Domain name resolution method and system for DNS server
By developing a domain name resolution method and system in the DNS server, it can conduct in-depth analysis and parsing of the domain names that the browser wants to connect to, solving the problem that existing DNS servers are difficult to provide resolution functions that are beyond the IP, and achieving efficient and effective domain name resolution and security evaluation.
Patent Information
- Application Number
- CN202510026738.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-08
- Publication Date
- 2025-05-06
- Estimated Expiration
- 2045-01-08
AI Technical Summary
Existing DNS servers are difficult to provide parsing functions for more information outside of IP, and cannot effectively respond to the increasingly strong demands of Internet function enhancement and real-life space.
By developing a domain name resolution method and system in a DNS server, it is possible to conduct in-depth analysis of the domain names that the browser wants to connect to, determine its security, and convert the domain name into an IP address that the browser can better recognize. The system includes a risk identification module, a deep analysis module, a domain name analysis module and an address identification module. Through the coordinated work of these modules, comprehensive analysis and analysis of domain names can be achieved.
In-depth analysis and parsing of domain names is realized, more information outside the IP can be provided, the quality and efficiency of the parsing process can be improved, and the efficiency and effectiveness of the parsing process can be ensured.
Smart Images

Figure CN119946017A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of domain name resolution, and in particular to a domain name resolution method and system for a DNS server. Background Art
[0002] DNS is the abbreviation of Domain Name System, which is used to name computers and network services in hierarchical structures from organizations to domains. DNS servers can provide domain name resolution services for clients, resolving the domain name entered by the client into the IP address corresponding to the domain name, and then the client can use the IP address to access the website corresponding to the domain name.
[0003] In recent years, the Internet has developed very rapidly. Domain names are one of the earliest products that appeared with the Internet. People have become more and more familiar with them. Domain names will have characteristics related to domain names from the time they are applied for registration to the time they are put into use. However, with the continuous enhancement of Internet functions and the increasingly strong interaction with the real space, DNS is needed to provide more information resolution functions beyond IP.
[0004] Therefore, the present invention provides a domain name resolution method and system for a DNS server. Summary of the invention
[0005] The present invention provides a domain name resolution method and system for a DNS server, which can perform in-depth analysis on a domain name that a browser wants to connect to, determine the security of the domain name, and convert the domain name into an IP address that is better recognized by the browser, so as to facilitate the browser to access again.
[0006] The present invention provides a domain name resolution method for a DNS server, comprising:
[0007] Step 1: Obtain the domain name requested for analysis sent by the browser, identify the domain name risk level of the domain name requested for analysis in the DNS server, and match the domain name requested for analysis with a resolution service segment of the corresponding level;
[0008] Step 2: Identify the top-level domain of the domain name requested for analysis in the resolution service segment, determine the domain name attributes of the domain name requested for analysis, perform in-depth analysis on the domain name attributes and generate a DNS analysis record;
[0009] Step 3: Generate the DNS record type of the requested domain name for analysis according to the DNS analysis record and the domain name risk level, and determine the execution object of the requested domain name for analysis;
[0010] Step 4: Determine the actual IP address of the requested analysis domain name according to the execution object, control the browser to connect to the actual IP address, and store the actual IP address in the browser.
[0011] In one practicable manner,
[0012] The step 1 comprises:
[0013] Step 11: transmitting the domain name requested for analysis sent by the browser to the DNS server, identifying the readable address of the domain name requested for analysis in the DNS server, performing source tracing analysis on the readable address, obtaining several pieces of domain name information of the domain name requested for analysis, and screening the usage protocol of the domain name requested for analysis in the domain name information;
[0014] Step 12: Determine the accessible resource range of the domain name requested for analysis according to the usage agreement, analyze the access-feedback relationship between the domain name requested for analysis and the accessible resource range in the DNS server, and determine the access security corresponding to each accessible resource;
[0015] Step 13: Filter the domain name path of the requested analysis domain name in the domain name information, build the corresponding access method when the requested analysis domain name accesses each of the accessible resources in combination with the accessible resource range, determine a number of access ports corresponding to each of the access methods, and determine the path security corresponding to each of the accessible resources according to the port information corresponding to each of the access ports;
[0016] Step 14: Generate a domain name risk level of the requested analysis domain name based on the access security and path security, obtain a resolution service segment matching the domain name risk level in the DNS server, and transmit the requested analysis domain name to the corresponding resolution service segment.
[0017] In one practicable manner,
[0018] The step 2 comprises:
[0019] Step 21: In the resolution service section, the domain name requested for analysis is mapped to different preset domain name systems to obtain the expression form of the domain name requested for analysis in each preset domain name system, and the tail character string corresponding to each expression form is obtained to determine the top-level domain of the domain name requested for analysis;
[0020] Step 22: Determine the generation source of the domain name requested for analysis according to the top-level domain, determine several domain name information of the generation source in combination with the expression form of the domain name requested for analysis in each of the preset domain name systems, obtain information keywords corresponding to each of the domain name information respectively, and establish a domain name attribute for determining the domain name requested for analysis;
[0021] Step 23: Construct the domain name format corresponding to the domain name requested for analysis in each of the preset domain name systems according to the domain name attributes, input the domain name information into each of the domain name formats respectively to generate the analysis result of the domain name requested for analysis in each of the preset domain name systems, and generate the DNS analysis record of the domain name requested for analysis.
[0022] In one practicable manner,
[0023] The step 3 comprises:
[0024] Step 31: Decompose the DNS analysis record at the domain name risk level to obtain a plurality of flow data of the domain name requested for analysis, and generate a plurality of search conditions of the domain name requested for analysis according to the data value and risk dimension corresponding to each of the flow data;
[0025] Step 32: searching for a plurality of associated data of the domain name requested for analysis in the DNS server according to the search condition, constructing a trust part of the domain name requested for analysis according to the associated data, locating the trust parts in the DNS analysis record respectively, and determining the trust performance characteristics of the domain name requested for analysis in different preset domain name systems;
[0026] Step 33: Establish a DNS record of the requested domain name for analysis according to the trust performance characteristics, analyze the record integrity corresponding to each record type in the DNS record, select the first record type with the highest record integrity, and determine the execution object of the requested domain name for analysis.
[0027] In one practicable manner,
[0028] Also includes:
[0029] Obtaining the untrusted portion of the domain name requested for analysis, locating each of the untrusted portions in the DNS analysis record, and determining untrusted performance characteristics of the domain name requested for analysis in different preset domain name systems;
[0030] Input each of the untrusted performance characteristics into the cloud DNS for security testing, and determine the security level corresponding to the untrusted part in each of the preset domain name systems according to the test results;
[0031] Screening the second record type with the highest security level;
[0032] When the second record type is consistent with the first record type, determining an execution object of the request to analyze the domain name;
[0033] On the contrary, the object corresponding to the second record type is regarded as the execution object of the request to analyze the domain name.
[0034] In one practicable manner,
[0035] The step 4 comprises:
[0036] Step 41: construct an address conversion scheme according to the address format of the execution object, convert the requested analysis domain name into an IP address using the address conversion scheme, and input the IP address into the address format to obtain the actual IP address of the requested analysis domain name;
[0037] Step 42: Control the browser to connect to the actual IP address, collect a number of browsing access information of the browser during the connection process, determine the browsing web page attributes of the request analysis domain name according to the browsing access information, and store the actual IP address in the attribute storage area corresponding to the browser.
[0038] In one practicable manner,
[0039] Also includes:
[0040] Regularly update each attribute storage area respectively;
[0041] Respectively obtain the browsing frequencies corresponding to different stored domain names in each of the attribute storage areas to construct the browsing preferences of the browser;
[0042] A corresponding secure domain name is recommended to the browser according to the browsing preference.
[0043] In one practicable manner,
[0044] Also includes:
[0045] When the risk level of the domain name of the domain name requested for analysis is higher than the standard risk level, the browser is controlled to log out.
[0046] The present invention provides a domain name resolution system for a DNS server, comprising:
[0047] A risk identification module is used to obtain the requested analysis domain name sent by the browser, identify the domain name risk level of the requested analysis domain name in the DNS server, and match the resolution service segment of the corresponding level for the requested analysis domain name;
[0048] A deep analysis module, used to identify the top-level domain of the domain name requested for analysis in the resolution service segment, determine the domain name attributes of the domain name requested for analysis, perform deep analysis on the domain name attributes and generate a DNS analysis record;
[0049] A domain name analysis module, used to generate a DNS record type of the requested domain name for analysis according to the DNS analysis record and the domain name risk level, and determine an execution object of the requested domain name for analysis;
[0050] The address identification module is used to determine the actual IP address of the requested analysis domain name according to the execution object, control the browser to connect to the actual IP address, and store the actual IP address in the browser.
[0051] In one practicable manner,
[0052] The risk identification module includes:
[0053] The protocol analysis unit is used to transmit the domain name requested for analysis sent by the browser to the DNS server, identify the readable address of the domain name requested for analysis in the DNS server, perform source tracing analysis on the readable address, obtain several domain name information of the domain name requested for analysis, and screen the usage protocol of the domain name requested for analysis from the domain name information;
[0054] A security identification unit, configured to determine the accessible resource range of the domain name requested for analysis according to the usage agreement, analyze the access-feedback relationship between the domain name requested for analysis and the accessible resource range in the DNS server, and determine the access security corresponding to each accessible resource;
[0055] A deep access unit, used to filter the domain name path of the requested analysis domain name in the domain name information, build an access method corresponding to the requested analysis domain name accessing each of the accessible resources in combination with the accessible resource range, determine a number of access ports corresponding to each of the access methods, and determine the path security corresponding to each of the accessible resources according to the port information corresponding to each of the access ports;
[0056] A risk matching unit is used to generate a domain name risk level of the requested analysis domain name according to the access security and path security, obtain a resolution service segment matching the domain name risk level in the DNS server, and transmit the requested analysis domain name to the corresponding resolution service segment.
[0057] The achievable beneficial effects of the above technical solution are as follows: when a browser sends a request, the domain name risk level of the domain name requested for analysis is analyzed in the DNS server, so as to match the corresponding resolution service segment for it, which can not only improve the quality of resolution, but also ensure the efficiency and effectiveness of the resolution process, and then determine the domain name attributes of the domain name requested for analysis by identifying the top-level domain of the domain name requested for analysis, and generate the corresponding DNS analysis record. After the analysis is completed, the DNS record type of the domain name requested for analysis is determined by comprehensively analyzing the DNS analysis record and the domain name risk level, thereby determining the execution object of the domain name requested for analysis, and finally determining the actual IP address of the domain name requested for analysis, controlling the browser to access the corresponding actual IP address, and completing this resolution work. In this way, the domain name can be converted into an IP address recognizable by a computer, so as to facilitate the browser to access again.
[0058] Other features and advantages of the present invention will be described in the following description, and partly become apparent from the description, or understood by practicing the present invention. The purpose and other advantages of the present invention can be realized and obtained by the structures particularly pointed out in the written description and the accompanying drawings.
[0059] The technical solution of the present invention is further described in detail below through the accompanying drawings and embodiments. BRIEF DESCRIPTION OF THE DRAWINGS
[0060] The accompanying drawings are used to provide a further understanding of the present invention and constitute a part of the specification. Together with the embodiments of the present invention, they are used to explain the present invention and do not constitute a limitation of the present invention. In the accompanying drawings:
[0061] Figure 1 A schematic diagram of a work flow of a domain name resolution method for a DNS server in an embodiment of the present invention;
[0062] Figure 2 The present invention is a schematic diagram of the composition of a domain name resolution system for a DNS server in an embodiment of the present invention. DETAILED DESCRIPTION
[0063] The preferred embodiments of the present invention are described below in conjunction with the accompanying drawings. It should be understood that the preferred embodiments described herein are only used to illustrate and explain the present invention, and are not used to limit the present invention.
[0064] Example 1
[0065] This embodiment provides a domain name resolution method for a DNS server, such as Figure 1 As shown, including:
[0066] Step 1: Obtain the domain name requested for analysis sent by the browser, identify the domain name risk level of the domain name requested for analysis in the DNS server, and match the domain name requested for analysis with a resolution service segment of the corresponding level;
[0067] Step 2: Identify the top-level domain of the domain name requested for analysis in the resolution service segment, determine the domain name attributes of the domain name requested for analysis, perform in-depth analysis on the domain name attributes and generate a DNS analysis record;
[0068] Step 3: Generate the DNS record type of the requested domain name for analysis according to the DNS analysis record and the domain name risk level, and determine the execution object of the requested domain name for analysis;
[0069] Step 4: Determine the actual IP address of the requested analysis domain name according to the execution object, control the browser to connect to the actual IP address, and store the actual IP address in the browser.
[0070] In this example, the domain name requested for analysis indicates that the browser has not yet connected and the domain name needs to be resolved. Its format is like www.example.com;
[0071] In this example, the domain risk level indicates the browsing risk involved in requesting the risky domain name;
[0072] In this example, the resolution service segment indicates a service location in a DNS server used to resolve a risky domain name;
[0073] In this example, the top-level domain indicates the method used to identify the source of the domain name requested for analysis. It is the last part in the domain name system, usually located at the far right of the domain name, immediately following the last dot, including: generic top-level domains, country and region top-level domains, new generic top-level domains, sponsored top-level domains, and infrastructure top-level domains;
[0074] In this example, the DNS record types include: A record, AAAA record, CNAME record, MX record, and NS record;
[0075] In this example, the execution objects include: PV4, PV6, another known domain name, mail server, text information storage domain, authoritative DNS server, primary DNS server, server host and port, return domain name, and application layer service;
[0076] In this example, the actual IP address refers to an IP address that a computer can understand, such as 192.0.2.1.
[0077] The working principle and beneficial effects of the above technical solution are as follows: when a browser sends a request, the domain name risk level of the domain name requested for analysis is analyzed in the DNS server, so as to match it with the corresponding resolution service segment, which can not only improve the quality of resolution, but also ensure the efficiency and effectiveness of the resolution process. Then, the domain name attributes of the domain name requested for analysis are determined by identifying the top-level domain of the domain name requested for analysis, and a corresponding DNS analysis record is generated. After the analysis is completed, the DNS record type of the domain name requested for analysis is determined by comprehensively analyzing the DNS analysis record and the domain name risk level, thereby determining the execution object of the domain name requested for analysis. Finally, the actual IP address of the domain name requested for analysis is determined, and the browser is controlled to access the corresponding actual IP address to complete this resolution work. In this way, the domain name can be converted into an IP address recognizable by a computer, which is convenient for the browser to access again.
[0078] Example 2
[0079] On the basis of Embodiment 1, the domain name resolution method for a DNS server, the step 1, comprises:
[0080] Step 11: transmitting the domain name requested for analysis sent by the browser to the DNS server, identifying the readable address of the domain name requested for analysis in the DNS server, performing source tracing analysis on the readable address, obtaining several pieces of domain name information of the domain name requested for analysis, and screening the usage protocol of the domain name requested for analysis in the domain name information;
[0081] Step 12: Determine the accessible resource range of the domain name requested for analysis according to the usage agreement, analyze the access-feedback relationship between the domain name requested for analysis and the accessible resource range in the DNS server, and determine the access security corresponding to each accessible resource;
[0082] Step 13: Filter the domain name path of the requested analysis domain name in the domain name information, build the corresponding access method when the requested analysis domain name accesses each of the accessible resources in combination with the accessible resource range, determine a number of access ports corresponding to each of the access methods, and determine the path security corresponding to each of the accessible resources according to the port information corresponding to each of the access ports;
[0083] Step 14: Generate a domain name risk level of the requested analysis domain name based on the access security and path security, obtain a resolution service segment matching the domain name risk level in the DNS server, and transmit the requested analysis domain name to the corresponding resolution service segment.
[0084] In this example, the readable address indicates the address of the domain name requested for analysis that can be identified in the DNS server;
[0085] In this example, the domain name information represents a number of pieces of information presented by the request to analyze the domain name;
[0086] In this instance, protocols are used to represent the rules and standards related to domain name registration, management and resolution;
[0087] In this instance, the accessible resource scope indicates the network resources that the domain name requesting the analysis can access;
[0088] In this example, the access-feedback relationship represents the feedback made by the DNS server when the request for analyzing the domain name accesses different resources;
[0089] In this example, the domain name path indicates the path of the domain name requested for analysis when accessing resources;
[0090] In this example, the access port refers to the computer port involved in making the access;
[0091] In this example, the path security refers to the security of different ports that the access path passes through, and the access security refers to the security level of accessing resources.
[0092] The working principle and beneficial effects of the above technical solution are as follows: when a browser makes a request, the requested analysis domain name is transmitted to the DNS server for address identification, the readable address of the requested analysis domain name is determined, and then the source is traced based on the address to determine several domain name information of the requested analysis domain name, and the usage protocol of the requested analysis domain name is screened therefrom. By using the usage protocol, the accessible resource range of the requested analysis domain name can be determined, and the relationship between the requested analysis domain name and the accessible resource range is analyzed in the DNS server, thereby determining the security of the resources accessed by the requested analysis domain name, and then analyzing the access ports involved in the domain name path, thereby determining the domain name risk level of the requested analysis domain name, and finally matching the requested analysis domain name with the corresponding resolution service segment, thereby ensuring the efficiency and quality of subsequent resolution work.
[0093] Example 3
[0094] On the basis of Embodiment 1, the method for domain name resolution for a DNS server, the step 2, comprises:
[0095] Step 21: In the resolution service section, the domain name requested for analysis is mapped to different preset domain name systems to obtain the expression form of the domain name requested for analysis in each preset domain name system, and the tail character string corresponding to each expression form is obtained to determine the top-level domain of the domain name requested for analysis;
[0096] Step 22: Determine the generation source of the domain name requested for analysis according to the top-level domain, determine several domain name information of the generation source in combination with the expression form of the domain name requested for analysis in each of the preset domain name systems, obtain information keywords corresponding to each of the domain name information respectively, and establish a domain name attribute for determining the domain name requested for analysis;
[0097] Step 23: Construct the domain name format corresponding to the domain name requested for analysis in each of the preset domain name systems according to the domain name attributes, input the domain name information into each of the domain name formats respectively to generate the analysis result of the domain name requested for analysis in each of the preset domain name systems, and generate the DNS analysis record of the domain name requested for analysis.
[0098] In this example, the preset domain name system includes: PV4, PV6, another known domain name, mail server, text information storage domain, authoritative DNS server, primary DNS server, server host and port, return domain name and application layer service;
[0099] In this example, the tail string represents the last string of the expression;
[0100] In this example, the domain name attribute indicates the top-level domain attribute of the domain name for which analysis is requested.
[0101] The working principle and beneficial effects of the above technical solution are as follows: by mapping the requested analysis domain name to different preset domain name systems to identify the expression form of the requested analysis domain name in different systems, by identifying the tail character string to determine the top-level domain name of the requested analysis domain name, then tracing the requested analysis domain name, collecting a number of domain name information, further determining the domain name attributes of the requested analysis domain name based on the information keywords of each domain name information, and finally determining the domain name format of the requested analysis domain name in different preset domain name systems, and performing analysis, determining the DNS analysis records of the requested analysis domain name in different preset domain name systems, in this way, the requested analysis domain name can be comprehensively analyzed to reduce omissions.
[0102] Example 4
[0103] On the basis of Embodiment 1, the domain name resolution method for a DNS server, the step 3, comprises:
[0104] Step 31: Decompose the DNS analysis record at the domain name risk level to obtain a plurality of flow data of the domain name requested for analysis, and generate a plurality of search conditions of the domain name requested for analysis according to the data value and risk dimension corresponding to each of the flow data;
[0105] Step 32: searching for a plurality of associated data of the domain name requested for analysis in the DNS server according to the search condition, constructing a trust part of the domain name requested for analysis according to the associated data, locating the trust parts in the DNS analysis record respectively, and determining the trust performance characteristics of the domain name requested for analysis in different preset domain name systems;
[0106] Step 33: Establish a DNS record of the requested domain name for analysis according to the trust performance characteristics, analyze the record integrity corresponding to each record type in the DNS record, select the first record type with the highest record integrity, and determine the execution object of the requested domain name for analysis.
[0107] In this example, the data value represents the numerical value presented by the flow data;
[0108] In this example, the risk dimension represents the dimension of security risk corresponding to the traffic data;
[0109] In this example, the associated data refers to data stored in the DNS server and is secure;
[0110] In this example, the trust portion indicates the secure portion of the domain name being requested for analysis.
[0111] The working principle and beneficial effects of the above technical solution are as follows: in order to determine the execution object of the domain name requested for analysis, the domain name requested for analysis is first decomposed, and several traffic data of the domain name requested for analysis are determined. Then, the search conditions are formed according to the data value and risk dimension of the traffic data of each day. The trust part of the domain name requested for analysis is determined by searching the DNS server for the associated data corresponding to each search condition, and the trust performance characteristics of the trust part in different preset domain name systems are determined. The integrity of each DNS record is further identified to determine the execution object of the domain name requested for analysis. In this way, the execution object of the domain name requested for analysis can be quickly located.
[0112] Example 5
[0113] Based on Embodiment 4, the domain name resolution method for a DNS server further includes:
[0114] Obtaining the untrusted portion of the domain name requested for analysis, locating each of the untrusted portions in the DNS analysis record, and determining untrusted performance characteristics of the domain name requested for analysis in different preset domain name systems;
[0115] Input each of the untrusted performance characteristics into the cloud DNS for security testing, and determine the security level corresponding to the untrusted part in each of the preset domain name systems according to the test results;
[0116] Screening the second record type with the highest security level;
[0117] When the second record type is consistent with the first record type, determining an execution object of the request to analyze the domain name;
[0118] On the contrary, the object corresponding to the second record type is regarded as the execution object of the request to analyze the domain name.
[0119] The working principle and beneficial effects of the above technical solution: When the record type corresponding to the non-trusted part of the domain name requested for analysis is inconsistent with the record type of the trusted part, in order to avoid risk intrusion, the execution object of the domain name requested for analysis is determined according to the record type corresponding to the non-trusted part.
[0120] Example 6
[0121] On the basis of Embodiment 1, the domain name resolution method for a DNS server, the step 4, comprises:
[0122] Step 41: construct an address conversion scheme according to the address format of the execution object, convert the requested analysis domain name into an IP address using the address conversion scheme, and input the IP address into the address format to obtain the actual IP address of the requested analysis domain name;
[0123] Step 42: Control the browser to connect to the actual IP address, collect a number of browsing access information of the browser during the connection process, determine the browsing web page attributes of the request analysis domain name according to the browsing access information, and store the actual IP address in the attribute storage area corresponding to the browser.
[0124] The working principle and beneficial effects of the above technical solution are as follows: when performing address conversion, a conversion scheme is established according to the address format of the implementation object, and then the request analysis domain name is converted into an actual IP address, and the browser is further controlled to connect to the actual IP address, and the browser's browsing access information is obtained during the access process, and the browsing web page attributes of the request analysis domain name are determined, and finally the actual IP address is stored in the corresponding area for easy browsing next time.
[0125] Example 7
[0126] Based on Example 6, the domain name resolution method for a DNS server further includes:
[0127] Regularly update each attribute storage area respectively;
[0128] Respectively obtain the browsing frequencies corresponding to different stored domain names in each of the attribute storage areas to construct the browsing preferences of the browser;
[0129] A corresponding secure domain name is recommended to the browser according to the browsing preference.
[0130] The working principle and beneficial effects of the above technical solution: In order to improve the user's experience of use, web page recommendations are made according to the user's preferences to increase the user's interest in use.
[0131] Example 8
[0132] Based on Embodiment 1, the domain name resolution method for a DNS server further includes:
[0133] When the risk level of the domain name of the domain name requested for analysis is higher than the standard risk level, the browser is controlled to log out.
[0134] In this example, the standard risk level is: medium risk level.
[0135] The working principle and beneficial effects of the above technology: When the domain name requested for analysis is a dangerous domain name, access is stopped in time to avoid network risks.
[0136] Example 9
[0137] This embodiment provides a domain name resolution system for a DNS server, such as Figure 2 As shown, including:
[0138] A risk identification module is used to obtain the requested analysis domain name sent by the browser, identify the domain name risk level of the requested analysis domain name in the DNS server, and match the resolution service segment of the corresponding level for the requested analysis domain name;
[0139] A deep analysis module, used to identify the top-level domain of the domain name requested for analysis in the resolution service segment, determine the domain name attributes of the domain name requested for analysis, perform deep analysis on the domain name attributes and generate a DNS analysis record;
[0140] A domain name analysis module, used to generate a DNS record type of the requested domain name for analysis according to the DNS analysis record and the domain name risk level, and determine an execution object of the requested domain name for analysis;
[0141] The address identification module is used to determine the actual IP address of the requested analysis domain name according to the execution object, control the browser to connect to the actual IP address, and store the actual IP address in the browser.
[0142] In this example, the domain name requested for analysis indicates that the browser has not yet connected and the domain name needs to be resolved. Its format is like www.example.com;
[0143] In this example, the domain risk level indicates the browsing risk involved in requesting the risky domain name;
[0144] In this example, the resolution service segment indicates a service location in a DNS server used to resolve a risky domain name;
[0145] In this example, the top-level domain indicates the method used to identify the source of the domain name requested for analysis. It is the last part in the domain name system, usually located at the far right of the domain name, immediately following the last dot, including: generic top-level domains, country and region top-level domains, new generic top-level domains, sponsored top-level domains, and infrastructure top-level domains;
[0146] In this example, the DNS record types include: A record, AAAA record, CNAME record, MX record, and NS record;
[0147] In this example, the execution objects include: PV4, PV6, another known domain name, mail server, text information storage domain, authoritative DNS server, primary DNS server, server host and port, return domain name, and application layer service;
[0148] In this example, the actual IP address refers to an IP address that can be understood by a computer, such as 192.0.2.1.
[0149] The working principle and beneficial effects of the above technical solution are as follows: when a browser sends a request, the domain name risk level of the domain name requested for analysis is analyzed in the DNS server, so as to match it with the corresponding resolution service segment, which can not only improve the quality of resolution, but also ensure the efficiency and effectiveness of the resolution process. Then, the domain name attributes of the domain name requested for analysis are determined by identifying the top-level domain of the domain name requested for analysis, and a corresponding DNS analysis record is generated. After the analysis is completed, the DNS record type of the domain name requested for analysis is determined by comprehensively analyzing the DNS analysis record and the domain name risk level, thereby determining the execution object of the domain name requested for analysis. Finally, the actual IP address of the domain name requested for analysis is determined, and the browser is controlled to access the corresponding actual IP address to complete this resolution work. In this way, the domain name can be converted into an IP address recognizable by a computer, which is convenient for the browser to access again.
[0150] Example 10
[0151] On the basis of Example 9, the domain name resolution system for a DNS server, the risk identification module includes:
[0152] The protocol analysis unit is used to transmit the domain name requested for analysis sent by the browser to the DNS server, identify the readable address of the domain name requested for analysis in the DNS server, perform source tracing analysis on the readable address, obtain several domain name information of the domain name requested for analysis, and screen the usage protocol of the domain name requested for analysis from the domain name information;
[0153] A security identification unit, configured to determine the accessible resource range of the domain name requested for analysis according to the usage agreement, analyze the access-feedback relationship between the domain name requested for analysis and the accessible resource range in the DNS server, and determine the access security corresponding to each accessible resource;
[0154] A deep access unit, used to filter the domain name path of the requested analysis domain name in the domain name information, build an access method corresponding to the requested analysis domain name accessing each of the accessible resources in combination with the accessible resource range, determine a number of access ports corresponding to each of the access methods, and determine the path security corresponding to each of the accessible resources according to the port information corresponding to each of the access ports;
[0155] A risk matching unit is used to generate a domain name risk level of the requested analysis domain name according to the access security and path security, obtain a resolution service segment matching the domain name risk level in the DNS server, and transmit the requested analysis domain name to the corresponding resolution service segment.
[0156] In this example, the readable address indicates the address of the domain name requested for analysis that can be identified in the DNS server;
[0157] In this example, the domain name information represents a number of pieces of information presented by the request to analyze the domain name;
[0158] In this instance, protocols are used to represent the rules and standards related to domain name registration, management and resolution;
[0159] In this instance, the accessible resource scope indicates the network resources that the domain name requesting analysis can access;
[0160] In this example, the access-feedback relationship represents the feedback made by the DNS server when the request for analyzing the domain name accesses different resources;
[0161] In this example, the domain name path indicates the path of the domain name requested for analysis when accessing resources;
[0162] In this example, the access port refers to the computer port involved in making the access;
[0163] In this example, the path security refers to the security of different ports that the access path passes through, and the access security refers to the security level of accessing resources.
[0164] The working principle and beneficial effects of the above technical solution are as follows: when a browser makes a request, the requested analysis domain name is transmitted to the DNS server for address identification, the readable address of the requested analysis domain name is determined, and then the source is traced based on the address to determine several domain name information of the requested analysis domain name, and the usage protocol of the requested analysis domain name is screened therefrom. By using the usage protocol, the accessible resource range of the requested analysis domain name can be determined, and the relationship between the requested analysis domain name and the accessible resource range is analyzed in the DNS server, thereby determining the security of the resources accessed by the requested analysis domain name, and then analyzing the access ports involved in the domain name path, thereby determining the domain name risk level of the requested analysis domain name, and finally matching the requested analysis domain name with the corresponding resolution service segment, thereby ensuring the efficiency and quality of subsequent resolution work.
[0165] Obviously, those skilled in the art can make various changes and modifications to the present invention without departing from the spirit and scope of the present invention. Thus, if these modifications and variations of the present invention fall within the scope of the claims of the present invention and their equivalents, the present invention is also intended to include these modifications and variations.
Claims
1. A domain name resolution method for a DNS server, characterized in that: include: Step 1: Obtain the domain name requested for analysis sent by the browser, identify the domain name risk level of the domain name requested for analysis in the DNS server, and match the domain name requested for analysis with a resolution service segment of the corresponding level; Step 2: Identify the top-level domain of the domain name requested for analysis in the resolution service segment, determine the domain name attributes of the domain name requested for analysis, perform in-depth analysis on the domain name attributes and generate a DNS analysis record; Step 3: Generate the DNS record type of the requested domain name for analysis according to the DNS analysis record and the domain name risk level, and determine the execution object of the requested domain name for analysis; Step 4: Determine the actual IP address of the requested analysis domain name according to the execution object, control the browser to connect to the actual IP address, and store the actual IP address in the browser.
2. A method for domain name resolution for a DNS server as claimed in claim 1, characterized in that: The step 1 comprises: Step 11: transmitting the domain name requested for analysis sent by the browser to the DNS server, identifying the readable address of the domain name requested for analysis in the DNS server, performing source tracing analysis on the readable address, obtaining several pieces of domain name information of the domain name requested for analysis, and screening the usage protocol of the domain name requested for analysis in the domain name information; Step 12: Determine the accessible resource range of the domain name requested for analysis according to the usage agreement, analyze the access-feedback relationship between the domain name requested for analysis and the accessible resource range in the DNS server, and determine the access security corresponding to each accessible resource; Step 13: Filter the domain name path of the requested analysis domain name in the domain name information, build the corresponding access method when the requested analysis domain name accesses each of the accessible resources in combination with the accessible resource range, determine a number of access ports corresponding to each of the access methods, and determine the path security corresponding to each of the accessible resources according to the port information corresponding to each of the access ports; Step 14: Generate a domain name risk level of the requested analysis domain name based on the access security and path security, obtain a resolution service segment matching the domain name risk level in the DNS server, and transmit the requested analysis domain name to the corresponding resolution service segment.
3. A method for domain name resolution for a DNS server as claimed in claim 1, characterized in that: The step 2 comprises: Step 21: In the resolution service section, the domain name requested for analysis is mapped to different preset domain name systems to obtain the expression form of the domain name requested for analysis in each preset domain name system, and the tail character string corresponding to each expression form is obtained to determine the top-level domain of the domain name requested for analysis; Step 22: Determine the generation source of the domain name requested for analysis according to the top-level domain, determine several domain name information of the generation source in combination with the expression form of the domain name requested for analysis in each of the preset domain name systems, obtain information keywords corresponding to each of the domain name information respectively, and establish a domain name attribute for determining the domain name requested for analysis; Step 23: Construct the domain name format corresponding to the domain name requested for analysis in each of the preset domain name systems according to the domain name attributes, input the domain name information into each of the domain name formats respectively to generate the analysis result of the domain name requested for analysis in each of the preset domain name systems, and generate the DNS analysis record of the domain name requested for analysis.
4. A method for domain name resolution for a DNS server as claimed in claim 1, characterized in that: The step 3 comprises: Step 31: Decompose the DNS analysis record at the domain name risk level to obtain a plurality of flow data of the domain name requested for analysis, and generate a plurality of search conditions of the domain name requested for analysis according to the data value and risk dimension corresponding to each of the flow data; Step 32: searching for a plurality of associated data of the domain name requested for analysis in the DNS server according to the search condition, constructing a trust part of the domain name requested for analysis according to the associated data, locating the trust parts in the DNS analysis record respectively, and determining the trust performance characteristics of the domain name requested for analysis in different preset domain name systems; Step 33: Establish a DNS record of the requested domain name for analysis according to the trust performance characteristics, analyze the record integrity corresponding to each record type in the DNS record, select the first record type with the highest record integrity, and determine the execution object of the requested domain name for analysis.
5. A method for domain name resolution for a DNS server as claimed in claim 4, characterized in that: Also includes: Obtaining the untrusted portion of the domain name requested for analysis, locating each of the untrusted portions in the DNS analysis record, and determining untrusted performance characteristics of the domain name requested for analysis in different preset domain name systems; Input each of the untrusted performance characteristics into the cloud DNS for security testing, and determine the security level corresponding to the untrusted part in each of the preset domain name systems according to the test results; Screening the second record type with the highest security level; When the second record type is consistent with the first record type, determining an execution object of the request to analyze the domain name; On the contrary, the object corresponding to the second record type is regarded as the execution object of the request to analyze the domain name.
6. A method for domain name resolution for a DNS server as claimed in claim 1, characterized in that: The step 4 comprises: Step 41: construct an address conversion scheme according to the address format of the execution object, convert the requested analysis domain name into an IP address using the address conversion scheme, and input the IP address into the address format to obtain the actual IP address of the requested analysis domain name; Step 42: Control the browser to connect to the actual IP address, collect a number of browsing access information of the browser during the connection process, determine the browsing web page attributes of the request analysis domain name according to the browsing access information, and store the actual IP address in the attribute storage area corresponding to the browser.
7. A method for domain name resolution for a DNS server as claimed in claim 6, characterized in that: Also includes: Regularly update each attribute storage area respectively; Respectively obtain the browsing frequencies corresponding to different stored domain names in each of the attribute storage areas to construct the browsing preferences of the browser; A corresponding secure domain name is recommended to the browser according to the browsing preference.
8. A method for domain name resolution for a DNS server as claimed in claim 1, characterized in that: Also includes: When the risk level of the domain name of the domain name requested for analysis is higher than the standard risk level, the browser is controlled to log out.
9. A domain name resolution system for a DNS server, characterized in that: include: A risk identification module is used to obtain the requested analysis domain name sent by the browser, identify the domain name risk level of the requested analysis domain name in the DNS server, and match the resolution service segment of the corresponding level for the requested analysis domain name; A deep analysis module, used to identify the top-level domain of the domain name requested for analysis in the resolution service segment, determine the domain name attributes of the domain name requested for analysis, perform deep analysis on the domain name attributes and generate a DNS analysis record; A domain name analysis module, used to generate a DNS record type of the requested domain name for analysis according to the DNS analysis record and the domain name risk level, and determine an execution object of the requested domain name for analysis; The address identification module is used to determine the actual IP address of the requested analysis domain name according to the execution object, control the browser to connect to the actual IP address, and store the actual IP address in the browser.
10. A domain name resolution system for a DNS server as claimed in claim 9, characterized in that: The risk identification module includes: The protocol analysis unit is used to transmit the domain name requested for analysis sent by the browser to the DNS server, identify the readable address of the domain name requested for analysis in the DNS server, perform source tracing analysis on the readable address, obtain several domain name information of the domain name requested for analysis, and screen the usage protocol of the domain name requested for analysis from the domain name information; A security identification unit, configured to determine the accessible resource range of the domain name requested for analysis according to the usage agreement, analyze the access-feedback relationship between the domain name requested for analysis and the accessible resource range in the DNS server, and determine the access security corresponding to each accessible resource; A deep access unit, used to filter the domain name path of the requested analysis domain name in the domain name information, build an access method corresponding to the requested analysis domain name accessing each of the accessible resources in combination with the accessible resource range, determine a number of access ports corresponding to each of the access methods, and determine the path security corresponding to each of the accessible resources according to the port information corresponding to each of the access ports; A risk matching unit is used to generate a domain name risk level of the requested analysis domain name according to the access security and path security, obtain a resolution service segment matching the domain name risk level in the DNS server, and transmit the requested analysis domain name to the corresponding resolution service segment.
Citation Information
Patent Citations
Method for ensuring and forwarding TOP domain name of DNS cache server
CN117459494A
Network address management and functional object discovery system
US20140222987A1