Domain name system DNS service processing method, routing device and storage medium

By verifying and updating the IP address in the DNS reply information on the routing device, the problem of DNS hijacking is solved, ensuring that the website accessed by the terminal is secure, and the security improvement of DNS service processing is achieved.

CN120111028APending Publication Date: 2025-06-06HUAWEI TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202311665784.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-12-06
Publication Date
2025-06-06

AI Technical Summary

Technical Problem

During the DNS request process, DNS hijacking is prone to occur, causing terminals to access phishing websites, resulting in privacy leakage and other security issues.

Method used

By implementing a DNS service processing method on the routing device, receiving the DNS request from the terminal, verifying the IP address in the DNS reply information. If the verification fails, the reliable IP address in the IP address information of the local domain name is sent to the terminal, and secondary verification and update are performed through the second DNS server to ensure that the terminal accesses the correct IP address.

Benefits of technology

It effectively prevents DNS hijacking, ensures that the website accessed by the terminal is safe, avoids privacy leakage and other security risks, and does not affect the user's Internet experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120111028A_ABST
    Figure CN120111028A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a domain name system (DNS) service processing method, routing equipment, a storage medium and a program product, relates to the technical field of network security, and can improve the security of DNS service processing. The DNS service processing method is applied to routing equipment, and comprises the following steps: receiving a DNS request sent by a terminal, and sending the DNS request to a first DNS server; receiving DNS response information sent by the first DNS server, wherein the DNS response information comprises the first IP address; if the local domain name IP address information does not include the first IP address, a second IP address is sent to the terminal, the domain name in the DNS request and the first IP address are sent to a second DNS server, and the second IP address is an IP address matched with the domain name in the DNS request in the local domain name IP address information; receiving a third IP address sent by the second DNS server; and if the third IP address is different from the second IP address, updating the second IP address in the local domain name IP address information to the third IP address.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of network security technology, and in particular to a domain name system DNS service processing method, routing equipment, storage medium and program product. Background Art

[0002] In a local area network, after a terminal sends a DNS request to a Domain Name System (DNS) server through a router, the DNS server will send the Internet Protocol (IP) address corresponding to the domain name in the DNS request to the terminal through the router, so that the terminal can access the corresponding website through the IP address. However, during the DNS request process, if DNS hijacking occurs, the DNS server will send a tampered IP address to the terminal, which may cause the terminal to access phishing websites through the tampered IP address, resulting in privacy leakage. Summary of the invention

[0003] In view of this, the present application provides a domain name system DNS business processing method, routing device, storage medium and program product, which can improve the security of DNS business processing.

[0004] A first aspect provides a domain name system DNS service processing method, which is applied to a routing device, and the method includes: receiving a DNS request sent by a terminal, and sending the DNS request to a first DNS server; receiving DNS response information sent by the first DNS server, and the DNS response information includes a first IP address; if the local domain name IP address information does not include the first IP address, sending a second IP address to the terminal, and sending the domain name in the DNS request and the first IP address to a second DNS server, and the second IP address is an IP address in the local domain name IP address information that matches the domain name in the DNS request; receiving a third IP address sent by the second DNS server; if the third IP address is different from the second IP address, updating the second IP address in the local domain name IP address information to the third IP address.

[0005] On the one hand, the IP address in the NDS response information is verified based on the local domain name IP address information of the routing device, and the address in the local domain name IP address information is sent to the terminal when the verification fails, so as to prevent the terminal from accessing the phishing website based on the IP address after DNS hijacking; on the other hand, when the verification fails, the address in the local domain name IP address information is verified twice based on the second DNS server, so as to realize the update of the IP address in the local domain name IP address information, so as to ensure that when the IP address in the local domain name IP address information becomes invalid and changes, the IP address is updated, and the website corresponding to the domain name can be accessed based on the updated correct IP address at the next request of the terminal, and the two verification processes avoid misjudgment and are imperceptible to the user, and will not affect the user's Internet experience; the whole process is executed by the routing device, and the user does not need to perform additional configuration based on the terminal, and the requirements for the terminal are relatively low; in addition, since the IP address in the DNS response information is first verified based on the local domain name IP address information, the delay in the response to accessing the website is less affected.

[0006] In a possible implementation, the method further includes: receiving first DNS hijacking result information sent by a second DNS server; if it is determined that DNS hijacking has occurred according to the first DNS hijacking result information, switching the first DNS server from a default DNS server to a backup DNS server. After switching the backup DNS server, when a DNS request sent by a terminal is received, a DNS request will be sent to the backup DNS server. If the backup DNS server has not been hijacked, the backup DNS server can normally return the correct IP address to the terminal, so that the terminal can access the corresponding website based on the correct IP address, and this method has less impact on the delay in accessing the website.

[0007] In a possible implementation, after the default DNS server is switched to the backup DNS server, it also includes: receiving the second DNS hijacking result information sent by the second DNS server; if it is determined that DNS hijacking has occurred according to the second DNS hijacking result information, the DNS-over-TLS function is turned on. If it is still hijacked after switching the backup DNS server, the DNS-over-TLS function is turned on, and DNS-over-TLS, a safer way, is used for DNS proxy in the future to prevent DNS hijacking. It should be understood that DNS proxy refers to the process of sending the DNS request of the terminal to the DNS server, and sending the IP address in the response information sent by the DNS server to the terminal. If it is determined that DNS hijacking has not occurred after switching the backup DNS server, it means that the backup DNS server has not been hijacked, and there is no need to turn on the DNS-over-TLS function. The backup DNS server is still used for DNS proxy, which can increase the speed of accessing the website.

[0008] In a possible implementation, after the DNS-over-TLS function is turned on for a preset period of time, the method also includes: receiving another DNS request sent by the terminal, sending another DNS request to the first DNS server; receiving another DNS response information sent by the first DNS server, the other DNS response information including a fourth IP address; sending the domain name and the fourth IP address in another DNS request to the second DNS server; receiving the third DNS hijacking result information and the fifth IP address sent by the second DNS server; if it is determined that DNS hijacking has not occurred according to the third DNS hijacking result information, then turning off the DNS-over-TLS function to improve the response speed of subsequent terminal access to the website. If it is determined that DNS hijacking has occurred according to the third DNS hijacking result information, continue to use the DNS-over-TLS function to perform subsequent DNS proxy processes to prevent DNS hijacking. Optionally, if it is determined that DNS hijacking has not occurred according to the third DNS hijacking result information, then turning off the DNS-over-TLS function and switching the first DNS server to the default DNS server to improve the response speed of subsequent terminal access to the website.

[0009] In a possible implementation, the method further includes: if it is determined that DNS hijacking has occurred according to the first DNS hijacking result information, the DNS hijacking information is sent to the cloud server to retain the hijacking information for subsequent maintenance and to facilitate prompting the user.

[0010] In a possible implementation, the method further includes: periodically updating the local domain name IP address information. By updating and maintaining the local domain name IP address information, the result of verifying the IP address in the DNS response information through the local domain name IP address information can be made more accurate, and the probability of misjudgment due to changes in the IP address corresponding to the domain name can be reduced.

[0011] In a possible implementation, periodically updating the local domain name IP address information includes: periodically sending the domain name in the local domain name IP address information to the second DNS server at a first frequency; receiving the IP address corresponding to the domain name in the local domain name IP address information sent by the second DNS server; and updating the IP address in the local domain name IP address information according to the IP address corresponding to the domain name in the local domain name IP address information sent by the second DNS server. Based on the second DNS server, the update and maintenance of the local domain name IP address information can be implemented more securely.

[0012] In a possible implementation, periodically updating the local domain name IP address information further includes: periodically sending a domain name update request to a domain name update server at a second frequency, the second frequency being less than the first frequency; receiving a domain name sent by the domain name update server, and updating the domain name in the local domain name IP address information according to the domain name sent by the domain name update server. By updating and maintaining the domain name, the IP address in the DNS response information returned by the DNS request can be more specifically verified based on the latest key domain name, so as to achieve more flexible and targeted protection against DNS hijacking.

[0013] In a second aspect, a routing device is provided, including: a processor and a memory, wherein the memory is used to store at least one program, and when the program is executed by the processor, the routing device executes the above method.

[0014] According to a third aspect, a readable storage medium is provided, including a program or an instruction. When the program or the instruction runs on a routing device, the above method is executed.

[0015] According to a fourth aspect, a program product is provided. The program product includes a program. When the program is executed on a routing device, the routing device executes the above method. BRIEF DESCRIPTION OF THE DRAWINGS

[0016] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings required for use in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative labor.

[0017] Figure 1 A schematic diagram of a DNS hijacking scenario in the related art;

[0018] Figure 2 This is a schematic diagram of interactive signaling of a DNS service processing method in an embodiment of the present application;

[0019] Figure 3 A schematic diagram of a DNS service processing method in an embodiment of the present application;

[0020] Figure 4 A schematic diagram of an anti-hijacking process in an embodiment of the present application;

[0021] Figure 5 This is a schematic diagram of a prompt interface for DNS hijacking information in an embodiment of the present application;

[0022] Figure 6 This is a schematic diagram of a process for updating and maintaining local domain name IP address information in an embodiment of the present application;

[0023] Figure 7 This is a structural block diagram of a routing device in an embodiment of the present application. DETAILED DESCRIPTION

[0024] In order to better understand the technical solution of the present application, the embodiments of the present application are described in detail below with reference to the accompanying drawings.

[0025] It should be clear that the described embodiments are only part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in the field without creative work are within the scope of protection of the present application.

[0026] The terms used in the embodiments of the present application are only for the purpose of describing specific embodiments, and are not intended to limit the present application. The singular forms "a", "said" and "the" used in the embodiments of the present application and the appended claims are also intended to include plural forms, unless the context clearly indicates other meanings.

[0027] Before describing the embodiments of the present application, the related technologies and their technical problems are described first. Figure 1 As shown, in the related art, there may be a scenario where multiple terminals access the Internet through a router, and the multiple terminals may include, for example, computers, tablet computers, mobile phones, etc. When a terminal accesses a website, the terminal sends a DNS request to query the domain name, that is, to query the IP address corresponding to the domain name. The router performs DNS proxy through the DNS server provided by the operator. Under normal circumstances, the domain name points to the correct website and returns the IP address of the correct website to the terminal. The terminal can access the corresponding correct site through the IP address; however, when DNS hijacking occurs, the domain name points to the IP address of the hijacked phishing website, that is, the IP address of the phishing website is returned to the terminal. At this time, the terminal will access the phishing website. If an online shopping or payment website is pointed to a phishing website, it may cause personal account information leakage, or when a user visits a website, personal privacy information is leaked, and the browsed website is implanted with advertisements. Problems such as DNS hijacking may be achieved by forging DNS responses, attacking DNS servers, and tampering with DNS caches. An encrypted DNS service can be configured on the terminal to avoid DNS hijacking, for example, by using DNS-over-TLS or DNS-over-HTTPS technology to verify whether the DNS query result has been tampered with. However, on the one hand, this way of configuring DNS service is relatively complicated and has a high threshold for users; on the other hand, this way of configuring DNS service requires the support of the terminal, and some old terminals or smart home devices may not support it; on the other hand, this way of configuring DNS service will increase the response delay of accessing the website. The embodiment of the present application can solve the above problems, and the technical solution of the embodiment of the present application is described below.

[0028] like Figure 2 and Figure 3 As shown, an embodiment of the present application provides a domain name system DNS service processing method, which is applied to a routing device, and the method includes:

[0029] Step 101, the routing device receives a DNS request sent by the terminal. The terminal is an electronic device that is connected to the routing device for communication, and the terminal includes but is not limited to mobile phones, computers, tablet computers, mobile phones, portable computers, wearable devices, smart home devices and other devices with Wi-Fi functions. Routing devices include but are not limited to routers, CPE (Customer Premises Equipment), accompanying Wi-Fi devices, Fi mobile routing devices and other devices that provide Wi-Fi access. The DNS request includes a domain name, such as www.xx.com, and the terminal obtains the IP address corresponding to the domain name by sending a DNS request.

[0030] Step 102: The routing device sends a DNS request to a first DNS server, which is a server provided by the operator.

[0031] Step 103: The routing device receives DNS response information sent by the first DNS server, where the DNS response information includes the first IP address.

[0032] Step 104, the routing device determines whether the local domain name IP address information includes the first IP address. For example, the local domain name IP address information can be a list of mapping relationships between domain names and IP addresses. The list can store the mapping relationship between domain names and IP addresses in the form of a hash table. The local domain name IP address information is maintained and stored on the routing device. The domain names in the list include some key domain names. The key domain names can be domain names such as bank website domain names, payment page domain names, etc., which are easy to leak user information. The IP address in the local domain name IP address information is a reliable IP address. Therefore, the local domain name IP address information can be used to verify whether the first IP address is hijacked. If the domain name in the DNS request of the terminal is a domain name already in the local domain name IP address information, step 104 is executed to verify the IP address in the DNS response information; if the domain name in the DNS request of the terminal is not a domain name already in the local domain name IP address information, step 104 is not executed because the IP address in the DNS response information cannot be verified through the local domain name IP address information.

[0033] If the local domain name IP address information does not include the first IP address, it means that the IP address verification in the DNS response information has failed, that is, there is no corresponding relationship between the first IP address and the domain name in the DNS request in the local domain name IP address information, then execute step 105 and step 106; if the local domain name IP address information includes the first IP address, it means that the IP address verification in the DNS response information has succeeded, that is, there is a corresponding relationship between the first IP address and the domain name in the DNS request in the local domain name IP address information, then execute step 107.

[0034] Step 105, the routing device sends the second IP address to the terminal, the second IP address is the IP address in the local domain name IP address information that matches the domain name in the DNS request, that is, if the local domain name IP address information does not include the first IP address, it means that the first IP address may be the IP address of a phishing website after DNS hijacking. Therefore, in order to prevent the terminal from accessing the phishing website, the routing device sends a reliable second IP address in the local domain name IP address information to the terminal. If the second IP address is available, the terminal can access the website corresponding to the requested domain name www.xx.com through the second IP address.

[0035] Step 106: The routing device sends the domain name and the first IP address in the DNS request to the second DNS server. The second DNS server is different from the first DNS server provided by the above-mentioned operator. The second DNS server is a secure DNS server, that is, the second DNS server and the routing device are connected through a more secure communication method, so it can be ensured that the communication between the routing device and the second DNS server will not be hijacked. After obtaining the domain name and the first IP address, the second DNS server will verify whether the domain name and the first IP address are hijacked, and send the correct third IP address corresponding to the domain name to the routing device.

[0036] Step 107: The routing device sends the first IP address to the terminal. That is, in step 104, if the IP address in the DNS response information is successfully verified, the IP address is directly sent to the terminal so that the terminal can access the website based on the IP address.

[0037] After step 106, the routing device executes step 108 and receives the third IP address sent by the second DNS server;

[0038] Step 109: The routing device determines whether the third IP address is the same as the second IP address.

[0039] If so, that is, if the third IP address is the same as the second IP address, it means that the second IP address sent to the terminal in step 105 is correct, that is, the terminal can access the website corresponding to the requested domain name through the second IP address in step 105; if not, that is, if the third IP address is different from the second IP address, it means that the second IP address sent to the terminal in step 105 is wrong, which may be because the IP address corresponding to the domain name has been changed, but the IP address in the local domain name IP address information has not been changed. Therefore, step 110 is executed to update the second IP address in the local domain name IP address information to the third IP address. In this way, although the terminal cannot access the website corresponding to the domain name according to the second IP address received in the aforementioned step 105, after the access fails, the terminal will send a DNS request again to access the website corresponding to the domain name. In the process of accessing the website corresponding to the domain name again, since the IP address corresponding to the domain name in the local domain name IP address information has been updated to the correct address, the terminal can normally access the website corresponding to the domain name.

[0040] The DNS service processing method in the embodiment of the present application, on the one hand, verifies the IP address in the NDS response information based on the local domain name IP address information of the routing device, and sends the address in the local domain name IP address information to the terminal when the verification fails, so as to prevent the terminal from accessing the phishing website based on the IP address after DNS hijacking; on the other hand, when the verification fails, the address in the local domain name IP address information is verified twice based on the second DNS server to realize the update of the IP address in the local domain name IP address information, so as to ensure that when the IP address in the local domain name IP address information is invalid and changed, the IP address is updated, and the website corresponding to the domain name can be accessed based on the updated correct IP address when the terminal sends a DNS request next time, and the two verification processes avoid misjudgment and are imperceptible to the user, and will not affect the user's Internet experience; the whole process is executed in the routing device, and the user does not need to perform additional configuration based on the terminal, and the requirements for the terminal are relatively low; in addition, since the IP address in the DNS response information is first verified based on the local domain name IP address information, the delay in responding to accessing the website is less affected.

[0041] In some embodiments, the above method also includes: after step 106, executing step 111, the routing device receives the first DNS hijacking result information sent by the second DNS server, wherein the third IP address and the first DNS hijacking result information received by the routing device in steps 108 and 111 can be received in the same message or message, or in different messages or messages, and the hijacking result information includes two possible results, one is hijacked, and the other is not hijacked. In the case of hijacking, the first IP address is not the correct IP address corresponding to the domain name in the DNS request, so the correct third IP address needs to be returned; in the case of not being hijacked, it means that although the first IP address is not an IP address that has been tampered with due to hijacking, the IP address corresponding to the domain name in the DNS request has been changed, that is, the first IP address has expired, so the correct third IP address needs to be returned. After step 111, executing step 112, determining whether DNS hijacking has occurred based on the first DNS hijacking result information, if so, that is, if DNS hijacking has occurred based on the first DNS hijacking result information, then entering the anti-hijacking process, such as Figure 4 As shown, the anti-hijacking process includes: step 201, the routing device switches the first DNS server from the default DNS server to the backup DNS server. The address of the backup DNS server is, for example, 114.114.114.114. For DNS hijacking, it may be targeted at the default DNS server, so the default DNS server is switched to the backup DNS server. If there is no hijacking of the backup DNS server, it is possible to solve the problem of DNS hijacking. After switching the backup DNS server, after receiving the DNS request sent by the terminal, the routing device will send a DNS request to the backup DNS server. If the backup DNS server is not hijacked, the routing device can normally return the correct IP address to the terminal, so that the terminal can access the corresponding website based on the correct IP address, and this method has less impact on the delay in accessing the website. It should be understood that both the default DNS server and the backup DNS server belong to the first DNS server.

[0042] In some embodiments, Figure 4As shown, after the routing device switches the default DNS server to the backup DNS server in step 201, it also includes: step 202, the routing device receives the second DNS hijacking result information sent by the second DNS server. Between step 201 and step 202, the routing device will perform DNS proxy based on the backup DNS server. If it is determined that no DNS hijacking has occurred during the DNS proxy based on the backup DNS server, the backup DNS server will continue to be used for DNS proxy. If the second DNS hijacking result information sent by the second DNS server is received during the DNS proxy based on the backup DNS server, step 203 is executed, the routing device determines whether DNS hijacking has occurred according to the second DNS hijacking result information. If so, that is, if it is determined that DNS hijacking has occurred according to the second DNS hijacking result information, step 204 is executed, the routing device turns on the DNS-over-TLS function. If not, that is, if it is determined that no DNS hijacking has occurred according to the second DNS hijacking result information, the backup DNS server will continue to be used for DNS proxy. It should be understood that the DNS proxy involved in this article refers to the process of sending the DNS request of the terminal to the DNS server and sending the IP address in the response information sent by the DNS server to the terminal.

[0043] Specifically, between step 201 and step 202, the routing device performs a DNS proxy process based on the backup DNS server and Figure 2The process in is similar. For example, after the first DNS server is switched to the backup DNS server in step 201, when the routing device receives another DNS request sent by the terminal, the domain name in the DNS request is www.aa.com, the DNS request will be sent to the backup DNS server, and the DNS response information sent by the backup DNS server will be received. The DNS response information includes IP address A, and it is determined whether the local domain name IP address information includes IP address A. If so, it means that there is no hijacking, and IP address A is sent to the terminal, and the backup DNS server is continued to be used for DNS proxy; if not, it means that hijacking or IP address change may occur, and the IP address B matching www.aa.com in the local domain name IP address information is sent to the terminal, and www.aa.com and IP address A are sent to the second DNS server, and the routing device The IP address C and the second DNS hijacking result information sent by the second DNS server are received. If the IP address C and the IP address B are different, the IP address B corresponding to www.aa.com in the local domain name IP address information is replaced and updated with the IP address C. In step 203, it is determined whether DNS hijacking occurs according to the second DNS hijacking result information. If so, it means that it is still hijacked after switching to the backup DNS server. Therefore, the DNS-over-TLS function is enabled, that is, DNS-over-TLS is used in the subsequent more secure way to perform DNS proxy to prevent DNS hijacking. If it is determined in step 203 that DNS hijacking does not occur, it means that the backup DNS server is not hijacked. In order to increase the speed of accessing the website, it is not necessary to enable the DNS-over-TLS function, and the backup DNS server is still used for DNS proxy.

[0044] In some embodiments, Figure 4 As shown, after the DNS-over-TLS function is enabled for a preset period of time, the method further includes:

[0045] Step 301: The routing device receives another DNS request sent by the terminal, where the domain name in the other DNS request is, for example, www.bb.com;

[0046] Step 302: The routing device sends another DNS request to the first DNS server, where the first DNS server may be the default DNS server mentioned above, the backup DNS server mentioned above, or another DNS server provided by the operator.

[0047] Step 303: The routing device receives another DNS response information sent by the first DNS server, where the other DNS response information includes a fourth IP address.

[0048] Step 304: The routing device sends the domain name and the fourth IP address in another DNS request to the second DNS server. The second DNS server determines whether hijacking occurs according to the domain name and the fourth IP address, and generates corresponding third DNS hijacking result information. The second DNS server sends the third DNS hijacking result information and the correct fifth IP address corresponding to the domain name to the routing device.

[0049] Step 305: The routing device receives the third DNS hijacking result information and the fifth IP address sent by the second DNS server;

[0050] Step 306: The routing device determines whether DNS hijacking occurs according to the third DNS hijacking result information. If not, that is, if it is determined according to the third DNS hijacking result information that DNS hijacking does not occur, step 307 is executed: the routing device turns off the DNS-over-TLS function. After turning off the DNS-over-TLS function, it is restored to DNS proxy based on the default DNS server. For example, in step 302, the default DNS server is sent, that is, it is verified whether the hijacking based on the default DNS server is ended. If the hijacking is ended, the DNS-over-TLS function is turned off and the first DNS server is restored to the default DNS server; if yes, that is, if it is determined according to the third DNS hijacking result information that DNS hijacking occurs, the DNS-over-TLS function continues to be kept on.

[0051] Specifically, the above-mentioned preset time length is, for example, 2 hours, that is, 2 hours after the DNS-over-TLS function is turned on, when the routing device receives the DNS request of the terminal again, the above steps 301 to 306 are used to verify whether the hijacking of the first DNS server provided by the operator is ended. If the hijacking is ended, the DNS-over-TLS function is turned off to improve the response speed of subsequent terminal access to the website. If the hijacking is not ended, the DNS-over-TLS function continues to be used to perform subsequent DNS proxy processes to prevent DNS hijacking. As an alternative implementation method, if the hijacking is ended, the DNS-over-TLS function is turned off and the first DNS server is switched to the default DNS server to improve the response speed of subsequent terminal access to the website. The process of steps 302 to 306 above is only to verify whether the hijacking of the first DNS server is completed. For another DNS request sent by the terminal in step 301, the DNS-over-TLS function is still turned on during this process, that is, for another DNS request sent by the terminal in step 301, the DNS-over-TLS function is still used to perform DNS proxy and return the correct IP address to the terminal to ensure the normal processing of the DNS request.

[0052] In some embodiments, the anti-hijacking process further includes step 401, that is, if it is determined in step 112 that DNS hijacking occurs according to the first DNS hijacking result information, step 401 is executed and the routing device sends the DNS hijacking information to the cloud server. Figure 5 As shown, the cloud server can push DNS hijacking information to the terminal to prompt the user, or the terminal can obtain DNS hijacking information by accessing the cloud server. DNS hijacking information may include information such as the hijacked domain name and hijacking time.

[0053] In some embodiments, the above method also includes: the routing device periodically updates the local domain name IP address information. By updating and maintaining the local domain name IP address information, the result of verifying the IP address in the DNS response information through the local domain name IP address information can be made more accurate, thereby reducing the probability of misjudgment due to changes in the IP address corresponding to the domain name.

[0054] In some embodiments, Figure 6 As shown, the routing device periodically updates the local domain name IP address information, including: step 401, the routing device establishes a Datagram Transport Layer Security (DTLS) long connection with the second DNS server. After the DTLS long connection is successfully established, step 402 is executed, the routing device periodically sends the domain names in the local domain name IP address information to the second DNS server at a first frequency, so as to query the IP addresses corresponding to these domain names through the second DNS server. For example, the first frequency is once every 5 minutes; step 403, the routing device receives the IP address corresponding to the domain name in the local domain name IP address information sent by the second DNS server, and the transmission of the IP address is encrypted by the Transport Layer Security (TLS) protocol to prevent tampering; step 404, the routing device updates the IP address in the local domain name IP address information according to the IP address corresponding to the domain name in the local domain name IP address information sent by the second DNS server, that is, updates and maintains the IP address in the local domain name IP address information stored in the routing device.

[0055] In some embodiments, Figure 6As shown, periodically updating the local domain name IP address information also includes: step 501, the routing device periodically sends a domain name update request to the domain name update server at a second frequency, the second frequency is less than the first frequency, and the second frequency is, for example, once a day; step 502, the routing device receives the domain name sent by the domain name update server, and updates the domain name in the local domain name IP address information according to the domain name sent by the domain name update server. By updating and maintaining the domain name, the IP address in the DNS response information returned by the DNS request can be more specifically verified based on the latest key domain name, so as to achieve more flexible and targeted protection against DNS hijacking.

[0056] like Figure 7 As shown, the embodiment of the present application also provides a routing device 900, including: a processor 901 and a memory 902, the memory 902 is used to store at least one program, and when the program is executed by the processor 901, the routing device 900 executes the method in any of the above embodiments. The memory 902 can be a separate device or integrated in the processor 901. The routing device 900 can also include a transceiver 903, and the transceiver 903 can include a transmitter and a receiver. The processor 901, the memory 902 and the transceiver 903 can be devices integrated on different chips, for example, the processor 901 and the memory 902 can be integrated in a baseband chip, the transceiver 903 can be integrated in a radio frequency chip, and the processor 901, the memory 902 and the transceiver 903 can also be devices integrated on the same chip. The transceiver 903 can also be a communication interface, such as an input / output interface, a circuit, etc.

[0057] An embodiment of the present application further provides a readable storage medium, including a program or an instruction. When the program or the instruction runs on a routing device, the method in any of the above embodiments is executed.

[0058] The embodiment of the present application also provides a program product, which includes a program. When the program is executed on a device, the routing device executes the method in any of the above embodiments.

[0059] In the above embodiments, all or part of the embodiments may be implemented by software, hardware, firmware or any combination thereof. When implemented by software, all or part of the embodiments may be implemented in the form of a program product. The program product includes one or more instructions. When the instructions are loaded and executed on a routing device or a computer, all or part of the processes or functions described in the present application are generated. The computer may be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device.

[0060] In the embodiments of the present application, "at least one" refers to one or more, and "plurality" refers to two or more. "And / or" describes the association relationship of associated objects, indicating that three relationships may exist. For example, A and / or B can represent the existence of A alone, the existence of A and B at the same time, and the existence of B alone. Among them, A and B can be singular or plural. The character " / " generally indicates that the previous and subsequent associated objects are in an "or" relationship. "At least one of the following" and similar expressions refer to any combination of these items, including any combination of single or plural items. For example, at least one of a, b and c can be represented by: a, b, c, ab, ac, bc, or abc, where a, b, c can be single or multiple.

[0061] The above are only preferred embodiments of the present application and are not intended to limit the present application. For those skilled in the art, the present application may have various modifications and variations. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included in the protection scope of the present application.

Claims

1. A domain name system DNS service processing method, applied to a routing device, It is characterized in that The method comprises: Receiving a DNS request sent by a terminal, and sending the DNS request to a first DNS server; Receiving DNS response information sent by the first DNS server, wherein the DNS response information includes a first IP address; If the local domain name IP address information does not include the first IP address, a second IP address is sent to the terminal, and the domain name in the DNS request and the first IP address are sent to a second DNS server, where the second IP address is an IP address in the local domain name IP address information that matches the domain name in the DNS request; Receiving a third IP address sent by the second DNS server; If the third IP address is different from the second IP address, the second IP address in the local domain name IP address information is updated to the third IP address.

2. The method according to claim 1, It is characterized in that Also includes: Receiving the first DNS hijacking result information sent by the second DNS server; If it is determined according to the first DNS hijacking result information that DNS hijacking has occurred, the first DNS server is switched from a default DNS server to a backup DNS server.

3. The method according to claim 2, It is characterized in that After the default DNS server is switched to the standby DNS server, the method further includes: Receiving the second DNS hijacking result information sent by the second DNS server; If it is determined that DNS hijacking has occurred according to the second DNS hijacking result information, the DNS-over-TLS function is enabled.

4. The method according to claim 3, It is characterized in that After enabling the DNS-over-TLS function for a preset period of time, the method further includes: receiving another DNS request sent by the terminal, and sending the another DNS request to the first DNS server; receiving another DNS response information sent by the first DNS server, wherein the another DNS response information includes a fourth IP address; Sending the domain name in the other DNS request and the fourth IP address to the second DNS server; Receiving the third DNS hijacking result information and the fifth IP address sent by the second DNS server; If it is determined according to the third DNS hijacking result information that DNS hijacking has not occurred, the DNS-over-TLS function is disabled.

5. The method according to claim 2, It is characterized in that Also includes: If it is determined that DNS hijacking has occurred based on the first DNS hijacking result information, the DNS hijacking information is sent to the cloud server.

6. The method according to any one of claims 1 to 5, It is characterized in that Also includes: The local domain name IP address information is updated periodically.

7. The method according to claim 6, It is characterized in that The periodic updating of the local domain name IP address information includes: Periodically sending the domain name in the local domain name IP address information to the second DNS server at a first frequency; Receiving an IP address corresponding to the domain name in the local domain name IP address information sent by the second DNS server; The IP address in the local domain name IP address information is updated according to the IP address corresponding to the domain name in the local domain name IP address information sent by the second DNS server.

8. The method according to claim 7, It is characterized in that The periodic updating of the local domain name IP address information further includes: periodically sending a domain name update request to a domain name update server at a second frequency, wherein the second frequency is less than the first frequency; The domain name sent by the domain name update server is received, and the domain name in the local domain name IP address information is updated according to the domain name sent by the domain name update server.

9. A routing device, It is characterized in that include: A processor and a memory, wherein the memory is used to store at least one program, and when the program is executed by the processor, the routing device executes the method according to any one of claims 1 to 8.

10. A readable storage medium, It is characterized in that The method comprises a program or an instruction. When the program or the instruction is executed on the routing device, the method according to any one of claims 1 to 8 is executed.

11. A program product, It is characterized in that The program product includes a program, and when the program is executed on a routing device, the routing device is caused to execute the method according to any one of claims 1 to 8.