request is triggered after a DDoS attack occurs on the top-level DNS. The first agent is deployed on the recursive DNS. Send the first link information to the control terminal; The control terminal receives a link switching request, which is sent by the control terminal after determining, based on the first link information, that the recursive DNS is using a regular link. The regular link used by the recursive DNS is switched to an alternative link between the top-level DNS and the recursive DNS. The service resources of the top-level DNS corresponding to the alternative link and the regular link are different.

6. The method as described in claim 5, characterized in that, Also includes: The system receives a second link query request, which is used to query the links between the recursive DNS and the top-level DNS. The second link query request is sent by the control terminal after receiving a link recovery request, which is triggered after the DDoS attack on the top-level DNS is resolved. Send the second link information to the control terminal; The control terminal receives a link recovery instruction, which is sent after determining, based on the second link information, that the recursive DNS is using the regular link. Restore the backup link used by the recursive DNS to the regular link.

7. A DDoS attack defense device, applied to the control end, characterized in that, include: The first receiving module is used to receive a link switching request, which is triggered after a DDoS attack occurs in the top-level DNS. The first sending module is used to send a first link query request to the first agent. The first link query request is used to query the links between the recursive DNS and the top-level DNS. The first agent is deployed on the recursive DNS. The second receiving module is used to receive the first link information sent by the first agent; The second sending module is configured to send a link switching instruction to the first agent if it is determined based on the first link information that the recursive DNS is using a regular link, so as to switch the regular link used by the recursive DNS to a backup link between the top-level DNS and the backup link and the regular link, wherein the service resources of the top-level DNS corresponding to the backup link and the regular link are different.

8. A DDoS attack defense device, applied to a first proxy, characterized in that, include: The first receiving module is used to receive a first link query request. The first link query request is used to query the links between the recursive DNS and the top-level DNS. The first link query request is sent by the control terminal after receiving the link switching request. The link switching request is triggered after a DDoS attack occurs on the top-level DNS. The first proxy is deployed on the recursive DNS. The first sending module is used to send the first link information to the control terminal; The second receiving module is used to receive the link switching request sent by the control terminal. The link switching request is sent by the control terminal after determining, based on the first link information, that the recursive DNS is using a regular link. The second sending module is used to switch the regular link used by the recursive DNS to an alternative link between the top-level DNS and the regular link, wherein the service resources of the top-level DNS corresponding to the alternative link and the regular link are different.

9. An electronic device, characterized in that, include: At least one processor, and a memory communicatively connected to said at least one processor, wherein: The memory stores a computer program that can be executed by the at least one processor to enable the at least one processor to perform the method as described in any one of claims 1-6.

10. A storage medium, characterized in that, When the computer program in the storage medium is executed by the processor of the electronic device, the electronic device is able to perform the method as described in any one of claims 1-6.

11. A computer program product, characterized in that, Includes a computer program that, when executed by a processor, implements the method of any one of claims 1-6.

Citation Information

Patent Citations

  • DDoS attack defense method and device

    CN107104921A

  • Network address upgrading processing method

    CN110636148A