Domain name system (DNS) recursive analysis speed limiting method and device based on proof of work

The proof of work mechanism restricts client requests, which solves the problem of excessive resource consumption in the existing technology, and realizes lightweight DNS recursive resolution speed limit to ensure protection effect.

CN120301658APending Publication Date: 2025-07-11INTERNET DOMAIN NAME SYST BEIJING ENG RES CENT
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510516583.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-23
Publication Date
2025-07-11

AI Technical Summary

Technical Problem

The DNS recursive resolution speed limiting strategy based on statistics in the prior art consumes too much resources and may exceed the memory resource range, affecting server performance or causing protection to fail to take effect.

Method used

The proof of work (POW) mechanism is used to generate captcha-type opt records through the recursive server, the client calculates the proof of work and resends the request, and the recursive server verifies that it meets the conditions before processing the request, reducing resource consumption.

Benefits of technology

It effectively limits the client's ability to frequently initiate effective recursive requests, reduces resource consumption for statistical data and state updates, and ensures that protection can take effect.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120301658A_ABST
    Figure CN120301658A_ABST
Patent Text Reader

Abstract

The invention discloses a DNS recursive analysis speed limiting method and device based on proof of workload, and the method comprises the steps: receiving a recursive query request sent by a client, and judging whether a pressure threshold value is exceeded or not according to a self recursive pressure state; if yes, an opt record of a captcha type is generated according to the recursive pressure state of the captcha type and added into a response packet, and response is refused; after receiving the response result, the client calculates out the workload proof meeting the condition according to the matching rule field, and sends the recursive query request to the recursive server again; the recursive query request sent again comprises an opt record of a captcha type generated by the client; receiving a recursive query request re-sent by the client, and verifying whether the proof of workload meets conditions or not; and if yes, processing the recursive query request and updating the recursive query times, and if not, refusing the response. According to the method, resources consumed by statistical data and state updating are reduced, and protection can be ensured to take effect.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of computer network security technology, and in particular to a DNS recursive resolution speed limiting method and device based on proof of work. Background Art

[0002] Currently, the protection method for recursive DNS request attacks against random domain names usually collects statistics on different request source addresses or domain names and request types in order to implement targeted rate limit strategies.

[0003] However, this statistics-based speed limit strategy relies on the recording of a large amount of data and the corresponding status updates. The DNS server itself will generate additional statistics and status maintenance, so it will also generate additional CPU and memory resources. In extreme cases, if the number of source addresses / domain names and other targets being counted is large, it may also exceed the memory resource range allowed by the local statistics, causing excessive consumption of resources for statistics and status updates, thereby affecting server performance or causing protection to fail to take effect. Summary of the invention

[0004] To this end, the present application provides a DNS recursive resolution speed limiting method and device based on proof of work to solve the problem of excessive resource consumption of statistical-based speed limiting strategies in the prior art.

[0005] In order to achieve the above objectives, this application provides the following technical solutions:

[0006] In a first aspect, a DNS recursive resolution rate limiting method based on proof of work is provided, wherein the method is applied to a recursive server, the recursive server monitors its own recursive pressure state according to a certain period, and counts the number of recursive queries processed by itself per second, and the method comprises:

[0007] Step 1: Receive the recursive query request sent by the client, and determine whether it exceeds the preset pressure threshold according to its own recursive pressure state;

[0008] Step 2: If the pressure threshold is not exceeded, the recursive query request is directly processed and the number of recursive queries in this cycle is updated;

[0009] Step 3: If the pressure threshold is exceeded, generate an opt record of captcha type according to the recursive pressure status of itself, add it to the response packet, and return a response result with a response code of refused to the client; the opt record of captcha type includes a server or client identification field, a random code or nonce value field, a matching rule field, and a remaining cycle time field; after receiving the response result, the client calculates a proof of work that meets the conditions according to the matching rule field and resends a recursive query request to the recursive server; the resent recursive query request contains an opt record of captcha type generated by the client.

[0010] Step 4: Receive the recursive query request resent by the client and verify whether the proof of work meets the conditions; if it meets the conditions, process the recursive query request and update the recursive query times, if it does not meet the conditions, return a response result with a response code of refused to the client.

[0011] Preferably, when the client resends a recursive query request to the recursive server, if the recursive server has entered a new cycle, it is processed according to the matching rules of the new cycle.

[0012] Preferably, in step 3, when generating an opt record of captcha type according to the recursive pressure status of itself, the server or client identification field is filled with 0, the random code or nonce value field is filled with the random code of this cycle, the matching rule field is filled with the matching rule value, and the remaining cycle time field is filled with the remaining time of this cycle.

[0013] Preferably, in step 3, when the client calculates a proof of work that meets the conditions according to the matching rule field after receiving the response result, it specifically includes: the client concatenates the domain name, type code, random code provided by the recursive server, and a nonce value it requests in sequence to form a string, calculates the hash value of the string through the SHA-256 algorithm, and determines whether it meets the requirements according to the matching rule value.

[0014] Preferably, in step 3, when the client generates an opt record of captcha type, the server or client identification field is filled with 1, the random code or nonce value field is filled with a nonce value that meets the conditions, the matching rule field is filled with 0, and the remaining cycle time field is filled with 0.

[0015] Preferably, in step 4, when verifying whether the proof of work meets the conditions, it is to verify whether the nonce value meets the conditions.

[0016] Preferably, when verifying whether the nonce value meets the conditions, it specifically includes: concatenating the request domain name, request type, random code of the current period, and nonce value in sequence and calculating the hash value to confirm whether the conditions are met.

[0017] In a second aspect, a DNS recursive resolution rate limiting device based on proof of work includes:

[0018] A recursive query request receiving module, configured to receive a recursive query request sent by a client and determine whether it exceeds a preset pressure threshold according to its own recursive pressure status;

[0019] A recursive query request processing module, configured to directly process the recursive query request and update the recursive query count of the current period if the pressure threshold is not exceeded;

[0020] A pseudo-resource record type generation module, configured to generate an opt record of captcha type according to its own recursive pressure status and add it to the response packet if the pressure threshold is exceeded, and return a response result with a response code of refused to the client; the opt record of captcha type includes a server or client identification field, a random code or nonce value field, a matching rule field, and a remaining time field of the period; after receiving the response result, the client calculates a proof of work that meets the conditions according to the matching rule field and resends a recursive query request to the recursive server; the resended recursive query request includes an opt record of captcha type generated by the client;

[0021] A proof of work verification module, configured to receive the recursive query request resended by the client and verify whether the proof of work meets the conditions; if the conditions are met, process the recursive query request and update the recursive query count, if the conditions are not met, return a response result with a response code of refused to the client.

[0022] In a third aspect, a computer device includes a memory and a processor, the memory stores a computer program, and when the processor executes the computer program, the steps of a DNS recursive resolution rate limiting method based on proof of work are implemented.

[0023] In a fourth aspect, a computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps of a DNS recursive resolution rate limiting method based on proof of work are implemented.

[0024] Compared with the prior art, the present application has at least the following beneficial effects:

[0025] The present application provides a method and device for limiting the speed of DNS recursive resolution based on proof of work. By receiving a recursive query request sent by a client and determining whether the recursive pressure status exceeds a pre-set pressure threshold according to its own recursive pressure status; if not, processing the recursive query request and updating the number of recursive queries; if exceeded, generating an opt record of the captcha type according to its own recursive pressure status and adding it to the response packet, and returning a response result with a response code of refused to the client; after receiving the response result, the client calculates a proof of work that meets the conditions according to the matching rule field and resends a recursive query request to the recursive server; the resent recursive query request contains an opt record of the captcha type generated by the client; receiving the recursive query request resent by the client and verifying whether the proof of work meets the conditions; if it meets the conditions, processing the recursive query request and updating the number of recursive queries, if it does not meet the conditions, returning a response result with a response code of refused to the client. The present application limits the ability of the client to frequently initiate valid recursive requests, reduces the resources consumed by statistical data and status updates, and thus ensures that the protection can take effect. Brief Description of the Drawings

[0026] To more intuitively illustrate the prior art and the present application, exemplary drawings are given below. It should be understood that the specific shapes and structures shown in the drawings generally should not be regarded as limiting conditions when implementing the present application; for example, those skilled in the art are capable of making routine adjustments or further optimizations to the addition / deletion / attribution division of certain units (components), specific shapes, positional relationships, connection methods, dimensional proportional relationships, etc. based on the technical concept disclosed in the present application and the exemplary drawings.

[0027] Figure 1 It is a flowchart of a method for limiting the speed of DNS recursive resolution based on proof of work provided in the first embodiment of the present application. Detailed Embodiments

[0028] The following further details the present application through specific embodiments in conjunction with the drawings.

[0029] In the description of the present application: Unless otherwise specified, "a plurality of" means two or more. The terms "first", "second", "third", etc. in the present application are intended to distinguish the objects being referred to, and do not have special significance in terms of technical connotations (for example, it should not be understood as emphasizing the importance level or order, etc.). Expressions such as "including", "comprising", "having", etc. also mean "not limited to" (certain units, components, materials, steps, etc.).

[0030] Terms such as "upper", "lower", "left", "right", "middle", etc. cited in this application are usually indications of the general relative position relationship for the convenience of intuitive understanding with reference to the accompanying drawings, and are not absolute limitations on the position relationship in the actual product.

[0031] Embodiment 1

[0032] This embodiment provides a method for limiting the speed of DNS recursive resolution based on proof of work. In this method, a custom pseudo-resource record (opt) is agreed upon between the client and the recursive server. The opt record is named as the captcha type. Through this opt record, the recursive server can be used to verify whether the client has the right to perform recursive queries.

[0033] Among them, the opt of the captcha type sets the following fields:

[0034] Field A: Field A is the server / client identifier, which is used to indicate whether the sender of the opt record is from a client request or a server response. The corresponding filling value for the server is 0, and the corresponding filling value for the client is 1;

[0035] Field B: Field B is a random code / nonce value. If the value of Field A is 0, then Field B corresponds to a random code. If the value of Field A is 1, then Field B corresponds to a nonce value. The data length of this field is 32 bytes (256 bits);

[0036] Field C: Field C is a matching rule, which is only valid when the value of Field A is 0. The numerical range is from 1 to 256, and is used to indicate the target value that the client searches for through calculation; when the value of Field A is 1, it is filled with 0;

[0037] Field D: Field D is the remaining time of the cycle, which is only valid when the value of Field A is 0, and is filled with the remaining valid time of the server's current verification cycle (in seconds); when Field A is 1, this field is filled with 0.

[0038] Please refer to Figure 1 , this embodiment provides a method for limiting the speed of DNS recursive resolution based on proof of work, including:

[0039] S1: Receive a recursive query request sent by the client, and determine whether it exceeds a pre-set pressure threshold according to its own recursive pressure status;

[0040] Specifically, the DNS recursive server internally sets the statistics of its own queries per second (QPS), and at the same time sets a pressure threshold to identify the boundary of relatively high recursive query pressure.

[0041] In this embodiment, the C field of the captcha type is determined by the local recursive pressure level. The local machine can specify a ladder strategy and set the corresponding values of each ladder value and the matching rule after exceeding the pressure threshold. The greater the recursive pressure, the greater the value of the matching rule.

[0042] The recursive server maintains the monitoring of the pressure at a certain period. When a pressure statistical period is not completed initially, it is processed as no pressure. After the end of a subsequent statistical period, the QPS value will be obtained. This value is used as the pressure magnitude of the current period, and this pressure magnitude will be updated in the next period (the pressure magnitude of the next period corresponds to the QPS statistically calculated in this week's period). Whenever the pressure magnitude of this period is calculated, a random code (32 bytes) will be generated, and the matching rule will be set according to the pressure ladder.

[0043] S2: If the pressure threshold is not exceeded, directly process the recursive query request and update the recursive query count of this period;

[0044] Specifically, if the pressure threshold is not exceeded, directly process the recursive request and update the recursive count of this period for statistically calculating the recursive QPS.

[0045] S3: If the pressure threshold is exceeded, generate an opt record of the captcha type according to its own recursive pressure status and add it to the response packet, and return a response result with the response code being refused to the client; after receiving the response result, the client calculates the workload proof that meets the conditions according to the matching rule field and resends a recursive query request to the recursive server; the resented recursive query request contains the opt record of the captcha type generated by the client.

[0046] Specifically, if the pressure threshold is exceeded, obtain the matching rule according to the pressure ladder, generate the opt record of the captcha, add it to the response packet, and return the result with the response code (rcode) being refused to the client. Among them, the A field of the captcha type is filled with 0, the B field is filled with the random code of this period, the C field is filled with the matching rule value, and the D field is filled with the remaining time of this period.

[0047] After receiving the response, the client needs to calculate the workload proof (POW) that meets the requirements. The specific requirements are as follows: First, concatenate the domain name of its own request, the type code, the random code provided by the server, and a nonce value in sequence as the input, and then calculate the hash value according to the SHA-256 algorithm. During the calculation process, the nonce value can be selected to start incrementing from 0.

[0048] After the client calculates the hash value, it needs to confirm whether it meets the requirements according to the matching rule given by the server. If the matching rule is the numerical value n, the hash value that meets the requirements needs to satisfy that the binary value of the first n bits of data is 0. Therefore, the larger the numerical value of the matching rule, the stricter the requirement.

[0049] It should be noted that in the process of calculating the hash value, the process of finding the nonce value is usually an exhaustive process, that is, continuously modifying the nonce value to find a nonce value that meets the conditions. The larger the numerical value of the matching rule, the more time-consuming this process will be.

[0050] After finding a nonce value that meets the conditions, the client will initiate the previous query again, but will additionally provide the captcha opt record. Among them, the value of the A field is filled with 1, the B field is filled with the nonce value that meets the conditions, and the C field and D field are filled with 0.

[0051] It should be noted that in this step, after receiving the captcha type, the client can, according to its own strategy, cache the data therein so that within its valid time in the future, it can directly initiate a captcha containing a valid nonce, reducing 1 repeated request.

[0052] S4: Receive the recursive query request resent by the client and verify whether the proof of work meets the conditions; if it meets the conditions, process the recursive query request and update the recursive query count, if it does not meet the conditions, return a response result with the response code refused to the client.

[0053] Specifically, after the server receives the request resent by the client, it will verify whether the nonce value meets the conditions. At this time, the request domain name, request type, random code of this period, and nonce value need to be concatenated in sequence, calculate the hash value, and confirm whether it meets the conditions. If it meets the conditions, this recursive query is allowed to execute and the QPS-related count is updated, otherwise a response result with the response code refused is returned to the client.

[0054] If the server has entered a new period when the client sends a request, it will be processed according to the rules of the new period. That is, the server may directly process the request because the pressure is lower than the threshold, or because the random code has changed, resulting in the nonce value provided by the client no longer meeting the conditions, resulting in a refused result being returned, etc.

[0055] In a DNS recursive resolution rate limiting method based on proof of work provided in this embodiment, the protection principle using proof of work is as follows: The cost for the client to find a nonce and for the server to verify the nonce value is not equal. If the conditions are harsh, the client may need to perform many hash calculations to find a value that meets the conditions. However, for the server to verify its validity, it only needs to perform 1 hash calculation after inputting the value to complete.

[0056] A DNS recursive resolution rate limiting method based on proof of work provided in this embodiment restricts the client's ability to frequently initiate valid recursive requests in terms of the requirements for the client's computing resources. Compared with typical local statistics and rate limiting, it reduces the resource consumption in statistics for different request source addresses or request domain names and other features, reduces the maintenance of a large number of states, saves more resource consumption for the DNS recursive server, and thus ensures the effectiveness of the protection.

[0057] This embodiment provides a more lightweight protection method, which avoids the maintenance of a large amount of statistical data and related states, realizes a rate limiting method for DNS recursive resolution, and makes up for the deficiencies in existing related attack protection.

[0058] Embodiment 2

[0059] This embodiment provides a DNS recursive resolution rate limiting device based on proof of work, including:

[0060] A recursive query request receiving module, configured to receive a recursive query request sent by a client and determine whether it exceeds a preset pressure threshold according to its own recursive pressure status;

[0061] A recursive query request processing module, configured to directly process the recursive query request and update the number of recursive queries in this period if it does not exceed the pressure threshold;

[0062] A pseudo-resource record type generation module, configured to generate an opt record of the captcha type according to its own recursive pressure status and add it to the response packet and return a response result with a response code of refused to the client if it exceeds the pressure threshold; the opt record of the captcha type includes a server or client identification field, a random code or nonce value field, a matching rule field, and a remaining time field of the period; after receiving the response result, the client calculates a proof of work that meets the conditions according to the matching rule field and resends a recursive query request to the recursive server; the resent recursive query request includes an opt record of the captcha type generated by the client;

[0063] The proof-of-work verification module is used to receive the recursive query request resent by the client and verify whether the proof of work meets the conditions; if the conditions are met, the recursive query request is processed and the recursive query count is updated, and if the conditions are not met, a response result with the response code refused is returned to the client.

[0064] For the specific implementation content of each module in a DNS recursive resolution rate limiting device based on proof of work, reference can be made to the limitations on a DNS recursive resolution rate limiting method based on proof of work in the above text, which will not be elaborated here.

[0065] Embodiment III

[0066] This embodiment provides a computer device, including a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, the steps of a DNS recursive resolution rate limiting method based on proof of work are implemented.

[0067] Embodiment IV

[0068] This embodiment provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps of a DNS recursive resolution rate limiting method based on proof of work are implemented.

[0069] The technical features of the above embodiments can be combined arbitrarily (as long as there is no contradiction in the combination of these technical features). For the sake of concise description, not all possible combinations of the technical features in the above embodiments are described; these embodiments not explicitly written out should also be considered to be within the scope described in this specification.

Claims

1. A DNS recursive resolution rate limiting method based on proof of work, characterized in that The method is applied to a recursive server. The recursive server monitors its own recursive pressure status at a certain period and counts the number of recursive queries processed per second. The method includes: Step 1: Receive a recursive query request sent by a client, and determine whether it exceeds a pre-set pressure threshold according to its own recursive pressure status; Step 2: If it does not exceed the pressure threshold, directly process the recursive query request and update the number of recursive queries in this period; Step 3: If it exceeds the pressure threshold, generate an opt record of captcha type according to its own recursive pressure status, add it to the response packet, and return a response result with a response code of refused to the client; the opt record of captcha type includes a server or client identification field, a random code or nonce value field, a matching rule field, and a remaining time field of the period; after receiving the response result, the client calculates a workload proof that meets the conditions according to the matching rule field and resends a recursive query request to the recursive server; the resended recursive query request includes an opt record of captcha type generated by the client; Step 4: Receive the recursive query request resended by the client, and verify whether the workload proof meets the conditions; if it meets the conditions, process the recursive query request and update the number of recursive queries, if it does not meet the conditions, return a response result with a response code of refused to the client.

2. The DNS recursive resolution rate limiting method based on proof of work according to claim 1, wherein If the recursive server has entered a new period when the client resends a recursive query request to the recursive server, it shall be processed according to the matching rules of the new period.

3. The DNS recursive resolution rate limiting method based on proof of work according to claim 1, wherein In Step 3, when generating an opt record of captcha type according to its own recursive pressure status, the server or client identification field is filled with 0, the random code or nonce value field is filled with the random code of this period, the matching rule field is filled with the matching rule value, and the remaining time field of the period is filled with the remaining time of this period.

4. The DNS recursive resolution rate limiting method based on proof of work according to claim 3, characterized in that, In Step 3, when the client calculates a workload proof that meets the conditions according to the matching rule field after receiving the response result, it specifically includes: the client concatenates the domain name, type code, random code provided by the recursive server, and a nonce value of its own request in sequence to form a string, calculates the hash value of the string through the SHA-256 algorithm, and determines whether it meets the requirements according to the matching rule value.

5. The DNS recursive resolution rate limiting method based on proof of work according to claim 1, characterized in that In Step 3, when the client generates an opt record of captcha type, the server or client identification field is filled with 1, the random code or nonce value field is filled with a nonce value that meets the conditions, the matching rule field is filled with 0, and the remaining time field of the period is filled with 0.

6. The DNS recursive resolution rate limiting method based on proof of work according to claim 5, wherein, In Step 4, when verifying whether the workload proof meets the conditions, it is to verify whether the nonce value meets the conditions.

7. The method for limiting the speed of DNS recursive resolution based on proof of work according to claim 6, wherein When verifying whether the nonce value meets the conditions, it specifically includes: concatenating the request domain name, request type, random code of this period, and nonce value in sequence and calculating the hash value to confirm whether it meets the conditions.

8. A DNS recursive resolution speed limiting device based on proof of work, characterized in that, including: A recursive query request receiving module, configured to receive a recursive query request sent by a client, and determine whether it exceeds a pre-set pressure threshold according to its own recursive pressure status; A recursive query request processing module, configured to directly process the recursive query request and update the recursive query count of this cycle if the pressure threshold is not exceeded; A pseudo-resource record type generation module, configured to generate an opt record of captcha type according to its own recursive pressure status and add it to the response packet if the pressure threshold is exceeded, and return a response result with a response code of refused to the client; the opt record of captcha type includes a server or client identification field, a random code or nonce value field, a matching rule field, and a remaining cycle time field; after receiving the response result, the client calculates a proof of work that meets the conditions according to the matching rule field and resends a recursive query request to the recursive server; the resended recursive query request includes an opt record of captcha type generated by the client; A proof-of-work verification module, configured to receive the recursive query request resent by the client and verify whether the proof of work meets the conditions; if it meets the conditions, process the recursive query request and update the recursive query count, if it does not meet the conditions, return a response result with a response code of refused to the client.

9. A computer device, comprising a memory and a processor, the memory storing a computer program, characterized in that, When the processor executes the computer program, the steps of the method according to any one of claims 1 to 7 are implemented.

10. A computer-readable storage medium, on which a computer program is stored, characterized in that, When the computer program is executed by the processor, the steps of the method according to any one of claims 1 to 7 are implemented.