DNS recursive service verification method based on controllable authoritative server
By building a controllable and authoritative server and using active detection, the accuracy, stability and reliability of the DNS recursive server are verified, and the problems of low efficiency and waste of resources in the existing technology are solved, and efficient and accurate DNS recursive service verification is achieved.
Patent Information
- Application Number
- CN202311872981.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-12-29
- Publication Date
- 2025-07-01
AI Technical Summary
The prior art is difficult to effectively verify the accuracy, stability and reliability of DNS recursive servers. Especially in large-scale network service scanning and information acquisition scenarios, the concurrency performance, result reliability and stability of a single recursive DNS service are insufficient, resulting in waste of resources and low recognition efficiency.
The DNS recursive service verification method based on a controllable authoritative server is adopted. By building a controllable authoritative server, the DNS recursive server is verified by active detection, and the accurate identification and verification of DNS recursive services is achieved.
This method effectively solves the verification problem of DNS recursive servers, reduces resource consumption rate, improves identification efficiency and accuracy, and provides reliable support for security evaluation and maintenance of DNS recursive servers.
Smart Images

Figure CN120238516A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a DNS recursive service verification method based on a controllable authoritative server, which realizes the verification and identification of DNS recursive services and provides effective and reliable support for the security evaluation and maintenance of DNS recursive servers.
[0002] When accessing websites and services during daily Internet access, the client needs to first resolve the domain name of the access target into an IP address through the recursive DNS service, and then establish a network connection. If the IP address given by the DNS recursive server is incorrect, that is, not the IP address corresponding to the domain name accessed by the client, it will cause the user to be unable to access the target normally. In a worse case, the information accessed by the user will be hijacked, resulting in serious security problems. Therefore, the correctness, stability, and reliability of domain name resolution are one of the necessary conditions for our normal Internet access.
[0003] In the scenario of large-scale network service scanning and information acquisition, due to the wide distribution of clients, the concurrent performance, result reliability, and stability of a single recursive DNS service cannot meet this application scenario, and a large number of recursive DNS services need to be configured to solve the above problems. Therefore, in the actual scenario, it is necessary to collect a large number of public recursive DNS services to provide DNS resolution services for the clients in this scenario. Before providing DNS services, it is necessary to evaluate the correctness, stability, and reliability of the resolution results of these recursive DNS services to determine that these recursive DNS services can provide normal services, thereby improving the efficiency of network service scanning and information acquisition. Background Art
[0004] The Domain Name System (DNS), as an important part of the Internet architecture, provides a resolution service between domain names and IP addresses, enabling users to access the Internet more conveniently and quickly. DNS servers can be roughly classified into root servers, authoritative servers, and recursive servers according to the service type. The root server is the highest-level DNS server, responsible for returning the authoritative server address of the top-level domain name; the authoritative server is responsible for domain name queries and responses within a certain area; the recursive server is responsible for submitting query requests to the authoritative server on behalf of the user, parsing the response information of the authoritative server, and returning it to the user. Compared with root servers and authoritative servers, recursive servers are the most vulnerable to being the target and tool of network attacks because they directly serve all users. In order to effectively evaluate and maintain the security and stability of recursive servers, it is first necessary to accurately verify and identify DNS recursive servers. Therefore, the core of the present invention is to solve the verification problem of DNS recursive servers.
[0005] Currently, for the verification and identification of DNS recursive servers, the common methods are mainly divided into two types: active and passive. Among them, the active method utilizes the principle and characteristics of direct interaction between the authoritative server and the recursive server. By obtaining the IP address set of the nodes directly interacting with the authoritative server, the purpose of obtaining the IP address set of the recursive server is achieved, that is, the source IP address set in the DNS request received by the authoritative server is the address set of the recursive server. The disadvantage of this method is that since many recursive servers will perform security settings to block domain name queries of any host under the top-level or second-level domain names, the query requests may be filtered, resulting in a large amount of resources being consumed to detect IP addresses without response results. The passive method is to identify the recursive server by performing feature analysis on the obtained network traffic data. Although this method avoids the disadvantages of the active method, since the recursive server and the client use the same protocol and there is no obvious difference in the traffic characteristics between the two, it is very difficult to accurately identify the recursive server from the network traffic through protocol analysis. Summary of the Invention
[0006] In view of the above problems, the present invention proposes a DNS recursive service verification method based on a controllable authoritative server, which utilizes the communication characteristics of the DNS server and builds a controllable authoritative server to verify the DNS server in an active detection manner, so as to achieve accurate identification of the DNS recursive service.
[0007] The technical solution of the present invention is as follows:
[0008] A DNS recursive service verification method based on a controllable authoritative server, the steps of the method include:
[0009] In the first step, the client sends an access request to the recursive server, represented by the domain name "www.example.com" as an example. If the record information of "www.example.com" can be queried in the cache of the recursive server, the IP address corresponding to the queried domain name is returned to the client; otherwise, the recursive server executes the iterative query process. The order of iterative query is the root server, the top-level authoritative server, and the target authoritative server in sequence. Among them, the target authoritative server is the authoritative server that finally returns the result corresponding to the domain name request. The iterative query process is specifically as follows: The recursive server sends a request to the root server, and the root server returns the address of the top-level authoritative server of ".com" to the recursive server; then the recursive server sends a request to the top-level authoritative server of ".com", and the top-level authoritative server returns the address of the authoritative server of "example.com" to the recursive server; then the recursive server sends a request to the authoritative server of "example.com", and the authoritative server of "example.com" returns the resolved IP address result to the recursive server; finally, the recursive server returns this resolved result to the client;
[0010] In the second step, for the verification process of the DNS recursive server, when the client sends an access request to the detected DNS server, the result finally returned to the client is used as the judgment basis to implement the verification of the DNS recursive service.
[0011] The specific verification process is divided into two parts: "standard correct verification" and "standard error verification". Among them, "standard correct verification" is to actively detect the domain name of a real and known IP address, that is, use the detected DNS server to send an access request for a domain name whose IP address is known, and make a verification judgment according to the returned result;
[0012] "Standard error verification" is to set up a controllable authoritative server, set a non-existent domain name, and then use the detected DNS server to send an access request for this non-existent domain name, and make a verification judgment according to the returned result. By means of active detection, "standard correct verification" and "standard error verification" are carried out on the detected server, so as to realize the accurate verification and identification of the DNS recursive service, and provide a reliable support basis for the security evaluation and maintenance work of the DNS recursive server.
[0013] Beneficial effects
[0014] In the process of recursively verifying the DNS server, the present invention utilizes the communication characteristics of the DNS server, and by means of setting up a controllable authoritative server, actively detects the detected server, and makes a recursive verification judgment according to the returned response result. The method effectively solves the verification problem of the DNS recursive server.
[0015] The present invention uses a controllable authoritative server to build and realizes effective and accurate verification of DNS recursive service through active detection. The method has the characteristics of low resource consumption rate, high efficiency and high accuracy, and has strong practicality in the fields of security assessment and maintenance of DNS recursive servers.
[0016] Compared with the existing methods, the method proposed in the present invention reduces the resource consumption rate and improves the efficiency and accuracy of identification while realizing DNS recursive service verification, and the method is highly practical. The present invention proposes a DNS recursive service verification method based on a controllable authoritative server, which utilizes the resolution principle of the DNS server, deploys a controllable authoritative server in the network, initiates a query request to the detected DNS server on the client in an active detection manner, and verifies whether the detected DNS server is recursive by judging the returned result. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] Figure 1 This is the domain name resolution principle diagram of the DNS server;
[0018] Figure 2 Schematic diagram for verifying the DNS recursive service based on controllable authoritative servers;
[0019] Figure 3 This is a flowchart of recursive verification of DNS servers. DETAILED DESCRIPTION
[0020] The present invention will be further described below in conjunction with the accompanying drawings and embodiments.
[0021] Example
[0022] A DNS recursive service verification method based on a controllable authoritative server, the method comprising the following steps:
[0023] Specifically, the client first initiates an access request to the recursive server, such as Figure 1 As shown, Figure 1The domain name "www.example.com" is used as an example. If the record information of "www.example.com" can be found in the cache of the recursive server, the IP address corresponding to the queried domain name will be returned to the client; otherwise, the recursive server performs an iterative query process, and the order of iterative query is root server → top-level authoritative server → target authoritative server, where the target authoritative server is the authoritative server that finally returns the result corresponding to the domain name request. The iterative query process is as follows: the recursive server sends a request to the root server, and the root server returns the top-level authoritative server address of ".com" to the recursive server; then the recursive server sends a request to the top-level authoritative server of ".com", and the top-level authoritative server returns the authoritative server address of "example.com" to the recursive server; then the recursive server sends a request to the authoritative server of "example.com", and the authoritative server of "example.com" returns the resolved IP address result to the recursive server; finally, the recursive server returns the resolved result to the client.
[0024] DNS recursive server verification process: The present invention proposes a DNS recursive service verification method based on a controllable authoritative server. The method uses a self-built controllable authoritative server as Figure 1 The target authoritative server in the client initiates an access request to the detected DNS server (i.e., the server to be verified) in an active detection manner, and uses the result finally returned to the client as the judgment basis to realize the verification of the DNS recursive service, such as Figure 2 As shown:
[0025] The specific verification process of this method is divided into two parts: "standard correct verification" and "standard error verification". "Standard correct verification" is to initiate active detection of the domain name of a real and known IP address, that is, to use the detected DNS server to send a domain name access request with a known IP address, and perform verification and judgment based on the returned result; "Standard error verification" is to build a controllable authoritative server, set a non-existent domain name, and then use the detected DNS server to send an access request for the non-existent domain name, and perform verification and judgment based on the returned result. The specific implementation process is as follows: Figure 3 shown.
[0026] 1) Standard correct verification part
[0027] When performing standard correctness verification, the present invention takes into account the comprehensiveness of the verification method and selects domestic and foreign examples to implement recursive service verification of the detected server.
[0028] First, select the domestic server 114.114.114 as the verification instance. We already know the corresponding relationship between its stable domain name public1.114dns.com and the IP address. Then, on the client side, an access request with the domain name public1.114dns.com is sent to the server to be detected. When the received response result is 114.114.114.114, it is determined that the verification of this link is successful and the next verification step is entered; otherwise, it is determined that the recursive verification fails, that is, the server to be detected is not a DNS recursive server.
[0029] Then, select the foreign server 41.0.4 as the second verification instance. We also know the corresponding relationship between its stable domain name a.root-servers.net and the IP address. In the same way as the method in the above text, on the client side, an access request with the domain name a.root-servers.net is sent to the server to be detected. When the received response result is 198.41.0.4, it is determined that the verification of this link is successful and the next verification step is entered; otherwise, it is determined that the recursive verification fails, that is, the server to be detected is not a DNS recursive server.
[0030] 2) Standard error verification part
[0031] To make the verification method more reliable and accurate, the present invention proposes a standard error verification process for the server to be detected, which is realized by building a controllable authoritative server. Specifically, first build a controllable DNS authoritative server and set a self-built authoritative domain name address aaaa.com. Then, on the client side, an access request with the domain name www111.aaaa.com is sent to the server to be detected. Since there is no corresponding relationship between this domain name and the IP address configured on the controllable authoritative server side, the relevant fields in the response file received by the client have a standard answer format: if the ANCOUNT value in the DNS response file is 0, the QR, RA, NSCOUNT values are 1, and the RCODE is "NXDOMAIN", it is determined that the recursive verification of the server to be detected is successful; otherwise, it is determined that the recursive verification fails, that is, the server to be detected is not a DNS recursive server.
[0032] The present invention proposes a DNS recursive service verification method based on a controllable authoritative server, which actively detects the server to be detected through "standard correct verification" and "standard error verification", so as to accurately verify and identify the DNS recursive service, providing a reliable support basis for the security evaluation and maintenance work of DNS recursive servers.
[0033] In the process of recursively verifying the DNS server, the present invention utilizes the communication characteristics of the DNS server and actively probes the server to be detected by setting up a controllable authoritative server, and makes a recursive verification judgment based on the returned response result. The method effectively solves the verification problem of the DNS recursive server.
[0034] The present invention adopts the set-up controllable authoritative server and realizes the effective and accurate verification of the DNS recursive service through the way of active detection. The method has the characteristics of low resource consumption rate, high efficiency and high accuracy, and has strong practicability in the fields of security evaluation and maintenance of DNS recursive servers.
[0035] In summary, the above are only the preferred embodiments of the present invention and are not intended to limit the protection scope of the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.
Claims
1. A DNS recursive service verification method based on a controllable authoritative server, characterized in that The steps of this method include: In the first step, the client sends an access request to the recursive server, sending the domain name "www.example.com". If the record information of "www.example.com" can be queried in the cache of the recursive server, the IP address corresponding to the queried domain name is returned to the client; otherwise, the recursive server performs an iterative query process. The order of the iterative query is the root server, the top-level authoritative server, and the target authoritative server in sequence. Here, the target authoritative server is the authoritative server that finally returns the result corresponding to the domain name request. The iterative query process is specifically as follows: The recursive server sends a request to the root server, and the root server returns the address of the top-level authoritative server of ".com" to the recursive server; then the recursive server sends a request to the top-level authoritative server of ".com", and the top-level authoritative server returns the address of the authoritative server of "example.com" to the recursive server; after that, the recursive server sends a request to the authoritative server of "example.com", and the authoritative server of "example.com" returns the resolved IP address result to the recursive server; finally, the recursive server returns this resolved result to the client. In the second step, the client sends an access request to the DNS server to be detected, and uses the result finally returned to the client as the judgment basis to implement the verification of the DNS recursive service.
2. A DNS recursive service verification method based on a controllable authoritative server according to claim 1, characterized in that: The specific verification process is divided into two parts: "standard correct verification" and "standard error verification". Among them, "standard correct verification" is to actively detect the domain name of a real and known IP address, that is, use the DNS server to be detected to send a domain name access request with a known IP address, and make a verification judgment according to the returned result; "Standard error verification" is to set up a controllable authoritative server, set a non-existent domain name, then use the DNS server to be detected to send an access request for this non-existent domain name, and make a verification judgment according to the returned result.