DNS NSEC traffic classified storage method
By carefully judging the types and flag fields of DNS request and reply messages, combined with the global hash table, it is divided into ordinary, successful attack and failed attack types, which solves the problem of low accuracy of DNS NSEC attacks in the existing technology, and realizes efficient traffic classification and storage, and improves security defense capabilities.
Patent Information
- Application Number
- CN202510392416.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-31
- Publication Date
- 2025-07-04
AI Technical Summary
In the prior art, it is only determined whether there is a DNS NSEC attack by judging whether the number of DNS NSEC packets exceeds the threshold, resulting in low accuracy and occupancy of a large amount of memory, and failing to effectively distinguish whether the attack is successful or not.
By judging the types and flag fields of DNS request and reply messages, combining the global hash table, it is divided into ordinary types, attack success types and attack failure types, and different types of processing strategies and index tables are constructed to achieve the precise classification and storage of DNS NSEC traffic.
Improves the classification accuracy of DNS NSEC abnormal traffic, reduces misjudgment, improves retrieval performance, and helps security managers take targeted defense measures.
Smart Images

Figure CN120256432A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of computer technology, and in particular to a method for classifying and storing DNS NSEC traffic. Background Art
[0002] The NSEC (Next Secure) record is a part of DNSSEC (DNS Security Extensions), which is used to prove that a certain domain name does not exist in a certain zone, and can be used to ensure the integrity of DNS responses. The NSEC record will display all the valid labels of a domain name, as well as a hash value for ensuring the security of the zone.
[0003] For security vendors, the DNS Nsec subdomain traversal attack is a relatively concealed DNS subdomain traversal attack. It takes advantage of the DNSSEC protocol defect to send a large number of queries for non-existent subdomains, so that the attacked party replies with a DNS domain name does not exist response and returns the DNS domain name record of the next hop that actually exists, resulting in the attacker obtaining the actual subdomains. By making multiple requests until all domain names are traversed, all the actual subdomains under the domain name can be obtained.
[0004] Among current security vendors, it is determined whether there is a DNS NSEC attack by the number of DNS NSEC packets exceeding a threshold. The DNS NSEC attack is relatively concealed. The DNS NSEC attack can obtain all the subdomains under a domain name with a small number of packets, resulting in a low accuracy rate of the method for determining whether there is an NSEC attack by storing the number of packets. Summary of the Invention
[0005] The present invention provides a method for classifying and storing DNS NSEC traffic to overcome the technical problems in the prior art that all packets are regarded as NSEC attacks only by judging whether the number of DNS NSEC packet requests exceeds a threshold, and it is not judged whether the NSEC packet attack is successful, and all received DNS NSEC packets are stored, occupying a large amount of memory and having a low accuracy rate.
[0006] To achieve the above object, the technical solution of the present invention is:
[0007] A method for classifying and storing DNS NSEC traffic includes:
[0008] S1: Obtain the DNS packets generated by the DNS NSEC attack, and judge whether the type of the DNS packet is a DNS request packet or a DNS response packet; if it is a DNS request packet, enter S2 to judge and classify the DNS request packet, and if it is a DNS response packet, enter S3 to judge and classify the DNS response packet;
[0009] S2: Extract the request type and flag field of the DNS request message, determine whether the request type or the flag field meets the set requirements, and save the DNS request message that meets the set requirements;
[0010] S3: Extract the request zone type, response type and flag field of the DNS response message, determine whether the request zone type, response type and flag field of the DNS response message meet the set requirements. If they meet the set requirements, enter S4 to classify the DNS response message. If they do not meet the requirements, define the DNS response message as a normal type or as non-NSEC traffic and do not need to be saved;
[0011] S4: Obtain the destination IP address of the DNS response message and the parent domain name of the current message, search for the entry of the DNS response message in the initial global hash table, and classify the type of the DNS response message into a normal type, an attack success type and an attack failure type according to the content in the entry;
[0012] S5: Construct three types of NSEC type processing strategies respectively, index the NSEC of the DNS request message and the DNS response message according to the corresponding NSEC type processing strategy, form different types of NSEC index tables, and complete the classification and storage of the DNS message.
[0013] Further, determining whether the request type or the flag field meets the set requirements, and saving the DNS request message that meets the set requirements includes:
[0014] The request type is the NSEC request type, and the flag field is the Z flag bit of Type OPT in the additional zone of the DNS message. When the data of the Z flag bit is in the state that the DNS message can recognize and is willing to accept DNS Security RRS, it means that NSEC is allowed;
[0015] Save the DNS request message whose request type is the NSEC request type or the flag field is NSEC allowed.
[0016] Further, extracting the request zone type, response type and flag field of the DNS response message, and determining whether the request zone type, response type and flag field of the DNS response message meet the set requirements. The specific judgment process includes:
[0017] Determine whether the request zone type is the NSEC type. If the request zone type is the NSEC type, extract the response type of the DNS response message, and determine whether the response type includes the NSEC type. If the NSEC type is included, enter S4 to classify the DNS response message. If the NSEC type is not included, define the DNS response message as a normal type;
[0018] If the request zone type is not the NSEC type, determine whether the flag field is NSEC allowed. If it is NSEC allowed, further determine whether the response type includes the NSEC type. If it is included, enter S4 to classify the DNS response message. Otherwise, define the DNS response message as non-NSEC traffic and do not need to be saved. If it is not NSEC allowed, also define the DNS response message as non-NSEC traffic and do not need to be saved.
[0019] Furthermore, obtain the destination IP address of the DNS response message and the parent domain name of the current message, search for the entry of the DNS response message in the global hash table, and classify the type of the DNS response message into a normal type, an attack success type, and an attack failure type according to the content in the entry, including:
[0020] S41. Initialize the global hash table, where the global hash table includes, but is not limited to, domain names, resource records, the validity period of resource records in the hybrid storage, record types, and cache data;
[0021] S42. Extract the destination IP address of all DNS response messages, the parent domain name of the request zone, the response domain name of the response zone, and the nsec domain name of the response zone, and set the keywords for searching the DNS response message in the global hash table. The keywords include the destination IP address of the DNS response message and the parent domain name of the request zone;
[0022] S43. Arrange the DNS response messages determined to need classification in S3 in chronological order, define the first DNS response message as the attack success type, store the keywords of the first DNS response message in the global hash table, and construct the entry of the first DNS response message to form an initial global hash table; the entry includes the keywords of the DNS response message and the value containing the domain name, and the value of the first DNS response message is the nsec domain name of the response zone;
[0023] S44. Store the second DNS response message in the global hash table. Determine whether the nsec domain name in the response area of the second DNS response message has an additional null character at the beginning of the name compared to the nsec domain name in the value. If not, set the value of the second DNS response message to the response domain name in the response area, and define the second DNS response message as the attack failure type.
[0024] If so, compare the response domain name in the response area of the second DNS response message with the string in the value from back to front. If they are the same, set the value of the second DNS response message to the response domain name in the response area, and define the second DNS response message as the attack success type. If they are different, define the second DNS response message as the normal type.
[0025] Compare the nsec domain name of the remaining DNS response messages with the value saved in the previous DNS response message in sequence, determine whether an additional null character is added at the beginning of the domain name, and classify the remaining DNS response messages into the normal type, attack failure type, and attack success type according to the judgment result.
[0026] Furthermore, construct processing strategies for three NSEC types respectively. Index the NSEC of DNS request messages and DNS response messages according to the corresponding NSEC type processing strategies to form different types of NSEC index tables, and complete the classification and storage of DNS messages, including:
[0027] S51. Construct a processing strategy for the normal type to process DNS response messages of the normal type and form an index table, including:
[0028] Store DNS response messages of the normal type, record the sequence number of each DNS response message, and form an index table for indexing as NSEC general traffic.
[0029] S52. Construct a processing strategy for the attack success type to process DNS response messages of the attack success type and form an index table, including:
[0030] S521: Sort by time and record the basic items of the first DNS response message of the attack success type. The basic items of the DNS response message of the attack success type include the domain name attacked by the DNS response message, source ip address, destination ip address, and the number of attacks.
[0031] S522: Obtain the item ID, NSEC domain name, message sequence number of all DNS response messages of this type, and the message sequence number of the DNS request message corresponding to the same item ID of the DNS response message of this type, to form an attack sequence for the corresponding DNS response message; use the number of attack sequences to represent the number of attacks in the basic item;
[0032] Save the basic item of the DNS response message of the attack success type and the attack sequence of each DNS response message to form an index table of attack success;
[0033] S53. Construct a processing strategy for the attack failure type, process the DNS response messages of the attack failure type, and form an index table, including:
[0034] S531: Find the DNS request message corresponding to the same item ID of each DNS response message of this type, and record the message sequence numbers of both:
[0035] S532: Sort by time and record the basic item of the first DNS response message of the attack failure type. The basic item of the DNS response message of the attack failure type includes the domain name attacked by the DNS response message, source IP address, destination IP address, the first NSEC domain name, and the number of attacks;
[0036] S533: Obtain the item ID of all DNS response messages of this type, and jointly form an attack sequence for the corresponding DNS response message with the message sequence numbers of all DNS response messages and corresponding DNS request messages of this type; use the number of attack sequences to represent the number of attacks in the basic item;
[0037] Save the basic item of the DNS response message of the attack failure type and the sum attack sequence of each DNS response message to form an index table of attack failure.
[0038] Beneficial effects: The present invention provides a DNS NSEC traffic classification and storage method. First, different message types are judged, and different processing is performed on different message types. Then, different NSEC types in the message are judged, and different methods are selected to process different NSEC types in the message, and further, the type of DNS NSEC traffic is judged;
[0039] It can identify DNS NSEC traffic based on the source IP address of the attacker and the corresponding NSEC attack characteristics, improve the classification accuracy of DNS NSEC abnormal traffic, and by classifying the types of DNS NSEC into ordinary type, attack success type, and attack failure type, it can help security administrators take targeted security measures for the traffic;
[0040] Designing different indexing methods for different categories of DNS NSEC traffic can enable the NSEC traffic to be indexed quickly and improve the retrieval performance. BRIEF DESCRIPTION OF THE DRAWINGS
[0041] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0042] Figure 1 It is a flowchart of a DNS NSEC traffic classification storage method provided by the present invention;
[0043] Figure 2 It is a flowchart of DNS message processing provided by the present invention;
[0044] Figure 3 It is a flowchart of DNS NSEC traffic classification processing provided by the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0045] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts fall within the scope of protection of the present invention.
[0046] Currently, security vendors do not classify NSEC traffic in detail and simply divide it into normal and abnormal. In actual scenarios, the traffic classification of DNS NSEC messages is of great significance. Different attack types correspond to different handling methods. Especially for a DNS traffic tracing system, accurately classifying NSEC attack traffic can help administrators promptly understand the detailed attack categories and take defensive measures in a timely manner to ensure the stable operation of the network. Therefore, this embodiment provides a DNS NSEC traffic classification storage method, as Figure 1 shown, including:
[0047] S1: Obtain the DNS messages generated by DNS NSEC attacks and determine whether the type of the DNS message is a DNS request message or a DNS response message; if it is a DNS request message, proceed to S2 to judge and classify the DNS request message; if it is a DNS response message, proceed to S3 to judge and classify the DNS response message;
[0048] S2: Extract the request type and flag field of the DNS request message, determine whether the request type or the flag field meets the set requirements, and save the DNS request messages that meet the set requirements;
[0049] S3: Extract the request zone type, response type and flag field of the DNS response message, determine whether the request zone type, response type and flag field of the DNS response message meet the set requirements. If they meet the set requirements, enter S4 to classify the DNS response message. If they do not meet the requirements, define the DNS response message as a normal type or as non-NSEC traffic and do not need to be saved;
[0050] S4: Obtain the destination IP address of the DNS response message and the parent domain name of the current message, search for the entry of the DNS response message in the initial global hash table, and classify the type of the DNS response message into normal type, attack success type and attack failure type according to the content in the entry;
[0051] S5: Construct three NSEC type processing strategies respectively, index the NSEC of the DNS request message and the DNS response message according to the corresponding NSEC type processing strategy, form different types of NSEC index tables, and complete the classification and storage of the DNS messages.
[0052] Specifically, first obtain the DNS messages generated by DNS NSEC attacks and determine whether the type of the DNS message is a DNS request message or a DNS response message. If it is a DNS request message, enter S2 to judge and classify the DNS request message. If it is a DNS response message, enter S3 to judge and classify the DNS response message. Distinguishing request and response messages can help the detection system clarify the target and adopt different processing methods for different types of messages, which is convenient for subsequent judgment of the NSEC type in the message. Secondly, extract the request type and flag field of the DNS request message, determine whether the request type or the flag field meets the set requirements, and save the DNS request messages that meet the set requirements, cache the request messages belonging to NSEC traffic for subsequent analysis or matching of the corresponding response messages. Extract the request zone type, response type and flag field of the DNS response message, determine whether the request zone type, response type and flag field of the DNS response message meet the set requirements. If they meet the set requirements, enter S4 to classify the DNS response message. If they do not meet the requirements, define the DNS response message as a normal type or as non-NSEC traffic and do not need to be saved. This solution can effectively distinguish normal traffic and potential attack traffic, avoid misjudgment, and improve the recognition performance of NSEC attack traffic;
[0053] Again, a solution for obtaining the destination IP address of the DNS response message and the parent domain name of the current message, looking up the entry of the DNS response message in the initial global hash table, and classifying the DNS response message into a normal type, an attack success type, and an attack failure type according to the content in the entry can determine the type of DNS NSEC traffic and classify the DNS NSEC into a normal type, an attack success type, and an attack failure type, which can help security administrators take targeted security measures for the traffic;
[0054] Finally, processing strategies for three NSEC types are constructed respectively, and the NSEC of the DNS request message and the DNS response message are indexed according to the corresponding processing strategies for the NSEC types to form NSEC index tables of different types, completing the classification and storage of the DNS messages. By constructing the processing strategies for the normal type, the attack success type, and the attack failure type and forming the index tables, it is possible to effectively classify, store, and analyze DNS NSEC traffic, and it is possible to quickly look up through the index table when it is necessary to extract the attack and the corresponding attack sequence and domain name.
[0055] In a specific embodiment, the solution for obtaining the DNS messages generated by the DNS NSEC attack and determining whether the type of the DNS message is a DNS request message or a DNS response message is as follows: if it is a DNS request message, enter S2 to judge and classify the DNS request message; if it is a DNS response message, enter S3 to judge and classify the DNS response message:
[0056] Obtain the DNS messages generated by the DNS NSEC attack, and check the QR bit of the Flags in the DNS message header. The QR bit is the first bit (highest bit) of the Flags field and is used to identify whether the message is a request or a response: when QR = 0, it indicates that the message is a request message; when QR = 1, the message is a response message.
[0057] The DNS request message is mainly used to detect the behavior of the client, such as whether there is a malicious client sending a large number of NSEC queries to exhaust the server resources; the DNS response message is mainly used to detect the behavior of the server, such as whether it returns forged NSEC records or whether there is an NSEC cache poisoning attack. In this solution, distinguishing between the request and response messages can help the detection system clarify the target and take different processing methods for different types of messages, facilitating the subsequent judgment of the NSEC type in the message.
[0058] In a specific embodiment, the solution for extracting the request type and the flag field of the DNS request message, judging whether the request type or the flag field meets the set requirements, and saving the DNS request message that meets the set requirements is as follows:
[0059] The request type is the NSEC request type, and the flag field is the Z flag bit of Type OPT in the additional section of the DNS message. When the data of the Z flag bit is in a state where the DNS message can recognize and is willing to accept DNS Security RRS, it means that NSEC is allowed;
[0060] The specific process of DNS message judgment is as follows Figure 2 shown. Extract the request type request_tpye of the DNS request message and the Z flag field of the OPT RR in the additional section of the message, and determine whether the request type is an NSEC request or whether the request field is NSEC allowed. If request_tpye is an NSEC request or the Z field is NSEC allowed, cache the DNS request message and record the transaction id (tx id) of the message;
[0061] If request_tpye is not an NSEC request and the Z field is not NSEC allowed either, the DNS request message is non-NSEC traffic, proving that the DNS request message is not an NSEC attack message, and the processing ends.
[0062] Only the message that clearly requests an NSEC record is NSEC traffic. Therefore, in one way of this solution, by determining whether the request type is an NSEC request, this result exists in the QTYPE field (query type) of the DNS request message. If its value is NSEC (the type value is 47), it indicates that this is an NSEC request and the message belongs to NSEC traffic;
[0063] Another way of this solution is to determine whether the Z field is NSEC allowed. In the Z field (reserved field) of the DNS request message, some bits may be used to indicate whether it is allowed to return an NSEC record. For example, if a certain bit of the Z field is set to 1, it may indicate that the client supports or allows NSEC records. Therefore, check the Z field in the DNS request message. If the client clearly allows NSEC records, the server may return an NSEC record, thus indicating that the message belongs to NSEC traffic;
[0064] Cache the request messages belonging to NSEC traffic for subsequent analysis or matching of the corresponding response messages;
[0065] The DNS NSEC enumeration attack will generate a large number of messages. For each obtained NSEC domain name, we call it a sub-attack, which includes at least 1 DNS request and 1 DNS response. The Transaction id values of all request and response messages of the same sub-attack, that is, the same transaction ID (tx id), record the tx id, which can ensure that subsequent NSEC response messages can be matched with the request messages, and at the same time facilitate subsequent indexing of the messages.
[0066] In a specific embodiment, the request zone type, response type, and flag field of the DNS response message are extracted, and it is determined whether the request zone type, response type, and flag field of the DNS response message meet the set requirements. If they meet the set requirements, then proceed to S4 to classify the DNS response message. If they do not meet the requirements, then define the DNS response message as a normal type or define it as non-NSEC traffic and there is no need to save it. The solution is as follows:
[0067] Determine whether the request zone type is the NSEC type. If the request zone type is the NSEC type, then extract the response type of the DNS response message and determine whether the response type includes the NSEC type. If it includes the NSEC type, then proceed to S4 to classify the DNS response message. If it does not include the NSEC type, then define the DNS response message as a normal type;
[0068] If the request zone type is not the NSEC type, then determine whether the flag field is NSEC-allowed. If it is NSEC-allowed, then further determine whether the response type includes the NSEC type. If it includes it, then proceed to S4 to classify the DNS response message. If not, then define the DNS response message as non-NSEC traffic and there is no need to save it. If it is not NSEC-allowed, also define the DNS response message as non-NSEC traffic and there is no need to save it;
[0069] The judgment process of the DNS response message is as Figure 2 shown. First, extract the message request zone type request_type and determine whether request_type is the NSEC type:
[0070] If request_type = NSEC, then extract the response type resp_type of the message and determine whether resp_type is NSEC:
[0071] If resp_type is NSEC, then proceed to S4 to classify the message;
[0072] If resp_type is not NSEC, then define the message response category as NSEC1. The message of NSEC1 type is normal NSEC type traffic and is not attack traffic, that is, normal type;
[0073] If request_type = NSEC, then extract the Z flag field of the message optional OPT RR and determine whether the Z flag field is NSEC:
[0074] If the Z flag of the message is not NSEC, then the message is non-NSEC traffic and the processing ends;
[0075] If the Z flag of the message is NSEC, extract the response type resp_type of the message and determine whether resp_type contains the NSEC type:
[0076] If resp_type does not contain the NSEC type, the message is non-NSEC traffic and the processing ends;
[0077] If resp_type contains the NSEC type, enter S4 for classification.
[0078] In this solution, first, by extracting the request_type in the request area, quickly determine whether it is the NSEC type. If the request_type is the NSEC type, further extract the resp_type in the response area and determine whether it contains the NSEC type. It can perform multi-level judgments, improve the detection accuracy, and reduce false positives and false negatives;
[0079] If it is not the NSEC type, directly end the processing to avoid unnecessary resource consumption. By further extracting the resp_type in the response area and determining whether it is the NSEC type, classify NSEC into normal type or attack type according to the discrimination result. For normal type NSEC traffic, no further processing is required, only normal storage and indexing are needed. For traffic that may be of the attack type, further analyze through subsequent steps to determine whether it is attack traffic or whether the attack is successful, which can effectively distinguish normal traffic and potential attack traffic, avoid misjudgment, and improve the recognition performance of NSEC attack traffic.
[0080] In a specific embodiment, the solution for obtaining the destination ip address of the DNS response message and the parent domain name of the current message, looking up the entry of the DNS response message in the initial global hash table, and classifying the type of the DNS response message into normal type, attack success type, and attack failure type according to the content in the entry is as follows:
[0081] Construct the initial global hash table:
[0082] S41. Initialize the global hash table, where the global hash table includes but is not limited to domain names, resource records, the validity period of resource records in the hybrid storage, record types, and cache data;
[0083] S42. Extract the destination ip address of all DNS response messages, the parent domain name in the request area, the response domain name in the response area, and the nsec domain name in the response area, and set the keywords for looking up the DNS response message in the global hash table. The keywords include the destination ip address of the DNS response message and the parent domain name in the request area;
[0084] S43. Arrange the DNS response messages that need to be classified as determined in S3 in chronological order. Define the first DNS response message as the type of successful attack, store the keywords of the first DNS response message in the global hash table, and construct an entry for the first DNS response message to form the initial global hash table; the entry includes the keywords of the DNS response message and the value containing the domain name, and the value of the first DNS response message is the nsec domain name in the response area.
[0085] S44. Store the second DNS response message in the global hash table. Determine whether the nsec domain name in the response area of the second DNS response message has an additional null character at the beginning of the name compared to the nsec domain name in the value. If not, set the value of the second DNS response message to the response domain in the response area and define the second DNS response message as the type of failed attack.
[0086] If so, compare the response domain in the response area of the second DNS response message with the string in the value from back to front. If they are the same, set the value of the second DNS response message to the response domain in the response area and define the second DNS response message as the type of successful attack. If they are different, define the second DNS response message as the normal type.
[0087] Compare the nsec domain name of the remaining DNS response messages with the value saved in the previous DNS response message in turn, determine whether an additional null character is added at the beginning of the domain name, and classify the remaining DNS response messages into normal type, failed attack type, and successful attack type according to the judgment result.
[0088] The initialization of the global hash table and the classification process are as Figure 3 shown. For each DNS response message, first extract the destination IP address (dip), the parent domain name (domain) in the request area, the response domain (resp_domain) in the response area, and the nsec domain name (nsec_domain) in the response area, and convert all letters of the three domain names to lowercase letters.
[0089] Secondly, based on the keyword destination IP address of the DNS response message and the parent domain name in the request area (dip, domain), search in the global hash table to see if there is a corresponding entry. After the search, if there is no entry corresponding to the keyword (dip, domain) of a certain DNS response message, a new entry is created. The key value of the new entry is the keyword of the DNS response message, key = (dip, domain), value = nesc_domain. Add the new entry to the initial global hash table. In the hash table, it is represented in the following form:
[0090] key = (dip, domain), value = nesc_domain;
[0091] The initialized global hash table is empty. Therefore, the first DNS response message does not have a corresponding entry in the global hash table, and this entry needs to be added to the global hash table. At the same time, the first DNS response message is defined as a message of the attack success type;
[0092] Continue to search for the keyword of the second DNS response message. The destination IP addresses and the parent domain names in the request areas of all DNS response messages are the same. Therefore, all messages except the first DNS response message have records in the global hash table. After the search, there is an entry corresponding to the keyword (dip, domain) of the second DNS response message. Compare whether nsec_domain has one more '\0' character (i.e., the null character) at the beginning than the value value. If so, update the value value so that the value value of the current entry becomes the nsec domain name in the response area of the current DNS response message, that is, make it nsec_domain, and define the type of the message as NSEC2, that is, the attack failure type;
[0093] If there is no case of having one more null character, compare the characters of the value value of the current entry stored before the update and the response domain name in the response area corresponding to this DNS response message from back to front;
[0094] If the characters are the same, define this DNS response message as a message of the NSEC3 type, that is, the attack success type;
[0095] If the characters are different, mark this DNS response message as an NSEC1 message, that is, the normal type.
[0096] In this solution, the type of DNS NSEC traffic is judged, and the types of DNS NSEC are divided into the normal type, the attack success type, and the attack failure type, which can help security administrators take targeted security measures for the traffic.
[0097] In a specific embodiment, three types of NSEC processing strategies are constructed respectively. According to the processing strategies corresponding to the NSEC types, the NSEC of DNS request messages and DNS response messages are indexed to form different types of NSEC index tables. The solution for classifying and storing DNS messages is as follows:
[0098] S51. Construct a processing strategy for the normal type, process DNS response messages of the normal type, and form an index table, including:
[0099] Store DNS response messages of the normal type, record the sequence number of each DNS message, form an index table, and use it as an index for NSEC general traffic;
[0100] S52. Construct a processing strategy for the successful attack type, process DNS response messages of the successful attack type, and form an index table, including:
[0101] S521: Sort by time, record the basic items of the first DNS response message of the successful attack type. The basic items of the DNS response message of the successful attack type include the domain name attacked by the DNS response message, source IP address, destination IP address, and the number of attacks;
[0102] S522: Obtain the event id, nsec domain name, message sequence number of all DNS response messages of this type, and the message sequence number of the DNS request message corresponding to the same event id of the DNS response message of this type to form an attack sequence for the corresponding DNS response message; Use the number of attack sequences to represent the number of attacks in the basic items;
[0103] Save the basic items of the DNS response message of the successful attack type and the attack sequence of each DNS response message to form an index table for successful attacks; The index value structure is designed as follows:
[0104] The first item is the basic item (the domain name attacked, source IP address, destination IP address, number of attacks);
[0105] The second item is the attack sequence. Suppose there are N attacks, then the attack sequence is
[0106] (txid1, nesc_domain1, message sequence number), (txid2, nesc_domain2, message sequence number), (txid3, nesc_domain3, message sequence number), …, (txidN, nesc_domainN, message sequence number);
[0107] When N>1, the NSEC attack is valid;
[0108] S53. Construct a processing strategy for attack failure types, process DNS response messages of attack failure types, and form an index table, including:
[0109] S531: Find the DNS request messages corresponding to the same item id of each DNS response message of this type, and record the message sequence numbers of both:
[0110] S532: Sort by time and record the basic items of the first DNS response message of the attack failure type. The basic items of the DNS response message of the attack failure type include the domain name attacked by the DNS response message, source ip address, destination ip address, the first nsec domain name, and the number of attacks;
[0111] S533: Obtain the item ids of all DNS response messages of this type, and jointly form the attack sequence of the corresponding DNS response message with the message sequence numbers of all DNS response messages and corresponding DNS request messages of this type; use the number of attack sequences to represent the number of attacks in the basic items;
[0112] Save the basic items of the DNS response message of the attack failure type and the sum attack sequence of each DNS response message to form an index table for attack failure; the index value structure is designed as follows:
[0113] The first item is the basic item (the domain name attacked, source ip address, destination ip address, the first nesc_domain, number of attacks)
[0114] The second item is the attack sequence. Assuming there are N attacks, then the attack sequence is (tx id1, message sequence number, txid2, message sequence number,..., txidN, message sequence number);
[0115] When N>1, the NSEC attack is effective;
[0116] When looking for NSEC attack traffic, the attack list can extract the attack requests and responses. The NSEC domain of the Nth attack sequence of the message is the response of the NSEC domain of the N-1th attack sequence:
[0117] (1) For the domain where the NSEC attack is successful, enumerate the obtained domain names of the attack as the nesc_domain parameter in the attack sequence;
[0118] (2) For the domain where the NSEC attack fails, the method of enumerating each attack domain name domain of the attack is as follows:
[0119] If domain = the domain name attacked in the first basic item of the index item, then
[0120] When N = 1, the domain corresponding to the 1st tx id1 is nesc_domain in the basic item
[0121] When N > 1, the domain corresponding to the Nth tx idN is the concatenation of the (N - 1)th '\0' and nesc_domain. For example:
[0122] The domain corresponding to the second tx id2 is the concatenation of '\0' and nesc_domain
[0123] The domain corresponding to the third tx id3 is the concatenation of '\0' and the nesc_domain corresponding to the second tx id2
[0124] …
[0125] The domain corresponding to the Nth tx idN is the concatenation of '\0' and the nesc_domain corresponding to the second tx idN - 1.
[0126] In this solution, by constructing processing strategies for normal type, attack success type, and attack failure type, and forming an index table, it can effectively classify, store, and analyze DNS NSEC traffic, and can quickly retrieve through the index table when it is necessary to extract attacks and the corresponding attack sequences and domain names.
[0127] Finally, it should be noted that: the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that: they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements on some or all of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the scope of the technical solutions of the embodiments of the present invention.
Claims
1. A DNS NSEC traffic classification and storage method, characterized in that, Including: S1: Obtain DNS packets generated by DNS NSEC attacks, and determine whether the type of the DNS packet is a DNS request packet or a DNS response packet; If it is a DNS request packet, enter S2 to judge and classify the DNS request packet. If it is a DNS response packet, enter S3 to judge and classify the DNS response packet; S2: Extract the request type and flag field of the DNS request packet, determine whether the request type or the flag field meets the set requirements, and save the DNS request packets that meet the set requirements; S3: Extract the request zone type, response type and flag field of the DNS response packet, determine whether the request zone type, response type and flag field of the DNS response packet meet the set requirements. If they meet the set requirements, enter S4 to classify the DNS response packet. If they do not meet the requirements, define the DNS response packet as a normal type or as non-NSEC traffic and do not need to be saved; S4: Obtain the destination IP address of the DNS response packet and the parent domain name of the current packet, search for the entry of the DNS response packet in the initial global hash table, and classify the type of the DNS response packet into a normal type, an attack success type and an attack failure type according to the content in the entry; S5: Construct three types of NSEC type processing strategies respectively, index the NSEC of the DNS request packet and the DNS response packet according to the corresponding NSEC type processing strategy, form different types of NSEC index tables, and complete the classification and storage of the DNS packets.
2. The DNS NSEC traffic classification and storage method according to claim 1, wherein Determine whether the request type or the flag field meets the set requirements, and save the DNS request packets that meet the set requirements, including: The request type is the NSEC request type, and the flag field is the Z flag bit of Type OPT in the additional section of the DNS packet. When the data of the Z flag bit is in the state that the DNS packet can recognize and is willing to accept DNS Security RRS, it means that NSEC is allowed; Save the DNS request packets whose request type is the NSEC request type or the flag field is NSEC allowed.
3. The DNS NSEC traffic classification and storage method according to claim 1, characterized in that Extract the request zone type, response type and flag field of the DNS response packet, and determine whether the request zone type, response type and flag field of the DNS response packet meet the set requirements. The specific judgment process includes: Judge whether the request zone type is the NSEC type. If the request zone type is the NSEC type, extract the response type of the DNS response packet, and judge whether the response type contains the NSEC type. If it contains the NSEC type, enter S4 to classify the DNS response packet. If it does not contain the NSEC type, define the DNS response packet as a normal type; If the request zone type is not the NSEC type, determine whether the flag field is NSEC-allowed. If it is NSEC-allowed, further determine whether the response type includes the NSEC type. If it does, enter S4 to classify the DNS response message. If not, define the DNS response message as non-NSEC traffic and do not need to be saved. If it is not NSEC-allowed, also define the DNS response message as non-NSEC traffic and do not need to be saved.
4. A DNS NSEC traffic classification and storage method according to claim 1, characterized in that Obtain the destination IP address of the DNS response message and the parent domain name of the current message, search for the entry of the DNS response message in the global hash table, and classify the type of the DNS response message into ordinary type, attack success type, and attack failure type according to the content in the entry, including: S41. Initialize the global hash table, which includes but is not limited to domain names, resource records, the validity period of resource records in the hybrid storage, record types, and cached data; S42. Extract the destination IP address of all DNS response messages, the parent domain name of the request zone, the response domain name of the response zone, and the nsec domain name of the response zone, and set the keywords for searching the DNS response message in the global hash table. The keywords include the destination IP address of the DNS response message and the parent domain name of the request zone; S43. Arrange the DNS response messages determined to need classification in S3 in chronological order, define the first DNS response message as the attack success type, and store the keywords of the first DNS response message in the global hash table to construct the entry of the first DNS response message to form an initial global hash table. The entry includes the keywords of the DNS response message and the value containing the domain name. The value of the first DNS response message is the nsec domain name of the response zone; S44. Store the second DNS response message in the global hash table, and determine whether the nsec domain name of the response zone of the second DNS response message has an extra null character at the beginning of the name compared with the nsec domain name in the value. If not, set the value of the second DNS response message to the response domain name of the response zone and define the second DNS response message as the attack failure type; If so, compare the response domain name of the response zone of the second DNS response message with the string in the value from back to front. If they are the same, set the value of the second DNS response message to the response domain name of the response zone and define the second DNS response message as the attack success type. If they are different, define the second DNS response message as the ordinary type; Compare the nsec domain name of the remaining DNS response messages with the value saved by the previous DNS response message in turn, determine whether an extra null character is added at the beginning of the domain name, and classify the remaining DNS response messages into ordinary type, attack failure type, and attack success type according to the judgment result.
5. A DNS NSEC traffic classification and storage method according to claim 4, characterized in that Construct three processing strategies for different NSEC types respectively. Index the NSEC in DNS request messages and DNS response messages according to the corresponding processing strategies for different NSEC types to form NSEC index tables of different types, and complete the classification and storage of DNS messages, including: S51. Construct a processing strategy for the normal type to process DNS response messages of the normal type and form an index table, including: Store DNS response messages of the normal type, record the sequence number of each DNS response message, and form an index table for indexing as NSEC general traffic; S52. Construct a processing strategy for the successful attack type to process DNS response messages of the successful attack type and form an index table, including: S521: Sort by time and record the basic items of the first DNS response message of the successful attack type. The basic items of the DNS response message of the successful attack type include the domain name attacked by the DNS response message, source IP address, destination IP address, and the number of attacks; S522: Obtain the event ID, NSEC domain name, message sequence number of all DNS response messages of this type, and the message sequence number of the corresponding DNS request message of the same event ID of the DNS response messages of this type to form an attack sequence for the corresponding DNS response message; Use the number of attack sequences to represent the number of attacks in the basic items; Save the basic items of the DNS response messages of the successful attack type and the attack sequence of each DNS response message to form an index table for successful attacks; S53. Construct a processing strategy for the failed attack type to process DNS response messages of the failed attack type and form an index table, including: S531: Find the corresponding DNS request message of the same event ID for each DNS response message of this type and record their message sequence numbers: S532: Sort by time and record the basic items of the first DNS response message of the failed attack type. The basic items of the DNS response message of the failed attack type include the domain name attacked by the DNS response message, source IP address, destination IP address, the first NSEC domain name, and the number of attacks; S533: Obtain the event ID of all DNS response messages of this type, and jointly form an attack sequence for the corresponding DNS response message with the message sequence numbers of all DNS response messages and the corresponding DNS request messages of this type; Use the number of attack sequences to represent the number of attacks in the basic items; Save the basic items of the DNS response messages of the failed attack type and the sum of the attack sequences of each DNS response message to form an index table for failed attacks.