Fraud domain name blocking method, device, system and equipment

By generating a domain blacklist through an independent fraud blocking server, and detecting and blocking fraudulent domains, the problem of low domain blocking efficiency and security risks in existing technologies is solved, achieving efficient and secure domain blocking.

CN119402466BActive Publication Date: 2026-02-24INNER MONGOLIA MOBILE +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411483033.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-10-23
Publication Date
2026-02-24
Estimated Expiration
2044-10-23

AI Technical Summary

Technical Problem

In existing technologies, domain name blocking is inefficient, leading to decreased caching performance, affecting normal user access, and failing to effectively monitor overseas and illegal DNS access. The blocking efficiency is insufficient and poses security risks.

Method used

By building an independent fraud blocking server, generating a domain blacklist, detecting terminal DNS requests and constructing resolution response packets, and avoiding the occupation of local cache, the interception and blocking of fraudulent domain names can be achieved.

Benefits of technology

It improved the efficiency of blocking fraudulent domain names, avoided caching performance degradation, achieved a 100% blocking success rate, prevented illegal domain name access, and enhanced network security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119402466B_ABST
    Figure CN119402466B_ABST
Patent Text Reader

Abstract

The present disclosure relates to a fraud domain blocking method, device, system and equipment, the system comprising: a fraud blocking server configured to receive a blocking instruction and generate a domain name blacklist based on the blocking instruction; a traffic detection server configured to obtain a DNS request sent by a terminal and send a mirror DNS message to the fraud blocking server based on the DNS request; the fraud blocking server is further configured to receive the mirror DNS message sent by the traffic detection server, judge whether the mirror DNS message is a fraud domain name based on the domain name blacklist, and obtain a domain name resolution result corresponding to the DNS request. In this way, by setting an independent fraud blocking server, the mirror DNS message is detected by the fraud blocking server, which can avoid the problem of occupying a separate cache for local DNS blocking and causing a decrease in buffer performance and normal user perception as the blocking volume increases, thereby greatly improving the blocking efficiency of the fraud domain name.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to the field of domain name resolution technology, and in particular to methods, devices, systems and equipment for blocking fraudulent domain names. Background Technology

[0002] In order to implement the spirit of the meeting on combating and governing telecommunications and online fraud and to fully implement prevention and control measures, the superior department has established an anti-fraud system (anti-fraud platform). Through ISMS (Information Security Management Systems) and the operator's DNS (Domain Name System), it sends domain name blocking and unblocking instructions to the local operator's DNS network management server. The network management server then sends instructions to the cached DNS and recursive DNS to complete the corresponding blocking and unblocking operations.

[0003] In existing technologies, local DNS blocking requires a separate cache address table, the same size as that used by normal users for DNS resolution. As the number of blocked entries increases, continuous scaling is necessary. Furthermore, the increased number of blocked entries lengthens the table lookup time for normal users, reducing cache performance and impacting normal user access. This results in the relatively low efficiency of fraud-related blocking in these technologies. Summary of the Invention

[0004] This disclosure provides a method, device, system, and equipment for blocking fraudulent domain names.

[0005] According to a first aspect of this disclosure, a system for blocking fraudulent domain names is provided, the system comprising:

[0006] A fraud-related blocking server is used to receive blocking instructions and generate a domain name blacklist based on the blocking instructions;

[0007] A traffic detection server is used to obtain DNS requests sent by terminals and send mirrored DNS messages to the fraud blocking server based on the DNS requests.

[0008] The fraud blocking server is also used to receive mirrored DNS messages sent by the traffic detection server, determine whether the mirrored DNS message is a fraudulent domain based on the domain blacklist, and obtain the domain name resolution result corresponding to the DNS request.

[0009] According to a second aspect of this disclosure, a method for blocking fraudulent domain names is provided, the method being applied to a fraud blocking server, the method comprising:

[0010] Receive blocking instructions and generate a domain name blacklist based on the blocking instructions;

[0011] Receive mirrored DNS messages sent by the traffic detection server; wherein, the mirrored DNS messages are generated based on DNS requests sent by the terminal;

[0012] Based on the domain blacklist, determine whether the mirrored DNS message is a fraudulent domain and obtain the corresponding domain name resolution result; wherein, the domain name resolution result includes an empty domain name resolution result or the domain name resolution result actually corresponding to the mirrored DNS message.

[0013] According to a third aspect of this disclosure, a device for blocking fraudulent domain names is provided, the device being applied to a fraud blocking server, the device comprising:

[0014] The domain name blacklist generation module is used to receive blocking instructions and generate a domain name blacklist based on the blocking instructions;

[0015] The message receiving module is used to receive mirrored DNS messages sent by the traffic detection server; wherein, the mirrored DNS messages are generated based on DNS requests sent by the terminal;

[0016] The domain name resolution module is used to determine whether the mirrored DNS message is a fraudulent domain name based on the domain name blacklist, and to obtain the domain name resolution result corresponding to the DNS request; wherein, the domain name resolution result includes an empty domain name resolution result or the domain name resolution result actually corresponding to the mirrored DNS message.

[0017] According to a fourth aspect of this disclosure, an electronic device is provided. The electronic device includes a memory and a processor, wherein the memory stores a computer program, and the processor executes the program to implement the method described above.

[0018] According to a fifth aspect of this disclosure, a computer-readable storage medium is provided having a computer program stored thereon that, when executed by a processor, implements the methods described above.

[0019] According to a sixth aspect of this disclosure, a computer program product is provided, comprising a computer program that, when executed by a processor, implements the methods described above in this disclosure.

[0020] The fraud-related domain name blocking method, apparatus, system, and device provided in this disclosure can receive blocking instructions from an upstream anti-fraud platform and generate a domain name blacklist based on these instructions. When a traffic detection server receives a DNS request from a terminal, it can generate a mirrored DNS message based on the request and send it to the fraud-related blocking server. The fraud-related blocking server uses the generated domain name blacklist to determine whether the mirrored DNS message is a fraudulent domain name and obtains the corresponding domain name resolution result. By setting up a separate fraud-related blocking server to detect mirrored DNS messages, the need for a separate cache for local DNS blocking is avoided, as this leads to decreased buffering performance and reduced user experience with increasing blocking volume. This significantly improves the efficiency of blocking fraudulent domain names. Attached Figure Description

[0021] Further details, features, and advantages of this disclosure are disclosed in the following description of exemplary embodiments in conjunction with the accompanying drawings, in which:

[0022] Figure 1 This is a schematic diagram illustrating the business scenarios of related technologies;

[0023] Figure 2 A schematic diagram of the business process for blocking fraudulent domain names provided as an exemplary embodiment of this disclosure;

[0024] Figure 3 A schematic diagram of a system architecture provided for an exemplary embodiment of this disclosure;

[0025] Figure 4 A flowchart illustrating a method for blocking fraudulent domain names provided as an exemplary embodiment of this disclosure;

[0026] Figure 5 A schematic block diagram of the functional modules of a fraudulent domain name blocking device provided as an exemplary embodiment of this disclosure;

[0027] Figure 6 A structural block diagram of an electronic device provided as an exemplary embodiment of this disclosure;

[0028] Figure 7 A block diagram of a computer system provided for an exemplary embodiment of this disclosure. Detailed Implementation

[0029] Embodiments of this disclosure will now be described in more detail with reference to the accompanying drawings. While some embodiments of this disclosure are shown in the drawings, it should be understood that this disclosure can be implemented in various forms and should not be construed as limited to the embodiments set forth herein. Rather, these embodiments are provided to provide a more thorough and complete understanding of this disclosure. It should be understood that the accompanying drawings and embodiments of this disclosure are for illustrative purposes only and are not intended to limit the scope of protection of this disclosure.

[0030] It should be understood that the steps described in the method embodiments of this disclosure may be performed in different orders and / or in parallel. Furthermore, the method embodiments may include additional steps and / or omit the steps shown. The scope of this disclosure is not limited in this respect.

[0031] The term "comprising" and its variations as used herein are open-ended, meaning "including but not limited to". The term "based on" means "at least partially based on". The term "one embodiment" means "at least one embodiment"; the term "another embodiment" means "at least one additional embodiment"; the term "some embodiments" means "at least some embodiments". Definitions of other terms will be given in the description below. It should be noted that the concepts of "first", "second", etc., used in this disclosure are only used to distinguish different devices, modules, or units, and are not intended to limit the order of functions performed by these devices, modules, or units or their interdependencies.

[0032] It should be noted that the terms "a" and "a plurality of" used in this disclosure are illustrative rather than restrictive, and those skilled in the art should understand that, unless otherwise expressly indicated in the context, they should be understood as "one or more".

[0033] The names of messages or information exchanged between multiple devices in the embodiments of this disclosure are for illustrative purposes only and are not intended to limit the scope of such messages or information.

[0034] It is understood that before using the technical solutions disclosed in the various embodiments of this disclosure, users should be informed of the types, scope of use, and usage scenarios of the personal information involved in this disclosure in an appropriate manner in accordance with relevant laws and regulations, and user authorization should be obtained.

[0035] For example, upon receiving a user's active request, a prompt message is sent to the user to explicitly inform them that the requested operation will require the acquisition and use of the user's personal information. This allows the user to independently choose whether to provide personal information to the software or hardware, such as the electronic device, application, server, or storage medium performing the operations of this disclosed technical solution, based on the prompt message.

[0036] As an optional but non-limiting implementation, in response to a user's active request, sending a prompt message to the user can be done via a pop-up window, where the prompt message can be presented in text format. Furthermore, the pop-up window can also include a selection control allowing the user to choose "agree" or "disagree" to provide personal information to the electronic device. It is understood that the above notification and user authorization process is merely illustrative and does not constitute a limitation on the implementation of this disclosure; other methods that comply with relevant laws and regulations may also be applied to the implementation of this disclosure.

[0037] The network elements involved in the relevant technologies mainly include: the upper-level anti-fraud platform, ISMS, local DNS network management, and various DNS servers.

[0038] Specifically, such as Figure 1 As shown, Figure 1 This is a business scenario illustration of the relevant technologies. Specifically, it may include the following steps:

[0039] Step 1: The central anti-fraud platform issues a blocking order for a specific domain name or a batch of domain names.

[0040] Step 2: After receiving the instruction, the provincial anti-fraud platform sends a response back to the central anti-fraud platform.

[0041] Step 3: The provincial anti-fraud platform issues the corresponding blocking instructions to ISMS.

[0042] Step 4: After receiving the instruction, ISMS returns a response to the provincial anti-fraud platform.

[0043] Step 5: ISMS sends the received blocking command to the corresponding local DNS network administrator.

[0044] Step 6: After receiving the instruction, the DNS administrator returns a response to the ISMS.

[0045] Step 7: The DNS administrator performs forced resolution on the issued domain name, sends the resolution result to each server, and refreshes the cache of this domain name.

[0046] Step 8: Each DNS server returns the results of the command execution.

[0047] Step 9: The DNS management system returns the final result of the command execution to the ISMS.

[0048] Step 10: Return the execution result, that is, ISMS returns the final result of the instruction execution to the provincial anti-fraud center.

[0049] Step 11: Return the execution result, that is, the provincial anti-fraud platform returns the final result of the instruction execution to the central anti-fraud platform.

[0050] Step 12: When the user sets the DNS to the local DNS, request the relevant fraudulent domain name.

[0051] Step 13: The local DNS directly returns the resolution result set by the user, thus achieving the purpose of blocking.

[0052] Therefore, the relevant technologies will have the following technical problems:

[0053] 1. In related technologies, domain name blocking is based on forcing the local network's cached DNS to resolve to the relevant resolution result. There is no ability to supervise and block DNS from overseas networks, privately built DNS within the country, or DNS registered within the country but not within the operational system. According to statistics, these domain name accesses account for about 30% of the total. If customers actively configure to bypass supervision or are passively configured due to DNS hijacking, there is a possibility that they can bypass the local DNS and the domestic network and continue to access the network. The existence of this unregulated traffic can cause serious social impacts and even affect national political security. Moreover, it is impossible to achieve the rapid handling and dynamic blocking capabilities of "one-point issuance, network-wide effect", which affects the overall effectiveness of network anti-fraud.

[0054] 2. In the current network, local DNS blocking requires a separate cache address table, which is the same as the cache used by normal users. As the amount of blocking increases, it needs to be continuously expanded. Moreover, as the number of blocked entries increases, the table lookup time for normal users will be extended, resulting in a decrease in cache performance and a decline in the user's normal experience.

[0055] 3. Because blocking and monitoring share the same channel and connect to multiple blocking command channels, during peak command periods, the performance of some cache servers may be insufficient, leading to blocking failures. The success rate of blocking may not reach 90%, resulting in low blocking efficiency.

[0056] Therefore, in order to solve the above-mentioned technical problems, this embodiment of the disclosure connects with the ISMS command channel to build a blacklist and whitelist database. By collecting and analyzing the provincial network exit traffic, it analyzes and judges the DNS request packets sent by users. If the domain name is a fraudulent or illegal domain name, it constructs a resolution response packet, for example, modifying the domain name resolution record to 0.0.0.0 (IPV6:0:0:0:0:0:0:0:0) and returns it to the user to complete the blocking.

[0057] This implementation solution addresses the issue of users being unable to block fraudulent domains accessed via external DNS. It also serves as an enhanced auxiliary tool for current fraud blocking, effectively supplementing the existing forced DNS resolution blocking mode and achieving a 100% success rate in blocking. Furthermore, by setting up a dedicated fraud blocking server, it avoids the problems associated with local DNS blocking, which requires a separate cache and leads to decreased buffering performance and user experience as the number of blocked domains increases.

[0058] The network elements involved in the embodiment may include: an upper-level anti-fraud platform, ISMS, a fraud-related blocking server, and a switch. The upper-level anti-fraud platform issues blocking / unblocking commands, ISMS relays commands, the fraud-related blocking server sends response packets to the switch, and the switch sends response packets to the user-side terminal.

[0059] For details, see Figure 2 As shown, Figure 2 This is a schematic diagram of the business process for blocking fraudulent domain names provided in this embodiment of the disclosure. It may include an anti-fraud platform, a fraud blocking server, a provincial network exit DPI (Deep Packet Inspection) data detection server, and a terminal. The process may include the following steps:

[0060] Step 1: The central anti-fraud platform issues a blocking order for a specific domain name or a batch of domain names.

[0061] Step 2: After receiving the instruction, the provincial anti-fraud platform sends a response back to the central anti-fraud platform.

[0062] Step 3: The provincial anti-fraud platform issues the corresponding blocking instructions to ISMS.

[0063] Step 4: After receiving the instruction, ISMS returns a response to the provincial anti-fraud platform.

[0064] Step 5: ISMS sends the received blocking command to the fraud blocking server through the WEBLOGIC interface.

[0065] Step 6: After receiving the instruction, the fraud blocking server returns a response to ISMS.

[0066] Step 7: Construct a blacklist of domain names for the fraud-related blocking server, and set the DNS resolution result of this domain name to an empty domain name resolution result, for example, it can be 0.0.0.0 (IPV6:0:0:0:0:0:0:0:0).

[0067] Step 8: The user's terminal requests this fraudulent domain name.

[0068] Step 9: The corresponding DNS request data from the provincial network exit is diverted to the fraud blocking server.

[0069] Step 10: When the fraud blocking server discovers that this domain name is on the blacklist, it constructs a data packet with an empty domain name resolution result based on the source address, destination address, and requested domain name of the user request, and sends it to the provincial network exit DPI data detection server.

[0070] Step 11: The provincial network exit DPI data detection server returns the domain name resolution result to the user in the corresponding domain name resolution response, thus achieving the purpose of blocking.

[0071] like Figure 3 As shown, Figure 3 This is a schematic diagram of the system architecture provided in this embodiment. The fraud blocking server provided in this embodiment includes two modules: a blocking management module and a handling program module. The blocking management module mainly interfaces with ISMS, receives fraud blocking information issued by higher-level departments, establishes handling tasks, establishes blacklists and whitelists, performs blocking statistics, log reporting, and completes post-blocking domain name testing. The whitelist includes important domains such as top-level domains, second-level domains, and government domains to prevent false blocking; the blacklist contains relevant handling task information received from ISMS. The blocking statistics module mainly performs statistics on the success rate of handling. The testing module mainly performs testing to determine whether the domain name is completely blocked after blocking. The handling program module mainly receives DNS request messages, completes tasks issued by the blocking management system, performs policy standardization matching, forges DNS response messages, records logs, and issues handling messages.

[0072] In the embodiments provided in this disclosure, ISMS issues instructions for handling fraudulent domain names to the fraud blocking server as needed, and constructs a detailed blacklist based on the content of these instructions. The specific domain name handling instructions are shown in Table 1.

[0073] Table 1:

[0074]

[0075]

[0076] In Table 1, entries are inserted or deleted based on the type of handling, such as stopping the creation of the blacklist for the corresponding domain name and restoring the blacklist for the corresponding domain name.

[0077] After the blocking management interface constructs the corresponding blacklist, it provides feedback on the results of the instructions for handling fraudulent domain names as required. The feedback instructions are shown in Table 2.

[0078] Table 2:

[0079]

[0080]

[0081] In the embodiments provided in this disclosure, a whitelist database can also be established. The whitelist is used to automatically filter domain names of important websites at the primary, secondary, and government levels to prevent accidental blocking from causing systemic issues. Table 3 shows a schematic diagram of the whitelist structure.

[0082] Table 3:

[0083]

[0084] The processing module in this embodiment primarily receives DNS request data from the distributed traffic in real time, and then retains information such as the source address IP1, destination address IP2, and domain name of the user's request. It determines whether the requested domain name is on the whitelist; if so, it allows access without interference. If not, it further determines whether it is on the blacklist; if not, it allows access without interference. If it is on the blacklist, it performs a blocking operation, constructing a message with a resolution result of, for example, 0.0.0.0 (IPv6:0:0:0:0:0:0:0:0), and generating a response data packet with a destination address of IP1 and a source address of IP2, logging the process. A resolution response message is sent to the switch, which forwards the response message to the user's terminal, which receives the response message. By sending the blocked response message to the user, the user, upon receiving this resolution result, cannot browse websites with this domain name, thus achieving the purpose of blocking fraudulent activities.

[0085] Therefore, in order to provide a fraudulent domain name blocking system based on the above embodiments, the present disclosure also provides a system that can include:

[0086] Fraud-related blocking servers are used to receive blocking instructions and generate domain blacklists based on those instructions.

[0087] Traffic detection servers are used to obtain DNS requests sent by terminals and send mirrored DNS messages to fraud blocking servers based on the DNS requests.

[0088] The fraud blocking server is also used to receive mirrored DNS messages sent by the traffic detection server, determine whether the mirrored DNS message is a fraudulent domain based on the domain blacklist, and obtain the domain name resolution result corresponding to the DNS request.

[0089] It is being implemented; for details, please refer to [link / reference]. Figure 2As shown, the fraud blocking server can receive blocking instructions from the anti-fraud platform and generate a domain name blacklist based on these instructions. This domain name blacklist is the blacklist described in the above embodiment. The traffic detection server in this embodiment can obtain DNS requests sent by terminals, generate mirrored DNS messages for the domain names requested to be resolved in the DNS requests, and send these mirrored DNS messages to the fraud blocking server. The fraud blocking server determines whether the mirrored DNS message contains fraudulent domain names by comparing it with domain names included in the domain name blacklist. If the domain name requested to be resolved in the mirrored DNS message is included in the domain name blacklist, it means that the mirrored DNS message contains fraudulent domain names; otherwise, if the domain name requested to be resolved in the mirrored DNS message is not included in the domain name blacklist, it means that the mirrored DNS message does not contain fraudulent domain names. Specifically, the traffic detection server can be the provincial network exit DPI data detection server described in the above embodiment, but the embodiment is not limited to this.

[0090] The fraud-related domain name blocking system provided in this embodiment includes a fraud-related blocking server and a traffic detection server. The fraud-related blocking server can receive blocking instructions sent by the superior anti-fraud platform and generate a domain name blacklist based on the blocking instructions. When the traffic detection server receives a DNS request sent by a terminal, it can generate a mirrored DNS message based on the DNS request and send the mirrored DNS message to the fraud-related blocking server. The fraud-related blocking server determines whether the mirrored DNS message is a fraudulent domain name based on the generated domain name blacklist and obtains the corresponding domain name resolution result. By setting up a separate fraud-related blocking server and using it to detect mirrored DNS messages, the system avoids the problem of local DNS blocking requiring a separate cache and the resulting decrease in buffer performance and user experience as the amount of blocking increases. This significantly improves the efficiency of blocking fraudulent domain names.

[0091] In this embodiment, when the mirrored DNS message contains a fraudulent domain name, it is resolved to an empty domain name resolution result. This prevents users from accessing websites corresponding to fraudulent domain names, thus achieving the goal of blocking the set domain name. Alternatively, when the mirrored DNS message contains a non-fraudulent domain name, it is resolved to the actual corresponding domain name resolution result, allowing users to access websites that do not correspond to the set domain name normally.

[0092] In this embodiment, the fraud blocking server is also used to send domain name resolution results to the traffic detection server. These domain name resolution results include empty domain name resolution results or actual corresponding domain name resolution results.

[0093] Traffic detection servers are also used to send domain name resolution results to terminals.

[0094] This embodiment utilizes a fraud-blocking server to detect DNS requests, enabling user security protection. Regardless of whether the DNS request contains a fraudulent domain name, it sends the domain name resolution result to the user's terminal, avoiding prolonged waiting times. Specifically, when the DNS request contains a fraudulent domain name, it returns an empty domain name resolution result. When the user accesses this empty result, a message such as "This page does not exist" or a warning message like "The page you are trying to access is illegal; please perform a security scan on your device" is displayed. When the DNS request does not contain a fraudulent domain name, it provides the actual corresponding domain name resolution result, allowing the user to access the page or website normally.

[0095] In the embodiments provided in this disclosure, in order to prevent users from bypassing supervision through active configuration or passive configuration due to reasons such as DNS hijacking, there may be situations where access can continue even if the local DNS or the domestic network is bypassed. The embodiments can collect network traffic in the target area to determine whether the collected network traffic contains bypassed DNS requests and perform fraud detection on these DNS requests.

[0096] Therefore, the traffic detection server is also used to collect network traffic in the target area and determine whether there are DNS requests in the collected data. When a DNS request is found, a mirrored DNS message is sent to the fraud blocking server based on the DNS request. This allows the fraud blocking server to detect the mirrored DNS message and determine whether it contains fraudulent domain names. For details, please refer to the execution process of the above embodiment; it will not be repeated here.

[0097] In the embodiments provided in this disclosure, in addition to generating or setting a domain name blacklist, a domain name whitelist can also be generated or set. For example, the fraud blocking server can receive important core domain names such as top-level domains, second-level domains, and government domains sent by the superior anti-fraud platform, and generate a domain name whitelist based on these core domain names to prevent wrongful blocking.

[0098] Therefore, the fraud-related blocking server is also used to receive core domain name information and generate a domain name whitelist based on the core domain name information.

[0099] The fraud-related blocking server is also used to determine whether the mirrored DNS message is in the domain whitelist. If the mirrored DNS message is not in the whitelist, it is used to determine whether the mirrored DNS message is a domain involved in fraud based on the domain blacklist.

[0100] Alternatively, when the mirrored DNS message is in the domain whitelist, the mirrored DNS message can be resolved to the actual domain name resolution result.

[0101] In this embodiment, the fraud blocking server can first determine whether the domain name to be detected is in the domain whitelist. If it is in the domain whitelist, further detection and judgment through the domain blacklist can be stopped; otherwise, if the domain name to be detected is not in the domain whitelist, further detection and judgment can be performed through the domain blacklist.

[0102] Based on the above embodiments, in another embodiment provided in this disclosure, such as Figure 4 As shown, a method for blocking fraudulent domain names is also provided. This method is applied to a fraud blocking server and may include the following steps:

[0103] In step S410, a blocking instruction is received, and a domain name blacklist is generated based on the blocking instruction.

[0104] In step S420, a mirrored DNS message sent by the traffic detection server is received.

[0105] Among them, the mirrored DNS message is generated based on the DNS request sent by the terminal.

[0106] In step S430, the mirror DNS message is determined to be a fraudulent domain name based on the domain name blacklist, and the corresponding domain name resolution result is obtained; wherein, the domain name resolution result includes an empty domain name resolution result or the domain name resolution result actually corresponding to the mirror DNS message.

[0107] In this embodiment, the fraud blocking server can receive blocking instructions from the anti-fraud platform and generate a domain name blacklist based on these instructions. This domain name blacklist is the same as the blacklist in the above embodiment. The traffic detection server in this embodiment can acquire DNS requests sent by terminals, generate mirrored DNS packets for the domain names requested in the DNS requests, and send these mirrored DNS packets to the fraud blocking server. The fraud blocking server determines whether the mirrored DNS packets contain fraudulent domain names by comparing them with domain names included in the blacklist. If the domain name requested in the mirrored DNS packets is included in the blacklist, it means the mirrored DNS packets contain fraudulent domain names; otherwise, if the domain name requested in the mirrored DNS packets is not included in the blacklist, it means the mirrored DNS packets do not contain fraudulent domain names. By setting up a separate fraud blocking server to detect mirrored DNS packets, the problem of local DNS blocking requiring a separate cache and experiencing decreased buffering performance and user experience as the blocking volume increases can be avoided. This significantly improves the efficiency of blocking fraudulent domain names.

[0108] In this embodiment, when the mirrored DNS message contains a fraudulent domain name, it can be resolved to an empty domain name resolution result. This prevents users from accessing websites corresponding to fraudulent domain names, thus achieving the purpose of blocking the set domain name. Alternatively, when the mirrored DNS message contains a non-fraudulent domain name, it can be resolved to the actual corresponding domain name resolution result, allowing users to access websites that do not correspond to the set domain name normally.

[0109] In this embodiment, network traffic in the target area can also be collected, and it can be determined whether there are DNS requests in the collected data. If there are DNS requests in the collected data, a mirrored DNS message is sent to the fraud blocking server based on the DNS request. This allows for the detection of whether the mirrored DNS message contains a fraudulent domain name. If the mirrored DNS message contains a fraudulent domain name, it can be resolved to an empty domain name resolution result.

[0110] In this embodiment, a domain whitelist can also be generated based on core domains, etc., and the domain to be detected can be first determined to be in the domain whitelist. If it is in the domain whitelist, further detection and judgment through the domain blacklist can be stopped; otherwise, if the domain to be detected is not in the domain whitelist, further detection and judgment can be performed through the domain blacklist.

[0111] By dividing each functional module according to its corresponding function, this disclosure provides a device for blocking fraudulent domain names. The device for blocking fraudulent domain names can be a server, a terminal, or a chip applied to a server. Figure 5 This is a schematic block diagram of the functional modules of a fraudulent domain name blocking device provided as an exemplary embodiment of this disclosure. Figure 5 As shown, the fraudulent domain name blocking device includes:

[0112] Domain name blacklist generation module 10 is used to receive blocking instructions and generate a domain name blacklist based on the blocking instructions;

[0113] The message receiving module 20 is used to receive mirrored DNS messages sent by the traffic detection server; wherein the mirrored DNS messages are generated based on DNS requests sent by the terminal;

[0114] The domain name resolution module 30 is used to determine whether the mirrored DNS message is a fraudulent domain name based on the domain name blacklist, and to obtain the domain name resolution result corresponding to the DNS request; wherein, the domain name resolution result includes an empty domain name resolution result or the domain name resolution result actually corresponding to the mirrored DNS message.

[0115] The fraud-related domain name blocking device provided in this embodiment includes a fraud-related blocking server and a traffic detection server. The fraud-related blocking server can receive blocking instructions sent by an upper-level anti-fraud platform and generate a domain name blacklist based on the blocking instructions. When the traffic detection server receives a DNS request sent by a terminal, it can generate a mirrored DNS message based on the DNS request and send the mirrored DNS message to the fraud-related blocking server. The fraud-related blocking server determines whether the mirrored DNS message is a fraudulent domain name based on the generated domain name blacklist and obtains the corresponding domain name resolution result. By setting up a separate fraud-related blocking server and using it to detect mirrored DNS messages, the problem of local DNS blocking requiring a separate cache and experiencing decreased buffering performance and user experience as the amount of blocking increases can be avoided. This significantly improves the efficiency of blocking fraudulent domain names.

[0116] This disclosure also provides an electronic device, including: at least one processor; a memory for storing processor-executable instructions; wherein the at least one processor is configured to execute the instructions to implement the methods disclosed in this disclosure.

[0117] Figure 6 This is a schematic diagram of the structure of an electronic device provided as an exemplary embodiment of this disclosure. For example... Figure 6 As shown, the electronic device 1800 includes at least one processor 1801 and a memory 1802 coupled to the processor 1801. The processor 1801 can perform the corresponding steps in the methods disclosed in the embodiments of this disclosure.

[0118] The processor 1801 described above can also be called a central processing unit (CPU), which can be an integrated circuit chip with signal processing capabilities. Each step in the method disclosed in this embodiment can be implemented by the integrated logic circuitry in the processor 1801 or by software instructions. The processor 1801 can be a general-purpose processor, a digital signal processor (DSP), an ASIC (Application Specific Integrated Circuit), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components. The general-purpose processor can be a microprocessor or any conventional processor. The steps of the method disclosed in this embodiment can be directly implemented by a hardware decoding processor, or implemented by a combination of hardware and software modules in the decoding processor. The software modules can be located in the memory 1802, such as random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, registers, or other mature storage media in the art. The processor 1801 reads information from the memory 1802 and, in conjunction with its hardware, completes the steps of the method described above.

[0119] Furthermore, various operations / processes according to this disclosure, implemented via software and / or firmware, can be transmitted from a storage medium or network to a computer system with a dedicated hardware architecture, such as... Figure 7 The computer system 1900 shown is equipped with the programs that constitute the software. When various programs are installed, the computer system is able to perform various functions, including those described above. Figure 7 A block diagram of a computer system provided for an exemplary embodiment of this disclosure.

[0120] Computer System 1900 is intended to represent various forms of digital electronic computer devices, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. Electronic devices can also represent various forms of mobile devices, such as personal digital processors, cellular phones, smartphones, wearable devices, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the present disclosure described and / or claimed herein.

[0121] like Figure 7As shown, the computer system 1900 includes a computing unit 1901, which can perform various appropriate actions and processes based on a computer program stored in a read-only memory (ROM) 1902 or a computer program loaded from a storage unit 1908 into a random access memory (RAM) 1903. The RAM 1903 may also store various programs and data required for the operation of the computer system 1900. The computing unit 1901, ROM 1902, and RAM 1903 are interconnected via a bus 1904. An input / output (I / O) interface 1905 is also connected to the bus 1904.

[0122] Multiple components in computer system 1900 are connected to I / O interface 1905, including: input unit 1906, output unit 1907, storage unit 1908, and communication unit 1909. Input unit 1906 can be any type of device capable of inputting information into computer system 1900. Input unit 1906 can receive input digital or character information and generate key signal inputs related to user settings and / or function control of the electronic device. Output unit 1907 can be any type of device capable of presenting information and may include, but is not limited to, a monitor, speaker, video / audio output terminal, vibrator, and / or printer. Storage unit 1908 may include, but is not limited to, hard disks and optical disks. Communication unit 1909 allows computer system 1900 to exchange information / data with other devices via a network such as the Internet, and may include, but is not limited to, modems, network cards, infrared communication devices, wireless communication transceivers, and / or chipsets, such as Bluetooth™ devices, WiFi devices, WiMax devices, cellular communication devices, and / or the like.

[0123] The computing unit 1901 can be a variety of general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the computing unit 1901 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special-purpose artificial intelligence (AI) computing chips, various computing units running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. The computing unit 1901 performs the various methods and processes described above. For example, in some embodiments, the methods disclosed in this disclosure can be implemented as a computer software program tangibly contained in a machine-readable medium, such as storage unit 1908. In some embodiments, part or all of the computer program can be loaded and / or installed on an electronic device via ROM 1902 and / or communication unit 1909. In some embodiments, the computing unit 1901 can be configured to perform the methods disclosed in this disclosure by any other suitable means (e.g., by means of firmware).

[0124] This disclosure also provides a computer-readable storage medium, wherein when the instructions in the computer-readable storage medium are executed by a processor of an electronic device, the electronic device is able to perform the methods disclosed in this disclosure.

[0125] The computer-readable storage medium in this disclosure can be a tangible medium that may contain or store a program for use by or in conjunction with an instruction execution system, apparatus, or device. The aforementioned computer-readable storage medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specifically, the aforementioned computer-readable storage medium may include electrical connections based on one or more wires, a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.

[0126] The aforementioned computer-readable medium may be included in the aforementioned electronic device; or it may exist independently and not assembled into the electronic device.

[0127] This disclosure also provides a computer program product, including a computer program, wherein the computer program, when executed by a processor, implements the methods disclosed in the embodiments of this disclosure.

[0128] In embodiments of this disclosure, computer program code for performing the operations of this disclosure can be written in one or more programming languages ​​or a combination thereof. These programming languages ​​include, but are not limited to, object-oriented programming languages ​​such as Java, Smalltalk, and C++, as well as conventional procedural programming languages ​​such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving remote computers, the remote computer can be connected to the user's computer via any type of network (including a local area network (LAN) or a wide area network (WAN)), or it can be connected to an external computer.

[0129] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this disclosure. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.

[0130] The modules, components, or units described in the embodiments of this disclosure can be implemented in software or hardware. The names of the modules, components, or units do not necessarily constitute a limitation on the module, component, or unit itself.

[0131] The functions described above in this document can be performed at least in part by one or more hardware logic components. For example, without limitation, exemplary hardware logic components that can be used include: field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), system-on-a-chip (SoCs), complex programmable logic devices (CPLDs), and so on.

[0132] The above description is merely an embodiment of this disclosure and an explanation of the technical principles employed. Those skilled in the art should understand that the scope of this disclosure is not limited to technical solutions formed by specific combinations of the above-described technical features, but should also cover other technical solutions formed by arbitrary combinations of the above-described technical features or their equivalents without departing from the above-described concept. For example, technical solutions formed by substituting the above features with (but not limited to) technical features disclosed in this disclosure that have similar functions.

[0133] While specific embodiments of this disclosure have been described in detail by way of example, those skilled in the art should understand that the examples are for illustrative purposes only and not intended to limit the scope of this disclosure. Those skilled in the art should understand that modifications can be made to the above embodiments without departing from the scope and spirit of this disclosure. The scope of this disclosure is defined by the appended claims.

Claims

1. A system for blocking fraudulent domain names, characterized in that, The system includes: A fraud-related blocking server is used to receive blocking instructions and generate a domain name blacklist based on the blocking instructions; The traffic detection server is used to collect network traffic in the target area and determine whether there is a DNS request in the collected data. When there is a DNS request in the collected data, it obtains the DNS request sent by the terminal and sends a mirrored DNS message to the fraud blocking server based on the DNS request. The fraud blocking server is also used to receive mirrored DNS messages sent by the traffic detection server, receive core domain name information, generate a domain name whitelist based on the received core domain name information, and determine whether the mirrored DNS message is in the domain name whitelist; if not, it determines whether the mirrored DNS message is a fraudulent domain name based on the domain name blacklist, and obtains the domain name resolution result corresponding to the DNS request; the domain name resolution result includes an empty domain name resolution result or the actual corresponding domain name resolution result; Specifically, when the mirrored DNS message is a domain name involved in fraud, the fraud blocking server resolves the mirrored DNS message to an empty domain name resolution result; when the mirrored DNS message is a domain name not involved in fraud, the mirrored DNS message resolves the actual corresponding domain name resolution result. The fraud blocking server is also used to send the domain name resolution result to the traffic detection server; The traffic detection server is also used to send the domain name resolution result to the terminal.

2. The system according to claim 1, characterized in that, The traffic detection server is also used to collect network traffic in the target area and determine whether there is a DNS request in the collected data. When there is a DNS request in the collected data, a mirrored DNS message is sent to the fraud blocking server based on the DNS request.

3. The system according to claim 1, characterized in that, The fraud blocking server is also used to receive core domain name information and generate a domain name whitelist based on the core domain name information; The fraud blocking server is also used to determine whether the mirrored DNS message is in the domain name whitelist. If the mirrored DNS message is not in the whitelist, it determines whether the mirrored DNS message is a fraudulent domain name based on the domain name blacklist. Alternatively, when the mirrored DNS message is in the domain name whitelist, the mirrored DNS message is resolved to the actual corresponding domain name resolution result.

4. A method for blocking fraudulent domain names, characterized in that, The method is applied to servers used for blocking fraudulent activities, and the method includes: Receive blocking instructions and generate a domain name blacklist based on the blocking instructions; Receive mirrored DNS messages sent by the traffic detection server; wherein, the mirrored DNS messages are generated based on DNS requests sent by the terminal; The system receives core domain name information, generates a domain name whitelist based on the received core domain name information, and determines whether the mirrored DNS message is in the domain name whitelist. If not, it determines whether the mirrored DNS message is a fraudulent domain name based on the domain name blacklist and obtains the corresponding domain name resolution result. The domain name resolution result includes an empty domain name resolution result or the actual domain name resolution result corresponding to the mirrored DNS message. The domain name resolution result is sent to the traffic detection server; wherein, when the mirror DNS message is a fraudulent domain name, the mirror DNS message is resolved to an empty domain name resolution result; when the mirror DNS message is a non-fraudulent domain name, the mirror DNS message is resolved to the actual corresponding domain name resolution result.

5. A device for blocking fraudulent domain names, characterized in that, The device is used in a fraud blocking server, and the device includes: The domain name blacklist generation module is used to receive blocking instructions and generate a domain name blacklist based on the blocking instructions; The message receiving module is used to receive mirrored DNS messages sent by the traffic detection server; wherein, the mirrored DNS messages are generated based on DNS requests sent by the terminal; The domain name resolution module is used to receive core domain name information, generate a domain name whitelist based on the received core domain name information, and determine whether the mirrored DNS message is in the domain name whitelist; if not, it determines whether the mirrored DNS message is a fraudulent domain name based on the domain name blacklist, and obtains the domain name resolution result corresponding to the DNS request; wherein, the domain name resolution result includes an empty domain name resolution result or the actual domain name resolution result corresponding to the mirrored DNS message; and sends the domain name resolution result to the traffic detection server; wherein, when the mirrored DNS message is a fraudulent domain name, the mirrored DNS message is resolved to an empty domain name resolution result; when the mirrored DNS message is a non-fraudulent domain name, the mirrored DNS message is resolved to the actual corresponding domain name resolution result; the domain name resolution result includes the empty domain name resolution result or the actual corresponding domain name resolution result.

6. An electronic device, characterized in that, include: At least one processor; Memory for storing the at least one processor-executable instruction; The at least one processor is configured to execute the instructions to implement the method as described in claim 4.

7. A computer-readable storage medium, characterized in that, When the instructions in the computer-readable storage medium are executed by the processor of the electronic device, the electronic device is able to perform the method as described in claim 4.

8. A computer program product, characterized in that, It includes a computer program that, when executed by a processor, implements the method of claim 4.

Citation Information

Patent Citations

  • SDN-based methods, devices, equipment, and media for blocking network fraud.

    CN113452670A

  • Bypass blocking method and system

    CN117560217A