Cache poisoning attack prevention method and device based on DNS protocol extension
By encapsulating proof-type opt records in DNS query requests, verification between the recursive server and the authoritative server is solved, and the unreliability and resource consumption of DNS cache poisoning attacks are achieved, and efficient prevention effects are achieved.
Patent Information
- Application Number
- CN202510516582.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-23
- Publication Date
- 2025-07-18
AI Technical Summary
When preventing DNS cache poisoning attacks, the results are unreliable and the detection process consumes a lot of resources.
By encapsulating proof-type opt records in DNS query requests, checking between the recursive server and the authoritative server to ensure the legitimacy of the reply packet and cache it after the verification is passed.
It realizes that while ensuring security, it reduces resource consumption and effectively prevents DNS cache poisoning attacks.
Smart Images

Figure CN120342702A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the technical field of cache poisoning attack prevention, and specifically relates to a method and device for preventing cache poisoning attacks based on DNS protocol extension. Background Art
[0002] DNS cache poisoning attack takes advantage of the basic characteristics of DNS responses, forges incorrect results for a certain zone, and injects them into the cache of the attacked recursive server.
[0003] The basic idea is that the attacker selects the zone to be attacked, and then queries the target recursive server for domain names that have not been cached. Since the domain names are not in the cache, the target recursive server will send a query to the authoritative server of this zone. At this time, the attacker can use a large number of forged responses to attack the recursive server, and each forged response packet has a different forged transaction ID number. If the attacker successfully injects the forged response, the recursive server will cache the NS record constructed by the attacker and its corresponding A record (NS server address) in the forged response. Thereafter, since the attacker has successfully poisoned the NS-related records in this zone, all subsequent recursive queries in this zone of this recursive server will initiate queries to the server provided by the attacker, enabling the attacker to substantially control all results of this authoritative zone.
[0004] Currently, there are already some prevention methods for DNS cache poisoning attacks, but each has its own advantages and disadvantages. The more typical ones are the random domain name case scheme and the DNSSEC scheme.
[0005] The random domain name case scheme is a method for preventing DNS cache poisoning attacks by introducing randomness in DNS queries. The core idea of this method is to randomize the case of domain names in DNS requests to increase the difficulty for attackers to forge DNS responses.
[0006] The DNSSEC scheme is a scheme for enhancing DNS security by signing DNS data. The core concept of DNSSEC is to ensure the integrity, authenticity of DNS responses, and prevent DNS data from being tampered with or forged during transmission.
[0007] However, the reliability of the random domain name case scheme is affected by the length of the requested domain name. The additional protection effect provided by shorter domain names is relatively weak, resulting in unreliable results; while the DNSSEC scheme has the best protection effect, but also has a relatively obvious impact on the performance of recursive queries, resulting in more resources consumed during the detection process. Summary of the Invention
[0008] To this end, the present application provides a method and device for preventing cache poisoning attacks based on DNS protocol extension to solve the problems of unreliable results of existing DNS cache poisoning attack prevention methods and excessive resource consumption during the detection process.
[0009] To achieve the above object, the present application provides the following technical solutions:
[0010] In the first aspect, a method for preventing cache poisoning attacks based on DNS protocol extension, the method is applied to a recursive server, and includes:
[0011] Step 1: Receive a DNS query request sent by a client;
[0012] Step 2: Send a recursive query request to an authoritative server according to the DNS query request; the recursive query request is encapsulated with an opt record of the proof type on the basis of a normal request packet; after receiving the recursive query request, the authoritative server processes the query and fills in the response data, generates a response packet and returns it to the recursive server; the response packet retains the opt record of the proof type;
[0013] Step 3: Receive the response packet returned by the authoritative server and verify the response packet according to the opt record of the proof type;
[0014] Step 4: If the verification fails, discard the response packet;
[0015] Step 5: If the verification passes, determine that the response packet comes from the authoritative server and cache the response packet;
[0016] Step 6: Send a response to the client according to the cached response packet.
[0017] Preferably, in step 2, the opt record of the proof type is in bytes and is an integer value.
[0018] Preferably, in step 2, the opt record of the proof type is filled with actual random data, and the data length corresponds to the value in field A.
[0019] Preferably, in step 2, when the recursive server encapsulates the opt record of the proof type in the recursive query request, it specifically includes: generating random data with a length defined by the policy according to the local policy, then filling the length into field A and the random data into field B.
[0020] Preferably, in step 3, when verifying the response packet according to the opt record of the proof type, specifically:
[0021] Determine whether the response packet contains an opt record of the proof type. If not, the verification fails. If so, determine whether the length value in field A of the opt record of the proof type in the response packet matches the value when it was sent by itself. If not, the verification fails. If it matches, compare the random data in field B byte by byte. If the random data does not match, the verification fails. If the random data matches, the verification passes.
[0022] In a second aspect, a cache poisoning attack prevention device based on DNS protocol extension includes:
[0023] A DNS request receiving module, configured to receive a DNS query request sent by a client;
[0024] A recursive query request sending module, configured to send a recursive query request to an authoritative server according to the DNS query request; the recursive query request is encapsulated with an opt record of the proof type on the basis of a normal request packet; after receiving the recursive query request, the authoritative server processes the query and fills in the response data, generates a response packet and returns it to the recursive server; the response packet retains the opt record of the proof type;
[0025] A verification module, configured to receive the response packet returned by the authoritative server and verify the response packet according to the opt record of the proof type;
[0026] A data discarding module, configured to discard the response packet if the verification fails;
[0027] A data caching module, configured to determine that the response packet comes from the authoritative server if the verification passes and cache the response packet;
[0028] A response module, configured to send a response to the client according to the cached response packet.
[0029] Preferably, when the recursive query request sending module encapsulates an opt record of the proof type in the recursive query request, it specifically includes: generating random data with a length defined by the policy according to the local policy, then filling the length into field A and the random data into field B.
[0030] Preferably, when the verification module verifies the response packet according to the opt record of the proof type, specifically:
[0031] Determine whether the response packet contains an opt record of the proof type. If not, the verification fails. If so, determine whether the length value in field A of the opt record of the proof type in the response packet matches the value when it was sent by itself. If not, the verification fails. If it matches, compare the random data in field B byte by byte. If the random data does not match, the verification fails. If the random data matches, the verification passes.
[0032] In a third aspect, a computer device includes a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, the steps of a method for preventing cache poisoning attacks based on DNS protocol extension are implemented.
[0033] In a fourth aspect, a computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps of a method for preventing cache poisoning attacks based on DNS protocol extension are implemented.
[0034] Compared with the prior art, the present application has at least the following beneficial effects:
[0035] The present application provides a method for preventing cache poisoning attacks based on DNS protocol extension. By receiving a DNS query request sent by a client; sending a recursive query request to an authoritative server according to the DNS query request; the recursive query request is encapsulated with an opt record of the proof type on the basis of a normal request packet; after receiving the recursive query request, the authoritative server processes the query and fills in the response data, generates a response packet and returns it to the recursive server; the response packet retains the opt record of the proof type; receiving the response packet returned by the authoritative server and verifying the response packet according to the opt record of the proof type; if the verification fails, discard the response packet; if the verification passes, determine that the response packet comes from the authoritative server and cache the response packet; send a response to the client according to the cached response packet. The method for preventing cache poisoning attacks based on DNS protocol extension provided by the present application takes into account both the reliability and performance of protection, not only consumes less resources, but also can reliably prevent DNS cache poisoning attacks. BRIEF DESCRIPTION OF THE DRAWINGS
[0036] To more intuitively illustrate the prior art and the present application, exemplary drawings are given below. It should be understood that the specific shapes and structures shown in the drawings generally should not be regarded as limiting conditions when implementing the present application; for example, those skilled in the art are capable of making routine adjustments or further optimizations to the addition / deletion / attribution division of certain units (components), specific shapes, positional relationships, connection methods, dimensional proportional relationships, etc. based on the technical concept disclosed in the present application and the exemplary drawings.
[0037] Figure 1Flowchart of a method for preventing cache poisoning attacks based on DNS protocol extension provided in Embodiment 1 of this application. Detailed implementation manners
[0038] The following further details this application through specific embodiments in conjunction with the accompanying drawings.
[0039] In the description of this application: Unless otherwise specified, "a plurality of" means two or more. Terms such as "first", "second", "third", etc. in this application are intended to distinguish the objects being referred to, and do not have special significance in terms of technical connotations (for example, it should not be understood as emphasizing the importance level or order, etc.). Expressions such as "including", "comprising", "having", etc. also mean "not limited to" (certain units, components, materials, steps, etc.).
[0040] Terms such as "upper", "lower", "left", "right", "middle", etc. cited in this application are usually indications of the general relative position relationship for the convenience of intuitively understanding with reference to the accompanying drawings, and are not absolute limitations on the position relationship in the actual product.
[0041] Embodiment 1
[0042] This embodiment provides a method for preventing cache poisoning attacks based on DNS protocol extension. Through a custom pseudo-resource record type (opt) agreed upon between the authoritative server and the recursive server, this opt record is named the proof type, and this record tape is used as a basis for the recursive server to verify the legitimacy of the response.
[0043] Please refer to Figure 1 , this embodiment provides a method for preventing cache poisoning attacks based on DNS protocol extension. This method is applied to the recursive server and includes:
[0044] S1: Receive a DNS query request sent by the client;
[0045] Specifically, the DNS (Domain Name System) query request is a request sent to the recursive server for resolving a domain name into an IP address, and it is an important process for realizing the mapping between domain names and IP addresses in the Internet.
[0046] S2: Send a recursive query request to the authoritative server according to the DNS query request; The recursive query request is encapsulated with an opt record of the proof type on the basis of a normal request packet; After receiving the recursive query request, the authoritative server processes the query and fills the response data, generates a response packet and returns it to the recursive server; The proof type opt record is retained in the response packet;
[0047] Specifically, in this embodiment, the format definition of the opt record of the proof type is as follows:
[0048] Proof data length: an integer value that describes the length in bytes, i.e., the size of the proof data is measured in "bytes" and this size is an integer value;
[0049] Proof data: the actual random data filling, and the data length corresponds to the value in field A (NS server address).
[0050] In this embodiment, when the recursive server receives a DNS query request and triggers a recursive query request to the authoritative server, on the basis of the normal request packet, it encapsulates an opt record of the proof type. Specifically, according to the local policy, it generates random data with the length defined by the policy, fills the length into field A, fills the random data into field B, and then sends the request.
[0051] After receiving the recursive query request, the authoritative server will normally complete the query process, fill the response data, and then retain the opt record of the proof type sent by the recursive server in the response packet unchanged and send the response.
[0052] S3: Receive the response packet returned by the authoritative server and verify the response packet according to the opt record of the proof type;
[0053] When the recursive server receives the response packet, it will perform basic verification on the response packet. After the verification passes, it will verify the proof data in the response, specifically including:
[0054] Judge whether the response packet contains an opt record of the proof type. If the response packet does not contain a proof type record, it is directly regarded as an invalid response, and the response result is discarded, and the verification is determined to fail;
[0055] If the response packet contains an opt record of the proof type, then judge whether the length value in field A of the opt record of the proof type in the response packet is consistent with the value sent by itself. If the length value in field A is inconsistent with the value sent by itself, it is also regarded as an invalid response, and this response result needs to be discarded, and the verification is determined to fail;
[0056] If the verification of field A in the opt record of the proof type in the response packet passes, then compare the random data in field B byte by byte. If inconsistent data is found, it is regarded as an invalid response, and this response result needs to be discarded, and the verification is determined to fail; if the random data is consistent, the verification passes.
[0057] S4: If the verification fails, discard the response packet;
[0058] S5: If the verification passes, determine that the response packet comes from the authoritative server and cache the response packet.
[0059] Specifically, if all the verifications in the above steps pass, it is considered that this result comes from the real authoritative server rather than an attacker who attempts to attack through cache poisoning. At this time, the response result can be cached.
[0060] S6: Send a response to the client according to the cached response packet.
[0061] A method for preventing cache poisoning attacks based on DNS protocol extension provided by this embodiment. The recursive server can customize random data of any length according to its own strategy to prevent cache poisoning attacks and achieve a stable balance between security and performance (taking into account the reliability and performance of protection). It not only consumes less resources but also can reliably prevent DNS cache poisoning attacks.
[0062] Embodiment 2
[0063] This embodiment provides a device for preventing cache poisoning attacks based on DNS protocol extension, including:
[0064] A DNS request receiving module, configured to receive a DNS query request sent by a client;
[0065] A recursive query request sending module, configured to send a recursive query request to an authoritative server according to the DNS query request; on the basis of a normal request packet, the recursive query request encapsulates an opt record of the proof type; after receiving the recursive query request, the authoritative server processes the query and fills in response data, generates a response packet and returns it to the recursive server; the response packet retains the opt record of the proof type;
[0066] A verification module, configured to receive the response packet returned by the authoritative server and verify the response packet according to the opt record of the proof type;
[0067] A data discarding module, configured to discard the response packet if the verification fails;
[0068] A data caching module, configured to determine that the response packet comes from the authoritative server and cache the response packet if the verification passes;
[0069] A response module, configured to send a response to the client according to the cached response packet.
[0070] Specifically, when the recursive query request sending module encapsulates the opt record of the proof type in the recursive query request, it specifically includes: generating random data of the length defined by the policy according to the local policy, and then filling the length into field A and the random data into field B.
[0071] Specifically, when the verification module verifies the response packet according to the opt record of the proof type, it is specifically as follows:
[0072] Determine whether the response packet contains an opt record of the proof type. If not, the verification fails; if so, determine whether the length value in field A of the opt record of the proof type in the response packet matches the value when it is sent by itself. If not, the verification fails; if it matches, compare the random data in field B byte by byte. If the random data does not match, the verification fails; if the random data matches, the verification passes.
[0073] Regarding the specific implementation content of each module in a cache poisoning attack prevention device based on DNS protocol extension, reference can be made to the definition of a cache poisoning attack prevention method based on DNS protocol extension in the above text, which will not be elaborated here.
[0074] Embodiment III
[0075] This embodiment provides a computer device, including a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, it implements the steps of a cache poisoning attack prevention method based on DNS protocol extension.
[0076] Embodiment IV
[0077] This embodiment provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, it implements the steps of a cache poisoning attack prevention method based on DNS protocol extension.
[0078] The technical features of the above embodiments can be combined arbitrarily (as long as there is no contradiction in the combination of these technical features). For the sake of concise description, not all possible combinations of the technical features in the above embodiments are described; these embodiments not explicitly written out should also be considered to be within the scope described in this specification.
Claims
1. A method for preventing cache poisoning attacks based on DNS protocol extension, characterized in that, The method is applied to a recursive server and includes: Step 1: Receive a DNS query request sent by a client; Step 2: Send a recursive query request to an authoritative server according to the DNS query request; the recursive query request is encapsulated with an opt record of proof type on the basis of a normal request packet; after receiving the recursive query request, the authoritative server processes the query, fills in response data, generates a response packet and returns it to the recursive server; the proof type opt record is retained in the response packet; Step 3: Receive the response packet returned by the authoritative server and verify the response packet according to the proof type opt record; Step 4: If the verification fails, discard the response packet; Step 5: If the verification passes, determine that the response packet comes from the authoritative server and cache the response packet; Step 6: Send a response to the client according to the cached response packet.
2. The method for preventing cache poisoning attacks based on DNS protocol extension according to claim 1, characterized in that, In Step 2, the opt record of proof type is in bytes and is an integer value.
3. The cache poisoning attack prevention method based on DNS protocol extension according to claim 1, characterized in that In Step 2, the opt record of proof type is filled with actual random data, and the data length corresponds to the value in field A.
4. The method for preventing cache poisoning attacks based on DNS protocol extension according to claim 3, wherein, In Step 2, when the recursive server encapsulates an opt record of proof type in the recursive query request, it specifically includes: generating random data with a length defined by the local policy, then filling the length into field A and the random data into field B.
5. The cache poisoning attack prevention method based on DNS protocol extension according to claim 3, characterized in that, In Step 3, when verifying the response packet according to the proof type opt record, specifically: Judge whether the response packet contains an opt record of proof type. If not, the verification fails; if so, judge whether the length value in field A of the opt record of proof type in the response packet is consistent with the value when it is sent by itself. If not, the verification fails; if it is consistent, compare the random data in field B byte by byte. If the random data is inconsistent, the verification fails; if the random data is consistent, the verification passes.
6. A cache poisoning attack prevention device based on DNS protocol extension, characterized in that It includes: A DNS request receiving module, configured to receive a DNS query request sent by a client; A recursive query request sending module, configured to send a recursive query request to an authoritative server according to the DNS query request; The recursive query request is encapsulated with an opt record of proof type on the basis of a normal request packet; After receiving the recursive query request, the authoritative server processes the query, fills in response data, generates a response packet and returns it to the recursive server; The proof type opt record is retained in the response packet; A verification module, configured to receive the response packet returned by the authoritative server and verify the response packet according to the proof type opt record; A data discarding module, configured to discard the response packet if the verification fails; A data caching module, configured to determine that the response packet comes from the authoritative server and cache the response packet if the verification passes; A response module, configured to send a response to the client according to the cached response packet.
7. The cache poisoning attack prevention device based on DNS protocol extension according to claim 6, characterized in that, When the recursive query request sending module encapsulates the opt record of the proof type in the recursive query request, it specifically includes: generating random data with the length defined by the policy according to the local policy, and then filling the length into field A and the random data into field B.
8. The cache poisoning attack prevention device based on DNS protocol extension according to claim 6, characterized in that, When the verification module verifies the response packet according to the opt record of the proof type, specifically: Judge whether the response packet contains the opt record of the proof type. If not, the verification fails; if so, judge whether the length value in field A of the opt record of the proof type in the response packet matches the value when it is sent by itself. If not, the verification fails; if it matches, compare the random data in field B byte by byte. If the random data does not match, the verification fails; if the random data matches, the verification passes.
9. A computer device, comprising a memory and a processor, the memory storing a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the method described in any one of claims 1 to 7.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the steps of the method described in any one of claims 1 to 7.