A domain name resolution method and system for a DNS server

By conducting in-depth analysis of DNS servers, identifying domain name risk levels and attributes, and generating DNS analysis records, the problem of insufficient efficiency and quality of DNS servers in domain name resolution is solved, and an efficient and secure domain name resolution process is achieved.

CN119946017BActive Publication Date: 2025-12-05BEIJING TESTOR TECH
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510026738.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-01-08
Publication Date
2025-12-05
Estimated Expiration
2045-01-08

AI Technical Summary

Technical Problem

Existing DNS servers struggle to provide comprehensive IP address resolution capabilities during domain name resolution, and are unable to effectively identify domain name security and risks, resulting in insufficient resolution efficiency and quality.

Method used

By performing in-depth analysis of the domain name requested by the browser in the DNS server, the risk level of the domain name is identified, the corresponding resolution service segment is matched, the attributes of the top-level domain are determined, and DNS analysis records are generated, ultimately determining the target of the domain name and the actual IP address.

Benefits of technology

It improves the quality and efficiency of domain name resolution, ensures the efficiency and effectiveness of the resolution process, can identify the security of domain names and convert them into computer-recognizable IP addresses, making it easy for browsers to access them.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119946017B_ABST
    Figure CN119946017B_ABST
Patent Text Reader

Abstract

The application provides a domain name resolution method and system for a DNS server, comprising the following steps: identifying a domain name risk level of a request analysis domain name in a DNS server, matching a corresponding level of a resolution service segment for the request analysis domain name, identifying a top-level domain of the request analysis domain name to determine a domain name attribute, performing deep analysis on the domain name attribute and generating a DNS analysis record, generating a DNS record type of the request analysis domain name in combination with the domain name risk level, determining an execution object of the request analysis domain name, determining an actual IP address of the request analysis domain name according to the execution object, controlling a browser to be connected to the actual IP address, and storing the actual IP address in the browser, so that deep analysis can be performed on a domain name to be connected by the browser, the security of the domain name is determined, the domain name is converted into an IP address which is better recognized by the browser, and the browser is facilitated to access again.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of domain name resolution technology, and in particular to a domain name resolution method and system for a DNS server. Background Technology

[0002] DNS stands for Domain Name System, used to name computer and network services in hierarchical structures from organizations to domains. DNS servers provide domain name resolution services to clients, resolving the domain name entered by the client into the corresponding IP address, which the client can then use to access the website associated with that domain name.

[0003] In recent years, the Internet has developed very rapidly. Domain names are one of the earliest products that have appeared with the Internet, and people have become increasingly familiar with them. From the time a domain name is applied for and registered until it is put into use, it will generate characteristics related to the domain name. However, with the continuous enhancement of Internet functions and the increasingly strong interaction with the real world, DNS is needed to provide more information resolution functions beyond IP addresses.

[0004] Therefore, the present invention provides a domain name resolution method and system for DNS servers. Summary of the Invention

[0005] This invention provides a domain name resolution method and system for DNS servers, which can perform in-depth analysis on the domain name that the browser wants to connect to, determine the security of the domain name, and convert the domain name into an IP address that the browser can better recognize, so that the browser can access it again.

[0006] This invention provides a domain name resolution method for a DNS server, comprising:

[0007] Step 1: Obtain the domain name requested for analysis sent by the browser, identify the domain name risk level of the requested domain name in the DNS server, and match the corresponding level of resolution service segment for the requested domain name;

[0008] Step 2: Identify the top-level domain of the requested domain name in the DNS resolution service segment, determine the domain name attributes of the requested domain name, perform in-depth analysis on the domain name attributes, and generate DNS analysis records;

[0009] Step 3: Generate the DNS record type for the requested domain name based on the DNS analysis record and the domain name risk level, and determine the execution target of the requested domain name;

[0010] Step 4: Determine the actual IP address of the requested domain name based on the execution object, control the browser to connect to the actual IP address, and store the actual IP address in the browser.

[0011] In one feasible approach

[0012] Step 1 includes:

[0013] Step 11: The request to analyze the domain name sent by the browser is transmitted to the DNS server. The readable address of the request to analyze the domain name is identified in the DNS server. The readable address is traced and analyzed to obtain several domain name information of the request to analyze the domain name. The usage protocol of the request to analyze the domain name is filtered from the domain name information.

[0014] Step 12: Determine the accessible resource range of the requested analysis domain name according to the usage agreement, analyze the access-feedback relationship between the requested analysis domain name and the accessible resource range in the DNS server, and determine the access security level corresponding to each accessible resource;

[0015] Step 13: Filter the domain path of the requested analysis domain in the domain information, build the access method corresponding to the requested analysis domain when accessing each of the accessible resources in combination with the accessible resource range, determine several access ports corresponding to each access method, and determine the path security level corresponding to each accessible resource based on the port information corresponding to each access port.

[0016] Step 14: Generate the domain name risk level of the requested analysis domain name based on the access security and path security, obtain the resolution service segment that matches the domain name risk level from the DNS server, and transmit the requested analysis domain name to the corresponding resolution service segment.

[0017] In one feasible approach

[0018] Step 2 includes:

[0019] Step 21: In the DNS resolution service segment, the requested analysis domain name is mapped to different preset domain name systems to obtain the expression form of the requested analysis domain name in each preset domain name system, the tail string corresponding to each expression form is obtained, and the top-level domain of the requested analysis domain name is determined.

[0020] Step 22: Determine the generation source of the requested analysis domain name based on the top-level domain, and determine several domain name information of the generation source by combining the expression form of the requested analysis domain name in each of the preset domain name systems. Obtain the information keywords corresponding to each of the domain name information, and establish the domain name attributes of the requested analysis domain name.

[0021] Step 23: Construct the domain name format corresponding to the requested analysis domain name in each of the preset domain name systems based on the domain name attributes, input the domain name information into each of the domain name formats respectively to generate the analysis result of the requested analysis domain name in each of the preset domain name systems, and generate the DNS analysis record of the requested analysis domain name.

[0022] In one feasible approach

[0023] Step 3 includes:

[0024] Step 31: Decompose the DNS analysis record under the domain risk level to obtain several traffic data of the requested domain. Generate several lookup conditions for the requested domain based on the data value and risk dimension corresponding to each traffic data.

[0025] Step 32: Based on the search criteria, search the DNS server for several associated data of the requested domain name, construct the trust part of the requested domain name based on the associated data, locate the trust part in the DNS analysis record respectively, and determine the trust performance characteristics of the requested domain name in different preset domain name systems.

[0026] Step 33: Establish DNS records for the requested domain name based on the trust performance characteristics, analyze the record integrity of each record type in the DNS records, filter the first record type with the highest record integrity, and determine the execution target of the requested domain name.

[0027] In one feasible approach

[0028] Also includes:

[0029] Obtain the untrusted portion of the requested domain name, locate each untrusted portion in the DNS analysis record, and determine the untrusted behavior characteristics of the requested domain name in different preset domain name systems.

[0030] Each of the untrusted behavior characteristics is input into the cloud DNS for security testing, and the security level of the untrusted part in each preset domain name system is determined based on the test results.

[0031] Filter the second record type with the highest security level;

[0032] When the second record type is consistent with the first record type, the execution object of the requested analysis domain name is determined;

[0033] Conversely, the object corresponding to the second record type is regarded as the execution object of the requested analysis domain name.

[0034] In one feasible approach

[0035] Step 4 includes:

[0036] Step 41: Construct an address translation scheme based on the address format of the execution object, use the address translation scheme to convert the requested analysis domain name into an IP address, and input the IP address into the address format to obtain the actual IP address of the requested analysis domain name;

[0037] Step 42: Control the browser to connect to the actual IP address, collect several browsing access information during the connection process, determine the browsing webpage attributes of the requested analysis domain name based on the browsing access information, and store the actual IP address in the attribute storage area corresponding to the browser.

[0038] In one feasible approach

[0039] Also includes:

[0040] Each attribute storage area is updated periodically.

[0041] The browsing frequency corresponding to different stored domain names in each of the attribute storage areas is obtained respectively to construct the browser's browsing preferences;

[0042] Recommend appropriate secure domain names to the browser based on the browsing preferences.

[0043] In one feasible approach

[0044] Also includes:

[0045] When the domain risk level of the requested domain is higher than the standard risk level, the browser is controlled to log out.

[0046] This invention provides a domain name resolution system for a DNS server, comprising:

[0047] The risk identification module is used to obtain the domain name requested for analysis sent by the browser, identify the domain name risk level of the requested domain name in the DNS server, and match the corresponding level of resolution service segment for the requested domain name;

[0048] The deep analysis module is used to identify the top-level domain of the requested analysis domain name in the DNS service segment, determine the domain name attributes of the requested analysis domain name, perform deep analysis on the domain name attributes, and generate DNS analysis records.

[0049] The domain name analysis module is used to generate the DNS record type of the requested domain name based on the DNS analysis record and the domain name risk level, and to determine the execution target of the requested domain name.

[0050] The address recognition module is used to determine the actual IP address of the requested analysis domain name based on the execution object, control the browser to connect to the actual IP address, and store the actual IP address in the browser.

[0051] In one feasible approach

[0052] The risk identification module includes:

[0053] The protocol analysis unit is used to transmit the domain name request sent by the browser to the DNS server, identify the readable address of the domain name request in the DNS server, perform source analysis on the readable address to obtain several domain name information of the domain name request, and filter the usage protocol of the domain name request from the domain name information.

[0054] A security identification unit is used to determine the accessible resource range of the requested analysis domain name according to the usage protocol, analyze the access-feedback relationship between the requested analysis domain name and the accessible resource range in the DNS server, and determine the access security level corresponding to each accessible resource.

[0055] The deep access unit is used to filter the domain path of the requested analysis domain in the domain information, build the access method corresponding to the requested analysis domain when accessing each of the accessible resources in combination with the accessible resource range, determine a number of access ports corresponding to each access method, and determine the path security level corresponding to each accessible resource based on the port information corresponding to each access port.

[0056] The risk matching unit is used to generate a domain name risk level of the requested analysis domain name based on the access security and path security, obtain a resolution service segment that matches the domain name risk level from the DNS server, and transmit the requested analysis domain name to the corresponding resolution service segment.

[0057] The beneficial effects of the above technical solution are as follows: When a browser sends a request, the DNS server analyzes the domain risk level of the requested domain and matches it with the appropriate DNS resolution service segment. This improves the quality of resolution and ensures the efficiency and effectiveness of the resolution process. Then, by identifying the top-level domain of the requested domain, the domain attributes are determined, and corresponding DNS resolution records are generated. After the analysis is completed, the DNS record type of the requested domain is determined by comprehensively analyzing the DNS resolution records and the domain risk level, thereby determining the target of the requested domain. Finally, the actual IP address of the requested domain is determined, and the browser is controlled to access the corresponding actual IP address, completing the resolution work. In this way, the domain name can be converted into a computer-recognizable IP address, facilitating the browser's re-access.

[0058] Other features and advantages of the invention will be set forth in the following description, and will be apparent in part from the description, or may be learned by practicing the invention. The objects and other advantages of the invention may be realized and obtained by means of the structures particularly pointed out in the written description and the accompanying drawings.

[0059] The technical solution of the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. Attached Figure Description

[0060] The accompanying drawings are provided to further illustrate the invention and form part of the specification. They are used together with the embodiments of the invention to explain the invention and do not constitute a limitation thereof. In the drawings:

[0061] Figure 1 This is a schematic diagram illustrating the workflow of a domain name resolution method for a DNS server according to an embodiment of the present invention.

[0062] Figure 2 This is a schematic diagram of the composition of a domain name resolution system for a DNS server according to an embodiment of the present invention. Detailed Implementation

[0063] The preferred embodiments of the present invention will be described below with reference to the accompanying drawings. It should be understood that the preferred embodiments described herein are for illustration and explanation only and are not intended to limit the present invention.

[0064] Example 1

[0065] This embodiment provides a domain name resolution method for a DNS server, such as... Figure 1 As shown, it includes:

[0066] Step 1: Obtain the domain name requested for analysis sent by the browser, identify the domain name risk level of the requested domain name in the DNS server, and match the corresponding level of resolution service segment for the requested domain name;

[0067] Step 2: Identify the top-level domain of the requested domain name in the DNS resolution service segment, determine the domain name attributes of the requested domain name, perform in-depth analysis on the domain name attributes, and generate DNS analysis records;

[0068] Step 3: Generate the DNS record type for the requested domain name based on the DNS analysis record and the domain name risk level, and determine the execution target of the requested domain name;

[0069] Step 4: Determine the actual IP address of the requested domain name based on the execution object, control the browser to connect to the actual IP address, and store the actual IP address in the browser.

[0070] In this example, the requested domain name indicates that the browser has not yet connected and the domain name needs to be resolved, such as www.example.com;

[0071] In this example, the domain risk level indicates the browsing risk involved in requesting a risky domain;

[0072] In this example, the resolution service segment represents the service location within the DNS server used to resolve a risky domain name;

[0073] In this example, the top-level domain (TLD) represents the way the request to analyze the domain name originates. It is the last part of the domain name system, usually located at the far right of the domain name, immediately following the last dot. It includes: general top-level domains, country code top-level domains, new general top-level domains, sponsored top-level domains, and infrastructure top-level domains.

[0074] In this example, the DNS record types include: A record, AAAA record, CNAME record, MX record, and NS record;

[0075] In this example, the objects being executed include: PV4, PV6, another known domain name, mail server, text message storage domain, authoritative DNS server, primary DNS server, server host and port, return domain name, and application layer services;

[0076] In this example, the actual IP address refers to the IP address that the computer can understand, such as 192.0.2.1.

[0077] The working principle and beneficial effects of the above technical solution are as follows: When a browser sends a request, the DNS server analyzes the domain risk level of the requested domain and matches it with the appropriate DNS resolution service segment. This improves the quality of resolution and ensures the efficiency and effectiveness of the resolution process. Then, by identifying the top-level domain of the requested domain, the domain attributes are determined, and corresponding DNS resolution records are generated. After the analysis is completed, the DNS record type of the requested domain is determined by comprehensively analyzing the DNS resolution records and the domain risk level, thereby determining the target of the requested domain. Finally, the actual IP address of the requested domain is determined, and the browser is controlled to access the corresponding actual IP address, completing the resolution work. In this way, the domain name can be converted into a computer-recognizable IP address, making it easier for the browser to access it again.

[0078] Example 2

[0079] Based on Example 1, the method for domain name resolution for a DNS server, step 1 includes:

[0080] Step 11: The request to analyze the domain name sent by the browser is transmitted to the DNS server. The readable address of the request to analyze the domain name is identified in the DNS server. The readable address is traced and analyzed to obtain several domain name information of the request to analyze the domain name. The usage protocol of the request to analyze the domain name is filtered from the domain name information.

[0081] Step 12: Determine the accessible resource range of the requested analysis domain name according to the usage agreement, analyze the access-feedback relationship between the requested analysis domain name and the accessible resource range in the DNS server, and determine the access security level corresponding to each accessible resource;

[0082] Step 13: Filter the domain path of the requested analysis domain in the domain information, build the access method corresponding to the requested analysis domain when accessing each of the accessible resources in combination with the accessible resource range, determine several access ports corresponding to each access method, and determine the path security level corresponding to each accessible resource based on the port information corresponding to each access port.

[0083] Step 14: Generate the domain name risk level of the requested analysis domain name based on the access security and path security, obtain the resolution service segment that matches the domain name risk level from the DNS server, and transmit the requested analysis domain name to the corresponding resolution service segment.

[0084] In this example, a readable address refers to the address that the requested domain name can be recognized in the DNS server;

[0085] In this example, the domain information represents several pieces of information presented by the request to analyze the domain;

[0086] In this example, protocols are used to represent the rules and standards related to domain name registration, management, and resolution;

[0087] In this example, the accessible resource range represents the network resources that the requested analysis domain name can access;

[0088] In this example, the access-feedback relationship represents the response from the DNS server when a request to analyze a domain name accesses different resources;

[0089] In this example, the domain path represents the path that the requested domain name takes when accessing resources;

[0090] In this example, the access port refers to the computer port involved when making the access;

[0091] In this example, path security refers to the security of the different ports traversed by the access path, and access security refers to the degree of security of accessing resources.

[0092] The working principle and beneficial effects of the above technical solution are as follows: When a browser makes a request, the requested domain name is transmitted to the DNS server for address identification, which determines the readable address of the requested domain name. Then, based on this address, the source is traced to determine several domain name information entries for the requested domain name, and the usage protocol of the requested domain name is filtered out. By using the protocol, the accessible resource range of the requested domain name can be determined. The relationship between the requested domain name and the accessible resource range is analyzed in the DNS server, thereby determining the security level of the resources accessed by the requested domain name. Then, the access ports involved in the domain name path are analyzed to determine the domain name risk level of the requested domain name. Finally, the corresponding resolution service segment is matched for the requested domain name, ensuring the efficiency and quality of subsequent resolution work.

[0093] Example 3

[0094] Based on Example 1, the domain name resolution method for a DNS server, step 2 includes:

[0095] Step 21: In the DNS resolution service segment, the requested analysis domain name is mapped to different preset domain name systems to obtain the expression form of the requested analysis domain name in each preset domain name system, the tail string corresponding to each expression form is obtained, and the top-level domain of the requested analysis domain name is determined.

[0096] Step 22: Determine the generation source of the requested analysis domain name based on the top-level domain, and determine several domain name information of the generation source by combining the expression form of the requested analysis domain name in each of the preset domain name systems. Obtain the information keywords corresponding to each of the domain name information, and establish the domain name attributes of the requested analysis domain name.

[0097] Step 23: Construct the domain name format corresponding to the requested analysis domain name in each of the preset domain name systems based on the domain name attributes, input the domain name information into each of the domain name formats respectively to generate the analysis result of the requested analysis domain name in each of the preset domain name systems, and generate the DNS analysis record of the requested analysis domain name.

[0098] In this example, the default domain name system includes: PV4, PV6, another known domain name, mail server, text message storage domain, authoritative DNS server, primary DNS server, server host and port, return domain name, and application layer services;

[0099] In this example, the tail string represents the last string of the expression;

[0100] In this example, the domain attribute represents the top-level domain attribute of the requested domain.

[0101] The working principle and beneficial effects of the above technical solution are as follows: By mapping the requested domain name to different preset domain name systems, the expression form of the requested domain name in different systems is identified. The top-level domain of the requested domain name is determined by identifying the tail string. Then, the requested domain name is traced back to its source, and several domain name information is collected. Further, the domain name attributes of the requested domain name are determined based on the information keywords of each domain name information. Finally, the domain name format of the requested domain name in different preset domain name systems is determined and analyzed. The DNS analysis records of the requested domain name in different preset domain name systems are determined. In this way, the requested domain name can be analyzed in a comprehensive manner, reducing the occurrence of omissions.

[0102] Example 4

[0103] Based on Example 1, the domain name resolution method for a DNS server, step 3 includes:

[0104] Step 31: Decompose the DNS analysis record under the domain risk level to obtain several traffic data of the requested domain. Generate several lookup conditions for the requested domain based on the data value and risk dimension corresponding to each traffic data.

[0105] Step 32: Based on the search criteria, search the DNS server for several associated data of the requested domain name, construct the trust part of the requested domain name based on the associated data, locate the trust part in the DNS analysis record respectively, and determine the trust performance characteristics of the requested domain name in different preset domain name systems.

[0106] Step 33: Establish DNS records for the requested domain name based on the trust performance characteristics, analyze the record integrity of each record type in the DNS records, filter the first record type with the highest record integrity, and determine the execution target of the requested domain name.

[0107] In this example, the data value represents the numerical value presented by the traffic data;

[0108] In this example, the risk dimension represents the dimension of security risk corresponding to the traffic data;

[0109] In this example, the associated data represents secure data stored in a DNS server;

[0110] In this example, the trusted part represents the secure portion of the requested domain name.

[0111] The working principle and beneficial effects of the above technical solution are as follows: In order to determine the execution target of the requested analysis domain name, the requested analysis domain name is first decomposed to determine several traffic data of the requested analysis domain name. Then, based on the data value and risk dimension of the traffic data for each day, lookup conditions are constructed. By searching the associated data corresponding to each lookup condition in the DNS server, the trusted part of the requested analysis domain name is determined, and the trust performance characteristics of this trusted part in different preset domain name systems are determined. Furthermore, the integrity of each DNS record is identified to determine the execution target of the requested analysis domain name. In this way, the execution target of the requested analysis domain name can be quickly located.

[0112] Example 5

[0113] Based on Example 4, the method for domain name resolution for a DNS server further includes:

[0114] Obtain the untrusted portion of the requested domain name, locate each untrusted portion in the DNS analysis record, and determine the untrusted behavior characteristics of the requested domain name in different preset domain name systems.

[0115] Each of the untrusted behavior characteristics is input into the cloud DNS for security testing, and the security level of the untrusted part in each preset domain name system is determined based on the test results.

[0116] Filter the second record type with the highest security level;

[0117] When the second record type is consistent with the first record type, the execution object of the requested analysis domain name is determined;

[0118] Conversely, the object corresponding to the second record type is regarded as the execution object of the requested analysis domain name.

[0119] The working principle and beneficial effects of the above technical solution are as follows: When the record type corresponding to the untrusted part of the requested domain name is inconsistent with the record type of the trusted part, in order to avoid risk intrusion, the execution target of the requested domain name is determined according to the record type corresponding to the untrusted part.

[0120] Example 6

[0121] Based on Example 1, the domain name resolution method for a DNS server, step 4 includes:

[0122] Step 41: Construct an address translation scheme based on the address format of the execution object, use the address translation scheme to convert the requested analysis domain name into an IP address, and input the IP address into the address format to obtain the actual IP address of the requested analysis domain name;

[0123] Step 42: Control the browser to connect to the actual IP address, collect several browsing access information during the connection process, determine the browsing webpage attributes of the requested analysis domain name based on the browsing access information, and store the actual IP address in the attribute storage area corresponding to the browser.

[0124] The working principle and beneficial effects of the above technical solution are as follows: When performing address translation, a translation scheme is established based on the address format of the implementation object. Then, the requested domain name is converted into the actual IP address, and the browser is further controlled to connect to the actual IP address. During the access process, the browser's browsing access information is obtained to determine the browsing webpage attributes of the requested domain name. Finally, the actual IP address is stored in the corresponding area for easy access on the next visit.

[0125] Example 7

[0126] Based on Example 6, the method for domain name resolution for a DNS server further includes:

[0127] Each attribute storage area is updated periodically.

[0128] The browsing frequency corresponding to different stored domain names in each of the attribute storage areas is obtained respectively to construct the browser's browsing preferences;

[0129] Recommend appropriate secure domain names to the browser based on the browsing preferences.

[0130] The working principle and beneficial effects of the above technical solution are as follows: In order to improve the user experience, web pages are recommended based on user preferences, thereby increasing user interest.

[0131] Example 8

[0132] Based on Embodiment 1, the method for domain name resolution for a DNS server further includes:

[0133] When the domain risk level of the requested domain is higher than the standard risk level, the browser is controlled to log out.

[0134] In this example, the standard risk level is: medium risk level.

[0135] The working principle and beneficial effects of the above technology are as follows: when the requested domain name is a dangerous domain name, access is stopped in time to avoid network risks.

[0136] Example 9

[0137] This embodiment provides a domain name resolution system for a DNS server, such as... Figure 2 As shown, it includes:

[0138] The risk identification module is used to obtain the domain name requested for analysis sent by the browser, identify the domain name risk level of the requested domain name in the DNS server, and match the corresponding level of resolution service segment for the requested domain name;

[0139] The deep analysis module is used to identify the top-level domain of the requested analysis domain name in the DNS service segment, determine the domain name attributes of the requested analysis domain name, perform deep analysis on the domain name attributes, and generate DNS analysis records.

[0140] The domain name analysis module is used to generate the DNS record type of the requested domain name based on the DNS analysis record and the domain name risk level, and to determine the execution target of the requested domain name.

[0141] The address recognition module is used to determine the actual IP address of the requested analysis domain name based on the execution object, control the browser to connect to the actual IP address, and store the actual IP address in the browser.

[0142] In this example, the requested domain name indicates that the browser has not yet connected and the domain name needs to be resolved, such as www.example.com;

[0143] In this example, the domain risk level indicates the browsing risk involved in requesting a risky domain;

[0144] In this example, the resolution service segment represents the service location within the DNS server used to resolve a risky domain name;

[0145] In this example, the top-level domain (TLD) represents the way the request to analyze the domain name originates. It is the last part of the domain name system, usually located at the far right of the domain name, immediately following the last dot. It includes: general top-level domains, country code top-level domains, new general top-level domains, sponsored top-level domains, and infrastructure top-level domains.

[0146] In this example, the DNS record types include: A record, AAAA record, CNAME record, MX record, and NS record;

[0147] In this example, the objects being executed include: PV4, PV6, another known domain name, mail server, text message storage domain, authoritative DNS server, primary DNS server, server host and port, return domain name, and application layer services;

[0148] In this example, the actual IP address refers to the IP address that the computer can understand, such as 192.0.2.1.

[0149] The working principle and beneficial effects of the above technical solution are as follows: When a browser sends a request, the DNS server analyzes the domain risk level of the requested domain and matches it with the appropriate DNS resolution service segment. This improves the quality of resolution and ensures the efficiency and effectiveness of the resolution process. Then, by identifying the top-level domain of the requested domain, the domain attributes are determined, and corresponding DNS resolution records are generated. After the analysis is completed, the DNS record type of the requested domain is determined by comprehensively analyzing the DNS resolution records and the domain risk level, thereby determining the target of the requested domain. Finally, the actual IP address of the requested domain is determined, and the browser is controlled to access the corresponding actual IP address, completing the resolution work. In this way, the domain name can be converted into a computer-recognizable IP address, making it easier for the browser to access it again.

[0150] Example 10

[0151] Based on Example 9, the risk identification module in the domain name resolution system for a DNS server includes:

[0152] The protocol analysis unit is used to transmit the domain name request sent by the browser to the DNS server, identify the readable address of the domain name request in the DNS server, perform source analysis on the readable address to obtain several domain name information of the domain name request, and filter the usage protocol of the domain name request from the domain name information.

[0153] A security identification unit is used to determine the accessible resource range of the requested analysis domain name according to the usage protocol, analyze the access-feedback relationship between the requested analysis domain name and the accessible resource range in the DNS server, and determine the access security level corresponding to each accessible resource.

[0154] The deep access unit is used to filter the domain path of the requested analysis domain in the domain information, build the access method corresponding to the requested analysis domain when accessing each of the accessible resources in combination with the accessible resource range, determine a number of access ports corresponding to each access method, and determine the path security level corresponding to each accessible resource based on the port information corresponding to each access port.

[0155] The risk matching unit is used to generate a domain name risk level of the requested analysis domain name based on the access security and path security, obtain a resolution service segment that matches the domain name risk level from the DNS server, and transmit the requested analysis domain name to the corresponding resolution service segment.

[0156] In this example, a readable address refers to the address that the requested domain name can be recognized in the DNS server;

[0157] In this example, the domain information represents several pieces of information presented by the request to analyze the domain;

[0158] In this example, protocols are used to represent the rules and standards related to domain name registration, management, and resolution;

[0159] In this example, the accessible resource range represents the network resources that the requested analysis domain name can access;

[0160] In this example, the access-feedback relationship represents the response from the DNS server when a request to analyze a domain name accesses different resources;

[0161] In this example, the domain path represents the path that the requested domain name takes when accessing resources;

[0162] In this example, the access port refers to the computer port involved when making the access;

[0163] In this example, path security refers to the security of the different ports traversed by the access path, and access security refers to the degree of security of accessing resources.

[0164] The working principle and beneficial effects of the above technical solution are as follows: When a browser makes a request, the requested domain name is transmitted to the DNS server for address identification, which determines the readable address of the requested domain name. Then, based on this address, the source is traced to determine several domain name information entries for the requested domain name, and the usage protocol of the requested domain name is filtered out. By using the protocol, the accessible resource range of the requested domain name can be determined. The relationship between the requested domain name and the accessible resource range is analyzed in the DNS server, thereby determining the security level of the resources accessed by the requested domain name. Then, the access ports involved in the domain name path are analyzed to determine the domain name risk level of the requested domain name. Finally, the corresponding resolution service segment is matched for the requested domain name, ensuring the efficiency and quality of subsequent resolution work.

[0165] Obviously, those skilled in the art can make various modifications and variations to this invention without departing from its spirit and scope. Therefore, if these modifications and variations fall within the scope of the claims of this invention and their equivalents, this invention also intends to include these modifications and variations.

Claims

1. A domain name resolution method for a DNS server, characterized in that, include: Step 1: Obtain the domain name requested for analysis sent by the browser, identify the domain name risk level of the requested domain name in the DNS server, and match the corresponding level of resolution service segment for the requested domain name; Step 2: Identify the top-level domain of the requested domain name in the DNS resolution service segment, determine the domain name attributes of the requested domain name, perform in-depth analysis on the domain name attributes, and generate DNS analysis records; Step 3: Generate the DNS record type for the requested domain name based on the DNS analysis record and the domain name risk level, and determine the execution target of the requested domain name; Step 4: Determine the actual IP address of the requested domain name based on the execution object, control the browser to connect to the actual IP address, and store the actual IP address in the browser.

2. The domain name resolution method for a DNS server as described in claim 1, characterized in that, Step 1 includes: Step 11: The request to analyze the domain name sent by the browser is transmitted to the DNS server. The readable address of the request to analyze the domain name is identified in the DNS server. The readable address is traced and analyzed to obtain several domain name information of the request to analyze the domain name. The usage protocol of the request to analyze the domain name is filtered from the domain name information. Step 12: Determine the accessible resource range of the requested analysis domain name according to the usage agreement, analyze the access-feedback relationship between the requested analysis domain name and the accessible resource range in the DNS server, and determine the access security level corresponding to each accessible resource; Step 13: Filter the domain path of the requested analysis domain in the domain information, build the access method corresponding to the requested analysis domain when accessing each of the accessible resources in combination with the accessible resource range, determine several access ports corresponding to each access method, and determine the path security level corresponding to each accessible resource based on the port information corresponding to each access port. Step 14: Generate the domain name risk level of the requested analysis domain name based on the access security and path security, obtain the resolution service segment that matches the domain name risk level from the DNS server, and transmit the requested analysis domain name to the corresponding resolution service segment.

3. The domain name resolution method for a DNS server as described in claim 1, characterized in that, Step 2 includes: Step 21: In the DNS resolution service segment, the requested analysis domain name is mapped to different preset domain name systems to obtain the expression form of the requested analysis domain name in each preset domain name system, the tail string corresponding to each expression form is obtained, and the top-level domain of the requested analysis domain name is determined. Step 22: Determine the generation source of the requested analysis domain name based on the top-level domain, and determine several domain name information of the generation source by combining the expression form of the requested analysis domain name in each of the preset domain name systems. Obtain the information keywords corresponding to each of the domain name information, and establish the domain name attributes of the requested analysis domain name. Step 23: Construct the domain name format corresponding to the requested analysis domain name in each of the preset domain name systems based on the domain name attributes, input the domain name information into each of the domain name formats respectively to generate the analysis result of the requested analysis domain name in each of the preset domain name systems, and generate the DNS analysis record of the requested analysis domain name.

4. The domain name resolution method for a DNS server as described in claim 1, characterized in that, Step 3 includes: Step 31: Decompose the DNS analysis record under the domain risk level to obtain several traffic data of the requested domain. Generate several lookup conditions for the requested domain based on the data value and risk dimension corresponding to each traffic data. Step 32: Based on the search criteria, search the DNS server for several associated data of the requested domain name, construct the trust part of the requested domain name based on the associated data, locate the trust part in the DNS analysis record respectively, and determine the trust performance characteristics of the requested domain name in different preset domain name systems. Step 33: Establish DNS records for the requested domain name based on the trust performance characteristics, analyze the record integrity of each record type in the DNS records, filter the first record type with the highest record integrity, and determine the execution target of the requested domain name.

5. A domain name resolution method for a DNS server as described in claim 4, characterized in that, Also includes: Obtain the untrusted portion of the requested domain name, locate each untrusted portion in the DNS analysis record, and determine the untrusted behavior characteristics of the requested domain name in different preset domain name systems. Each of the untrusted behavior characteristics is input into the cloud DNS for security testing, and the security level of the untrusted part in each preset domain name system is determined based on the test results. Filter the second record type with the highest security level; When the second record type is consistent with the first record type, the execution object of the requested analysis domain name is determined; Conversely, the object corresponding to the second record type is regarded as the execution object of the requested analysis domain name.

6. A domain name resolution method for a DNS server as described in claim 1, characterized in that, Step 4 includes: Step 41: Construct an address translation scheme based on the address format of the execution object, use the address translation scheme to convert the requested analysis domain name into an IP address, and input the IP address into the address format to obtain the actual IP address of the requested analysis domain name; Step 42: Control the browser to connect to the actual IP address, collect several browsing access information during the connection process, determine the browsing webpage attributes of the requested analysis domain name based on the browsing access information, and store the actual IP address in the attribute storage area corresponding to the browser.

7. A domain name resolution method for a DNS server as described in claim 6, characterized in that, Also includes: Each attribute storage area is updated periodically. The browsing frequency corresponding to different stored domain names in each of the attribute storage areas is obtained respectively to construct the browser's browsing preferences; Recommend appropriate secure domain names to the browser based on the browsing preferences.

8. A domain name resolution method for a DNS server as described in claim 1, characterized in that, Also includes: When the domain risk level of the requested domain is higher than the standard risk level, the browser is controlled to log out.

9. A domain name resolution system for a DNS server, characterized in that, include: The risk identification module is used to obtain the domain name requested for analysis sent by the browser, identify the domain name risk level of the requested domain name in the DNS server, and match the corresponding level of resolution service segment for the requested domain name; The deep analysis module is used to identify the top-level domain of the requested analysis domain name in the DNS service segment, determine the domain name attributes of the requested analysis domain name, perform deep analysis on the domain name attributes, and generate DNS analysis records. The domain name analysis module is used to generate the DNS record type of the requested domain name based on the DNS analysis record and the domain name risk level, and to determine the execution target of the requested domain name. The address recognition module is used to determine the actual IP address of the requested analysis domain name based on the execution object, control the browser to connect to the actual IP address, and store the actual IP address in the browser.

10. A domain name resolution system for a DNS server as described in claim 9, characterized in that, The risk identification module includes: The protocol analysis unit is used to transmit the domain name request sent by the browser to the DNS server, identify the readable address of the domain name request in the DNS server, perform source analysis on the readable address to obtain several domain name information of the domain name request, and filter the usage protocol of the domain name request from the domain name information. A security identification unit is used to determine the accessible resource range of the requested analysis domain name according to the usage protocol, analyze the access-feedback relationship between the requested analysis domain name and the accessible resource range in the DNS server, and determine the access security level corresponding to each accessible resource. The deep access unit is used to filter the domain path of the requested analysis domain in the domain information, build the access method corresponding to the requested analysis domain when accessing each of the accessible resources in combination with the accessible resource range, determine a number of access ports corresponding to each access method, and determine the path security level corresponding to each accessible resource based on the port information corresponding to each access port. The risk matching unit is used to generate a domain name risk level of the requested analysis domain name based on the access security and path security, obtain a resolution service segment that matches the domain name risk level from the DNS server, and transmit the requested analysis domain name to the corresponding resolution service segment.

Citation Information

Patent Citations

  • Method for ensuring and forwarding TOP domain name of DNS cache server

    CN117459494A

  • Network address management and functional object discovery system

    US20140222987A1