Variable-length APT attack malicious domain name detection method and system based on P4 programmable language
By accurately matching DNS query and reply messages in the P4 data plane of the traffic probe, the malicious domain name detection problem of variable-length DNS query messages in high-throughput network traffic is solved, and the reliability and efficiency of APT attack detection is improved.
Patent Information
- Application Number
- CN202510596611.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-09
- Publication Date
- 2025-07-11
AI Technical Summary
The prior art cannot effectively locate and detect variable-length DNS query packets in high-throughput network traffic, resulting in inefficient reliability and efficiency of APT attack detection.
The P4 programmable language enables accurate matching of DNS query and response messages on the data plane of the traffic probe. The centralized controller issues a list of malicious domain names. The P4 control plane of the traffic probe converts the domain name format and sends it to the data plane for rule matching to identify malicious domain names.
It improves the accuracy and efficiency of detection of malicious domain names in APT attack C2 stage in high-throughput network traffic, providing guarantees for subsequent attack handling.
Smart Images

Figure CN120301679A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a method and system for detecting malicious domain names of variable-length APT attacks based on the P4 programmable language, belonging to the technical field of network security research. Background Art
[0002] An APT (Advanced Persistent Threat) attack is a complex network attack method, whose purpose is to intrude into the target system for a long time and continuously, steal sensitive information, and perform data theft, destruction or extortion. Such attacks are usually carried out by state-sponsored groups, hacker organizations or advanced individuals who possess sophisticated technologies and resources. The C2 server is a key component in APT attacks. It is used to communicate with the infected systems (i.e., "bots" or "botnets"), and usually establishes a connection with the C2 server through DNS domain name queries. Detecting malicious domain names of APT attacks for high-throughput network traffic through the data plane implemented by the P4 programmable language will undoubtedly improve the detection efficiency of attack clues in the C2 stage of APT attacks. The P4 language cannot read and match the content of variable-length packets. However, the DNS domain name query packet stores the domain name part in a variable-length manner. Therefore, special design is required for the detection of variable-length APT malicious domain names implemented based on the P4 language to ensure the accuracy and efficiency of APT malicious domain name detection.
[0003] Therefore, how to accurately locate malicious domain name queries for variable-length DNS queries or response packets through the data plane of the P4 programmable language in the context of high-throughput network traffic analysis, and improve the reliability and efficiency of detecting malicious domain names of APT attacks is an urgent problem to be solved by APT attack detection systems. Summary of the Invention
[0004] Aiming at the deficiencies of the prior art, the present invention provides a method and system for detecting malicious domain names of variable-length APT attacks based on the P4 programmable language, which realizes the detection of DNS malicious domain name queries initiated by compromised hosts in the C2 stage of APT attacks in the P4 data plane of the traffic probe, and provides an economical and efficient method for realizing the detection function of variable-length DNS malicious domain name queries in the P4 data plane of the traffic probe. The malicious domain name list sent from the P4 control plane of the traffic probe to the P4 data plane is used to accurately match the requested domain names in the DNS query or response packets in the analyzed traffic, so as to achieve the goal of discovering attack clues in the C2 stage of APT attack organizations.
[0005] Specifically, the centralized controller issues a malicious domain name list to the P4 control plane of the traffic probe. The P4 control plane of the traffic probe converts the format of the malicious domain name list according to the storage method of domain names in the DNS protocol, and then issues it to the P4 data plane of the traffic probe through the control channel. After the data plane performs rule matching on the DNS query or response query problem in the traffic, it identifies the DNS query or response of the malicious domain name query, thus providing guarantee for the discovery of APT attack clues and subsequent APT attack disposal.
[0006] The technical solution of the present invention is as follows: A variable-length APT attack malicious domain name detection method based on the P4 programmable language, the steps are as follows: (1) After the P4 control plane of the traffic probe is started, a malicious domain name table is created; (2) The P4 control plane of the traffic probe receives the APT attack malicious domain name information sent by the centralized controller and stores and records it; (3) The P4 control plane of the traffic probe re-encodes the malicious domain names recorded in step (2) to generate malicious domain name DNS codes and fills the malicious domain name table; (4) The P4 control plane of the traffic probe issues the malicious domain name table to the P4 data plane of the traffic probe through the communication sub-interface inside the device (synchronizes the table to the data plane of the device and is used as the basis for IP data packet matching); (5) The P4 data plane of the traffic probe receives the IP data packet and filters out the DNS packet; (6) Using the DNS packet obtained in step (5), read the DNS packet and perform matching; (7) After the P4 control plane receives the alarm information from the P4 data plane, it records it in the log file and adds a timestamp.
[0007] Preferably according to the present invention, in step (1), the malicious domain name table includes an entry index, a malicious domain name, a malicious domain name DNS code, a malicious domain name DNS code mask, and an APT organization name. Among them, the entry index is the index value in each entry of the malicious domain name table, the malicious domain name is the dns domain name sent by the attacked host in the C2 stage of the APT attack, the malicious domain name DNS code is the value obtained by re-encoding the malicious domain name according to the format defined by the dns protocol, the malicious domain name DNS code mask is the data length obtained by re-encoding the malicious domain name according to the format defined by the dns protocol, and the APT organization name is the name of the organization that uses the current malicious domain name for APT attacks. The initialized malicious domain name table is empty.
[0008] Preferably according to the present invention, in step (2), the APT attack malicious domain name information includes multiple malicious domain names and an APT organization name.
[0009] Preferably according to the present invention, in step (3), the specific steps are as follows: Re - encode the malicious domain names recorded in step (2) according to the following formula to generate malicious domain name DNS codes: C1 D 1C2 D 2C3 D 3 Among them, a domain name is composed of multiple strings spliced together, usually separated by the special character ".", and is divided into three parts in the order from left to right. D 1 is the first part of the domain name. D 2 is the second part of the domain name. D 3 is the third part of the domain name, C1 is the number of characters of the domain name D 1, C2 is the number of characters of the domain name D 2, C3 is the number of characters of the domain name D 3; Fill the generated malicious domain name DNS code into the malicious domain name DNS code field of the malicious domain name table, fill the value of C1 + C2 + C3 + 3 into the malicious domain name DNS code mask, fill the malicious domain name and the APT organization name obtained in step (2) into the malicious domain name and APT organization name in the malicious domain name table, and the entry index field of the malicious domain name table starts incrementing from zero.
[0010] Preferably according to the present invention, in step (5), the specific steps are as follows: After receiving the IP data packet, read out the next - header protocol type NH type in the IP header and the destination port number D port in the UDP header, and perform matching according to the following formula: NH type = 0x11 && D port = 0x35 Filter out the DNS packets.
[0011] Preferably according to the present invention, in step (6), the specific steps are as follows: Read the query domain name field Q domain in the DNS packet, and perform matching with the entries of the malicious domain name table according to the following formula: Q domain &M len , M domain &M len Among them, M len is the malicious domain name DNS code mask, M domain is the malicious domain name DNS code. If the result of Q domain &M len is the same as Mdomain &M len If the result is equal, the matching is successful, record the entry information in the malicious domain name table, and execute step (6.1); otherwise, execute step (6.2). (6.1) Extract the alarm information, including extracting the source address, destination address, and protocol type from the IP header obtained in step (5). Extract the source port and destination port from the UDP header. Extract the malicious domain name and APT organization name from the entry recorded in step (6). Send the alarm information to the P4 control plane of the traffic probe. (6.2) Release the packet.
[0012] The variable-length APT attack malicious domain name detection system based on the P4 programmable language includes: The malicious domain name table creation and filling module is used to create a malicious domain name table, receive APT attack malicious domain name information, store and record it, and then re-encode the recorded malicious domain names to generate malicious domain name DNS codes and fill the malicious domain name table. The packet distribution module is used to merge the malicious domain name table into the IP data packet and then distribute it. The matching module is used to receive the IP data packet, filter out the DNS packet, read the DNS packet and perform matching. The recording module is used to record the alarm information in the log file and add a timestamp after receiving it.
[0013] The beneficial effects of the present invention are as follows: The centralized controller of the present invention issues a malicious domain name list to the P4 control plane of the traffic probe. The P4 control plane of the traffic probe converts the format of the malicious domain name list according to the way of storing domain names in the DNS protocol, and then issues it to the P4 data plane of the traffic probe through the control channel. After the data plane performs rule matching on the DNS query or response query problem in the traffic, it identifies the DNS query or response of the malicious domain name query, thus providing guarantee for the discovery of APT attack clues and subsequent APT attack handling. Brief Description of the Drawings
[0014] Figure 1 It is a schematic diagram of the detection topology of the present invention; Figure 2 It is a schematic diagram of the malicious domain name table of the present invention, including an entry index occupying 16 bits, a malicious domain name field occupying 128 bits, a malicious domain name DNS code field occupying 256 bits, a malicious domain name DNS code mask field occupying 256 bits, and an APT attack organization field occupying 32 bits; Figure 3Schematic diagram of the DNS message format of the present invention, including an identification field set by the client program and the result returned by the server, a flag field indicating the type of the message, a question number field indicating how many questions are carried in the DNS, a resource record number field indicating the resource records in the DNS response, an authoritative resource record field indicating the authoritative resource records in the DNS response, an additional resource record field indicating the additional resource records in the DNS response, a query question field for the variable-length DNS query domain name, an answer field in the variable-length DNS response, an authoritative resource record field in the variable-length DNS response, and an additional resource record field in the variable-length DNS response; Figure 4 Schematic diagram of the detection process of the present invention; Specific implementation manner
[0015] The present invention will be further described below by way of embodiments in conjunction with the accompanying drawings, but not limited thereto.
[0016] Embodiment 1: As Figure 4 shown, this embodiment provides a variable-length APT attack malicious domain name detection method based on the P4 programmable language. The connection topology diagram of the traffic probe in the network is shown in Figure 1 , the upper part is the position of the centralized controller in the network, which is used to mark the position of the centralized controller in the process of variable-length APT attack malicious domain name detection for the traffic probe; the lower part is the traffic probe and the monitored network, which are used for the positions of the traffic probe and the monitored network in the process of programmable APT attack malicious domain name monitoring.
[0017] The steps are as follows: S100: After the P4 control plane of the traffic probe is started, a malicious domain name table is created and configured with null values; The malicious domain name table includes an entry index, a malicious domain name, a malicious domain name DNS encoding, a malicious domain name DNS encoding mask, and an APT organization name. Among them, the entry index is the index value in each entry of the malicious domain name table, the malicious domain name is the dns domain name sent by the attacked host in the C2 stage of the APT attack, the malicious domain name DNS encoding is the value obtained by re-encoding the malicious domain name according to the format defined by the dns protocol, the malicious domain name DNS encoding mask is the data length obtained by re-encoding the malicious domain name according to the format defined by the dns protocol, and the APT organization name is the name of the organization that uses the current malicious domain name for APT attacks. The malicious domain name table is initialized to be empty; S200: The P4 control plane of the traffic probe receives the APT attack malicious domain name information (including multiple malicious domain names and APT organization names) sent by the centralized controller and records it; S300: After encoding the malicious domain names in the APT attack malicious domain name information received in step S200, fill the relevant information into the local malicious domain name table; The specific steps are as follows: Re-encode the malicious domain names recorded in step S200 according to the following formula to generate malicious domain name DNS codes: C1 D 1C2 D 2C3 D 3 Among them, a domain name is composed of multiple strings spliced together, usually separated by the special character ".", and is divided into three parts in the order from left to right. D 1 is the first part of the domain name. D 2 is the second part of the domain name. D 3 is the third part of the domain name, C1 is the number of characters of the domain name D 1, C2 is the number of characters of the domain name D 2, C3 is the number of characters of the domain name D 3; Fill the generated malicious domain name DNS code into the malicious domain name DNS code field of the malicious domain name table, fill the value of C1 + C2 + C3 + 3 into the malicious domain name DNS code mask, fill the malicious domain name and APT organization name obtained in step (2) into the malicious domain name and APT organization name in the malicious domain name table, and the table entry index field of the malicious domain name table starts incrementing from zero; S400: The traffic probe P4 control plane distributes the malicious domain name table to the traffic probe P4 data plane; S500: The traffic probe P4 data plane filters out DNS packets from the traffic; The specific steps are as follows: After receiving the IP data packet, read out the next header protocol type NH in the IP header of the packet type and the destination port number D in the UDP header port , and match according to the following formula: NH type = 0x11 && D port = 0x35 Filter out DNS packets (when both conditions in the formula are met, it is a DNS packet, that is, the dns packet in the UDP protocol, 0x11 represents the udp packet, and 0x35 represents the dns protocol in the udp packet); S600: The traffic probe P4 data plane reads the query domain name field Q in the packet domain , and match with the malicious domain name table entries according to the following formula: Q domain& M len , Mdomain &M len Among them, M len is the DNS encoding mask of malicious domain names, and M domain is the DNS encoding of malicious domain names. If Q domain &M len results are equal to those of M domain &M len results, the matching is successful, record the entry information of the malicious domain name table, and execute step S601; otherwise, execute step S602; S601: Extract the alarm information, including extracting the source address, destination address, and protocol type from the IP header obtained in step S500; Extract the source port and destination port from the UDP header; Extract the malicious domain name and APT organization name recorded in the entry in step S600; Send the alarm information to the P4 control plane of the traffic probe; S602: Release the message; S700: The P4 control plane receives the alarm information and records it in the log information.
[0018] Embodiment 2: A variable-length APT attack malicious domain name detection system based on the P4 programmable language, including: A malicious domain name table creation and filling module, which is used to create a malicious domain name table, receive APT attack malicious domain name information, store and record it, and then re-encode the recorded malicious domain names to generate DNS encodings of malicious domain names and fill the malicious domain name table; A message distribution module, which is used to merge the malicious domain name table into the IP data message and then distribute it; A matching module, which is used to receive the IP data message, filter out the DNS message, read the DNS message and perform matching; A recording module, which is used to record the alarm information in a log file and add a timestamp after receiving it.
[0019] The above are only the preferred embodiments of the present invention and are not used to limit the present invention. For those skilled in the art, the present invention can have various changes and modifications. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.
Claims
1. A variable-length APT attack malicious domain name detection method based on the P4 programmable language, characterized in that The steps are as follows: (1) Create a malicious domain name table; (2) Receive APT attack malicious domain name information and store and record it; (3) Re-encode the malicious domain names recorded in step (2) to generate malicious domain name DNS codes and fill the malicious domain name table; (4) Send down the malicious domain name table through the communication sub-interface inside the device; (5) Receive IP data packets and filter out DNS packets; (6) Read the DNS packets and perform matching; (7) After receiving the warning information, record it in the log file and add a timestamp.
2. The variable-length APT attack malicious domain name detection method based on the P4 programmable language according to claim 1, wherein, In step (1), the malicious domain name table includes an entry index, a malicious domain name, a malicious domain name DNS code, a malicious domain name DNS code mask, and an APT organization name. Among them, the entry index is the index value in each entry of the malicious domain name table, the malicious domain name is the dns domain name sent by the attacked host in the C2 stage of the APT attack, the malicious domain name DNS code is the value obtained by re-encoding the malicious domain name according to the format defined by the dns protocol, the malicious domain name DNS code mask is the data length obtained by re-encoding the malicious domain name according to the format defined by the dns protocol, and the APT organization name is the name of the organization that uses the current malicious domain name for APT attacks. The initial malicious domain name table is empty.
3. The variable-length APT attack malicious domain name detection method based on the P4 programmable language according to claim 2, wherein In step (2), the APT attack malicious domain name information includes multiple malicious domain names and an APT organization name.
4. The variable-length APT attack malicious domain name detection method based on the P4 programmable language according to claim 3, characterized in that In step (3), the specific steps are: Re-encode the malicious domain names recorded in step (2) according to the following formula to generate malicious domain name DNS codes: C1 D 1C2 D 2C3 D 3 Among them, D 1 is the first part of the domain name, D 2 is the second part of the domain name, D 3 is the third part of the domain name, C1 is the number of characters of domain name D 1, C2 is the number of characters of domain name D 2, C3 is the number of characters of domain name D 3; Fill the generated malicious domain name DNS code into the malicious domain name DNS code field of the malicious domain name table, fill the value of C1 + C2 + C3 + 3 into the malicious domain name DNS code mask, fill the malicious domain name and the APT organization name obtained in step (2) into the malicious domain name and the APT organization name in the malicious domain name table, and the entry index field of the malicious domain name table increments starting from zero.
5. The variable-length APT attack malicious domain name detection method based on the P4 programmable language according to claim 4, wherein In step (5), the specific steps are: After receiving an IP data packet, read out the next-hop protocol type NH in the IP header of the packet type and the destination port number D in the UDP header port , and perform matching according to the following formula: NH type =0x11&&D port =0x35 Filter out DNS packets.
6. The variable-length APT attack malicious domain name detection method based on the P4 programmable language according to claim 5, wherein, In step (6), the specific steps are: Read the query domain name field Q in the DNS packet domain , and match it with the entries in the malicious domain name list according to the following formula: Q domain &M len ,M domain &M len Among them, M len is the DNS encoding mask of malicious domain names, and M domain is the DNS encoding of malicious domain names. If the result of Q domain &M len is equal to the result of M domain &M len , the matching is successful, record the entry information of the malicious domain name table, and execute step (6.1); otherwise, execute step (6.2). (6.1) Extract warning information, including extracting the source address, destination address, and protocol type from the IP header obtained in step (5); Extract the source port and destination port from the UDP header; Extract the malicious domain name and the APT organization name in the entry recorded in step (6); Send the warning information; (6.2) Release the packet.
7. A variable-length APT attack malicious domain name detection system based on the P4 programmable language, which is applied to the variable-length APT attack malicious domain name detection method based on the P4 programmable language according to claim 1, and is characterized in that, It includes: A malicious domain name table creation and filling module, which is used to create a malicious domain name table, receive APT attack malicious domain name information, store and record it, then re-encode the recorded malicious domain names to generate malicious domain name DNS codes, and fill the malicious domain name table; A packet sending-down module, which is used to merge the malicious domain name table into the IP data packet and then send it down; A matching module, which is used to receive IP data packets, filter out DNS packets, read the DNS packets and perform matching; A recording module, which is used to record the warning information in the log file and add a timestamp after receiving it.