DNS server security non-inductive detection system based on browser search

By deploying a DNS server secure sensing detection system with multi-dimensional security verification and active monitoring mechanism in the browser, the problems of high cost, difficulty in sensing detection and large cache dependence in the existing technology are solved, and DNS resolution with high security and high accuracy is achieved, improving user experience.

CN120301685AActive Publication Date: 2025-07-11BEIJING UNIV OF POSTS & TELECOMM

Patent Information

Application Number
CN202510620690.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-14
Publication Date
2025-07-11
Estimated Expiration
2045-05-14

AI Technical Summary

Technical Problem

The prior art has high cost and difficulty in implementing invisible detection of DNS domain name servers, and is also highly dependent on cache effectiveness, resulting in security risks and inaccurate resolution.

Method used

By deploying a DNS server security and senseless detection system based on browser search in the browser, a multi-dimensional security verification and active monitoring mechanism is adopted, including a reception module, a legality approval and trustworthiness screening module, a multi-layer verification module and a health status monitoring and dynamic risk assessment module, it realizes full-link security protection from the user end to the network infrastructure.

Benefits of technology

It significantly improves the security and resolution accuracy of DNS servers, reduces cost and overhead, ensures the security and trustworthiness of user access, and provides faster response time and smooth access experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120301685A_ABST
    Figure CN120301685A_ABST
Patent Text Reader

Abstract

The invention discloses a non-inductive detection system for DNS server security based on browser search, and belongs to the technical field of network security detection. The system is deployed in a browser, the browser serves as a security verification node and a network sensing terminal, and the system comprises a receiving module, a legality approval and credibility screening module, a multi-layer verification module and a health state monitoring and dynamic risk assessment module. The multi-layer verification module comprises an authenticity verification module, a multi-path request and consistency comparison module and a comparison analysis and redundancy screening module; according to the system disclosed by the invention, when a user uses a browser to input a keyword to access a network, the security protection of the conversion process from the keyword to the URL is realized, and the non-inductive detection of the local DNS server is realized. According to the system, through multi-layer verification and consistency comparison, more potential attacks and data tampering risks can be identified, and a full-link security protection system from a user side to a network infrastructure is constructed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of network security detection, and particularly relates to a passive detection system for DNS server security based on browser search. Background Art

[0002] With the rapid development of the Internet, users usually access websites in the browser by keyword search, which involves a multi-level parsing process from keywords to URLs (Uniform Resource Locators) and then to IP addresses. In this process, there are security risks such as DNS tampering and domain name hijacking. Especially when the local DNS server (LDNS) is attacked or misconfigured, users may be redirected to malicious websites.

[0003] When detecting the security of DNS domain name servers, many companies in the industry adopt direct detection or detection at multiple detection points. This method has a large cost overhead, requires maintaining multiple detection points, increases the cost of infrastructure and operation and maintenance complexity, and this method is easily detected by the domain name server. Frequent detection requests may be recognized by the target domain name server, resulting in countermeasures such as blocking specific IPs or traffic, that is, it is difficult to achieve passivity.

[0004] Currently, there is DNS resolution using the caching mechanism. Many DNS servers will cache query results to improve the response speed of subsequent requests. This method relies on the effectiveness of the cache to reduce network latency. However, this method has the following disadvantages: (1) If the cache fails, that is, if the data in the cache expires or is tampered with, users will receive outdated or incorrect resolution results, leading to security risks; (2) Due to different cache update times of different DNS servers, it may result in inconsistent resolution results for users in different network environments; (3) Attackers can use means such as cache poisoning to interfere with DNS resolution results and make users access malicious websites, that is, there is a risk of cache pollution. Summary of the Invention

[0005] Aiming at the problems of large cost overhead, difficulty in achieving passive detection, or strong dependence on cache effectiveness when detecting the security of DNS domain name servers, the present invention proposes a passive detection system for DNS server security based on browser search, and constructs a full-link security protection system from the user side to the network infrastructure through a multi-dimensional security verification and active monitoring mechanism. All technical solutions of the present invention are implemented on the premise of complying with relevant laws and regulations on personal information protection and meet the relevant circumstances of legal use.

[0006] The non-intrusive detection system for DNS server security based on browser search provided by the present invention uses the browser as a security verification node and a network perception terminal, and the non-intrusive detection system of the present invention is deployed in the browser. The non-intrusive detection system of the present invention includes a receiving module, a legality approval and credibility screening module, a multi-layer verification module, and a health status monitoring and dynamic risk assessment module. The multi-layer verification module includes an authenticity verification module, a multi-path request and consistency comparison module, and a comparison analysis and redundancy screening module.

[0007] When a user uses a browser to input a request, the receiving module normalizes the user request and outputs keywords in a preset format. The legality approval and credibility screening module performs the following operations: First, it performs semantic analysis and expansion on the keywords output by the receiving module, generates a list of candidate URLs based on the keywords and the expanded words, then further screens the candidate URLs in combination with the user's historical access records and the current context, then checks the legality of the screened candidate URLs, and finally evaluates the credibility of the legal candidate URLs, and outputs the candidate URLs sorted from high to low according to credibility.

[0008] The multi-layer verification module initiates a DNS resolution request for the candidate URLs, including sending resolution requests to the local DNS server and K external trusted DNS servers, obtaining the resolution paths and results, and monitoring the security of the resolution paths and results of the local DNS server; K is greater than 1; the multi-path request and consistency comparison module simultaneously sends resolution requests for the candidate URLs to the K external trusted DNS servers and the local DNS server, compares the resolution results of the local DNS server with the resolution results returned by the external DNS servers, and if they are inconsistent, triggers the security verification mechanism in the authenticity verification module.

[0009] The functions implemented by the authenticity verification module include: detecting whether the local DNS has been tampered with; verifying the resolution paths and results of the external trusted DNS servers; performing anomaly analysis on the historical resolution patterns of the local DNS server using a graph neural network; using the IP address resolved by the local DNS server as the target website, dynamically generating an HTTP request that conforms to the business characteristics of the target website using an intelligent camouflage engine, and performing security verification on the target website.

[0010] The comparison analysis and redundancy screening module removes redundancy from the resolution results returned by the external trusted DNS servers, compares the differences between the resolution results of the local DNS server and the external trusted DNS servers, and makes a final decision output based on the principle of preferentially using the resolution results of the external trusted DNS servers.

[0011] The health status monitoring and dynamic risk assessment module monitors the health status and performance of the local DNS server in real time.

[0012] The described authenticity verification module uses the IP address resolved by the local DNS server as the target website for security verification. The verification method is as follows: Crawl the historical traffic data of the target website, and extract the typical traffic characteristics of the target website from it, including HTTP request header information, request time interval rules, and user interaction behaviors; Then, the intelligent camouflage engine generates simulated HTTP GET or POST requests that conform to the business characteristics of the target website based on the extracted typical traffic characteristics, and sends requests to the target website at randomized request intervals; Finally, by comparing the differences in the responses of the target website to the service nodes and the pure dial-test nodes, man-in-the-middle attacks or page hijacking behaviors are detected and identified.

[0013] The described health status monitoring and dynamic risk assessment module constructs a three-dimensional monitoring matrix for the local DNS server, including: (1) At the infrastructure level, use the stealth probe technology to collect DNS resolution data from the terminal browser in real time, including DNS resolution delay, TTL value, and resolution path; The stealth probe technology refers to embedding a lightweight HTTP verification request in the normal user request, processing the user request traffic using a traffic feature obfuscation algorithm to simulate the statistical characteristics of real user traffic, and then sending it to the terminal browser, and the terminal browser returns the DNS resolution data collected in real time; (2) At the user behavior level, collect user behavior data, including page loading trajectories, resource request time sequences, and interaction event streams; (3) At the security protection layer, the server side monitors the TLS handshake process, certificate chain integrity, and compliance with the HSTS protocol for user access in real time.

[0014] The described health status monitoring and dynamic risk assessment module uses the constructed health assessment model to monitor risks and identify anomalies for the local DNS server; The health assessment model contains 21-dimensional data, which are: DNS resolution response time, DNS return result consistency, DNS resolution path topology change, TTL abnormal fluctuation situation, abnormal geographical location of the DNS server IP, abnormal recursive query depth, abnormal DNS response packet size, abnormal load characteristics of the DNS server, domain name resolution failure frequency, DNSSEC verification status, abnormal situation of the EDNS0 extension field, DNS response cache hit rate, abnormal software version of the DNS server, abnormal characteristics of DNS request redirection, abnormal proportion of DNS server response types, DNS server reachability, fluctuation of DNS resolution success rate, domain name blacklist trigger record, frequency of historical abnormal events of the DNS server, difference degree between the DNS return IP and the expected IP, and abnormal flag bits of the DNS response message. Among them, DNSSEC represents, and EDNS0 is an extension mechanism of the DNS protocol.

[0015] The advantages and positive effects of the present invention are as follows:

[0016] (1) Through multi-layer verification and consistency comparison, the system of the present invention can identify more potential attacks and risks of data tampering, significantly improving security. The system of the present invention first conducts a trusted authentication on the candidate URL, and at the same time initiates a distributed parsing request to the LDNS and other hierarchical DNS servers. Through cross-comparing the parsing results, multiple verifications are achieved. It not only verifies the mapping relationship from the domain name to the IP, but also dynamically simulates and generates HTTP requests that conform to the real user traffic characteristics of the target website through an intelligent camouflage engine, effectively avoiding the problem that pure probing traffic is easily detected and blocked.

[0017] (2) The legality approval and credibility screening module of the system of the present invention combines semantic extension technology to expand the keywords in the user request, establishes a dynamic URL candidate pool, further screens the candidate URLs in combination with the user's historical access records and the current context, conducts a legality check based on the threat intelligence library, the validity of the HTTPS certificate, etc., and performs a credibility score. The system of the present invention innovatively constructs a multi-dimensional intelligent screening mechanism that integrates semantic extension, historical behavior analysis, and real-time intelligence perception (i.e., the current context) to ensure the high security and credibility of the user's accessed URL.

[0018] (3) By comparing the results of external authoritative DNS and local DNS, the system of the present invention can reduce the parsing inaccuracy caused by single-source errors, further improving the parsing accuracy. Different from traditional probing schemes, the system of the present invention gives full play to the group perception advantage of the browser terminal. Through the collection of massive user behavior data, the network traffic characteristics in the real scenario are refined. When the system conducts security probing, it dynamically selects the most matching simulation request parameters and traffic patterns to generate highly simulated probing requests, improving the concealment and effectiveness of the probing. At the same time, the system of the present invention establishes a parsing path traceability mechanism to accurately locate and isolate abnormal parsing nodes, ensuring that users always obtain a safe and trusted parsing service.

[0019] (4) When using the system of the present invention, due to the background-unaware security access mechanism and real-time health monitoring, users can enjoy a faster response time and a smoother access experience, and the overall user experience is significantly improved.

[0020] (5) When using the system of the present invention, problems existing in the prior art such as large cost overhead, difficulty in achieving unperceived detection, and high dependence on cache effectiveness are solved. Through a multi-dimensional security verification and active monitoring mechanism, a full-link security protection system from the user side to the network infrastructure is constructed. Brief Description of the Drawings

[0021] Figure 1 is a schematic diagram of the unperceived detection system for DNS server security based on browser search in an embodiment of the present invention;

[0022] Figure 2 is a functional implementation flow chart of the legality verification and credibility screening module of an embodiment of the present invention;

[0023] Figure 3 It is a functional implementation flow chart of the authenticity verification module of an embodiment of the present invention. DETAILED DESCRIPTION

[0024] The present invention will be further described in detail below with reference to the accompanying drawings and embodiments.

[0025] like Figure 1 As shown, the DNS server security non-sensing detection system based on browser search in the embodiment of the present invention mainly includes the following modules:

[0026] 1) Receiving module: responsible for receiving user input requests, performing preliminary normalization processing on the request content, and then outputting keywords in a preset format.

[0027] 2) Legality verification and credibility screening module: mainly responsible for generating a list of URL candidates, and combining multi-dimensional data sources such as context and historical access records to verify the legality and credibility of candidate URLs.

[0028] 3) Multi-layer verification module: responsible for initiating DNS resolution requests and monitoring the security of resolution paths and results. This module includes an authenticity verification module, a multi-path request and consistency comparison module, and a comparison analysis and redundancy screening module.

[0029] 4) Authenticity verification module: Performs authenticity verification on DNS resolution results, verifies the credibility of the results through multi-source cross-validation, data consistency check, etc., and ensures the validity and integrity of the resolution data.

[0030] 5) Multi-path request and consistency comparison module: This module initiates multi-path requests to multiple external authoritative DNS servers to obtain independent resolution results, and performs consistency comparison with local DNS results to identify potential tampering or attack risks.

[0031] 6) Comparison analysis and redundancy screening module: responsible for comparing resolution data from different DNS sources and performing data consistency and redundancy screening.

[0032] 7) Health status monitoring and dynamic risk assessment module: real-time monitoring of the health status and performance of the local DNS server, including indicators such as response time, availability, and resolution accuracy.

[0033] The system of the present invention achieves the following two key goals through the above modules:

[0034] (1) When a user uses a browser to enter keywords to access the network, security protection for the transformation process from keywords to URLs. After the user enters keywords in the browser, the receiving module performs preliminary preprocessing on the keywords, such as removing meaningless characters and unifying formatting; subsequently, the legality approval and credibility screening module will combine semantic expansion technology (based on existing natural language processing models, such as BERT or GPT) to perform semantic analysis on the keywords, intelligently generate synonymous or near-synonymous expansions of the keywords, and thus establish a dynamic URL candidate pool. Then, the candidate URLs are checked for legality in combination with a threat intelligence library and a black and white list mechanism, and security filtering and sorting are implemented based on criteria such as domain name reputation scoring and HTTPS certificate validity. In this process, a multi-dimensional intelligent screening mechanism integrating semantic expansion, historical behavior analysis, and real-time intelligence perception is innovatively constructed to ensure the high security credibility of the URLs accessed by users.

[0035] (2) While protecting the security of the user using the browser to enter keywords, implement invisible detection of the local DNS server. When the user searches and accesses normally through the browser, the multi-layer verification module implicitly initiates a resolution request to the local DNS server, and at the same time triggers multiple external authoritative DNS servers for distributed resolution, innovatively adopting a distributed multi-path comparison and verification mechanism. On this basis, the present invention introduces an intelligent camouflage engine, uses historical user access behavior feature data to construct a dynamic HTTP request parameter model (including request header features, request timing features, interaction behavior features, etc.) to imitate real user request traffic and avoid the recognition and countermeasures of the DNS server against detection behavior. At the same time, the system also innovatively deploys an invisible probe technology, embedding lightweight detection requests with feature obfuscation in normal user traffic, making the security monitoring traffic and normal user traffic almost indistinguishable, thus achieving true invisible detection.

[0036] The implementation functions of each module are described below.

[0037] After receiving the user request, the receiving module first obtains the keywords of the request entered by the user through the browser; then performs preliminary content processing, performs basic normalization processing on the keywords, including removing irrelevant characters, formatting, etc.; finally, structures the request data and converts the request into a structured data format that is easy for subsequent analysis and processing.

[0038] Such as Figure 2As shown in the figure, the legality approval and credibility screening module first performs semantic analysis on the keywords output by the receiving module, expands the semantics of the keywords, searches for relevant extended words, and then generates a list of candidate URLs based on the keywords and relevant extended words; then, in combination with the user's historical access records, high-correlation candidate URLs are screened out from the list; then, the candidate URLs are further screened according to the current context such as time and location; then, legality approval is performed, that is, technologies such as domain name reputation scoring and HTTPS detection are used to check the legality of the candidate URLs, and the legality of the candidate URLs is verified based on the threat intelligence library and the black and white list mechanism; finally, credibility evaluation is performed, and multi-dimensional evaluation indicators are integrated, such as integrating page reputation rating, certificate validity, service continuity, etc., to evaluate the credibility of the candidate URLs. The method for the legality approval and credibility screening module of the embodiment of the present invention to generate a list of URL candidates is: when the keywords are obtained, the module first automatically identifies and expands the semantic synonyms and related words of the keywords through a semantic expansion algorithm such as the BERT model based on the Transformer architecture, and generates a list of candidate URLs based on the keywords and the extended words; then, in combination with the user's historical click behavior data, such as the user's past keyword-URL click records, and real-time context information such as time and region, a list of candidate URLs with high relevance is screened out from the list. This process integrates existing natural language processing technologies and historical data analysis, but its application method in DNS security detection is one of the innovation points of the present invention.

[0039] The legality approval and credibility screening module of the system of the present invention constructs a dynamic URL candidate pool by integrating user keyword requests, real-time environmental data (including geographical location, network environment, etc.) and a multi-dimensional intelligent analysis engine (covering semantic understanding, context association, historical behavior modeling), and implements hierarchical security filtering. On the one hand, the legality approval and credibility screening module verifies the legality of the candidate URLs based on the threat intelligence library and the black and white list mechanism, and on the other hand, realizes the security weight ranking of the candidate URLs through a credibility evaluation model. The credibility evaluation model of the embodiment of the present invention is constructed by integrating indicators such as page reputation rating, certificate validity, and service continuity.

[0040] The multi - layer verification module verifies candidate URLs in sequence, giving priority to processing candidate URLs with high credibility, including: first, initiating DNS resolution requests, including sending resolution requests to the local DNS server to obtain the target IP address, and sending requests to authoritative DNSs. Multiple trusted external authoritative DNSs can be simultaneously sent resolution requests to obtain the resolution path and results; then, real - time monitoring of the DNS resolution path is carried out to identify potential security risks; finally, IP consistency check is performed, that is, checking the consistency between the target IP address of the resolution result and the expected target IP address of the authoritative resolution data recorded in the trusted URL list from the legality approval and credibility screening module. To strengthen the verification system, the system of the present invention constructs a multi - level cross - verification architecture, not only initiating recursive queries to the local DNS, but also synchronously triggering cloud - based distributed detection nodes for global DNS resolution, and accessing the blockchain evidence - storing system to realize the traceability of the resolution path.

[0041] The multi - path request and consistency comparison module first sends resolution requests to multiple authoritative DNS servers and trusted external DNS servers to obtain the resolution paths and results returned by each DNS server, and at the same time obtains the resolution result of the local DNS server. Subsequently, hash comparison technology is used to compare the resolution result of the local DNS with the results returned by external DNSs to quickly identify the differences between the resolution results; when the results are found to be inconsistent, the system will automatically trigger the security verification mechanism in the authenticity verification module.

[0042] The authenticity verification module receives the local and external authoritative DNS resolution paths and results from the multi - path request and consistency comparison module, uses hash technology to compare the resolution paths and timestamps to detect whether the local DNS has been tampered with. At the same time, through the DNS root server signature chain based on the blockchain, the historical resolution results, resolution paths, resolved IP addresses, TTL (time - to - live) values and their signature data of authoritative DNS servers for key domain names are verified to prevent the resolution records from being maliciously tampered with and improve the credibility of the results. In addition, graph neural networks such as GCN or GraphSAGE are used to perform anomaly analysis on the historical resolution patterns of the local DNS server. The input data of the graph neural network includes: the topological structure of the local DNS server resolving URLs, with the servers providing DNS services as nodes and the edges constructed from the resolution paths; node features, represented as DNS resolution feature vectors including features such as TTL fluctuations, resolution delays, IP consistency, etc.; and the historical interaction relationships between nodes, such as represented by changes in historical resolution paths. The graph neural network outputs the anomaly risk scores of each node and the nodes or paths with high - risk abnormal behaviors in the network to assist in identifying potential abnormal risks.

[0043] At the security verification mechanism level, the IP address resolved by the local DNS server is used as the target website. The authenticity verification module of the present invention adopts an intelligent camouflage engine to dynamically generate HTTP requests that meet the business characteristics of the target website, including header fingerprint simulation, request interval jitter, interactive behavior reproduction and other technologies, so that the verification process has both real user behavior characteristics and can avoid the anti-detection mechanism of malicious nodes. The specific implementation method is as follows: first, the historical traffic of the target website is obtained, and through historical traffic analysis and machine learning, for example, classification algorithms in supervised learning or deep learning models such as LSTM networks are used to extract typical traffic features of the target website, including HTTP request header information such as User-Agent and Accept-Encoding, request time interval rules such as request frequency, access peak hours, and user interaction behaviors such as Cookie usage mechanism, API request features, form submission, etc.; secondly, the intelligent camouflage engine uses the extracted feature data to generate simulated HTTP GET or POST requests that meet the typical access business features of the target website, and initiates requests with randomized request intervals (jitter); finally, by comparing the response differences of the target website to the structure of the data returned by the business node and the pure dialing node, such as loading resources, Cookie processing, and interactive logic, possible man-in-the-middle attacks or page hijacking behaviors are detected and identified. The system of the present invention dynamically adjusts the HTTP request parameters of the target website according to the extracted features to simulate the real user traffic features, effectively avoiding the problem that pure dialing traffic is easily detected and shielded. In the above implementation, although feature extraction and behavior simulation involve existing machine learning and traffic simulation technologies, the present invention innovatively applies them to the field of imperceptible security detection of DNS servers, achieving a significant improvement in the concealment and effectiveness of detection behavior.

[0044] The system of the present invention gives full play to the group sensing advantages of browser terminals, extracts the network traffic characteristics in real scenarios through the collection of massive user behavior data. A policy library is preset in the intelligent camouflage engine, and the data models stored therein include: typical traffic characteristics of different industries and different types of websites, such as HTTP header information, Cookie usage characteristics, request time distribution, page interaction event sequences; historical records of various attacks and abnormal events and corresponding traffic characteristics; statistical characteristics of access requests under dynamic environmental factors such as different geographical locations, network conditions, and time periods. When the system of the present invention performs security probing, according to the typical traffic characteristics of the current target website, it calls the corresponding data models from the policy library in real time, and dynamically selects the most matching simulation request parameters and traffic patterns based on the context information of the current request, including the target URL type, user location, time, etc., to generate highly simulated probing requests, thereby improving the concealment and effectiveness of the probing. At the same time, the policy library has a self-optimization mechanism, regularly extracts features from new terminal access data through machine learning algorithms (such as supervised learning and reinforcement learning), automatically updates and improves the data models, thereby continuously improving the adaptability of the probing policy library. The policy library can provide intelligent guidance for cloud robot probing, realizing the transformation of the security mode from passive defense to active prediction. At the same time, the present invention establishes a parsing path traceability mechanism to accurately locate and isolate abnormal parsing nodes, ensuring that users always obtain safe and trustworthy parsing services.

[0045] The comparison analysis and redundancy screening module compares the parsing results of candidate URLs and removes redundancy for multiple identical parsing results returned externally. The comparison analysis and redundancy screening module synthesizes the parsing results of the local DNS and external authoritative DNS servers, and uses a difference detection algorithm such as the Levenshtein distance to identify abnormal differences in the local parsing results. Make a final decision according to the comparison analysis results, give priority to the parsing results from external trusted sources, and combine the domain name reputation score provided by the legality approval and credibility screening module to adjust and optimize the final output result to ensure the accuracy and credibility of the parsing result. The final decision includes the destination IP address of the parsing, the parsing path, the credibility score, etc.

[0046] The health status monitoring and dynamic risk assessment module monitors key indicators such as the response time, availability, and parsing accuracy of the local DNS server in real time to determine the health status of the LDNS. The health status monitoring and dynamic risk assessment module deeply explores the perception ability of the browser terminal and constructs a three-dimensional monitoring matrix for the LDNS: 1) The infrastructure layer collects network metadata such as DNS parsing delay, TTL value, and parsing path in real time; 2) The user behavior layer analyzes operation characteristics such as page loading trajectory, resource request timing, and interaction event stream; 3) The security protection layer implements TLS (Transport Layer Security Protocol) handshake monitoring, certificate chain verification, and HSTS (HTTP Strict Transport Security) compliance check. A dynamic threat score is achieved through a multi-modal risk assessment model (integrating traffic fingerprint analysis, protocol compliance verification, and behavior baseline comparison). The health status monitoring and dynamic risk assessment module of the present invention first collects DNS parsing data such as TTL value, parsing path, and parsing delay from the terminal browser in real time through an invisible probe; secondly, a JavaScript script is embedded in the user side to record user behavior data such as page loading trajectory, resource request timing, and interaction event stream; finally, the server side performs real-time security monitoring on the TLS handshake process, certificate chain integrity, and HSTS protocol usage compliance of user access.

[0047] To achieve a balance between security and experience, the system of the present invention introduces the invisible probe technology. The invisible probe is a lightweight HTTP verification request embedded in the user's normal request. A lightweight verification request is embedded in the user's normal access process, and a traffic feature obfuscation algorithm is used to obfuscate the verification request traffic of security detection with the traffic of the user's normal business request, making them indistinguishable. Then, the user request traffic is sent to the terminal browser, and the terminal browser parses the HTTP verification request and returns the DNS parsing data collected in real time. The present invention innovatively embeds lightweight HTTP verification requests in the user's normal access process. These requests are processed through a traffic feature obfuscation algorithm to simulate the statistical characteristics of real user traffic, such as request interval, packet size, and HTTP header characteristics, so that the security monitoring traffic and the real business traffic are difficult to distinguish in terms of statistical and behavioral characteristics, avoiding the detection request being identified and blocked by the DNS server or network device.

[0048] More specifically, in the embodiments of the present invention, the health status monitoring and dynamic risk assessment module obtains network status data in 21 dimensions based on the process data of the local DNS server for resolving URLs, including: DNS resolution response time, DNS return result consistency, DNS resolution path topology structure change, abnormal fluctuation of TTL (time to live), abnormal geographical location of the DNS server IP, abnormal recursive query depth, abnormal DNS response packet size, abnormal load characteristics of the DNS server, domain name resolution failure frequency, DNSSEC (DNS Security Extensions) verification status, abnormal situation of the EDNS0 extension field, DNS response cache hit rate, abnormal software version of the DNS server, abnormal characteristics of DNS request redirection, abnormal proportion of DNS server response types, DNS server reachability, fluctuation of DNS resolution success rate, domain name blacklist trigger record, frequency of historical abnormal events of the DNS server, difference degree between the DNS returned IP and the expected IP, and abnormal flag bits of the DNS response message. Through the above dimensions, a health assessment model of the local DNS server is comprehensively constructed to achieve real-time risk monitoring and abnormal identification of the DNS server. EDNS0 is an extension mechanism of the DNS protocol.

[0049] The health status monitoring and dynamic risk assessment module of the present invention statistically analyzes the average value, variance, and trend change of the resolution success rate of the DNS resolution response time for the data in the three-dimensional monitoring matrix of the collected local DNS server; performs dynamic risk trend analysis on the above indicators through time series analysis techniques (such as ARIMA model or LSTM neural network); uses time series analysis techniques to evaluate the dynamic risk status of the DNS server and predict potential problems; and identifies abnormal situations such as a significant increase in DNS response delay, abnormal decrease in resolution success rate, or abnormal fluctuation in resolution accuracy through abnormal detection algorithms such as Isolation Forest or an anomaly detection model based on an autoencoder, thereby ensuring the stability of the DNS service.

[0050] The health status monitoring and dynamic risk assessment module processes the collected data through a multi-modal risk assessment model (integrating machine learning algorithms such as random forest, graph neural network, and sequence model) to output the dynamic threat score of the DNS resolution node, thereby effectively identifying abnormal and attack behaviors in the DNS resolution link. The above data collection and model evaluation methods involve existing data analysis and machine learning technologies, but the present invention innovatively integrates a three-layer data monitoring mode to form a collaborative monitoring and risk assessment system, achieving comprehensive, real-time, and accurate monitoring and protection of the DNS server security risks.

[0051] The present invention also introduces an intelligent learning mechanism. Based on abnormal access patterns collected from a large number of terminals, such as DNS resolution anomalies, page hijacking cases, DNS server response anomaly records, etc., a cloud robot probing strategy library is constructed. Machine learning (such as clustering algorithms and reinforcement learning) is used to continuously optimize the probing strategy to adapt to newly emerging security threats and achieve dynamic adjustment, realizing minute-level synchronization from regional risk warning to global defense strategy. Finally, a security-enhanced DNS resolution ecosystem of "terminal perception - intelligent decision-making - cloud evolution" is formed, which builds a personalized trusted access space for each user while providing seamless security escort.

[0052] Generally speaking, the embodiments disclosed in the present invention can be implemented in hardware or dedicated circuits, software, firmware, logic, or any combination thereof. Some aspects can be implemented in hardware, while other aspects can be implemented in firmware or software executed by a controller, microprocessor, or other computing device. When aspects of this embodiment are illustrated or described as block diagrams, flowcharts, or using some other graphical representation, it will be understood that the blocks, devices, systems, technologies, or methods described herein can be implemented as non-limiting examples in hardware, software, firmware, dedicated circuits or logic, general hardware or controllers or other computing devices, or some combination thereof.

[0053] Except for the technical features described in the specification, they are all known technologies to those skilled in the art. The present invention omits the description of well-known components and well-known technologies to avoid redundancy and unnecessarily limit the present invention. The implementation manners described in the above embodiments do not represent all implementation manners consistent with the present application. On the basis of the technical solution of the present invention, various modifications or deformations that can be made by those skilled in the art without creative efforts are still within the protection scope of the present invention.

Claims

1. A browser search-based non-intrusive detection system for DNS server security, characterized in that The system includes a receiving module, a legality approval and credibility screening module, a multi-layer verification module, and a health status monitoring and dynamic risk assessment module. The multi-layer verification module includes an authenticity verification module, a multi-path request and consistency comparison module, and a comparison analysis and redundancy screening module; Taking the browser as a security verification node and a network perception terminal, the system is deployed in the browser; the user uses the browser to input a request, and the receiving module normalizes the user request and outputs keywords in a preset format; The legality approval and credibility screening module first performs semantic analysis and expansion on the keywords output by the receiving module, generates a list of candidate URLs based on the keywords and the expanded words, further screens the candidate URLs in combination with the user's historical access records and the current context, then checks the legality of the screened candidate URLs, and finally evaluates the credibility of the legal candidate URLs, and outputs the candidate URLs sorted from high to low according to credibility; The multi-layer verification module initiates a DNS resolution request for the candidate URLs, including sending resolution requests to the local DNS server and K external trusted DNS servers, obtaining the resolution paths and results, and monitoring the security of the resolution paths and results of the local DNS server; K is greater than 1; The multi-path request and consistency comparison module simultaneously sends resolution requests for the candidate URLs to K external trusted DNS servers and the local DNS server, compares the resolution results returned by the local DNS server with the resolution results returned by the external DNS servers. If they are inconsistent, it triggers the authenticity verification module, otherwise it directly calls the comparison analysis and redundancy screening module; The functions implemented by the authenticity verification module include: detecting whether the local DNS has been tampered with; verifying the resolution paths and results of the external trusted DNS servers; performing anomaly analysis on the historical resolution patterns of the local DNS server using a graph neural network; using the IP address resolved by the local DNS server as the target website, dynamically generating an HTTP request that conforms to the business characteristics of the target website using an intelligent camouflage engine, and performing security verification on the target website; The comparison analysis and redundancy screening module removes redundancy from the resolution results returned by the external trusted DNS servers, compares the differences between the resolution results of the local DNS server and the external trusted DNS servers, and makes a final decision output based on the principle of preferentially using the resolution results of the external trusted DNS servers; The health status monitoring and dynamic risk assessment module monitors the health status and performance of the local DNS server in real time.

2. The system according to claim 1, wherein The legality check of the candidate URLs by the legality approval and credibility screening module includes: using domain name reputation scoring and HTTPS to detect legality, and checking legality based on the threat intelligence library and the black and white list mechanism.

3. The system according to claim 1, wherein The authenticity verification module receives the resolution paths and results of the local DNS server and the external trusted DNS servers, performs a hash comparison on the resolution paths and timestamps, and detects whether the local DNS has been tampered with.

4. The system according to claim 1, characterized in that, The described authenticity verification module verifies the historical resolution results, resolution paths, TTL values, and signatures of external trusted DNS servers through a blockchain-based DNS root server signature chain; TTL represents the time to live.

5. The system according to claim 1, wherein The described authenticity verification module uses a graph neural network to perform anomaly analysis on the historical resolution patterns of the local DNS server. The input data of the graph neural network includes: the topological structure of the local DNS server for resolving URLs, with the servers providing DNS services as nodes and edges constructed according to the resolution paths; node features, represented by DNS resolution feature vectors, which contain TTL fluctuations, resolution delays, and IP consistency; and the historical interaction relationships between nodes, represented as changes in historical resolution paths. The graph neural network outputs the anomaly risk scores for each node and the nodes or paths with high-risk abnormal behaviors in the network.

6. The system according to claim 1, wherein The described authenticity verification module uses the IP address resolved by the local DNS server as the target website for security verification. The verification method is as follows: crawl the historical traffic data of the target website and extract the typical traffic features of the target website, including HTTP request header information, request time interval patterns, and user interaction behaviors. Then, the intelligent spoofing engine generates simulated HTTP GET or POST requests that conform to the business characteristics of the target website based on the extracted typical traffic features and sends requests to the target website at randomized request intervals. Finally, by comparing the differences in the responses of the target website to business nodes and pure probing nodes, man-in-the-middle attacks or page hijacking behaviors are detected and identified.

7. The system according to claim 6, wherein The described intelligent spoofing engine is provided with a policy library. The data models stored in the policy library include: the typical traffic features of different industries and different types of websites, the historical records of various attacks and abnormal events and their corresponding traffic features, and the statistical features of access requests under dynamic environmental factors. The intelligent spoofing engine selects the most matching simulated request parameters and traffic patterns from the policy library based on the typical traffic features of the current target website to generate HTTP GET or POST requests.

8. The system according to claim 1, wherein The described health status monitoring and dynamic risk assessment module constructs a three-dimensional monitoring matrix for the local DNS server, including: (1) at the infrastructure level, use stealth probe technology to collect DNS resolution data from the terminal browser in real time, including DNS resolution latency, TTL value, and resolution path; the stealth probe technology refers to embedding lightweight HTTP verification requests in normal user requests, processing the user request traffic using a traffic feature obfuscation algorithm to simulate the statistical features of real user traffic, and then sending it to the terminal browser, and the terminal browser returns the DNS resolution data collected in real time; (2) at the user behavior level, collect user behavior data, including page loading trajectories, resource request timings, and interaction event streams; (3) at the security protection layer, the server side monitors the TLS handshake process, certificate chain integrity, and compliance with the HSTS protocol for user access in real time; TLS represents the Transport Layer Security protocol, and HSTS represents the HTTP Strict Transport Security protocol.

9. The system according to claim 1 or 8, characterized in that The described health status monitoring and dynamic risk assessment module uses the constructed health assessment model to monitor risks and identify anomalies in the local DNS server; the health assessment model contains 21-dimensional data, namely: DNS resolution response time, DNS return result consistency, DNS resolution path topology structure change, TTL abnormal fluctuation situation, DNS server IP geographical location anomaly, recursive query depth anomaly, DNS response packet size anomaly, DNS server load abnormal feature, domain name resolution failure frequency, DNSSEC verification status, EDNS0 extension field abnormal situation, DNS response cache hit rate, DNS server software version anomaly, DNS request redirection abnormal feature, DNS server response type ratio anomaly, DNS server reachability, DNS resolution success rate fluctuation, domain name blacklist trigger record, DNS server historical abnormal event frequency, DNS return IP and expected IP difference degree, DNS response message flag bit anomaly; Among them, DNSSEC represents DNS Security Extensions.

Citation Information

Patent Citations

  • Method for optimizing DNS domain name resolution

    CN107071091A

  • Domain name resolution method, domain name resolution device and electronic equipment

    CN112600868A

  • Domain name resolution method and system thereof

    CN112769976A

  • DNS tunnel attack defense system, method and device and storage medium

    CN117061237A

  • Antimicrobial, antiparasite, antiviral and antioxidant compositions of fish comprising Rhus verniciflua lignum extract

    KR1020190058394A

Cited By

  • Domain name system security detection method and device based on multi-dimensional active security detection

    CN120729603A

  • Traffic hijacking detection method and device based on multi-dimensional protocol feature cross validation

    CN122179154A