Filtering and responding method and system for DNS (Domain Name Server) request

By resolving DNS requests in the kernel state and using XDP programs and zero-copy transmission technology, the performance bottlenecks and excessive resource consumption caused by DNS request processing at the application layer are solved, and DNS request processing with low latency, high concurrency and efficient resource utilization is achieved.

CN120281519APending Publication Date: 2025-07-08SHANGHAI DNSII INFORMATION TECH
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202510380866.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-28
Publication Date
2025-07-08

AI Technical Summary

Technical Problem

In the prior art, the filtering and response of DNS requests are mainly carried out at the application layer of the operating system, resulting in performance bottlenecks, excessive resource consumption and problems of separation from underlying optimization, including high latency, context switching overhead, limited high concurrency processing capability, excessive CPU and memory consumption, and incompatibility with hardware acceleration.

Method used

The domain name of the DNS request is resolved in the kernel state and matched with the black and white list. The request is captured through the XDP program, and the zero-copy transmission and multi-queuing mode are used to divert the processing between the kernel state and the user state. Combined with the fast filtering of the kernel state and the flexible processing of the user state, the low latency and high concurrency of the DNS request are achieved.

Benefits of technology

By quickly filtering exception domain name requests in the kernel state, the cost of invalid traffic processing is reduced, the low latency and efficient processing is ensured, the black and white list is dynamically adjusted, the system's anti-attack ability is improved, resource allocation is optimized, and the high concurrency needs of large-scale DNS traffic are met.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120281519A_ABST
    Figure CN120281519A_ABST
Patent Text Reader

Abstract

The invention relates to a DNS (Domain Name Server) request filtering and responding method and system. The method comprises the following steps of: receiving a DNS request; analyzing and matching a domain name field in the DNS request in a kernel mode, and if the analyzed domain name is matched with a preset blacklist, directly discarding the domain name or returning a redirection response; if the analyzed domain name is matched with a preset white list, forwarding the DNS request to a Socket interface of a user mode, and performing DNS response through a user mode program; otherwise, the DNS request is transmitted to the Socket interface of the application layer in an unvarnished mode to generate a DNS response. Compared with the prior art, the method has the advantages of high-performance filtering, low-delay response, dynamic flexibility, high concurrent processing, efficient resource utilization and the like.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of communication data processing, and in particular, to a method and system for filtering and responding to DNS requests. Background Art

[0002] Currently, the filtering and response of DNS requests are both carried out at the application layer of the operating system (such as Linux), such as a method, device, and system for processing DNS behavior disclosed in the invention with the publication number CN103957284A. The method includes: parsing the received network packet; judging the type of DNS behavior corresponding to the network packet according to the parsing result; determining the processing entity according to the DNS behavior type, where the processing entity includes the kernel and / or the application layer; transferring the network packet to the determined processing entity, and the determined processing entity processes the network packet. When the DNS behavior type is an attack behavior, it is determined that the processing entity is the kernel; when the DNS behavior type is a domain name resolution behavior, it is determined that the processing entity is the application layer. The kernel layer includes the network layer, the driver layer, etc., and can implement functions such as caching and attack prevention, while the application layer can perform basic parsing of network packets, including obtaining the address after domain name resolution, the data storage address, etc.

[0003] The above method still processes DNS requests other than attacks through the application layer, and there are many problems such as performance bottlenecks, excessive resource consumption, and fragmentation from underlying optimizations, which are specifically manifested as follows:

[0004] 1. Performance Bottleneck

[0005] High latency: The processing logic of the application layer often involves operations such as complex rule matching, log recording, or dynamic decision-making. Compared with more underlying implementations (such as the network layer or hardware acceleration), the processing time significantly increases.

[0006] Context switching overhead: When requests are frequent, the operating system needs to frequently perform context switching between the user mode and the kernel mode, further increasing the response time.

[0007] Limited high-concurrency processing ability: The application layer usually relies on software threads or coroutines to process concurrent requests, and it is easy to reach a bottleneck under high load.

[0008] 2. Excessive Resource Consumption

[0009] CPU consumption: The application layer logic requires a large amount of computing resources to process tasks such as rule matching, domain name resolution, and security detection, which is easy to cause CPU overload.

[0010] Memory overhead: The application layer usually needs to cache a large amount of data (such as rule sets, status information, etc.), and the memory requirement is large, which may affect the stability of the system.

[0011] 3. Disconnection from underlying optimization

[0012] Incompatible with hardware acceleration: The application layer loading cannot fully utilize the acceleration features of modern hardware (such as eBPF supported by network cards), which limits the optimization space.

[0013] Low cross-layer collaboration efficiency: The application layer cannot directly interact with the network layer or the kernel layer, resulting in fragmented processing flows and affecting the overall efficiency. Summary of the Invention

[0014] The purpose of the present invention is to overcome the defects that the filtering and response of DNS requests are currently carried out in the application layer of the operating system, resulting in performance bottlenecks, excessive resource consumption, and disconnection from underlying optimization, and to provide a DNS request filtering and response method and system.

[0015] The purpose of the present invention can be achieved through the following technical solutions:

[0016] A DNS request filtering and response method includes the following steps:

[0017] Receive a DNS request;

[0018] Parse and match the domain name field in the DNS request in the kernel state. If the parsed domain name matches the preset blacklist, directly discard the domain name or return a redirect response; if the parsed domain name matches the preset whitelist, forward the DNS request to the user-state Socket interface and perform DNS response through the user-state program; otherwise, pass the DNS request through to the application-layer Socket interface to generate a DNS response.

[0019] Furthermore, zero-copy transmission is achieved between the kernel state and the user state through shared memory.

[0020] Furthermore, the receiving of the DNS request specifically is: Load an XDP program based on eBPF at the driver layer of the network interface to capture DNS requests entering the network interface.

[0021] Furthermore, the user-state Socket interface is a user-state Socket interface queue based on XDP.

[0022] Furthermore, the forwarding of the DNS request to the user-state Socket interface and performing DNS response through the user-state program specifically is:

[0023] Use the user-state Socket interface queue based on XDP to pass the DNS request to the user-state program;

[0024] Receive DNS requests from the XDP-based user-space Socket interface queue through a user-space program, perform domain name resolution according to the whitelist, and generate corresponding DNS responses based on the DNS requests.

[0025] Furthermore, the XDP-based user-space Socket interface queue adopts a multi-queue mode to distribute the received DNS request traffic to multiple user-space threads for parallel processing.

[0026] Furthermore, the method further includes regularly updating the blacklist and whitelist in the user space and synchronizing them to the kernel space.

[0027] The present invention also provides a DNS request filtering and response system, including:

[0028] A network interface module for capturing DNS requests entering the network interface;

[0029] The kernel space is used to resolve and match the domain name fields in the DNS requests captured by the network interface module. If the resolved domain name matches the preset blacklist, the domain name is directly discarded or a redirection response is returned; if the resolved domain name matches the preset whitelist, it is marked as normal and the DNS request is forwarded to the user-space Socket interface; otherwise, it is marked as pass-through and the DNS request is passed through to the application-layer Socket interface.

[0030] The user space is used to receive the DNS requests marked as normal transmitted through the user-space Socket interface, perform domain name resolution through a user-space program, and generate corresponding DNS responses; receive the DNS requests marked as pass-through transmitted through the application-layer Socket interface, process them, and generate DNS responses.

[0031] Furthermore, zero-copy transmission is achieved between the kernel space and the user space through shared memory.

[0032] Furthermore, the user-space Socket interface is an XDP-based user-space Socket interface queue;

[0033] The specific process of forwarding the DNS request to the user-space Socket interface and generating a DNS response through a user-space program is as follows:

[0034] Use the XDP-based user-space Socket interface queue to pass the DNS request to the user-space program;

[0035] Receive the DNS request from the XDP-based user-space Socket interface queue through the user-space program, perform domain name resolution according to the whitelist, and generate corresponding DNS responses based on the DNS requests;

[0036] The XDP-based user-space Socket interface queue adopts a multi-queue mode, and distributes the received DNS request traffic to multiple user-space threads for parallel processing.

[0037] Compared with the prior art, the present invention has the following advantages:

[0038] (1) The present invention captures DNS requests entering the network interface through an XDP program, runs at the earliest stage of packet processing, and directly processes abnormal domain name requests by matching the DNS requests with blacklists and whitelists in the kernel space, greatly reducing the processing cost of invalid traffic; for DNS requests in the whitelist, they are quickly passed to the user space through AF_XDP, which can ensure low-latency processing of DNS requests and overall improve the processing efficiency of DNS requests.

[0039] (2) Low-latency response: Domain names in the whitelist are quickly passed to the user space through AF_XDP, realizing zero-copy packet transfer between the user space and the kernel space, ensuring low-latency processing of DNS requests, and further reducing the cost of context switching.

[0040] (3) Dynamic flexibility: Dynamic rule update: Dynamically adjust the black and white lists through a user-space program to achieve flexible real-time control; Hierarchical processing: Quickly filter high-frequency abnormal domain names in the kernel space, and the user space is responsible for complex logic processing.

[0041] (4) Reliability: Shunting mechanism: The kernel layer directly processes malicious traffic, improves the anti-attack ability of the system, and reduces the processing pressure on the user space; Resource isolation: Abnormal traffic does not enter the user space, ensuring that normal traffic is processed with high priority.

[0042] (5) High-concurrency processing: Support multi-queue and multi-thread mechanisms to meet the high-concurrency requirements of large-scale DNS traffic.

[0043] (6) Efficient resource utilization: Combine the efficient filtering in the kernel space with the flexible processing in the user space to optimize resource allocation and system load. BRIEF DESCRIPTION OF THE DRAWINGS

[0044] Figure 1 It is a schematic flowchart of a method for filtering and responding to DNS requests provided in an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0045] To make the objectives, technical solutions and advantages of the embodiments of the present invention clearer, the following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the accompanying drawings in the embodiments of the present invention. Apparently, the described embodiments are some but not all of the embodiments of the present invention. Components of the embodiments of the present invention generally described and illustrated in the accompanying drawings herein can be arranged and designed in a variety of different configurations.

[0046] Therefore, the following detailed description of the embodiments of the present invention provided in the accompanying drawings is not intended to limit the scope of the claimed present invention, but merely represents selected embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the scope of protection of the present invention.

[0047] It should be noted that: like reference numerals and letters denote like items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings.

[0048] Embodiment 1

[0049] As Figure 1 shown, this embodiment provides a method for filtering and responding to DNS requests, including the following steps:

[0050] S1: Receive a DNS request;

[0051] S2: Parse and match the domain name field in the DNS request in the kernel state. If the parsed domain name matches the preset blacklist, directly discard the domain name or return a redirect response;

[0052] S3: If the parsed domain name matches the preset whitelist, forward the DNS request to the Socket interface in the user state for DNS response through the user state program;

[0053] S4: Otherwise, pass the DNS request through to the Socket interface in the application layer to generate a DNS response.

[0054] Preferably, in step S1, receiving a DNS request specifically means: loading an eBPF-based XDP program in the driver layer of the network interface to capture DNS requests entering the network interface.

[0055] Specifically, an eBPF-based XDP (eXpress Data Path) program is loaded in the driver layer of the network interface to capture DNS request packets entering the network interface.

[0056] The XDP program processes the data packet before it enters the protocol stack, with extremely low latency.

[0057] XDP, which stands for eXpress Data Path, is a high-performance network data path provided by the Linux kernel. It allows user-space programs to directly process packets at the lowest layer of the kernel network stack, namely the network card driver layer. XDP programs are typically written in eBPF (extended Berkeley Packet Filter), attached to the network card, and executed immediately when packets arrive. They can process packets before they enter the kernel protocol stack, such as filtering, forwarding, or modifying packets.

[0058] In step S2, the processing procedure of this embodiment is specifically as follows: quickly parse the domain name field in the packet, and directly discard or return a redirection response for the domain name that matches the blacklist.

[0059] In step S3, preferably, zero-copy transmission is achieved between the kernel space and the user space through shared memory.

[0060] The user space and the kernel space are two core operating modes of the operating system: the user space runs application programs with restricted permissions and cannot directly access hardware or perform privileged operations. All resource requests (such as file reading and writing, network communication) must trigger a switch to the kernel space through system calls; the kernel space runs the core code of the operating system, has the highest permissions, is responsible for managing hardware, memory, and key system services, and returns the results to the user space after processing. This hierarchical mechanism ensures system security and stability through permission isolation, and at the same time realizes the cooperation between user programs and the kernel through efficient system call interfaces, ensuring that application programs can complete complex tasks without directly damaging core resources.

[0061] Specifically, the Socket interface in the user space is an AF_XDP (user-space Socket interface based on XDP) queue.

[0062] Equivalently, mark the normal domain names that match the whitelist as passed, and forward the packets to the AF_XDP (user-space Socket interface based on XDP) queue.

[0063] Forward the DNS request to the Socket interface in the user space, and the specific process of DNS response through the user-space program is as follows:

[0064] Use the AF_XDP queue to pass the DNS request to the user-space program;

[0065] Receive the DNS request from the AF_XDP queue through the user-space program, perform domain name resolution according to the whitelist, and generate the corresponding DNS response based on the DNS request.

[0066] Equivalently, use AF_XDP to pass the DNS request packet marked as a normal domain name to the user-space program.

[0067] The user-mode program receives packets from the AF_XDP queue, performs domain name resolution according to the normal domain name whitelist, and generates corresponding DNS responses based on the requests.

[0068] Preferably, the user-mode Socket interface queue based on XDP adopts a multi-queue mode, and distributes the received DNS request traffic to multiple user-mode threads for parallel processing.

[0069] That is, using the multi-queue mode of AF_XDP, the normal domain name traffic is distributed to multiple user-mode threads for parallel processing, further improving the system throughput.

[0070] In step S4, the processing procedure of this embodiment is specifically as follows: Normal domain names that do not match both the blacklist and the white list are marked as pass-through, and the data packets are passed through to the application-layer Socket interface, and the application-layer Socket interface normally processes and generates DNS responses.

[0071] Preferably, the method further includes periodically updating the blacklist and the white list in the user mode and synchronizing them to the kernel mode.

[0072] In this embodiment, the abnormal domain name blacklist is periodically updated and synchronized to the kernel mode.

[0073] The user-mode program dynamically adjusts the normal domain name whitelist according to the traffic behavior pattern to optimize the performance.

[0074] Embodiment 2

[0075] This embodiment provides a DNS request filtering and response system, including:

[0076] A network interface module, configured to capture DNS requests entering the network interface;

[0077] The kernel mode is configured to parse and match the domain name field in the DNS requests captured by the network interface module. If the resolved domain name matches the preset blacklist, the domain name is directly discarded or a redirection response is returned; if the resolved domain name matches the preset white list, it is marked as normal and the DNS request is forwarded to the user-mode Socket interface; otherwise, it is marked as pass-through and the DNS request is passed through to the application-layer Socket interface;

[0078] The user mode is configured to receive the DNS requests marked as normal transmitted through the user-mode Socket interface, and perform domain name resolution through the user-mode program to generate corresponding DNS responses; receive the DNS requests marked as pass-through transmitted through the application-layer Socket interface, process them, and generate DNS responses.

[0079] Zero-copy transmission is achieved between the kernel mode and the user mode through shared memory.

[0080] The user-space Socket interface is a user-space Socket interface queue based on XDP;

[0081] Forwarding the DNS request to the user-space Socket interface and performing DNS response through the user-space program is specifically as follows:

[0082] Using the user-space Socket interface queue based on XDP to deliver the DNS request to the user-space program;

[0083] Receiving the DNS request from the user-space Socket interface queue based on XDP through the user-space program, performing domain name resolution according to the whitelist, and generating the corresponding DNS response according to the DNS request;

[0084] The user-space Socket interface queue based on XDP adopts a multi-queue mode to distribute the received DNS request traffic to multiple user-space threads for parallel processing.

[0085] It should be noted that the specific content and beneficial effects of the system of this application can be seen in the above method embodiments and will not be elaborated here.

[0086] The preferred specific embodiments of the present invention have been described in detail above. It should be understood that those of ordinary skill in the art can make many modifications and variations based on the concept of the present invention without creative work. Therefore, all technical solutions that can be obtained by those skilled in the art in the technical field of this application based on the concept of the present invention through logical analysis, reasoning, or limited experiments on the basis of the prior art should be within the protection scope determined by the claims.

Claims

1. A method for filtering and responding to DNS requests, characterized in that It includes the following steps: Receive a DNS request; In the kernel state, parse and match the domain name field in the DNS request. If the parsed domain name matches the preset blacklist, directly discard the domain name or return a redirect response; if the parsed domain name matches the preset whitelist, forward the DNS request to the Socket interface in the user state and perform DNS response through the user state program; Otherwise, pass the DNS request transparently to the Socket interface in the application layer to generate a DNS response.

2. The filtering and response method for DNS requests according to claim 1, characterized in that, Zero-copy transmission is achieved between the kernel state and the user state through shared memory.

3. A method for filtering and responding to DNS requests according to claim 1, characterized in that, The receiving of the DNS request specifically is: Load an eBPF-based XDP program in the network interface driver layer to capture DNS requests entering the network interface.

4. A filtering and response method for DNS requests according to claim 1, characterized in that The Socket interface in the user state is a user state Socket interface queue based on XDP.

5. A method for filtering and responding to DNS requests according to claim 4, characterized in that, The forwarding of the DNS request to the Socket interface in the user state and performing DNS response through the user state program specifically is: Use the user state Socket interface queue based on XDP to pass the DNS request to the user state program; Receive the DNS request from the user state Socket interface queue based on XDP through the user state program, perform domain name resolution according to the whitelist, and generate a corresponding DNS response based on the DNS request.

6. A method for filtering and responding to DNS requests according to claim 5, characterized in that, The user state Socket interface queue based on XDP adopts a multi-queue mode to distribute the received DNS request traffic to multiple user state threads for parallel processing.

7. A method for filtering and responding to DNS requests according to claim 1, characterized in that, The method further includes periodically updating the blacklist and whitelist in the user state and synchronizing them to the kernel state.

8. A filtering and response system for DNS requests, characterized in that, It includes: A network interface module for capturing DNS requests entering the network interface; The kernel state for parsing and matching the domain name field in the DNS request captured by the network interface module. If the parsed domain name matches the preset blacklist, directly discard the domain name or return a redirect response; if the parsed domain name matches the preset whitelist, mark it as normal and forward the DNS request to the Socket interface in the user state; Otherwise, mark it as transparent and pass the DNS request transparently to the Socket interface in the application layer; The user state for receiving the DNS request marked as normal transmitted through the Socket interface in the user state and performing domain name resolution through the user state program to generate a corresponding DNS response; Receive the DNS request marked as transparent transmitted through the Socket interface in the application layer, process it, and generate a DNS response.

9. The filtering and response system for DNS requests according to claim 8, wherein, Zero-copy transmission is achieved between the kernel state and the user state through shared memory.

10. A filtering and response system for DNS requests according to claim 8, wherein, The Socket interface in the user state is a user state Socket interface queue based on XDP; The forwarding of the DNS request to the Socket interface in the user state and performing DNS response through the user state program specifically is: Use the user state Socket interface queue based on XDP to pass the DNS request to the user state program; Receive DNS requests from the XDP-based user-space Socket interface queue through a user-space program, perform domain name resolution according to the whitelist, and generate corresponding DNS responses based on the DNS requests; The XDP-based user-space Socket interface queue adopts a multi-queue mode to distribute the received DNS request traffic to multiple user-space threads for parallel processing.

Citation Information

Patent Citations

  • DNS behavior processing method, device and system

    CN103957284A