DNS (Domain Name Server) cache attack protection method and device, computer equipment and program product

By sending request packets of UDP and TCP protocols in the local DNS server and performing matching verification of response packets, the problem of insufficient protection of DNS cache attacks in the prior art is solved, and higher security and stability are achieved.

CN120185880APending Publication Date: 2025-06-20CHINA TELECOM CLOUD TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510330630.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-20
Publication Date
2025-06-20

AI Technical Summary

Technical Problem

When defending against DNS cache attacks, the existing technology lacks protection capabilities and poses a risk of being compromised.

Method used

By sending a request packet based on the UDP protocol and TCP protocol in the local DNS server, and receiving the response packet returned by the DNS server, performing matching verification to ensure the authenticity of the response packet, thereby improving protection capabilities.

Benefits of technology

Improve the protection capability of DNS cache attacks, ensure the security and stability of the domain name query process, and avoid cache tampering.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120185880A_ABST
    Figure CN120185880A_ABST
Patent Text Reader

Abstract

The invention relates to a DNS cache attack protection method and device, computer equipment, a computer readable storage medium and a computer program product. The method comprises the following steps: receiving a domain name resolution request sent by a client; under the condition that a resolution result corresponding to the domain name resolution request does not exist in a local cache, sending a request packet formed based on a UDP protocol and a TCP protocol to a DNS server; receiving a corresponding response packet sent by the DNS server; analyzing the response packet to obtain an analysis result; under the condition that the analysis result represents that the request packet is successfully matched, matching the first analysis result with the second analysis result; under the condition that the first analysis result is successfully matched with the second analysis result, extracting a target analysis result corresponding to the domain name analysis request based on the first analysis result and the second analysis result; and storing the target analysis result in a local cache, and sending the target analysis result to the client. By adopting the method, the security in the domain name resolution process can be effectively improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of cloud computing technology, and in particular, to a method, apparatus, computer device, computer-readable storage medium, and computer program product for protecting against DNS cache attacks. Background Art

[0002] The DNS (Domain Name System) is a service on the Internet. It maps domain names and IP addresses to each other in a distributed database, and stores the correspondence between domain names and IPs in the database, thus making it more convenient to access the Internet. When an IP address needs to be queried, a request is sent to the local DNS server. The local DNS server sends the request to the authoritative DNS server through the UDP protocol. The authoritative DNS server sends the response packet containing the resolution result received to the local DNS server. At this time, cache attacks may also target the local DNS server, sending forged response packets. When the forged response packet sent by the attacker arrives at the local DNS server before the correct response packet sent by the authoritative DNS server and matches the IP address, port, and random query ID of the original request packet, it can successfully tamper with the local DNS server cache data and control the user's access result, resulting in the control of the domain names of the entire authorized domain and threatening network security.

[0003] In the related art, methods such as randomizing the source port of the query request and increasing the number of authoritative DNS servers queried are used to defend against cache attacks. Although the probability of the cache being attacked can be reduced to a certain extent, there is still a risk of being breached. Summary of the Invention

[0004] Based on this, it is necessary to provide a method, apparatus, computer device, computer-readable storage medium, and computer program product for protecting against DNS cache attacks that can improve the protection ability of the local DNS server against cache attacks for the above technical problems.

[0005] In a first aspect, this application provides a method for protecting against DNS cache attacks, including:

[0006] Receiving a domain name resolution request sent by a client;

[0007] In the case where the resolution result corresponding to the domain name resolution request does not exist in the local cache, sending a first request packet formed based on the UDP protocol and a second request packet formed based on the TCP protocol to the DNS server;

[0008] Receiving a first response packet corresponding to the first request packet and a second response packet corresponding to the second request packet sent by the DNS server;

[0009] Parse the first response packet to obtain a first parsing result, and parse the second response packet to obtain a second parsing result;

[0010] When the first parsing result indicates a successful match with the first request packet and the second parsing result indicates a successful match with the second request packet, match the first parsing result with the second parsing result;

[0011] When the first parsing result matches the second parsing result, based on the first parsing result and the second parsing result, extract the target parsing result corresponding to the domain name resolution request;

[0012] Store the target parsing result in the local cache and send it to the client.

[0013] In one embodiment, the process of matching the parsing result with the request packet includes:

[0014] Match the relevant parameters in the parsing result with the relevant parameters in the request packet. When the two sets of relevant parameters are the same, the parsing result matches the request packet successfully; the relevant parameters include the sending IP address, port, query ID, domain name, and query type in the domain name resolution request.

[0015] In one embodiment, the matching of the first parsing result with the second parsing result includes:

[0016] Match the answer resource record in the first parsing result with the answer resource record in the second parsing result;

[0017] When the answer resource records match successfully, match the authority resource record in the first parsing result with the authority resource record in the second parsing result.

[0018] In one embodiment, the answer resource record includes the domain name, the valid duration of the target parsing result in the local cache, and the IP address corresponding to the domain name resolution request; the matching of the answer resource record in the first parsing result with the answer resource record in the second parsing result includes:

[0019] Match the domain name, valid duration, and IP address in the first parsing result and the second parsing result respectively. When the domain name, valid duration, and IP address are all the same, the answer resource records of the first parsing result and the second parsing result match successfully.

[0020] In one embodiment, the authorized resource record includes a domain name, the valid duration of the target resolution result in the local cache, an Internet protocol, a DNS server record, the name of the DNS server, the type corresponding to the DNS server record, and the IP address corresponding to the domain name resolution request; the matching of the authorized resource record in the first resolution result with the authorized resource record in the second resolution result includes:

[0021] Matching the domain name, valid duration, Internet protocol, DNS server record, name, type, and IP address in the first resolution result and the second resolution result respectively. When the domain name, valid duration, Internet protocol, DNS server record, name, type, and IP address are all the same, the authorized resource record in the first resolution result and the authorized resource record in the second resolution result are successfully matched.

[0022] In one embodiment, the method further includes:

[0023] When receiving the domain name resolution request sent by the client and there is a resolution result corresponding to the domain name resolution request in the local cache, directly sending the resolution result to the client.

[0024] In a second aspect, the present application further provides a protection device against DNS cache attacks, including:

[0025] A receiving module, configured to receive a domain name resolution request sent by a client;

[0026] A sending module, configured to send a first request packet formed based on the UDP protocol and a second request packet formed based on the TCP protocol to a DNS server when there is no resolution result corresponding to the domain name resolution request in the local cache;

[0027] The receiving module is further configured to receive a first response packet corresponding to the first request packet and a second response packet corresponding to the second request packet sent by the DNS server;

[0028] A parsing module, configured to parse the first response packet to obtain a first resolution result, and parse the second response packet to obtain a second resolution result;

[0029] A matching module, configured to match the first resolution result with the second resolution result when the first resolution result indicates successful matching with the first request packet and the second resolution result indicates successful matching with the second request packet;

[0030] An extraction module, configured to, when the first parsing result matches the second parsing result successfully, extract a target parsing result corresponding to the domain name resolution request based on the first parsing result and the second parsing result;

[0031] The sending module is further configured to store the target parsing result in a local cache and send it to a client.

[0032] In a third aspect, the present application further provides a computer device, including a memory and a processor, where the memory stores a computer program, and when the processor executes the computer program, the following steps are implemented:

[0033] Receive a domain name resolution request sent by a client;

[0034] When there is no parsing result corresponding to the domain name resolution request in the local cache, send a first request packet formed based on the UDP protocol and a second request packet formed based on the TCP protocol to a DNS server;

[0035] Receive a first response packet corresponding to the first request packet and a second response packet corresponding to the second request packet sent by the DNS server;

[0036] Parse the first response packet to obtain a first parsing result, and parse the second response packet to obtain a second parsing result;

[0037] When the first parsing result indicates successful matching with the first request packet and the second parsing result indicates successful matching with the second request packet, match the first parsing result with the second parsing result;

[0038] When the first parsing result matches the second parsing result successfully, extract a target parsing result corresponding to the domain name resolution request based on the first parsing result and the second parsing result;

[0039] Store the target parsing result in the local cache and send it to the client.

[0040] In a fourth aspect, the present application further provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the following steps are implemented:

[0041] Receive a domain name resolution request sent by a client;

[0042] When there is no parsing result corresponding to the domain name resolution request in the local cache, send a first request packet formed based on the UDP protocol and a second request packet formed based on the TCP protocol to a DNS server;

[0043] Receive a first response packet corresponding to the first request packet and a second response packet corresponding to the second request packet sent by the DNS server;

[0044] Parse the first response packet to obtain a first parsing result, and parse the second response packet to obtain a second parsing result;

[0045] In the case where the first parsing result indicates a successful match with the first request packet and the second parsing result indicates a successful match with the second request packet, match the first parsing result with the second parsing result;

[0046] In the case where the first parsing result matches the second parsing result, based on the first parsing result and the second parsing result, extract a target parsing result corresponding to the domain name resolution request;

[0047] Store the target parsing result in the local cache and send it to the client.

[0048] In a fifth aspect, the present application further provides a computer program product, including a computer program, which when executed by a processor implements the following steps:

[0049] Receive a domain name resolution request sent by a client;

[0050] In the case where there is no parsing result corresponding to the domain name resolution request in the local cache, send a first request packet formed based on the UDP protocol and a second request packet formed based on the TCP protocol to the DNS server;

[0051] Receive a first response packet corresponding to the first request packet and a second response packet corresponding to the second request packet sent by the DNS server;

[0052] Parse the first response packet to obtain a first parsing result, and parse the second response packet to obtain a second parsing result;

[0053] In the case where the first parsing result indicates a successful match with the first request packet and the second parsing result indicates a successful match with the second request packet, match the first parsing result with the second parsing result;

[0054] In the case where the first parsing result matches the second parsing result, based on the first parsing result and the second parsing result, extract a target parsing result corresponding to the domain name resolution request;

[0055] Store the target parsing result in the local cache and send it to the client.

[0056] The above DNS cache attack prevention method, device, computer device, computer-readable storage medium and computer program product. First, receive a domain name resolution request sent by a client; in the case where the resolution result corresponding to the domain name resolution request does not exist in the local cache, send a first request packet formed based on the UDP protocol and a second request packet formed based on the TCP protocol to the DNS server; receive a first response packet corresponding to the first request packet and a second response packet corresponding to the second request packet sent by the DNS server; parse the first response packet to obtain a first parsing result, and parse the second response packet to obtain a second parsing result; in the case where the first parsing result indicates a successful match with the first request packet and the second parsing result indicates a successful match with the second request packet, match the first parsing result with the second parsing result; in the case where the first parsing result and the second parsing result match successfully, extract the target parsing result corresponding to the domain name resolution request based on the first parsing result and the second parsing result; store the target parsing result in the local cache and send it to the client.

[0057] In this way, the local DNS server sends request packets formed based on the UDP protocol and the TCP protocol to the DNS server. After receiving the response packets returned by the DNS server, they are respectively matched with the corresponding request packets, and then matched with each other after successful matching, so as to determine that the response packets are returned by the DNS server, improving the security during the domain name query process. BRIEF DESCRIPTION OF THE DRAWINGS

[0058] To more clearly illustrate the technical solutions in the embodiments of the present application or related technologies, the following will briefly introduce the drawings required for use in the description of the embodiments of the present application or related technologies. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other related drawings can also be obtained based on these drawings.

[0059] Figure 1 It is an application environment diagram of the DNS cache attack prevention method in an embodiment;

[0060] Figure 2 It is a flowchart of the DNS cache attack prevention method in an embodiment;

[0061] Figure 3 It is a flowchart of the DNS cache attack prevention method in another embodiment;

[0062] Figure 4 It is a structural block diagram of the DNS cache attack prevention device in an embodiment;

[0063] Figure 5 It is an internal structure diagram of a computer device in an embodiment. Detailed implementation manners

[0064] In order to make the objectives, technical solutions and advantages of the present application more clear and understandable, the present application will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.

[0065] The DNS cache attack protection method provided by the embodiments of the present application can be applied to an application environment as Figure 1 shown. The client sends a domain name resolution request to the local DNS server. The local DNS server looks up the corresponding resolution result in the local cache. If it does not exist, it sends the request packets formed based on the UDP protocol and the TCP protocol to the DNS server and receives the corresponding resolution result. Among them, the local DNS server 102 communicates with the DNS server 104 through the network. The data storage system can store the data that the DNS server 104 needs to process. The data storage system can be integrated on the server 104, or can be placed in the cloud or other network servers. Among them, the client can be, but is not limited to, various personal computers, laptop computers, smart phones, tablet computers, Internet of Things devices and portable wearable devices. The Internet of Things devices can be smart speakers, smart TVs, smart air conditioners, smart in-vehicle devices, projection devices, etc. The portable wearable devices can be smart watches, smart bracelets, head-mounted devices, etc. The head-mounted device can be a virtual reality (VR) device, an augmented reality (AR) device, smart glasses, etc. The local DNS server 102 and the DNS server 104 can be independent physical servers, or can be a server cluster or a distributed system composed of multiple physical servers, or can also be cloud servers providing cloud computing services.

[0066] In an exemplary embodiment, as Figure 2 shown, a DNS cache attack protection method is provided. Taking the method applied to the local DNS server 102 in Figure 1 as an example, the following steps 202 to step 214 are included. Among them:

[0067] Step 202: Receive a domain name resolution request sent by the client.

[0068] Optionally, receive a domain name resolution request sent by the client.

[0069] Step 204: When there is no resolution result corresponding to the domain name resolution request in the local cache, send a first request packet formed based on the UDP protocol and a second request packet formed based on the TCP protocol to the DNS server.

[0070] Among them, the DNS server is an authoritative server, which refers to a server authorized by the upper level to resolve domain names; the UDP protocol is the User Datagram Protocol, which is a connectionless and simple transport layer protocol used to transmit data in a network; the TCP protocol is the Transmission Control Protocol, which is a connection-oriented, reliable, and byte-stream-based transport layer communication protocol.

[0071] Exemplarily, after receiving a domain name resolution request, the local DNS server checks whether there is a resolution result corresponding to the domain name resolution request in the local cache. When there is no resolution result corresponding to the domain name resolution request in the local cache, a first request packet is formed according to the UDP protocol, and a second request packet is formed according to the TCP protocol, and the first request packet and the second request packet are sent to the DNS server.

[0072] Step 206: Receive a first response packet corresponding to the first request packet and a second response packet corresponding to the second request packet sent by the DNS server.

[0073] Optionally, after the DNS server generates a corresponding response packet according to the request packet, the local DNS server receives the first response packet and the second response packet sent by the DNS.

[0074] Step 208: Parse the first response packet to obtain a first parsing result, and parse the second response packet to obtain a second parsing result.

[0075] Optionally, after receiving the first response packet and the second response packet, parse the first response packet to obtain a first parsing result, and parse the second response packet to obtain a second parsing result.

[0076] Step 210: In the case where the first parsing result indicates successful matching with the first request packet and the second parsing result indicates successful matching with the second request packet, match the first parsing result with the second parsing result.

[0077] Exemplarily, match the first parsing result with the first request packet, match the second parsing result with the second request packet, and in the case where the first parsing result indicates successful matching with the first request packet and the second parsing result indicates successful matching with the second request packet, match the first parsing result with the second parsing result.

[0078] Step 212: In the case where the first parsing result matches the second parsing result successfully, based on the first parsing result and the second parsing result, extract the target parsing result corresponding to the domain name resolution request.

[0079] Among them, the target parsing result includes the IP address corresponding to the domain name in the domain name resolution request and the authorization information of the DNS server.

[0080] When the first parsing result matches the second parsing result successfully, based on the first parsing result and the second parsing result, extract the IP address corresponding to the domain name in the domain name resolution request and the authorization information of the DNS server.

[0081] Step 214, store the target parsing result in the local cache and send it to the client.

[0082] Exemplarily, store the IP address corresponding to the domain name in the domain name resolution request and the authorization information of the DNS server in the local cache and send it to the client.

[0083] In the above DNS cache attack prevention method, receive the domain name resolution request sent by the client; when the parsing result corresponding to the domain name resolution request does not exist in the local cache, send the first request packet formed based on the UDP protocol and the second request packet formed based on the TCP protocol to the DNS server; receive the first response packet corresponding to the first request packet and the second response packet corresponding to the second request packet sent by the DNS server; parse the first response packet to obtain the first parsing result, parse the second response packet to obtain the second parsing result; when the first parsing result indicates a successful match with the first request packet and the second parsing result indicates a successful match with the second request packet, match the first parsing result with the second parsing result; when the first parsing result matches the second parsing result successfully, based on the first parsing result and the second parsing result, extract the target parsing result corresponding to the domain name resolution request; store the target parsing result in the local cache and send it to the client.

[0084] In this way, the local DNS server sends request packets formed based on the UDP protocol and the TCP protocol to the DNS server. After receiving the response packets returned by the DNS server, they are respectively matched with the corresponding request packets, and then matched with each other after successful matching, so as to determine that the response packets are returned by the DNS server, improving the security during the domain name query process.

[0085] In an exemplary embodiment, the matching process between the parsing result and the request packet includes: matching the relevant parameters in the parsing result with the relevant parameters in the request packet, and when both relevant parameters are the same, the parsing result matches the request packet successfully;

[0086] Among them, the relevant parameters include the sending IP address, port, query ID, domain name, and query type in the domain name resolution request.

[0087] In actual implementation, extract the sending IP address, port, query ID, domain name, and query type in the domain name resolution request in the parsing result and the request packet, and when both relevant parameters are the same, the parsing result matches the request packet successfully.

[0088] Among them, the sending IP address in the domain name resolution request is the network address of the client. For example, the IP address of the client can be xxx.xxx.x.xxx; the port is the logical address in network communication; the query ID is a unique identifier used to identify a specific DNS query request; the domain name is the name of the website or resource for which resolution is requested; the query type is the DNS record type of the domain name resolution request.

[0089] In one embodiment, the sending IP address, port, query ID, domain name, and query type in the first parsing result and the first request packet are extracted. When the relevant parameters of both are the same, the first parsing result matches the first request packet successfully.

[0090] In another embodiment, if there are differences in the sending IP address, port, query ID, domain name, and query type in the domain name resolution request in the parsing result and the request packet, the response packet corresponding to the above parsing result is discarded.

[0091] In the above embodiments, by comparing the parsing result with the relevant parameters in the corresponding request packet, the security of the whole process is higher.

[0092] In an exemplary embodiment, matching the first parsing result with the second parsing result includes: matching the answer resource records in the first parsing result with the answer resource records in the second parsing result; when the answer resource records match successfully, matching the authority resource records in the first parsing result with the authority resource records in the second parsing result.

[0093] In actual implementation, matching the first parsing result with the second parsing result includes: matching the answer resource records in the first parsing result with the answer resource records in the second parsing result; when the answer resource records match successfully, matching the authority resource records in the first parsing result with the authority resource records in the second parsing result.

[0094] In one embodiment, if there are differences in the answer resource records and authority resource records between the first parsing result and the second parsing result, this parsing result is not trusted.

[0095] In the above embodiments, by comparing the parsing results of two different protocols for consistency, it is ensured that the parsing results finally stored in the local cache are correct.

[0096] In an exemplary embodiment, matching the response resource records in the first parsing result with the response resource records in the second parsing result includes: respectively matching the domain names, valid durations, and IP addresses in the first parsing result and the second parsing result. When the domain names, valid durations, and IP addresses are all the same, the response resource records in the first parsing result and the response resource records in the second parsing result are successfully matched.

[0097] Among them, the response resource record includes the domain name, the valid duration of the target parsing result in the local cache, and the IP address corresponding to the domain name resolution request.

[0098] In actual implementation, respectively matching the domain names, valid durations, and IP addresses in the first parsing result and the second parsing result. When the domain names, valid durations, and IP addresses are all the same, the response resource records in the first parsing result and the response resource records in the second parsing result are successfully matched.

[0099] For example, the response resource record can be www.a.com 60 22.22.22.22, where www.a.com is the domain name, 60 is the valid duration, and 22.22.22.22 is the IP address corresponding to the domain name resolution request.

[0100] In the above embodiment, by comparing the response resource records in different parsing results, data consistency is ensured and the reliability of the parsing results is improved.

[0101] In an exemplary embodiment, matching the authorization resource records in the first parsing result with the authorization resource records in the second parsing result includes: respectively matching the domain names, valid durations, Internet protocols, DNS server records, names, types, and IP addresses in the first parsing result and the second parsing result. When the domain names, valid durations, Internet protocols, DNS server records, names, types, and IP addresses are all the same, the authorization resource records in the first parsing result and the authorization resource records in the second parsing result are successfully matched.

[0102] Among them, the authorization resource record includes the domain name, the valid duration of the target parsing result in the local cache, the Internet protocol, the DNS server record, the name of the DNS server, the type corresponding to the DNS server record, and the IP address corresponding to the domain name resolution request;

[0103] In actual implementation, the domain names, valid durations, Internet protocols, DNS server records, names, types, and IP addresses in the first parsing result and the second parsing result are respectively matched. When the domain names, valid durations, Internet protocols, DNS server records, names, types, and IP addresses are all the same, the authorized resource records of the first parsing result and the authorized resource records of the second parsing result are successfully matched.

[0104] For example, the authorized resource record is a.com 172800 IN NS nsl.b.com nsl.b.com A 1.1.1.1, where a.com is the domain name, 172800 is the valid duration, IN is the Internet protocol, NS is the DNS server record, nsl.b.com is the name of the DNS server, A is the type corresponding to the DNS server record, and 1.1.1.1 is the IP address corresponding to the domain name resolution request.

[0105] In the above embodiment, by comparing the authorized resource records in different parsing results, the accuracy and reliability of the domain name parsing result are significantly improved, and the security and stability in the whole process are enhanced.

[0106] In an exemplary embodiment, the method further includes: when receiving a domain name resolution request sent by a client and there is a parsing result corresponding to the domain name resolution request in the local cache, directly sending the parsing result to the client.

[0107] In actual implementation, when receiving a domain name resolution request sent by a client and there is a parsing result corresponding to the domain name resolution request in the local cache, directly sending the parsing result to the client.

[0108] In the above embodiment, when there is a corresponding parsing result in the local cache, directly sending the parsing result to the client speeds up the efficiency of domain name resolution.

[0109] To illustrate in detail the method for protecting against DNS cache attacks in this application, an embodiment is described below, and the specific flowchart is as Figure 3 shown. Exemplarily, this application illustrates the method for protecting against DNS cache attacks in a specific domain name resolution scenario.

[0110] First, receive a domain name resolution request sent by a client.

[0111] After receiving a domain name resolution request, the local DNS server checks whether there is a corresponding resolution result in the local cache. If there is, it directly sends the corresponding resolution result to the client. When there is no resolution result corresponding to the domain name resolution request in the local cache, it forms a first request packet according to the UDP protocol and a second request packet according to the TCP protocol, and sends the first request packet and the second request packet to the DNS server.

[0112] Receive the first response packet corresponding to the first request packet and the second response packet corresponding to the second request packet sent by the DNS server. Parse the first response packet to obtain the first resolution result, and parse the second response packet to obtain the second resolution result.

[0113] Match the first resolution result with the first request packet, and match the second resolution result with the second request packet. When the first resolution result indicates successful matching with the first request packet and the second resolution result indicates successful matching with the second request packet, match the answer resource record in the first resolution result with the answer resource record in the second resolution result; when the answer resource records match successfully, match the authoritative resource record in the first resolution result with the authoritative resource record in the second resolution result.

[0114] When the first resolution result and the second resolution result match successfully, based on the first resolution result and the second resolution result, extract the IP address corresponding to the domain name in the domain name resolution request and the authorization information of the DNS server. Store the IP address corresponding to the domain name in the domain name resolution request and the authorization information of the DNS server in the local cache, and send them to the client.

[0115] The implementation mechanism of this application is simple. The DNS request and response of the UDP protocol and the TCP protocol are part of the standard protocol, and the DNS server does not need to be cooperatively transformed.

[0116] This application has high performance. The local DNS server sends requests of the UDP protocol and the TCP protocol to the DNS server at the same time, without special processing of the request packets.

[0117] The resolution result of this application is stable. The DNS request and response of the TCP protocol communicate through a reliable TCP connection established between the local DNS server and the DNS server. At the same time, the local DNS server performs consistency verification on the DNS response packets of the two different protocols, effectively guaranteeing the stability of the adopted results and avoiding cache tampering.

[0118] It should be understood that although the steps in the flowcharts involved in the above-described embodiments are shown in sequence according to the indications of the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless there is a clear description in this article, there is no strict order limit for the execution of these steps, and these steps can be executed in other orders. Moreover, at least a part of the steps in the flowcharts involved in the above-described embodiments may include multiple steps or multiple stages. These steps or stages are not necessarily executed at the same moment, but can be executed at different moments, and the execution order of these steps or stages is not necessarily sequential, but can be executed alternately or in turn with at least a part of other steps or steps or stages in other steps.

[0119] Based on the same inventive concept, an embodiment of the present application further provides a DNS cache attack protection device for implementing the protection method for the DNS cache attack involved above. The solution provided by this device to solve the problem is similar to the solution described in the above method. Therefore, the specific limitations in one or more embodiments of the DNS cache attack protection device provided below can refer to the limitations on the DNS cache attack protection method in the above text, and will not be repeated here.

[0120] In an exemplary embodiment, as Figure 4 shown, a DNS cache attack protection device is provided, including: a receiving module 401, a sending module 402, a parsing module 403, a matching module 404, and an extraction module 405, where:

[0121] The receiving module is used to receive a domain name resolution request sent by a client.

[0122] The sending module is used to send a first request packet formed based on the UDP protocol and a second request packet formed based on the TCP protocol to the DNS server when the parsing result corresponding to the domain name resolution request does not exist in the local cache.

[0123] The receiving module is further used to receive a first response packet corresponding to the first request packet and a second response packet corresponding to the second request packet sent by the DNS server.

[0124] The parsing module is used to parse the first response packet to obtain a first parsing result, and parse the second response packet to obtain a second parsing result.

[0125] The matching module is used to match the first parsing result with the second parsing result when the first parsing result indicates successful matching with the first request packet and the second parsing result indicates successful matching with the second request packet.

[0126] An extraction module, configured to, when the first parsing result and the second parsing result match successfully, extract a target parsing result corresponding to the domain name parsing request based on the first parsing result and the second parsing result.

[0127] The sending module is further configured to store the target parsing result in a local cache and send it to the client.

[0128] In some embodiments, the above-mentioned matching module is further configured to match relevant parameters in the parsing result with relevant parameters in the request packet, and when the relevant parameters of both are the same, the parsing result and the request packet match successfully; the relevant parameters include the sending IP address, port, query ID, domain name, and query type in the domain name parsing request.

[0129] In some embodiments, the above-mentioned matching module is further configured to match the response resource record in the first parsing result with the response resource record in the second parsing result;

[0130] When the response resource records match successfully, match the authoritative resource record in the first parsing result with the authoritative resource record in the second parsing result.

[0131] In some embodiments, the above-mentioned matching module is further configured to respectively match the domain name, valid duration, and IP address in the first parsing result and the second parsing result, and when the domain name, valid duration, and IP address are all the same, the response resource records of the first parsing result and the second parsing result match successfully.

[0132] In some embodiments, the above-mentioned matching module is further configured to respectively match the domain name, valid duration, Internet protocol, DNS server record, name, type, and IP address in the first parsing result and the second parsing result, and when the domain name, valid duration, Internet protocol, DNS server record, name, type, and IP address are all the same, the authoritative resource records of the first parsing result and the second parsing result match successfully.

[0133] In some embodiments, the above-mentioned sending module is further configured to, when receiving a domain name parsing request sent by the client and there is a parsing result corresponding to the domain name parsing request in the local cache, directly send the parsing result to the client.

[0134] Each module in the above-mentioned DNS cache attack protection device can be implemented in whole or in part by software, hardware, and their combination. The above-mentioned modules can be embedded in the processor in the computer device in hardware form or independent of the processor, or stored in the memory in the computer device in software form, so that the processor can call and execute the operations corresponding to the above-mentioned modules.

[0135] In an exemplary embodiment, a computer device is provided. The computer device may be a server, and its internal structure diagram may be as shown in Figure 5 . The computer device includes a processor, a memory, an input / output interface (Input / Output, abbreviated as I / O), a communication interface, a display unit, and an input device. Among them, the processor, the memory, and the input / output interface are connected through a system bus, and the communication interface, the display unit, and the input device are connected to the system bus through the input / output interface. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used to store relevant data of domain names. The input / output interface of the computer device is used to exchange information between the processor and external devices. The communication interface of the computer device is used to communicate with external terminals through a network connection. When the computer program is executed by the processor, it implements a method for protecting against DNS cache attacks.

[0136] The display unit of the computer device is used to form a visually visible picture, and may be a display screen, a projection device, or a virtual reality imaging device. The display screen may be a liquid crystal display screen or an electronic ink display screen. The input device of the computer device may be a touch layer covered on the display screen, or a button, a trackball, or a touchpad provided on the housing of the computer device, or an external keyboard, touchpad, or mouse, etc.

[0137] Those skilled in the art can understand that Figure 5 the structure shown in

[0138] is only a block diagram of some structures related to the solution of this application, and does not constitute a limitation on the computer device to which the solution of this application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine some components, or have different component arrangements.

[0139] Receive a domain name resolution request sent by a client;

[0140] In the case where the resolution result corresponding to the domain name resolution request does not exist in the local cache, send a first request packet formed based on the UDP protocol and a second request packet formed based on the TCP protocol to the DNS server;

[0141] Receive a first response packet corresponding to the first request packet and a second response packet corresponding to the second request packet sent by the DNS server;

[0142] Parse the first response packet to obtain a first parsing result, and parse the second response packet to obtain a second parsing result;

[0143] When the first parsing result indicates successful matching with the first request packet and the second parsing result indicates successful matching with the second request packet, match the first parsing result with the second parsing result;

[0144] When the first parsing result matches the second parsing result, based on the first parsing result and the second parsing result, extract the target parsing result corresponding to the domain name resolution request;

[0145] Store the target parsing result in the local cache and send it to the client.

[0146] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the following steps are implemented:

[0147] Receive a domain name resolution request sent by a client;

[0148] When there is no parsing result corresponding to the domain name resolution request in the local cache, send a first request packet formed based on the UDP protocol and a second request packet formed based on the TCP protocol to the DNS server;

[0149] Receive a first response packet corresponding to the first request packet and a second response packet corresponding to the second request packet sent by the DNS server;

[0150] Parse the first response packet to obtain a first parsing result, and parse the second response packet to obtain a second parsing result;

[0151] When the first parsing result indicates successful matching with the first request packet and the second parsing result indicates successful matching with the second request packet, match the first parsing result with the second parsing result;

[0152] When the first parsing result matches the second parsing result, based on the first parsing result and the second parsing result, extract the target parsing result corresponding to the domain name resolution request;

[0153] Store the target parsing result in the local cache and send it to the client.

[0154] In one embodiment, a computer program product is provided, including a computer program which, when executed by a processor, implements the following steps:

[0155] Receive a domain name resolution request sent by a client;

[0156] In the case where the resolution result corresponding to the domain name resolution request does not exist in the local cache, send a first request packet formed based on the UDP protocol and a second request packet formed based on the TCP protocol to a DNS server;

[0157] Receive a first response packet corresponding to the first request packet and a second response packet corresponding to the second request packet sent by the DNS server;

[0158] Parse the first response packet to obtain a first resolution result, and parse the second response packet to obtain a second resolution result;

[0159] In the case where the first resolution result indicates successful matching with the first request packet and the second resolution result indicates successful matching with the second request packet, match the first resolution result with the second resolution result;

[0160] In the case where the first resolution result matches the second resolution result, extract the target resolution result corresponding to the domain name resolution request based on the first resolution result and the second resolution result;

[0161] Store the target resolution result in the local cache and send it to the client.

[0162] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use, and processing of relevant data need to comply with relevant regulations.

[0163] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, database, or other medium used in the embodiments provided in the present application can include at least one of non-volatile memory and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetoresistive random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc. The databases involved in the embodiments provided in the present application can include at least one of relational databases and non-relational databases. Non-relational databases can include distributed databases based on blockchain, etc., without limitation. The processors involved in the embodiments provided in the present application can be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, data processing logics based on quantum computing, artificial intelligence (AI) processors, etc., without limitation.

[0164] The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope recorded in the present application.

[0165] The above-described embodiments merely represent several implementation manners of the present application. The description thereof is relatively specific and detailed, but it should not be construed as a limitation to the patent scope of the present application. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several modifications and improvements can still be made, and these all fall within the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the appended claims.

Claims

1. A method for protecting against DNS cache attacks, characterized in that: The method comprises: Receive the domain name resolution request sent by the client; If there is no resolution result corresponding to the domain name resolution request in the local cache, sending a first request packet formed based on the UDP protocol and a second request packet formed based on the TCP protocol to the DNS server; Receive a first response packet corresponding to the first request packet and a second response packet corresponding to the second request packet sent by the DNS server; Parsing the first response packet to obtain a first parsing result, parsing the second response packet to obtain a second parsing result; When the first parsing result representation successfully matches the first request packet, and the second parsing result representation successfully matches the second request packet, matching the first parsing result with the second parsing result; If the first resolution result successfully matches the second resolution result, extracting a target resolution result corresponding to the domain name resolution request based on the first resolution result and the second resolution result; The target parsing result is stored in the local cache and sent to the client.

2. The method according to claim 1, characterized in that The matching process between the parsing result and the request packet includes: The relevant parameters in the resolution result are matched with the relevant parameters in the request packet. If the relevant parameters of the two are the same, the resolution result and the request packet are successfully matched; the relevant parameters include the sending IP address, port, query ID, domain name and query type in the domain name resolution request.

3. The method according to claim 1, characterized in that The matching the first parsing result with the second parsing result includes: Matching the answer resource record in the first parsing result with the answer resource record in the second parsing result; In the case where the response resource record is matched successfully, the authorization resource record in the first resolution result is matched with the authorization resource record in the second resolution result.

4. The method according to claim 3, characterized in that The response resource record includes the domain name, the validity period of the target resolution result in the local cache, and the IP address corresponding to the domain name resolution request; The matching of the answer resource record in the first parsing result with the answer resource record in the second parsing result includes: The domain name, validity period and IP address in the first resolution result are matched respectively with those in the second resolution result. When the domain name, the validity period and the IP address are the same, the response resource record of the first resolution result and the response resource record of the second resolution result are matched successfully.

5. The method according to claim 3, characterized in that: The authorized resource record includes the domain name, the validity period of the target resolution result in the local cache, the Internet protocol, the DNS server record, the name of the DNS server, the type corresponding to the DNS server record and the IP address corresponding to the domain name resolution request; The matching of the authorization resource record in the first parsing result with the authorization resource record in the second parsing result includes: The first resolution result is matched with the domain name, validity period, Internet protocol, DNS server record, name, type and IP address in the second resolution result respectively. When the domain name, the validity period, the Internet protocol, the DNS server record, the name, the type and the IP address are the same, the authorized resource record of the first resolution result and the authorized resource record of the second resolution result are matched successfully.

6. The method according to claim 1, characterized in that The method further comprises: When a domain name resolution request sent by the client is received and a resolution result corresponding to the domain name resolution request exists in a local cache, the resolution result is directly sent to the client.

7. A protection device for DNS cache attacks, characterized in that: The device comprises: A receiving module, used for receiving a domain name resolution request sent by a client; A sending module, used for sending a first request packet formed based on the UDP protocol and a second request packet formed based on the TCP protocol to the DNS server when there is no resolution result corresponding to the domain name resolution request in the local cache; The receiving module is further configured to receive a first response packet corresponding to the first request packet and a second response packet corresponding to the second request packet sent by the DNS server; A parsing module, configured to parse the first response packet to obtain a first parsing result, and parse the second response packet to obtain a second parsing result; A matching module, configured to match the first parsing result with the second parsing result when the first parsing result representation matches the first request packet successfully and the second parsing result representation matches the second request packet successfully; an extraction module, configured to extract a target resolution result corresponding to the domain name resolution request based on the first resolution result and the second resolution result when the first resolution result matches the second resolution result successfully; The sending module is further used to store the target parsing result in a local cache and send it to the client.

8. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 6 are implemented.

9. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 6 are implemented.

10. A computer program product, comprising a computer program, characterized in that When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 6 are implemented.