Domain name system DNS server push method, electronic device and computer program product
By intercepting DNS response packets and pushing the second DNS server address through the access gateway, the problem that the static configuration of DNS scheme cannot adapt to the access needs of multiple sites and multiple campuses is solved, which improves the success rate and efficiency of DNS requests, and reduces the burden on network devices.
Patent Information
- Application Number
- CN202510852021.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-24
- Publication Date
- 2025-07-22
- Estimated Expiration
- 2045-06-24
AI Technical Summary
In the prior art, the statically configured DNS scheme cannot flexibly adapt to the multi-site and multi-campus access requirements, and the retry efficiency after the DNS request fails.
The DNS response message is intercepted by the access gateway, and the second DNS server address corresponding to the terminal's URL is determined based on the preset URL policy list, and the address is carried in the DNS response message for pushing, optimizing the processing flow after the DNS request fails.
It improves the success rate and efficiency of domain name resolution, reduces the processing pressure of network devices and DNS servers, and enhances the flexibility and stability of network access.
Smart Images

Figure CN120358283A_ABST
Abstract
Description
Technical Field
[0001] The embodiments of the present application relate to the field of communication technologies, and in particular, to a method for pushing a Domain Name System (DNS) server, an electronic device, and a computer program product. Background Art
[0002] In a Broadband Remote Access Server (BRAS), fixed DNS (which can be multiple) server addresses are statically configured. When a user accesses the network through protocols such as Point-to-Point Protocol over Ethernet / IP over Ethernet (PPPoE / IPoE for short), the BRAS will send these pre-configured DNS (Domain Name System) addresses (such as the primary DNS and the secondary DNS) to the user terminal to ensure that the user device uses the specified DNS server for domain name resolution. This configuration method is commonly used in enterprise networks or operator scenarios to achieve centralized control of DNS services (such as binding internal domain name resolution, forcing the use of secure DNS, or load-balanced Anycast DNS), ensuring the stability and security of resolution, and at the same time avoiding uncontrollable risks that may be brought by dynamically obtaining DNS. In the existing fixed network convergence service scenario, the static DNS configuration scheme cannot flexibly adapt to the access requirements of multiple sites and multiple campuses, and the retry efficiency after DNS request failures is low. Summary of the Invention
[0003] The embodiments of the present application provide a method for pushing a Domain Name System (DNS) server, an electronic device, and a computer program product, so as to at least solve the problems that in the related art, the static DNS configuration scheme cannot flexibly adapt to the access requirements of multiple sites and multiple campuses, and the retry efficiency after DNS request failures is low.
[0004] According to an embodiment of the present application, a method for pushing a Domain Name System (DNS) server, which is applied to an access gateway, includes:
[0005] intercepting a DNS response message sent by a first DNS server to a terminal;
[0006] in response to determining that the address of the first DNS server requested according to the DNS response message fails, determining the address of a second DNS server corresponding to the URL of the terminal according to a pre-set Uniform Resource Locator (URL) policy list, where the URL policy list includes the correspondence between URLs and DNS server addresses;
[0007] Send the DNS response message to the terminal, where the DNS response message carries the address of the second DNS server.
[0008] According to another embodiment of the present application, there is also provided a method for pushing a Domain Name System (DNS) server, which is applied to a terminal and includes:
[0009] Receive a DNS response message sent by an access gateway, where the DNS response message carries the address of a second DNS server. The address of the second DNS server is the DNS server address corresponding to a Uniform Resource Locator (URL) determined by the access gateway according to a pre-set URL policy list after intercepting a DNS response message sent by a first DNS server and in response to determining that a request for the address of the first DNS server fails. The URL policy list includes the correspondence between URLs and DNS server addresses;
[0010] Send a DNS request message to the second DNS server through the access gateway, where the DNS request message carries the address of the second DNS server.
[0011] According to still another embodiment of the present application, there is also provided a computer-readable storage medium storing a computer program, where the computer program is configured to execute the steps in any one of the above method embodiments when running.
[0012] According to still another embodiment of the present application, there is also provided an electronic device including a memory and a processor. A computer program is stored in the memory, and the processor is configured to run the computer program to execute the steps in any one of the above method embodiments.
[0013] According to still another embodiment of the present application, there is also provided a computer program product including a computer program, where the computer program implements the steps in any one of the above method embodiments when executed by a processor.
[0014] Through the above embodiments of the present application, the access gateway intercepts the DNS response message. If the DNS server request corresponding to the DNS response message fails, it re-determines the DNS server address corresponding to the URL of the terminal and pushes it to the terminal based on the DNS response message, optimizing the processing flow after a DNS request fails, improving the success rate and efficiency of domain name resolution, and at the same time reducing the processing pressure on network devices and DNS servers. Description of the Drawings
[0015] Figure 1 It is a schematic hardware structure diagram of a mobile terminal on which the method embodiment of the present application runs;
[0016] Figure 2 is the flow of the Domain Name System (DNS) server push method according to an embodiment of the present application Figure 1 ;
[0017] Figure 3 is the flow of the Domain Name System (DNS) server push method according to an embodiment of the present application Figure 2 ;
[0018] Figure 4 is a schematic diagram of domain name access according to an embodiment of the present application;
[0019] Figure 5 is a flow chart of DNS server push and domain name access according to an embodiment of the present application;
[0020] Figure 6 is a schematic diagram of DNS message filling according to an embodiment of the present application. Detailed implementation manners
[0021] In the following, embodiments of the present application will be described in detail with reference to the accompanying drawings and in conjunction with embodiments.
[0022] It should be noted that the terms "first", "second", etc. in the description and claims of the present application and the above-mentioned drawings are used to distinguish similar objects, and do not necessarily describe a specific order or sequence.
[0023] The method embodiments provided in the embodiments of the present application can be executed on a mobile terminal, a computer terminal, or a similar computing device. Taking the operation on a mobile terminal as an example, Figure 1 is a schematic hardware structure diagram of the mobile terminal on which the method embodiment of the present application runs. As Figure 1 shown, the mobile terminal may include one or more ( Figure 1 only one is shown in Figure 1 a processor 102 (the processor 102 may include, but is not limited to, a processing device such as a microprocessor MCU or a programmable logic device FPGA) and a memory 104 for storing data. Among them, the above-mentioned mobile terminal may further include a transmission device 106 for communication functions and an input / output device 108. Those of ordinary skill in the art can understand that Figure 1 the structure shown in Figure 1 is only schematic and does not limit the structure of the above-mentioned mobile terminal. For example, the mobile terminal may further include more or fewer components than
[0024] The memory 104 can be used to store computer programs, for example, software programs and modules of application software, such as the computer program corresponding to the DNS server pushing method in the embodiments of the present application. The processor 102 executes various functional applications and data processing by running the computer program stored in the memory 104, that is, implements the above method. The memory 104 may include a high-speed random access memory, and may also include a non-volatile memory, such as one or more magnetic storage devices, flash memories, or other non-volatile solid-state memories. In some instances, the memory 104 may further include a memory remotely disposed relative to the processor 102, and these remote memories can be connected to the mobile terminal through a network. Examples of the above network include but are not limited to the Internet, enterprise intranet, local area network, mobile communication network, and combinations thereof.
[0025] The transmission device 106 is used to receive or send data via a network. Specific examples of the above network may include a wireless network provided by a communication provider of the mobile terminal. In one instance, the transmission device 106 includes a network adapter (Network Interface Controller, abbreviated as NIC), which can be connected to other network devices through a base station and thus can communicate with the Internet. In one instance, the transmission device 106 may be a radio frequency (RF) module, which is used to communicate with the Internet wirelessly.
[0026] In this embodiment, a DNS server pushing method running on the above mobile terminal or network architecture is provided. Figure 2 It is a flow of the DNS server pushing method according to the embodiments of the present application. Figure 1 , as Figure 2 shown, applied to an access gateway, and the flow includes the following steps:
[0027] Step S202, intercept the DNS response message sent by the first DNS server to the terminal;
[0028] Step S204, in response to determining that the request for the address of the first DNS server fails, determine the address of the second DNS server corresponding to the terminal URL according to a pre-set uniform resource locator (URL) policy list;
[0029] Step S206, send a DNS response message to the terminal, where the DNS response message carries the address of the second DNS server.
[0030] Through the above steps S202 to S206, the access gateway intercepts the DNS response message. If the DNS server request corresponding to the DNS response message fails, it re-determines the DNS server address corresponding to the URL of the terminal and pushes it to the terminal based on the DNS response message, optimizing the processing flow after the DNS request fails, improving the success rate and efficiency of domain name resolution, and reducing the processing pressure on network devices and DNS servers at the same time.
[0031] DNS is one of the core infrastructures of the Internet, responsible for resolving human-readable domain names (such as www.example.com) into corresponding IP addresses (such as 192.0.2.1), so as to enable users to access network services through simple and memorable names. It is based on a distributed database architecture and completes the resolution request through the hierarchical cooperation of root servers, top-level domain servers, and authoritative domain name servers, and uses local caches to accelerate responses. DNS not only supports the efficient location of global network resources, but also expands functions such as load balancing (through Anycast technology) and security protection, and is a key technology to ensure the stable operation and secure access of the Internet. In this context, the DNS server push method aims to, when a terminal attempts to access a certain URL, if the initial DNS request fails (that is, no valid resolution result can be obtained from the first DNS server), the access gateway will intervene and intelligently select the address of a more suitable second DNS server according to a preset URL policy list and push it to the terminal. Through the intelligent selection of the access gateway, the terminal can quickly switch to the optimal DNS server, reduce the resolution delay, and improve the access success rate.
[0032] By enhancing the functions of the access gateway, dynamic optimization of DNS resolution is achieved, reducing the access failure rate caused by DNS configuration errors or server failures, reducing the network load at the same time, and enhancing the user experience. Specifically, by intelligently selecting the second DNS server, unnecessary retries after the initial request fails by the terminal are avoided, the number of recursive queries in the DNS resolution process is reduced, the average delay time of DNS resolution is directly reduced, and the utilization efficiency of network resources is improved.
[0033] In an embodiment, after the above step S202, the method further includes: judging whether the address of the first DNS server fails according to the DNS response message.
[0034] During the DNS request process, after the access gateway intercepts the response message sent back by the first DNS server, it needs to further analyze the response message to determine whether the request is successful. If the response message indicates that the request fails, the access gateway then initiates the DNS server push process. This step ensures that the push action is only executed when it is truly necessary to replace the DNS server, avoiding unnecessary resource consumption. By analyzing the received DNS response message, the access gateway can accurately identify the situation where the DNS request fails, and then trigger the intelligent push mechanism of the DNS server. This precise failure detection mechanism avoids the terminal blindly retrying after the DNS request fails, saving network bandwidth and processing resources. At the same time, it ensures the necessity and effectiveness of the DNS server push, improving the overall network performance and the satisfaction of end users.
[0035] Furthermore, determining whether the request for the address of the first DNS server fails based on the DNS response message can include: determining whether the request for the address of the first DNS server fails according to the return code rcode value in the FLAG field of the DNS response message. Specifically, it can be determined whether the rcode value in the FLAG field of the DNS response message is 0; in the case where the determination result is no, it is determined that the request for the address of the first DNS server fails; in the case where the determination result is yes, it is determined that the request for the address of the first DNS server is successful. In the DNS protocol, the FLAG field of the response message contains an important rcode value for indicating the request status. An rcode value of 0 usually indicates that the request is successful, while other non-zero values may indicate various error codes. For example, when the value is 1, it indicates a format error, and the server cannot understand the request message; when the value is 2, it indicates a server failure because the server cannot process this request due to server reasons, etc. By checking the rcode value, the access gateway can quickly determine whether the first DNS server has successfully processed the request. For example, when the rcode value is 1, it means that the first DNS server has rejected the request, which may be caused by server configuration errors or permission issues. At this time, the access gateway will determine that the request fails and initiate the subsequent DNS server push process.
[0036] Using the rcode value for failure judgment is an efficient and standard method that follows the design principles of the DNS protocol, ensuring that the access gateway can accurately identify the status of DNS requests. In this way, the access gateway can promptly respond to DNS request failure events, quickly take remedial measures, avoid long waits and ineffective retries, and thus significantly improve the efficiency of DNS resolution and the Internet experience of end users.
[0037] In one embodiment, before the above step S206, the above method further includes: adding a first field and a second field to the resource record area of the DNS response message, where the first field is used to carry a DNS server update indication, and the second field is used to carry the address of the second DNS server.
[0038] To notify the terminal of the DNS server update situation, the access gateway will add two fields to the resource record area of the DNS response message. The first field serves as a DNS server update indication to inform the terminal that the DNS server configuration has changed; the second field carries the address of the new DNS server, that is, the address information of the second DNS server. For example, when the access gateway detects that the first DNS server is not working properly, it will add these two fields to the DNS response message sent to the terminal to guide the terminal to update its DNS configuration and point to the better second DNS server. By adding specific indication fields and DNS server addresses in the DNS response message, the access gateway can effectively convey the DNS server update information to the terminal, ensuring that the terminal can timely adjust its DNS settings and avoiding network access problems caused by lagging DNS configuration. It not only improves the flexibility and adaptability of DNS resolution, but also enhances the self-healing ability of the network. Even when the DNS server fails or needs maintenance, it can ensure that the terminal's network access is not affected, maintaining the high availability of network services and the continuity of the user experience.
[0039] Further, adding a first field and a second field to the resource record area of the DNS response message may include: the resource record area includes an answer area, an authority area, and an additional area, and adding the first field and the second field to the answer area, the authority area, or the additional area of the resource record area of the DNS response message.
[0040] The resource record area of the DNS response message is divided into three parts: the answer area, the authority area, and the additional information area. Each area has its specific function. The access gateway can insert the first field (DNS server update indication) and the second field (the address of the second DNS server) into one of these areas. For example, if the DNS request of the terminal is to obtain the authoritative information of a specific domain name, the access gateway may choose to add these fields in the authority area so that when the terminal receives the DNS response, it can immediately recognize the DNS server update requirement and obtain the new DNS server address. Inserting the DNS server update indication and the new address information into different areas of the DNS response message can flexibly convey DNS update information according to the requirements in different scenarios. This method not only ensures the effectiveness of information transmission but also follows the specifications of the DNS protocol, avoiding major changes to the existing network architecture. In practical applications, regardless of whether the DNS request of the terminal is for domain name resolution, authoritative information confirmation, or other purposes, the access gateway can insert update information at an appropriate position to ensure that the terminal can correctly understand and respond to the changes of the DNS server, thereby improving the stability and efficiency of network access.
[0041] In an embodiment of the present application, a method for pushing a Domain Name System (DNS) server is further provided. Figure 3 It is a flow of the method for pushing a DNS server according to an embodiment of the present application. Figure 2 , as Figure 3 shown, which is applied to a terminal. The flow includes the following steps:
[0042] Step S302, receiving a DNS response message sent by an access gateway, where the DNS response message carries the address of a second DNS server, and the address of the second DNS server is the DNS server address corresponding to a URL determined according to a pre-set Uniform Resource Locator (URL) policy list after the access gateway intercepts the DNS response message sent by a first DNS server and in response to determining that the request for the address of the first DNS server fails.
[0043] Step S304, sending a DNS request message to the second DNS server through the access gateway, where the DNS request message carries the address of the second DNS server.
[0044] Through the above steps S302 to S304, the terminal receives the DNS response message, obtains the new DNS server address corresponding to the URL re-determined by the access gateway from the DNS response message, optimizes the processing flow after the DNS request fails, improves the success rate and efficiency of domain name resolution, and simultaneously reduces the processing pressure on network devices and DNS servers.
[0045] When the terminal receives a DNS response message, it will find that it contains the address of the second DNS server pushed by the access gateway. This means that for some reason, the first DNS server that the terminal originally tried to contact failed to respond to its request successfully. In this case, the terminal will initiate a new DNS request according to the new DNS server address carried in the DNS response message and directly query the required domain name information from the second DNS server. For example, when a user tries to access an educational resource website, if the first DNS request fails due to the overload of the first DNS server, the terminal will initiate a new request according to the address of the second DNS server pushed by the access gateway, thus avoiding long waiting times and multiple retries and improving the access speed.
[0046] The DNS server push mechanism on the terminal side, by directly using the new DNS server address pushed by the access gateway, avoids access delays and failures caused by DNS server failures or improper configurations. This method simplifies the DNS resolution process of the terminal and improves the response speed. Especially in a complex network environment with unbalanced DNS server loads, it can significantly enhance the network access experience of terminal users. At the same time, it also promotes the reasonable allocation of network resources, reduces invalid DNS requests, thereby reducing the risk of network congestion and enhancing the stability and security of the entire network.
[0047] Preferably, before the above step S304, the above method further includes: obtaining a DNS server update indication from a first field newly added to the resource record area of the DNS response message; in response to obtaining the DNS server update indication, obtaining the address of the second DNS server from a second field newly added to the resource record area of the DNS response message.
[0048] After receiving the DNS response message, the terminal will first check the newly added first field in the resource record area to obtain the DNS server update indication. Once the update indication is detected, the terminal will read the address of the new second DNS server from the second field and then initiate a new DNS request using this address. For example, when a user tries to access an online course platform and the first DNS request is unsuccessful, the terminal will read the update indication from the DNS response message and obtain the address of the new DNS server, and then directly send a request to this new DNS server in the hope of getting a faster resolution response. The response mechanism of the terminal to the DNS server update indication ensures that the terminal can immediately identify changes in the DNS server and take actions to avoid network access obstacles caused by outdated DNS configurations.
[0049] In the embodiments of the present application, the resource record area may include an answer area, an authority area, and an additional area, and both the first field and the second field are located in the answer area, the authority area, or the additional area of the resource record area.
[0050] The resource record area of the DNS response message is a key part for carrying DNS server response information. It is divided into an answer area, an authority area, and an additional area. When the access gateway pushes DNS server update instructions and new addresses, it will choose to insert the first field and the second field into one of these three areas. For example, if the DNS request of the terminal is to obtain the resolution result of a certain domain name, the access gateway may choose to insert these fields into the answer area so that the terminal can directly find the update instruction and the new DNS server address in the resolution result. Placing the DNS server update instruction and the new address information in different parts of the resource record area can ensure the accurate transmission of information according to the purposes and contexts of different DNS requests.
[0051] In the embodiments of the present application, the DNS node address that can accurately provide domain name resolution services is pushed to the terminal. By identifying the FLAG field in the DNS response message (mainly different values of rcode, representing the success, failure, or other status of the response message), the access gateway can determine in advance that the user request fails; further based on the policy management of the URL, accurately push the DNS address that can be determined to provide resolution services, and update the DNS address of the terminal.
[0052] URL-related ACLs are set on the access gateway (which can be statically configured, dynamically issued, or dynamically obtained from the DNS server, etc.) to set different DNS servers. When the user's DNS request fails, based on the different URLs it accesses, different ACLs are matched and hit, and the DNS node that can resolve the corresponding domain name is pushed in the response message to update the DNS service address of the terminal, so as to realize the ability of fixed-network users to access multiple sites and multiple parks, solve the problem that static DNS cannot fully respond, and avoid the problem of low efficiency of multiple requests and recursive requests during the retry process.
[0053] In the gradually developing fixed-network services, the access requirements of users are gradually expanding. However, the traditional DNS services dedicated to the internal networks of parks / enterprises often do not communicate with the general DNS servers on the public network, and it is impossible to query the internal network IP addresses during the process of gradually querying the root domain name servers, thus affecting the user access. And some existing technologies have relatively large problems in terms of efficiency and cost.
[0054] Figure 4 It is a schematic diagram of domain name access according to the embodiments of the present application, as Figure 4As shown in the figure, enterprise A has an internal access domain name www.qiye.a.com, with the corresponding IP address 10.0.0.1 and the corresponding domain name resolution server DNS a; the Internet has an access domain name www.hulianwang.com, with the corresponding IP address 20.0.0.1 and the corresponding domain name resolution servers DNS1 and DNS2;
[0055] Campus B has an internal access domain name www.xiaoyuan.b.com, with the corresponding IP address 30.0.0.1 and the corresponding domain name resolution server DNS b.
[0056] Because DNS a and DNS b are required for domain name resolution when accessing the campus network, the corresponding scenario users always fail to access. In an embodiment of a related technology, the access gateway provides a DNS proxy service. For DNS requests initiated by the terminal, it requests domain name resolution services from all DNS servers. According to the example, the DNS requests initiated by the user will be sent to all DNS servers (1, 2, a, b) at the same time, and the correct domain name resolution results will be returned by the servers that can resolve. However, this solution will amplify the DNS traffic in the network and increase the processing pressure on the DNS servers.
[0057] In another embodiment of a related technology, the access gateway provides a URL resolution service, terminates the DNS requests of the users, and maps the corresponding DNS service address through the local URL resolution ability, and then initiates DNS resolution again, and accurately sends it to the DNS server that can provide domain name resolution services. However, this solution will process URL resolution for each user's DNS request, increasing the processing pressure on the access gateway and reducing the DNS service efficiency.
[0058] In view of the above problems, the embodiments of the present application propose a new DNS server push and domain name access. Figure 5 It is a flowchart of DNS server push and domain name access according to the embodiments of the present application. As Figure 5 shown, it includes:
[0059] S501, when the terminal goes online, a default DNS is assigned, which is DNS1;
[0060] S502, when the terminal accesses a web page, it initiates a DNS request to DNS1 through the access gateway;
[0061] S503, if the domain name corresponding to DNS1 cannot be resolved, a DNS response is returned;
[0062] S504, the access gateway intercepts the response packet returned by DNS1, queries the correct DNS as DNSa, fills in the resolution response packet to update the DNS service address;
[0063] S505, The terminal initiates a secondary DNS request to DNSa through the access gateway;
[0064] S506, DNSa resolves the corresponding domain name IP address and returns it to the terminal through the access gateway.
[0065] When the terminal goes online, it is assigned a default DNS and makes a request based on DNS1. Since the user's actual access is to the domain name of Company A, DNS1 returns a failure; the access gateway discovers the parsing failure through the FLAG flag bit in the response message and intervenes in the failure return process; based on the ACL policy behavior of the URL, it identifies that the DNS service address for accessing Company A's request is DNSa; the access gateway adds the new DNS server address DNSa to the response message and pushes it; the terminal updates its local DNS address to DNSa and initiates a secondary request; DNSa can resolve it and returns the resolved domain name.
[0066] Access gateways such as BRAS / BNG intercept the DNS request return messages of users that fail, and based on the URL policy, push the correct DNS node, update the DNS address of the terminal, meet the requirements of secondary requests, and improve efficiency and success rate. The specific function points and implementation requirements are as follows:
[0067] 1. Intercept the DNS messages for which the terminal's request fails. In this embodiment, the access gateway filters the user messages, parses the DNS response messages, and judges the value of the rcode bit in the Flag field. When the value is equal to 1, 2, 3, 4, or 5, it means that the DNS server cannot resolve the domain name request, and at this time, it enters step 2 to perform the URL policy judgment to accurately provide the DNS address that can be served.
[0068] 2. Accurately anchor the DNS service address based on the URL policy. In the embodiment of the present application, the access gateway establishes a URL-based policy list locally on the device through static configuration, network management distribution, dynamic DNS acquisition, etc. After intercepting the DNS failure response message in step 1, it further parses the URL of the domain name request in the message, matches the local policy to complete the search for the DNS service address, and is used to push it to the user.
[0069] 3. Fill the new DNS service address in the DNS message and push it to the user along with the DNS response message. Figure 6 It is a schematic diagram of filling the DNS message according to the embodiment of the present application. As Figure 6 shown, after the resource record area (including the answer area, authority area, and additional area) of the DNS response message, a new field is added for filling. For example, after the resource data, a 32 / 128-bit address space is added to carry the updated DNS service address.
[0070] 4. The behavior of the terminal device receiving the DNS response message to update the DNS service address. In this embodiment, after the resource record area (including the answer area, the authority area, and the additional area) of the DNS response message, a new field is added for filling. For example, after the resource data, an 8-bit replace flag space is added to carry the behavior guidance for replacing the DNS service address. When the terminal device receives a flag with a specific indication bit, it performs a specific update behavior. The value design of the replace field is as follows:
[0071] 0x00 represents no update and is used for the response message of successful resolution. At this time, the DNS IP address is 0x00;
[0072] 0x01 represents the scenario where an update is required but the access gateway cannot update. At this time, the DNS IP address is 0x00;
[0073] 0x02 represents that it has been updated. At this time, the DNS IP address filled in is the address used for the update;
[0074] FxFF represents an error and is used for all abnormal scenarios. At this time, the DNS IP address is 0x00;
[0075] The remaining values are temporarily reserved for other future functional scenarios.
[0076] Through the description of the above implementation manners, those skilled in the art can clearly understand that the method according to the above embodiments can be implemented by means of software plus a necessary general hardware platform. Of course, it can also be implemented by hardware, but in many cases, the former is a better implementation manner. Based on such an understanding, the technical solution of the present application, in essence, or the part that makes a contribution to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disc) and includes several instructions for causing a terminal device (which can be a mobile phone, a computer, a server, or a network device, etc.) to execute the methods described in various embodiments of the present application.
[0077] In this embodiment, a Domain Name System (DNS) server push device is further provided. This device is used to implement the above embodiments and preferred implementation manners, and those that have been described will not be repeated. As used hereinafter, the term "module" can be a combination of software and / or hardware that can achieve a predetermined function. Although the devices described in the following embodiments are preferably implemented in software, implementation in hardware, or a combination of software and hardware is also possible and contemplated. The device includes:
[0078] An interception module, configured to intercept the DNS response message sent by the first DNS server to the terminal;
[0079] A determination module, configured to, in response to a failure in determining the address of a first DNS server, determine the address of a second DNS server corresponding to a terminal URL according to a preset list of uniform resource locator (URL) policies;
[0080] A first sending module, configured to send a DNS response message to a terminal, where the DNS response message carries the address of the second DNS server.
[0081] In this embodiment, a Domain Name System (DNS) server push device is further provided. The device includes:
[0082] A receiving module, configured to receive a DNS response message sent by an access gateway, where the DNS response message carries the address of the second DNS server, and the address of the second DNS server is the DNS server address corresponding to a URL determined by the access gateway according to a preset list of uniform resource locator (URL) policies after intercepting a DNS response message sent by the first DNS server and in response to a failure in determining the address of the first DNS server;
[0083] A second sending module, configured to send a DNS request message to the second DNS server through the access gateway, where the DNS request message carries the address of the second DNS server.
[0084] It should be noted that the above-mentioned modules can be implemented by software or hardware. For the latter, it can be achieved in the following ways, but not limited thereto: all the above-mentioned modules are located in the same processor; or, the above-mentioned modules are separately located in different processors in any combination form.
[0085] An embodiment of the present application further provides a computer-readable storage medium, in which a computer program is stored, and the computer program is configured to execute the steps in any one of the above method embodiments when running.
[0086] In an exemplary embodiment, the above computer-readable storage medium may include, but is not limited to: a USB flash drive, a read-only memory (ROM), a random access memory (RAM), a mobile hard disk, a magnetic disk, or an optical disc, and other various media that can store computer programs.
[0087] An embodiment of the present application further provides an electronic device, including a memory and a processor. A computer program is stored in the memory, and the processor is configured to run the computer program to execute the steps in any one of the above method embodiments.
[0088] In an exemplary embodiment, the above electronic device may further include a transmission device and an input / output device, wherein the transmission device is connected to the above processor, and the input / output device is connected to the above processor.
[0089] Specific examples in this embodiment may refer to the examples described in the above embodiments and exemplary embodiments, and will not be repeated here.
[0090] Obviously, those skilled in the art should understand that the above-mentioned modules or steps of the present application can be implemented by a general-purpose computing device. They can be concentrated on a single computing device or distributed on a network composed of multiple computing devices. They can be implemented by program codes executable by the computing device. Thus, they can be stored in a storage device and executed by the computing device. And in some cases, the steps shown or described can be executed in a different order from here, or they can be separately fabricated into individual integrated circuit modules, or multiple modules or steps among them can be fabricated into a single integrated circuit module to be implemented. In this way, the present application is not limited to any specific combination of hardware and software.
[0091] The above is only the preferred embodiment of the present application and is not used to limit the present application. For those skilled in the art, the present application can have various changes and modifications. Any modification, equivalent replacement, improvement, etc. made within the principle of the present application shall be included in the protection scope of the present application.
Claims
1. A method for pushing a Domain Name System (DNS) server, characterized in that, Applied to an access gateway, including: Intercepting a DNS response message sent by a first DNS server to a terminal; In response to determining that the address of the first DNS server cannot be requested successfully according to the DNS response message, determining the address of a second DNS server corresponding to the URL of the terminal according to a pre-set Uniform Resource Locator (URL) policy list, where the URL policy list includes the correspondence between URLs and DNS server addresses; Sending the DNS response message to the terminal, where the DNS response message carries the address of the second DNS server.
2. The method according to claim 1, characterized in that, After intercepting the DNS response message sent by the first DNS server to the terminal, the method further includes: Judging whether the address of the first DNS server cannot be requested successfully according to the DNS response message.
3. The method according to claim 2, wherein Judging whether the address of the first DNS server cannot be requested successfully according to the DNS response message includes: Judging whether the address of the first DNS server cannot be requested successfully according to the return code (rcode) value in the FLAG field of the DNS response message.
4. The method according to claim 1, wherein Before sending the DNS response message to the terminal, the method further includes: Adding a first field and a second field to the resource record area of the DNS response message, where the first field is used to carry a DNS server update indication, and the second field is used to carry the address of the second DNS server.
5. The method according to claim 4, characterized in that, Adding a first field and a second field to the resource record area of the DNS response message includes: The resource record area includes an answer area, an authority area, and an additional area. Adding the first field and the second field to the answer area, the authority area, or the additional area in the resource record area of the DNS response message.
6. A method for a Domain Name System (DNS) server to push, characterized in that, Applied to a terminal, including: Receiving a DNS response message sent by an access gateway, where the DNS response message carries the address of a second DNS server, and the address of the second DNS server is the DNS server address corresponding to the URL determined by the access gateway according to a pre-set Uniform Resource Locator (URL) policy list in response to determining that the address of the first DNS server cannot be requested successfully after intercepting the DNS response message sent by the first DNS server, and the URL policy list includes the correspondence between URLs and DNS server addresses; Sending a DNS request message to the second DNS server through the access gateway, where the DNS request message carries the address of the second DNS server.
7. The method according to claim 6, wherein Before sending the DNS request message to the second DNS server through the access gateway, the method further includes: Obtaining a DNS server update indication from the first field added to the resource record area of the DNS response message; In response to obtaining the DNS server update indication, obtaining the address of the second DNS server from the second field added to the resource record area of the DNS response message.
8. According to the method of claim 7, wherein, The resource record area includes an answer area, an authority area, and an additional area, and both the first field and the second field are located in the answer area, the authority area, or the additional area of the resource record area.
9. An electronic device, comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the steps of the method described in any one of claims 1 to 5 and 6 to 8.
10. A computer program product, characterized in that, It includes a computer program that, when executed by a processor, implements the steps of the method described in any one of claims 1 to 5 and 6 to 8.
Citation Information
Patent Citations
Domain name system (DNS) message processing method and network safety equipment
CN102223422A
Message processing method, device and system
CN102647341A
Redirecting method, device and system for domain name system DNS
CN105791450A
Method and device for solving abnormal DNS caching and computer readable storage medium
CN110830606A
Resource access method and terminal equipment
CN114765605A