Proxy recursive side domain name preservation method and system

Through the proxy recursive side domain name preservation method, BIND9's custom cache record function and recursive resolver cluster structure solve the problem that the DNS system does not support the overall domain preservation and restart time, and realizes the high availability of specific domain names and domain preservation and DNS resolution services.

CN120017635APending Publication Date: 2025-05-16HARBIN INST OF TECH
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202510207982.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-25
Publication Date
2025-05-16

AI Technical Summary

Technical Problem

The existing DNS system does not support obtaining all subdomains under one domain, making it difficult to achieve overall conservation of the domain, and the long restart time of the DNS software makes the resolution service unavailable, affecting Internet users.

Method used

The proxy recursive side domain name preservation method is adopted, and the custom cache recording function of BIND9 and the recursive parser cluster structure are used to achieve the preservation of specific domain names and domains as a whole, ensuring that at least one parser is available, and avoiding the interruption of the resolution service caused by restart.

Benefits of technology

It realizes the protection of specific domain names and domains as a whole, avoids resolution errors caused by malicious tampering, and ensures high availability and efficiency of DNS resolution services.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120017635A_ABST
    Figure CN120017635A_ABST
Patent Text Reader

Abstract

The invention discloses a proxy recursive side domain name preservation method and system, and relates to the technical field of DNS security. According to the technical scheme, DNS software does not need to be modified, specific domain names and domain overall preservation are supported, and the problem that DNS analysis services are not available within the restarting time of the software is solved. The technical key points are as follows: a BIND9 self-definition cache recording function is adopted, cache information which is most adaptive to a current query domain name is adopted in a DNS server, and two recursive resolvers are adopted as a resolver cluster, so that at least one resolver can normally provide an analysis service; the BIND9 starts a time delay solution; the invention discloses an overall architecture of a proxy recursive side domain name preservation scheme. The overall architecture comprises protected domain name list configuration, protected domain name record information collection, trusted record generation, a recursive parser controller, a proxy parser controller and a log module. According to the method, after the specific domain name or the whole domain is maliciously tampered, it can be ensured that the domain name or the domain can be correctly analyzed, and the serious influence of a malicious analysis result on Internet users is avoided.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of DNS security technology, and in particular to a proxy-type recursive domain name preservation method and system. Background Art

[0002] There is a risk of abuse of power in the current DNS (Domain Name System) system. RFC7720 stipulates that all root servers must use the root zone provided by IANA (The Internet Assigned Numbers Authority). The risk is that if a ccTLD (Country Code Top-level Domain) is deleted or tampered with in the root zone due to the damage to the functions of IANA, the domain name under the ccTLD will not be resolved or will be resolved incorrectly, which will also cause Internet users to be unable to access the services corresponding to the domain name under the ccTLD normally.

[0003] The existing patent document "A recursive domain name preservation method and system based on RPZ" (national and provincial code: 23, authorization announcement number: CN115174518B, publication date: 2023-11-21) uses the RPZ (Response Policy Zone) function of the DNS software to implement domain name preservation technology. However, the problem is that it only supports the preservation of specific domain names (such as "www.baidu.com", "www.gov.cn", etc.), and does not support the preservation of the entire domain (such as: ".com", ".cn", etc.). Taking ".cn" as an example, if it is now discovered that ".cn" has been attacked by malicious tampering, we want to preserve the entire domain name under ".cn", which cannot be done through RPZ. There are two main reasons for this: (1) The current DNS system does not support obtaining all subdomains under a domain; (2) Even if it is possible to obtain all specific domain names under ".cn", the order of magnitude is very large, and the memory requirements of the DNS software are extremely high.

[0004] The paper "Domain Name System Root Zone Monitoring and Emergency Disposal Technology" proposes a domain name preservation method based on cache reload, which can realize the technical solution of preserving specific domain names and the entire domain. However, its main drawback is that each time a preservation domain is added or deleted, the DNS software needs to be restarted, and the time to restart the software is positively correlated with the number of preservation domains. When it is in the order of 100,000, it takes 1 second to restart, 1 million takes 7 seconds, and 10 million takes 100 seconds. In other words, assuming that there are 10 million preservation domains, and a new preservation domain is added to it, it still takes 100 seconds to restart to successfully add the new preservation domain. The DNS server cannot provide DNS resolution services normally during this restart time, and the longer restart time will have a greater impact on Internet users. Summary of the invention

[0005] The technical problems to be solved by the present invention are:

[0006] The present invention aims to solve the problems that the current DNS system does not support obtaining all subdomains under a domain, has extremely high memory requirements for DNS software, cannot be correctly resolved after a specific domain name or the entire domain is maliciously tampered with, and cannot avoid the malicious resolution results from causing significant impact on Internet users. A proxy-type recursive side domain name preservation method and system are provided.

[0007] The technical solution adopted by the present invention to solve the above technical problems is:

[0008] A proxy-type recursive side domain name preservation method, the domain name preservation method is a proxy-type recursive side domain name preservation method based on BIND9, specifically:

[0009] Give the specific functions of BIND9 that domain name preservation relies on

[0010] The specific function is the custom cache record function of BIND9. The user-defined cache record function provided by BIND9 is: after the DNS software is started, it first reads the user-defined cache file, adds the records in it to the resolver cache, and then provides resolution services; after a domain name is attacked, the authentic and reliable record information of its authoritative server can be written into the custom cache file, and then the DNS server is restarted to load the custom cache, so as to achieve the purpose of "anchoring" the authoritative information of the domain name;

[0011] Dealing with BIND9 startup delay

[0012] Each time BIND9 adds a custom cache record, the DNS software needs to be restarted. When the number of custom cache records is large, the restart time is long. Each restart of BIND9 will cause the DNS resolution service to be unavailable for a period of time. Due to the function of BIND9 itself, the software must be restarted to read the custom cache file, and restarting the software conflicts with providing DNS resolution service. The service conflict is resolved by adjusting the structure of the recursive resolver, specifically:

[0013] Two recursive resolvers are used as a resolver cluster to ensure that at least one resolver can provide resolution services normally. In actual use, a proxy resolver is required. Internet users' DNS queries will be sent to this proxy resolver, and then the proxy resolver will choose which recursive resolver to forward the query to based on the current state of the resolver cluster. In this process, the proxy resolver is responsible for accepting user queries, forwarding user queries, and responding to user queries. The resolvers in the resolver cluster actually perform iterative resolution services.

[0014] Under normal circumstances, the proxy server can choose to forward the user's DNS query to any server in the cluster; when a domain name is found to be maliciously tampered with by the superior, it is necessary to preserve the domain name. At this time, it is necessary to alternately operate the servers in the cluster, that is, write the real information of the authoritative server of the attacked domain name into the custom cache file specified by BIND9, and then restart the corresponding resolver software;

[0015] The restart operations of the two resolvers should be mutually exclusive to ensure that at least one resolver in the cluster is available, and the restart of the resolver should be notified to the proxy resolver to ensure that the proxy server can forward the user's DNS query to the recursive resolver that can currently provide normal resolution services;

[0016] Constructing the overall architecture of the proxy-based recursive domain name preservation solution

[0017] The overall architecture of the proxy-based recursive domain name preservation solution includes the following modules:

[0018] (1) Protected domain name list configuration: used to manually add protected domain names;

[0019] (2) Collection of protected domain name record information: For a specific domain name, this module collects its IPv4 address record (A record) or IPv6 address record (AAAA record). For the entire domain, this module collects its authoritative server related records (including NS records and corresponding A / AAAA records). There are two ways to collect information: one is to obtain it from the Internet, and the other is to manually configure it. If the protected domain name has not been attacked at this time, it can be directly obtained through the Internet. If it has been attacked, it needs to be obtained through manual configuration;

[0020] (3) Trusted record generation: This module is mainly responsible for maintaining trusted record files for subsequent custom cache functions;

[0021] (4) Recursive resolver controller: This module is responsible for synchronizing custom cache records to each resolver in the resolver cluster. At the same time, at least one resolver in the resolver cluster must be available to meet the synchronization rules.

[0022] (5) Proxy resolver controller: This module is responsible for notifying the proxy resolver of the availability of resolvers in the cluster based on the synchronization information of the recursive resolver controller;

[0023] (6) Log module: This module is mainly responsible for the log backup function, including the configuration of the protected domain name log and the control log of the recursive resolver controller and the proxy resolver controller.

[0024] The present invention has the following beneficial technical effects:

[0025] The proxy-based recursive domain name preservation method and system proposed in the present invention is a technical solution that does not require modification of DNS software (BIND9, Berkeley Internet Name Domain) and supports the preservation of specific domain names and the entire domain, and solves the problem of unavailability of DNS resolution service during the software restart time. The specific advantages are as follows:

[0026] (1) Domain name preservation function: It can ensure that a specific domain name or the entire domain is correctly resolved after being maliciously tampered with, thereby preventing malicious resolution results from having a significant impact on Internet users.

[0027] (2) Applicable to domain names of various granularities: This invention is applicable to the preservation of domain names of various granularities. It is not only applicable to specific domain names, but also supports the preservation function of the entire domain.

[0028] (3) High availability: During the security configuration phase, the DNS resolution service will not become unavailable due to software restart.

[0029] (4) Efficiency: The DNS resolution performance of this security system is 1.29 times that of an ordinary recursive resolver, with little impact on query performance. BRIEF DESCRIPTION OF THE DRAWINGS

[0030] Figure 1 The principle block diagram of the BIND9 startup delay solution;

[0031] Figure 2 To add a flowchart for preserving domain names;

[0032] Figure 3This is the overall architecture diagram of the proxy-based recursive domain name preservation solution;

[0033] Figure 4 Diagram of the process of simulating the "root" attack on the "cn" top-level domain;

[0034] Figure 5 Flow chart of notifying the proxy-type domain name security management system of attacked domain names and real authoritative information (for testing purposes). DETAILED DESCRIPTION

[0035] The following is combined with Figure 1-5 The implementation of the proxy-based recursive domain name preservation method and system of the present invention is described as follows:

[0036] The proxy-based recursive domain name preservation method provided by the present invention does not require modification of the DNS software (BIND9, Berkeley Internet Name Domain) and supports the technical solution of specific domain names and overall domain preservation, and solves the problem of unavailability of DNS resolution service during the software restart time. The following will introduce this preservation solution from three aspects: (1) BIND9 custom cache record function; (2) BIND9 startup delay solution; (3) overall architecture of the proxy-based recursive domain name preservation solution.

[0037] 1. Custom cache record function of BIND9

[0038] RFC1034 stipulates the following for DNS server query and response: the DNS server will use the most suitable cache information for the current query domain name. For example, if the current query domain name is "www.abcd", and the DNS server has stored the cache of the authoritative server information of "cd" because it has previously queried the subdomain of "cd", the query will start from "cd" and ignore the initial step of querying from the root. According to this regulation, if it is found that "cd" has been maliciously tampered with by the superior, the attack can be avoided by simply keeping the cache of the authoritative server information of "cd" in the DNS server correct.

[0039] BIND9 and most DNS software provide the function of user-defined cache records, that is, after the DNS software is started, the user-defined cache file is read first, and the records in it are added to the resolver cache, and then the resolution service is provided. After a domain name is attacked, the authentic and reliable record information of its authoritative server can be written into the custom cache file, and then the DNS server can be restarted to load the custom cache, so as to achieve the purpose of "anchoring" the authoritative information of the domain name. The TTL (Time To Live) in BIND9 is implemented using the unsigned int type, so the TTL in the custom cache file can be set to a larger value, so there is no need to worry about the problem of invalidation of anchor information due to cache expiration.

[0040] This function can achieve the purpose of anchoring trusted authoritative information, but it has a very serious flaw, that is, each time a custom cache record is added, the DNS software needs to be restarted. According to tests, when the number of custom cache records reaches 100,000, the restart time of BIND9 will be more than 1 second, and when the number reaches 1 million, it will take nearly 10 seconds to start. This means that each restart of BIND9 will cause the DNS resolution service to be unavailable for a period of time, and the restart time of several seconds is unacceptable for public resolvers with high QPS.

[0041] 2. Solution to BIND9 startup delay

[0042] Because BIND9's own functions determine that reading custom cache files requires restarting the software, and restarting the software conflicts with providing DNS resolution services, so in order to solve this problem, it is necessary to adjust the structure of the recursive resolver.

[0043] One possible solution is Figure 1 As shown, green means the resolver is available, and red means the resolver is unavailable. Two recursive resolvers are used as a resolver cluster to ensure that at least one resolver can provide resolution services normally. In actual use, a proxy resolver is required. Internet users' DNS queries will be sent to this proxy resolver, and then the proxy resolver will choose which recursive resolver to forward the query to based on the current state of the resolver cluster. In this process, the proxy resolver is responsible for accepting user queries, forwarding user queries, and responding to user queries. The resolvers in the resolver cluster actually perform iterative resolution services.

[0044] Under normal circumstances, the proxy server can choose to forward the user's DNS query to any server in the cluster. When a domain name is found to have been maliciously tampered with by the superior, it is necessary to protect the domain name. At this time, it is necessary to alternately operate the servers in the cluster, that is, write the real information of the authoritative server of the attacked domain name into the custom cache file specified by BIND9, and then restart the corresponding resolver software. The process is as follows Figure 2 The restart operations of the two resolvers should be mutually exclusive to ensure that at least one resolver in the cluster is available, and the restart of the resolver should be notified to the proxy resolver to ensure that the proxy server can forward the user's DNS query to the recursive resolver that can currently provide normal resolution services.

[0045] 3. Overall architecture of the proxy-based recursive domain name preservation solution

[0046] The previous section describes how to use BIND9's own custom cache function to preserve domain names, as well as solutions to BIND9's own functional defects. This section will explain the overall architecture of this domain name preservation solution. Figure 3 As shown in FIG. 1 , it includes 6 modules: (1) configuration of protected domain name list: used to manually add protected domain names; (2) collection of protected domain name record information: for specific domain names, this module collects its IPv4 address record (A record) or IPv6 address record (AAAA record); for the entire domain, this module collects its authoritative server related records (including NS records and corresponding A / AAAA records). There are two ways to collect. If the protected domain name has not been attacked at this time, it can be directly obtained through the Internet. If it has been attacked, it needs to be obtained by manual configuration; (3) trusted record generation: this module is mainly responsible for maintaining trusted record files for subsequent custom cache functions; (4) recursive resolver controller: this module is responsible for synchronizing custom cache records to each resolver in the resolver cluster. The synchronization rules need to meet Figure 2 process, at least one resolver in the resolver cluster must be available to satisfy the synchronization rules at the same time; (5) Proxy resolver controller: This module is responsible for notifying the proxy resolver of the availability of resolvers in the cluster based on the synchronization information of the recursive resolver controller; (6) Log module: This module is mainly responsible for the log backup function, including the configuration of the protected domain name log and the control log of the recursive resolver controller and the proxy resolver controller.

[0047] The proxy resolver controller is specifically implemented as follows: the proxy resolver should select a query forwarding strategy based on the availability of resolvers in the resolver cluster, wherein the setting of the query forwarding strategy is updated in real time by the proxy resolver controller; when a new preserved domain name is added, the resolvers in the resolver cluster will be restarted in turn, and when a resolver is in a restarting state, it cannot provide resolution services, so this resolver should be ignored in the query forwarding strategy of the proxy resolver at this time; during this process, the proxy resolver controller will synchronize information with the recursive resolver controller to synchronize the availability of resolvers in the resolver cluster, and configure the corresponding query forwarding strategy for the proxy resolver according to the current availability.

[0048] When adding a new protected domain name, the recursive resolver controller is responsible for implementing Figure 2 The specific operation process of the recursive resolver controller is as follows: (1) obtain the resolver information in the resolver cluster; (2) determine whether there are any resolvers in the resolver cluster whose security information has not been synchronized. If not, the process ends; (3) select a resolver whose security information has not been synchronized; (4) stop the BIND9 service running on this resolver; (5) add the security information to the custom cache record file; (6) restart the BIND9 service on this resolver; (7) mark this resolver as "security information synchronized"; (8) jump to step (2); after the above process is completed, the resolvers in the resolver cluster have synchronized the new security information to ensure that the newly added domain name is resolved and protected; the service status of the resolver between steps (4) and (6) is unavailable, so in this process the recursive resolver controller will notify the proxy resolver controller of the resolver information in this step to ensure that it can correctly control the query forwarding strategy of the proxy resolver.

[0049] like Figure 1 As shown in the figure, the proxy resolver and the recursive resolver are both resolvers based on the software BIND9. The DNS query initiated by the user is actually sent to the proxy resolver, and then the proxy resolver sends the query to the recursive resolver in the resolver cluster. After that, the recursive resolver performs the actual DNS resolution work and returns the resolution result to the proxy resolver, and then the proxy resolver responds to the query user with the final result. Gray represents that the resolver is available, and white represents that it is unavailable. The half-gray and half-white recursive resolver in the resolver cluster represents that it is available at some times and unavailable at some times (i.e., the period of reconfiguring the custom cache and restarting). The gray proxy resolver represents that it is always available.

[0050] like Figure 2As shown in the figure, this figure describes how to synchronize the custom cache records related to the preserved domain name to the two recursive resolvers when a new preserved domain name needs to be added. The three figures represent three stages: (1) Synchronize the custom cache records to recursive resolver 2, at which time recursive resolver 2 is unavailable (white); (2) After resolver 2 completes synchronization, synchronize resolver 1, at which time resolver 1 is unavailable (white); (3) After resolver 1 completes synchronization, the preservation work is completed, and both resolvers are restored to an available state (gray), and both contain the custom trusted cache records of the preserved domain name.

[0051] like Figure 3 As shown, this figure is the overall architecture diagram of this invention, which mainly includes 6 modules. The functions of each module have been introduced in the previous text. Here is an explanation of the workflow. After obtaining a domain name to be protected, the system will perform the following tasks: (1) Add this domain name to the list of protected domain names (the protected domain name list configuration module is responsible for this); (2) Start collecting relevant record information of this domain name, which can be manually configured or directly obtained from the Internet (the protected domain name record information collection module is responsible for this); (3) Generate a trusted record file for all current protected domain names. This file will eventually be used to load the custom cache (the trusted record generation module is responsible for this); (4) Start synchronizing the record information of the protected domain name to the resolver in the resolver cluster. The synchronization process is Figure 2 During the demonstration process, it is necessary to coordinate with the proxy resolver to ensure that the proxy resolver knows the availability of the recursive resolver in the cluster (completed by the recursive resolver controller and the proxy resolver controller); (5) Log module: In the above steps, all domain name configuration information and control information will be collected by the log module and recorded in the corresponding log.

[0052] Verification of the technical effect of the present invention:

[0053] In the simulation experiment, this solution was tested in practice. The reason for the simulation experiment is that this domain name preservation solution is a preventive technology, and there has been no incident of domain name tampering in the DNS system.

[0054] The simulation environment is as follows:

[0055]

[0056] The experimental steps are as follows:

[0057] Step 1: Simulate the situation of "root" attacking the "cn" top-level domain, point the "cn" authoritative information in the "root" to the fake "cn" authoritative server, and point the authoritative information of "gov.cn" in the fake "cn" authoritative server to the fake "gov.cn" authoritative server, such as Figure 4 As shown;

[0058] Step 2: At this time, the attacked domain ".cn" and its authoritative server information are configured into the proxy domain name protection system, such as Figure 5 As shown;

[0059] Step 3: Verify whether the proxy domain name preservation system is effective, mainly to check the resolution results of the proxy domain name preservation system's resolver and the ordinary resolver for the "www.gov.cn" domain name.

[0060] Experimental results: The resolver of the proxy domain name preservation system can give the real record of "www.gov.cn", while the ordinary recursive resolver gets its forged result.

[0061] It has been verified that the method proposed in the present invention solves the technical problem proposed in the present invention. The method described in the present invention has been verified through practical application of the technical effect and practicality claimed by the present invention.

[0062] The method of the present invention has been verified through simulation experiments and practical applications, and the technical effects claimed by the present invention have been verified.

[0063] The algorithm (method) proposed in the present invention is the underlying technical core of the present invention, and various products can be derived based on the algorithm.

[0064] Based on the algorithm (method) proposed in the present invention, a proxy-type recursive side domain name preservation system is developed using a programming language. The system has program modules corresponding to the steps of the above technical solution, and executes the steps of the above proxy-type recursive side domain name preservation method during operation.

[0065] The computer program of the developed system (software) is stored on a computer-readable storage medium, and the computer program is configured to implement the steps of the above-mentioned proxy-based recursive domain name preservation method when called by a processor, that is, the present invention is materialized on a carrier to become a computer program product.

[0066] A proxy-type recursive-side domain name preservation device, the device includes at least one processor and a memory communicatively connected to the at least one processor, wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute the above-mentioned proxy-type recursive-side domain name preservation method to achieve domain name preservation.

[0067] Various implementations of the systems and techniques described herein can be realized in digital electronic circuit systems, integrated circuit systems, dedicated ASICs (application specific integrated circuits), computer hardware, firmware, software, and / or combinations thereof. These various implementations can include: being implemented in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which can be a special purpose or general purpose programmable processor that can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit data and instructions to the storage system, the at least one input device, and the at least one output device.

[0068] The computer programs (also referred to as programs, software, software applications, or codes) of the present invention include machine instructions for programmable processors, and these computer programs can be implemented using high-level procedural and / or object-oriented programming languages, and / or assembly / machine languages. As used in the present invention, the terms "machine-readable medium" and "computer-readable medium" refer to any computer program product, device, and / or device (e.g., disk, optical disk, memory, programmable logic device PLD) for providing machine instructions and / or data to a programmable processor, including a machine-readable medium that receives machine instructions as machine-readable signals. The term "machine-readable signal" refers to any signal for providing machine instructions and / or data to a programmable processor.

[0069] It should be understood that the various forms of processes shown above can be used to reorder, add or delete steps. For example, the steps recorded in this application can be executed in parallel, sequentially or in different orders, as long as the expected results of the technical solution disclosed in this application can be achieved, they are all within the scope of protection of the present invention.

Claims

1. A proxy-based recursive domain name preservation method, characterized in that: The domain name preservation method is a proxy-type recursive side domain name preservation method based on BIND9, specifically: Give the specific functions of BIND9 that domain name preservation relies on The specific function is the custom cache record function of BIND9. The user-defined cache record function provided by BIND9 is: after the DNS software is started, it first reads the user-defined cache file, adds the records in it to the resolver cache, and then provides resolution services; after a domain name is attacked, the authentic and reliable record information of its authoritative server can be written into the custom cache file, and then the DNS server is restarted to load the custom cache, so as to achieve the purpose of "anchoring" the authoritative information of the domain name; Dealing with BIND9 startup delay Each time BIND9 adds a custom cache record, the DNS software needs to be restarted. When the number of custom cache records is large, the restart time is long. Each restart of BIND9 will cause the DNS resolution service to be unavailable for a period of time. Due to the function of BIND9 itself, the software must be restarted to read the custom cache file, and restarting the software conflicts with providing DNS resolution service. The service conflict is resolved by adjusting the structure of the recursive resolver, specifically: Two recursive resolvers are used as a resolver cluster to ensure that at least one resolver can provide resolution services normally. In actual use, a proxy resolver is required. Internet users' DNS queries will be sent to this proxy resolver, and then the proxy resolver will choose which recursive resolver to forward the query to based on the current state of the resolver cluster. In this process, the proxy resolver is responsible for accepting user queries, forwarding user queries, and responding to user queries. The resolvers in the resolver cluster actually perform iterative resolution services. Under normal circumstances, the proxy server can choose to forward the user's DNS query to any server in the cluster; when a domain name is found to be maliciously tampered with by the superior, it is necessary to preserve the domain name. At this time, it is necessary to alternately operate the servers in the cluster, that is, write the real information of the authoritative server of the attacked domain name into the custom cache file specified by BIND9, and then restart the corresponding resolver software; The restart operations of the two resolvers should be mutually exclusive to ensure that at least one resolver in the cluster is available, and the restart of the resolver should be notified to the proxy resolver to ensure that the proxy server can forward the user's DNS query to the recursive resolver that can currently provide normal resolution services; Constructing the overall architecture of the proxy-based recursive domain name preservation solution The overall architecture of the proxy-based recursive domain name preservation solution includes the following modules: (1) Protected domain name list configuration: used to manually add protected domain names; (2) Collection of protected domain name record information: For a specific domain name, this module collects its IPv4 address record or IPv6 address record. For the entire domain, this module collects its authoritative server related records. There are two ways to collect information. If the protected domain name has not been attacked at this time, it can be directly obtained through the Internet. If it has been attacked, it needs to be obtained through manual configuration; (3) Trusted record generation: This module is mainly responsible for maintaining trusted record files for subsequent custom cache functions; (4) Recursive resolver controller: This module is responsible for synchronizing custom cache records to each resolver in the resolver cluster. At the same time, at least one resolver in the resolver cluster must be available to meet the synchronization rules. (5) Proxy resolver controller: This module is responsible for notifying the proxy resolver of the availability of resolvers in the cluster based on the synchronization information of the recursive resolver controller; (6) Log module: This module is mainly responsible for the log backup function, including the configuration of the protected domain name log and the control log of the recursive resolver controller and the proxy resolver controller.

2. A proxy-based recursive domain name preservation method according to claim 1, characterized in that: The proxy resolver controller is specifically implemented as follows: the proxy resolver should select a query forwarding strategy based on the availability of resolvers in the resolver cluster, wherein the setting of the query forwarding strategy is updated in real time by the proxy resolver controller; when a new preserved domain name is added, the resolvers in the resolver cluster will be restarted in turn, and when a resolver is in a restarting state, it cannot provide resolution services, so this resolver should be ignored in the query forwarding strategy of the proxy resolver at this time; during this process, the proxy resolver controller will synchronize information with the recursive resolver controller to synchronize the availability of resolvers in the resolver cluster, and configure the corresponding query forwarding strategy for the proxy resolver according to the current availability.

3. A proxy-based recursive domain name preservation method according to claim 1 or 2, characterized in that: The specific implementation of the recursive resolver controller is as follows: The specific operation process of the recursive resolver controller is as follows: (1) obtain the resolver information in the resolver cluster; (2) determine whether there are resolvers in the resolver cluster whose preservation information has not been synchronized. If not, the process ends; (3) select a resolver whose preservation information has not been synchronized; (4) stop the BIND9 service running on this resolver; (5) add the preservation information to the custom cache record file; (6) Restart the BIND9 service on this resolver; (7) Mark this resolver as "Synchronized Security Information"; (8) Jump to step (2); After the above process is completed, the resolvers in the resolver cluster will synchronize the new security information to ensure that the newly added domain name is resolved and protected; the service status of the resolver between steps (4) and (6) is unavailable, so during this process the recursive resolver controller will notify the proxy resolver controller of the resolver information in this step to ensure that it can correctly control the query forwarding strategy of the proxy resolver.

4. A proxy-based recursive domain name preservation method according to claim 1, characterized in that: In the collection of protected domain name record information, the IPv4 address record is an A record, and the IPv6 address record is an AAAA record. For the entire domain, this module collects records related to its authoritative server, including NS records and corresponding A / AAAA records.

5. According to the proxy-type recursive domain name preservation method of claim 1, the specific implementation of the recursive resolver controller is: the resolver of the proxy-type domain name preservation system can provide a real record of "www.gov.cn".

6. A proxy-type recursive domain name protection system, characterized in that: The system has a program module corresponding to the steps of any one of claims 1 to 3 above, and executes the steps of the proxy-type recursive side domain name preservation method when running.

7. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, and the computer program is configured to implement the steps of a proxy-based recursive domain name preservation method according to any one of claims 1 to 3 when called by a processor.

Citation Information

Patent Citations

  • A Recursive Side-DDoS Domain Name Preservation Method and System Based on RPZ

    CN115174518B

  • DNS deployment method based on web management and terminal

    CN110324173A

  • DNS server monitoring method and system, electronic device and storage medium

    CN113014573A

  • Recursive side domain name preservation method and system based on RPZ

    CN115174518A