Cache hit probability-based random prefix domain name attack protection method
By stating and comparing the cache hit rate of the client on the recursive server of the DNS system, the problems of large resource consumption and inreliable results in the existing technology are solved, and accurate identification and protection of random prefix domain name attacks are achieved, and the security and stability of the DNS system are improved.
Patent Information
- Application Number
- CN202510156111.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-12
- Publication Date
- 2025-05-13
AI Technical Summary
In the prior art, when detecting and protecting random prefix domain name attacks in DNS systems, resources are consumed heavily and the results are not reliable enough to accurately identify attack behaviors.
By creating cache hit rate statistics for each client on the recursive server, recording the cache hit rate for a certain period of time, and comparing it with the global cache hit rate. If the client hit rate is lower than global and exceeds the threshold, the recursive query is intercepted, and the time window division and statistical count update are performed.
It realizes a detection method with less resource consumption, which can identify random prefix domain name attacks in real time and accurately, reduce the misjudgment rate, and improve the security and stability of the DNS system.
Smart Images

Figure CN119996001A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information technology, and in particular to a random prefix domain name attack protection method based on cache hit probability. Background Art
[0002] DNS (Domain Name System) is a distributed database system on the Internet used to resolve domain names to IP addresses. It can convert domain names that are easy for people to remember into IP addresses that computers can recognize, thereby enabling access to websites or network services.
[0003] There is a type of attack based on changing prefixes for the DNS system, such as a simple random prefix domain name attack, which is usually intended to penetrate the cache of the DNS recursive server and generate recursion to consume server performance.
[0004] For this type of attack, if the full record involves all different domain names under a single recursive zone, and the total number of different domain names under the zone is calculated for judgment, the resource consumption may be very large. In addition, the simple number statistics may not reflect whether there is something special about the specific domain name, and there is a lack of basis for judging the nature of the relevant requests, so it is impossible to judge this type of attack more accurately. Summary of the invention
[0005] Based on this, an embodiment of the present application provides a random prefix domain name attack protection method based on cache hit probability. This method determines whether the client has potential random prefix domain name attack behavior based on the inspection and detection of the client cache hit rate.
[0006] In a first aspect, a random prefix domain name attack protection method based on cache hit probability is provided, the method comprising:
[0007] When the recursive server receives a client request, it checks and updates the client cache hit rate statistics, updates the client's recursive query count based on whether the query hits the cache, and simultaneously updates the recursive server's global statistics count;
[0008] Configure the minimum sample size for statistical counting, and make validity determination based on the global statistical count and the client's recursive query count;
[0009] Calculate the client and global cache hit rates. If the client hit rate is lower than the global cache hit rate and exceeds the threshold, intercept the recursive query and divide the time window. When updating the statistical count, clear the current window count to filter out abnormal clients in real time.
[0010] Optionally, the step of checking and updating the client cache hit rate statistics item includes:
[0011] When the recursive server receives a client request, it checks whether the client source address exists in the cache hit rate statistics table of the local machine. If not, it creates a statistics item for it.
[0012] If the client query hits the cache, the cache hit count and its total recursive query count are updated on the statistic item, and the values are increased by 1 respectively; if it does not hit, only the total recursive query count is increased by 1;
[0013] Set a time window for client statistics, clear the count of the current window at regular intervals, and retain the count of the current time window and the historical statistical count of the client, including cache hits and total recursive requests.
[0014] Optionally, the step of synchronously updating the global statistical count of the recursive server includes:
[0015] While updating the relevant counts of the client statistics items, the global cache hit count and the total recursive query count are updated; wherein, the update rule of the global statistics count is consistent with the update rule of the client statistics items.
[0016] Optionally, the step of configuring a minimum sample size for statistical counting includes:
[0017] The recursive server configures the minimum sample size of the global statistical count according to the policy. When the total recursive query sample size actually collected reaches the minimum sample size, the cache hit rate calculated based on the ratio of the current global cache hit count and the total recursive query count is determined as a valid reference;
[0018] The recursive server setting policy defines the minimum sample size of the statistical count of a specific client. When the total recursive query count of a client reaches the minimum sample size, the cache hit rate calculated based on the statistical count is determined as a valid reference.
[0019] Optionally, the step of calculating the client and global cache hit rates includes:
[0020] The calculation formula of the client cache hit rate is: R1 = N1 / N2, where R1 is the client cache hit rate, N1 is the client's current window cache hit count, and N2 is the client's current window total recursive query count;
[0021] The calculation formula for the global cache hit rate is: R2 = (N3-N1) / (N4-N2), where R2 is the global cache hit rate, N1 and N2 are the client's historical cache hit count and historical total recursive query count respectively, N3 is the global cache hit count, and N4 is the global total recursive query count.
[0022] Optionally, the step of intercepting the recursive query and dividing the time window specifically includes:
[0023] If the client cache hit rate is lower than the global cache hit rate and the range is greater than the threshold set by the policy, it is determined that the client may have random prefix domain name attack behavior, and the query that needs to be recursive is intercepted;
[0024] The recursive server sets the global time window division, starting from a certain timestamp, and divides each window according to the specified time length. When updating the client statistics count, if it is found that the time point comes to the new time window for the first time, the client's current window statistics count is cleared, and then the relevant values are accumulated.
[0025] In a second aspect, a random prefix domain name attack protection system based on cache hit probability is provided, the system comprising:
[0026] The receiving module is used to check and update the client cache hit rate statistics when receiving the client request, update the client's recursive query count according to whether the query hits the cache, and synchronously update the global statistical count of the recursive server;
[0027] The judgment module is used to configure the minimum sample size of the statistical count and make validity judgments based on the global statistical count and the recursive query count of the client;
[0028] The screening module is used to calculate the client and global cache hit rates. If the client hit rate is lower than the global cache hit rate and exceeds the threshold, the recursive query is intercepted and the time window is divided. When the statistical count is updated, the current window count is cleared to filter out abnormal clients in real time.
[0029] In a third aspect, an electronic device is provided, including a memory and a processor, wherein the memory stores a computer program, and when the processor executes the computer program, the random prefix domain name attack protection method described in any one of the first aspects is implemented.
[0030] In a fourth aspect, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the random prefix domain name attack protection method described in any one of the first aspects is implemented.
[0031] In a fifth aspect, a computer program product is provided, including a computer program / instruction, which, when executed by a processor, implements the random prefix domain name attack protection method described in any one of the first aspects above.
[0032] The beneficial effects brought by the technical solution provided by the embodiment of the present application include at least:
[0033] (1) Through the detection method based on cache hit rate, the full statistics of a large number of domain name records are avoided, the consumption of storage and computing resources is reduced, and the operation efficiency of the system is improved.
[0034] (2) By comparing the deviation between the client and global cache hit rates and combining the time window mechanism, it is possible to accurately identify random prefix domain name attack behaviors in real time, reduce the misjudgment rate, and effectively protect the DNS system from attacks.
[0035] (3) Through time window division and real-time count updates, it can dynamically adapt to traffic changes in different time periods, quickly respond to attack behaviors, and enhance the security and stability of the DNS system. BRIEF DESCRIPTION OF THE DRAWINGS
[0036] In order to more clearly illustrate the implementation methods of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for the implementation methods or the description of the prior art. Obviously, the drawings in the following description are only exemplary, and for ordinary technicians in this field, other implementation drawings can be derived from the provided drawings without creative work.
[0037] Figure 1 A flowchart of a random prefix domain name attack protection method based on cache hit probability provided by an embodiment of the present application;
[0038] Figure 2 A block diagram of a random prefix domain name attack protection system based on cache hit probability provided by an embodiment of the present application;
[0039] Figure 3 A schematic diagram of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0040] In order to make the purpose, technical solution and advantages of the present application more clearly understood, the present application is further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.
[0041] In the description of the present invention, the terms "comprises", "has" and any variations thereof are intended to cover non-exclusive inclusions. For example, a process, method, system, product or apparatus comprising a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may also include other steps or units that are not explicitly listed but are inherent to these processes, methods, products or apparatuses, or steps or units added based on further optimization schemes conceived by the present invention.
[0042] There is a type of attack based on changing prefixes for the DNS system, such as a simple random prefix domain name attack, which is usually intended to penetrate the cache of the DNS recursive server and generate recursion to consume server performance.
[0043] For this type of attack, if the full record involves all different domain names under a single recursive zone, and the total number of different domain names under the zone is calculated for judgment, the resource consumption may be very large. In addition, the simple number statistics may not reflect whether there is something special about the specific domain name, and there is a lack of basis for judging the nature of the relevant requests, so it is impossible to judge this type of attack more accurately.
[0044] This solution provides a detection method based on the client cache hit rate inspection to determine whether the client has potential random prefix domain name attack behavior.
[0045] In order to solve the problem that the detection process in the existing technology consumes a lot of resources and the results are not reliable enough, this solution will create a cache hit rate statistic item for each independent client on the recursive server, record its cache hit rate within a certain period of time, and compare it with the reasonable range to determine whether it is abnormal behavior.
[0046] Please refer to Figure 1 , which shows a flow chart of a random prefix domain name attack protection method based on cache hit probability provided by an embodiment of the present application, the purpose of which is to improve the existing protection against random prefix domain name attacks. The following steps may be included:
[0047] S1, when the recursive server receives a client request, it checks and updates the client cache hit rate statistics, updates the client's recursive query count based on whether the query hits the cache, and synchronously updates the global statistical count of the recursive server.
[0048] In this step, when the recursive server receives a recursive request from a client, it first checks whether the client source address already exists in the cache hit rate statistics table of the local machine. If not, a new statistical item is created for the client. Subsequently, the cache hit count and the total recursive query count in the statistical item are updated according to whether the client's query hits the cache. If the query hits the cache, both the cache hit count and the total recursive query count are increased by 1; if it does not hit, only the total recursive query count is increased by 1. At the same time, the recursive server will synchronously update the global cache hit count and the total recursive query count, and the update rules are consistent with the update rules of the client statistical items. In addition, a time window will be set for the statistics of the client, and the count of the current window will be cleared at regular intervals, but the count of the current time window and the historical statistical count of the client (including cache hits and total recursive requests) will be retained for subsequent analysis.
[0049] S2, configure the minimum sample size of statistical counts, and make validity determinations based on the global statistical counts and the client's recursive query counts.
[0050] In this step, the recursive server configures the minimum sample size of the global statistical count according to the preset strategy. When the total recursive query sample size actually collected reaches the minimum sample size, the cache hit rate calculated based on the ratio of the current global cache hit count and the total recursive query count is considered a valid reference. Similarly, the recursive server sets the minimum sample size of the statistical count for each client. When the total recursive query count of a client reaches the minimum sample size, the cache hit rate calculated based on the statistical count is considered valid. This process ensures that the calculation of the cache hit rate has sufficient data support, thereby improving the accuracy and reliability of subsequent comparative analysis.
[0051] S3 calculates the client and global cache hit rates. If the client hit rate is lower than the global cache hit rate and exceeds the threshold, the recursive query is intercepted and time windows are divided. When the statistical count is updated, the current window count is cleared to filter out abnormal clients in real time.
[0052] In this step, when the client's query does not hit the cache, the recursive server will calculate the client's cache hit rate (R1), the formula is: R1 = N1 / N2, where N1 is the cache hit count of the client's current window, and N2 is the total recursive query count of the current window. At the same time, the global cache hit rate (R2) is calculated, the formula is: R2 = (N3-N1) / (N4-N2), where N3 is the global cache hit count, and N4 is the global total recursive query count. Subsequently, the deviation between the client cache hit rate and the global cache hit rate is compared. If the client cache hit rate is lower than the global cache hit rate and the deviation exceeds the preset threshold, it is determined that the client may have a random prefix domain name attack behavior, and the recursive server will intercept the client's recursive query. In addition, the recursive server will set a global time window division, starting from a certain timestamp, and divide each window according to the specified time length. When updating the client statistics count, if it is found that the time point comes to the new time window for the first time, the client's current window statistics count will be cleared, and then the relevant values will be accumulated, so as to screen out abnormal clients in real time and ensure the security and stability of the system.
[0053] In an optional embodiment of the present application, the method can also be expanded into the following specific implementation process:
[0054] This solution will create a cache hit rate statistic for each independent client on the recursive server, record its cache hit rate within a certain period of time, and compare it with the reasonable range to determine whether it is abnormal behavior. The key points of the solution include:
[0055] (1) When a recursive server receives a recursive request from a client, it first checks whether the client's source address already exists in the local cache hit rate statistics table. If not, it will create one for it.
[0056] (2) If the query sent by the client hits the cache, the cache hit count and its total recursive query count are updated on the statistic item, and the values are increased by 1 respectively. If it does not hit, only the total recursive query count is increased by 1. A time window is set for the statistics of the client, that is, the count of the current window is cleared every certain period of time. In addition, the client will also retain the count of the current time window and the historical statistical count of the client (including cache hits and total recursive requests). When increasing the count, the count in the current window and the historical cumulative count will be updated in the same way.
[0057] (3) While updating the relevant counts of the statistical items, the global cache hit count and the total recursive query count also need to be updated. The rules are similar to those in point 2.
[0058] (4) The recursive server configures the minimum sample size of the global statistical count according to the policy. When the total recursive query sample size actually collected reaches the minimum sample size, the cache hit rate calculated based on the ratio of the current global cache hit count and the total recursive query count can be used as an effective reference.
[0059] (5) The recursive server also needs to set a policy to define the minimum sample size of the statistical count for a specific client. The rule is similar to that in point 4, that is, when the total recursive query count of a client reaches the minimum sample size, the cache hit rate calculated based on the statistical count can be considered valid.
[0060] (6) If the query sent by the client fails to hit the cache, a cache hit rate check is required to determine whether recursion can be performed. When calculating the cache hit rate of the client, assume that the client cache hit rate is R1, the client's current window cache hit count is N1, and the client's current window total recursive query count is N2. The formula is as follows:
[0061] R1=N1 / N2
[0062] The reference standard used for comparison, that is, the calculation of the actual global cache hit rate, needs to deduct the queries generated by the client (historical statistical count) from the total count. Assuming the global cache hit rate is R2, the client historical cache hit count is N1, the client historical total recursive query count is N2, the global cache hit count is N3, and the global total recursive query count is N4, the calculation formula is as follows:
[0063] R2=(N3-N1) / (N4-N2)
[0064] (7) After obtaining the client and global cache hit rates, it is necessary to compare the deviation between the client cache hit rate and the global cache hit rate to confirm whether it is within the allowable range of the policy defined on the recursive server. If the cache hit rate is lower than the global cache hit rate and the amplitude is greater than the threshold set by the policy, it is considered that the client may have a random prefix domain name attack behavior. In this case, the query that needs to perform recursion will be intercepted.
[0065] (8) The recursive server will set a global time window division, that is, starting from a certain timestamp, each window is divided according to the specified time queue. When updating the client statistical count, if it is found that the time point comes to a new time window for the first time, the client's current window statistical count needs to be cleared and then the relevant values are accumulated.
[0066] Based on the above settings, the recursive server can automatically screen out clients whose cache hit rates are significantly lower than a reasonable range, and intercept them. In summary, this application uses a predictive method with low resource consumption to detect and intercept random prefix domain name attacks.
[0067] Please refer to Figure 2 , which shows a block diagram of a random prefix domain name attack protection system based on cache hit probability provided by an embodiment of the present application. Figure 2 As shown, the system may include:
[0068] The receiving module is used to check and update the client cache hit rate statistics when receiving the client request, update the client's recursive query count according to whether the query hits the cache, and synchronously update the global statistical count of the recursive server;
[0069] The judgment module is used to configure the minimum sample size of the statistical count and make validity judgments based on the global statistical count and the recursive query count of the client;
[0070] The screening module is used to calculate the client and global cache hit rates. If the client hit rate is lower than the global cache hit rate and exceeds the threshold, the recursive query is intercepted and the time window is divided. When the statistical count is updated, the current window count is cleared to filter out abnormal clients in real time.
[0071] For the specific definition of the random prefix domain name attack protection system based on cache hit probability, please refer to the definition of the random prefix domain name attack protection method based on cache hit probability above, which will not be repeated here. Each module in the above-mentioned random prefix domain name attack protection system based on cache hit probability can be implemented in whole or in part by software, hardware and a combination thereof. The above-mentioned modules can be embedded in or independent of the processor in the computer device in the form of hardware, or can be stored in the memory of the computer device in the form of software, so that the processor can call and execute the operations corresponding to the above modules.
[0072] In one embodiment, an electronic device is provided. The electronic device may be a computer, and its internal structure diagram may be as follows: Figure 3 As shown. The electronic device includes a processor, a memory and a network interface connected through a system bus. Among them, the processor of the device is used to provide computing and control capabilities. The memory of the device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used for random prefix domain name attack protection data based on cache hit probability. The network interface of the computer device is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor, a random prefix domain name attack protection method based on cache hit probability is implemented.
[0073] Those skilled in the art will understand that Figure 3 The structure shown in the figure is only a block diagram of a part of the structure related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine certain components, or have a different arrangement of components.
[0074] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored, which involves all or part of the processes in the above-mentioned embodiment method.
[0075] In one embodiment, a computer program product is also provided, including a computer program / instruction, which involves all or part of the process in the above embodiment method.
[0076] Those of ordinary skill in the art can understand that all or part of the processes in the above-mentioned embodiment methods can be completed by instructing related hardware through a computer program, and the computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to memory, storage, database or other media used in the embodiments provided in this application may include non-volatile and / or volatile memory. Non-volatile memory may include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM) or flash memory. Volatile memory may include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in M forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDRSDRAM), enhanced SDRAM (ESDRAM), synchronous link (SyMchliMk) DRAM (SLDRAM), memory bus (RaMbus) direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM (RDRAM), etc.
[0077] The technical features of the above-described embodiments may be arbitrarily combined. To make the description concise, not all possible combinations of the technical features in the above-described embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0078] The above-described embodiments only express several implementation methods of the present application, and the descriptions thereof are relatively specific and detailed, but they cannot be construed as limiting the scope of the patent application. It should be pointed out that, for a person of ordinary skill in the art, several variations and improvements can be made without departing from the concept of the present application, and these all belong to the protection scope of the present application. Therefore, the protection scope of the patent application shall be subject to the attached claims.
Claims
1. A random prefix domain name attack protection method based on cache hit probability, characterized in that: The method comprises: When the recursive server receives a client request, it checks and updates the client cache hit rate statistics, updates the client's recursive query count based on whether the query hits the cache, and simultaneously updates the recursive server's global statistics count; Configure the minimum sample size for statistical counting, and make validity determination based on the global statistical count and the client's recursive query count; Calculate the client and global cache hit rates. If the client hit rate is lower than the global cache hit rate and exceeds the threshold, intercept the recursive query and divide the time window. When updating the statistical count, clear the current window count to filter out abnormal clients in real time.
2. The random prefix domain name attack protection method according to claim 1, characterized in that: The step of checking and updating the client cache hit rate statistics item comprises: When the recursive server receives a client request, it checks whether the client source address exists in the cache hit rate statistics table of the local machine. If not, it creates a statistics item for it. If the client query hits the cache, the cache hit count and its total recursive query count are updated on the statistic item, and the values are increased by 1 respectively; if it does not hit, only the total recursive query count is increased by 1; Set a time window for client statistics, clear the count of the current window at regular intervals, and retain the count of the current time window and the historical statistical count of the client, including cache hits and total recursive requests.
3. The random prefix domain name attack protection method according to claim 1, characterized in that: The step of synchronously updating the global statistical count of the recursive server comprises: While updating the relevant counts of the client statistics items, the global cache hit count and the total recursive query count are updated; wherein, the update rule of the global statistics count is consistent with the update rule of the client statistics items.
4. The random prefix domain name attack protection method according to claim 1, characterized in that: The step of configuring the minimum sample size for statistical counting comprises: The recursive server configures the minimum sample size of the global statistical count according to the policy. When the total recursive query sample size actually collected reaches the minimum sample size, the cache hit rate calculated based on the ratio of the current global cache hit count and the total recursive query count is determined as a valid reference; The recursive server setting policy defines the minimum sample size of the statistical count of a specific client. When the total recursive query count of a client reaches the minimum sample size, the cache hit rate calculated based on the statistical count is determined as a valid reference.
5. The random prefix domain name attack protection method according to claim 1, characterized in that: The step of calculating the client and global cache hit rates comprises: The calculation formula of the client cache hit rate is: R1 = N1 / N2, where R1 is the client cache hit rate, N1 is the client's current window cache hit count, and N2 is the client's current window total recursive query count; The calculation formula for the global cache hit rate is: R2 = (N3-N1) / (N4-N2), where R2 is the global cache hit rate, N1 and N2 are the client's historical cache hit count and historical total recursive query count respectively, N3 is the global cache hit count, and N4 is the global total recursive query count.
6. The random prefix domain name attack protection method according to claim 1, characterized in that: The steps of intercepting recursive queries and dividing time windows specifically include: If the client cache hit rate is lower than the global cache hit rate and the range is greater than the threshold set by the policy, it is determined that the client may have random prefix domain name attack behavior, and the query that needs to be recursive is intercepted; The recursive server sets the global time window division, starting from a certain timestamp, and divides each window according to the specified time length. When updating the client statistics count, if it is found that the time point comes to the new time window for the first time, the client's current window statistics count is cleared, and then the relevant values are accumulated.
7. A random prefix domain name attack protection system based on cache hit probability, characterized in that: The system comprises: The receiving module is used to check and update the client cache hit rate statistics when receiving the client request, update the client's recursive query count according to whether the query hits the cache, and synchronously update the global statistical count of the recursive server; The judgment module is used to configure the minimum sample size of the statistical count and make validity judgments based on the global statistical count and the recursive query count of the client; The screening module is used to calculate the client and global cache hit rates. If the client hit rate is lower than the global cache hit rate and exceeds the threshold, the recursive query is intercepted and the time window is divided. When the statistical count is updated, the current window count is cleared to filter out abnormal clients in real time.
8. An electronic device, characterized in that: The method comprises a memory and a processor, wherein the memory stores a computer program, and when the computer program is executed by the processor, the steps of the method according to any one of claims 1 to 6 are implemented.
9. A computer-readable storage medium, characterized in that: A computer program is stored thereon, and when the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 6 are implemented.
10. A computer program product comprising a computer program / instructions, characterized in that When the computer program / instructions are executed by a processor, the steps of the method according to any one of claims 1 to 6 are implemented.