Domain name resolution protection method and device, equipment and storage medium
By receiving domain name requests and sending the domain name to the corresponding resolution system according to the label matching mechanism, the problem of low efficiency of Internet domain name resolution protection in the existing technology is solved, and more efficient domain name access protection is achieved.
Patent Information
- Application Number
- CN202511006438.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-21
- Publication Date
- 2025-09-12
AI Technical Summary
The efficiency of Internet domain name resolution protection in existing technologies is low, and manual methods are usually used, resulting in insufficient efficiency.
By receiving the user's domain name request, the existence of cached resolution data is determined. If it does not exist, the domain name is sent to the preservation authority server or domain name preservation resolution data system for resolution based on the match between the domain name label and the preset label, and different processing methods are used to improve protection efficiency.
It improves the protection efficiency of Internet domain name resolution and ensures the smoothness and effectiveness of domain name access.
Smart Images

Figure CN120639744A_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of communication technologies, and in particular to a domain name resolution protection method, apparatus, device, and storage medium. Background Art
[0002] Internet domain name resolution protection involves taking appropriate measures to establish domain name resolution preservation resources for protected domain names. When the original Internet domain name resolution resources are compromised, the domain name resolution strategy is restored and the correct resolution results are returned, ensuring smooth and effective access to the protected domain name. Related technologies typically employ manual methods to protect Internet domain name resolution, resulting in low efficiency. Summary of the Invention
[0003] The present disclosure provides a domain name resolution protection method, apparatus, device and storage medium, which improve the efficiency of Internet domain name resolution protection at least to a certain extent.
[0004] Other features and advantages of the present disclosure will become apparent from the following detailed description, or may be learned in part by practice of the present disclosure.
[0005] According to one aspect of the present disclosure, a domain name resolution protection method is provided, comprising:
[0006] receiving a first access domain name request from a user, where the first access domain name request includes a domain name label and a first domain name;
[0007] Determining whether there is cached resolution data corresponding to the first domain name;
[0008] In the absence of cached resolution data, determining whether the domain name label matches a preset domain name label;
[0009] When the domain name tag matches the preset domain name tag, the first domain name is sent to the security authority server so that the security authority server resolves the first domain name.
[0010] In one embodiment of the present disclosure, the method further includes:
[0011] If the domain name label does not match the preset domain name label, determining whether the first domain name is a protected domain name;
[0012] In the case that the first domain name is a protected domain name, the first domain name is sent to a domain name preservation and resolution data system, so that the domain name preservation and resolution data system resolves the first domain name and constructs a domain name label corresponding to the first domain name.
[0013] In one embodiment of the present disclosure, the method further includes:
[0014] receiving a domain name label sent by the first domain name preservation and resolution data system;
[0015] Build a preservation view based on domain name tags.
[0016] In one embodiment of the present disclosure, determining whether cached resolution data corresponding to the first domain name exists includes:
[0017] Based on the comparison between the domain name label and the preservation view, it is determined whether there is cached resolution data corresponding to the first domain name.
[0018] In one embodiment of the present disclosure, the method further includes:
[0019] receiving a second access domain name request from a user, where the second access domain name request includes a second domain name;
[0020] In the case that the second domain name is a domain name protected by resolution, the second domain name is sent to the domain name preservation and resolution data system, so that the domain name preservation and resolution data system resolves the second domain name and constructs a domain name label corresponding to the second domain name.
[0021] In one embodiment of the present disclosure, constructing a domain name label corresponding to the second domain name includes:
[0022] A domain name label corresponding to the second domain name is determined based on a preset intelligent model and a resolution result obtained by resolving the second domain name.
[0023] In one embodiment of the present disclosure, the method further includes:
[0024] If cached resolution data corresponding to the first domain name exists, determining the cached resolution data corresponding to the first domain name;
[0025] Send cached parsed data to the user.
[0026] According to another aspect of the present disclosure, a domain name resolution protection device is provided, comprising:
[0027] A first receiving module is configured to receive a first domain name access request from a user, where the first domain name access request includes a domain name tag and a first domain name;
[0028] A first determining module, configured to determine whether there is cached resolution data corresponding to the first domain name;
[0029] A second determination module, for determining whether the domain name label matches a preset domain name label when no cached resolution data exists;
[0030] The first sending module is configured to send the first domain name to the security authority server when the domain name label matches the preset domain name label, so that the security authority server resolves the first domain name.
[0031] In one embodiment of the present disclosure, the apparatus further comprises:
[0032] a third determining module, configured to determine whether the first domain name is a protected domain name if the domain name label does not match the preset domain name label;
[0033] The second sending module is used to send the first domain name to the domain name preservation and resolution data system when the first domain name is a protected domain name, so that the domain name preservation and resolution data system resolves the first domain name and constructs a domain name label corresponding to the first domain name.
[0034] In one embodiment of the present disclosure, the apparatus further comprises:
[0035] A second receiving module is configured to receive the domain name label sent by the first domain name preservation and resolution data system;
[0036] Building blocks for constructing holds views based on domain labels.
[0037] In one embodiment of the present disclosure, the first determining module includes:
[0038] The determination unit is configured to determine whether there is cached resolution data corresponding to the first domain name based on the comparison between the domain name label and the preservation view.
[0039] In one embodiment of the present disclosure, the apparatus further comprises:
[0040] a third receiving module, configured to receive a second access domain name request from a user, where the second access domain name request includes a second domain name;
[0041] The third sending module is used to send the second domain name to the domain name preservation and resolution data system when the second domain name is a domain name protected by resolution, so that the domain name preservation and resolution data system resolves the second domain name and constructs a domain name label corresponding to the second domain name.
[0042] In one embodiment of the present disclosure, the third sending module includes:
[0043] The construction unit is configured to determine a domain name label corresponding to the second domain name based on a preset intelligent model and a resolution result obtained by resolving the second domain name.
[0044] In one embodiment of the present disclosure, the apparatus further comprises:
[0045] a third determining module, configured to determine the cached resolution data corresponding to the first domain name if there is cached resolution data corresponding to the first domain name;
[0046] The fourth sending module is used to send the cached parsed data to the user.
[0047] According to another aspect of the present disclosure, an electronic device is provided, comprising: a processor; and a memory for storing executable instructions of the processor; wherein the processor is configured to perform the above-mentioned domain name resolution protection method by executing the executable instructions.
[0048] According to another aspect of the present disclosure, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the above-mentioned domain name resolution protection method is implemented.
[0049] The domain name resolution protection method, apparatus, device and storage medium provided by the embodiments of the present disclosure receive a user's first access domain name request, determine whether there is cached resolution data corresponding to the first domain name, and if no cached resolution data exists, determine whether the domain name label matches a preset domain name label. If the domain name label matches the preset domain name label, the first domain name is sent to a security authority server so that the security authority server resolves the first domain name. By setting labels, different domain names are processed in different ways, thereby improving the efficiency of Internet domain name resolution protection.
[0050] It is to be understood that the foregoing general description and the following detailed description are exemplary and explanatory only and are not restrictive of the disclosure. BRIEF DESCRIPTION OF THE DRAWINGS
[0051] The accompanying drawings are incorporated into and constitute a part of the specification, illustrate embodiments consistent with the present disclosure, and together with the specification, are used to explain the principles of the present disclosure. Obviously, the drawings described below are only some embodiments of the present disclosure, and those skilled in the art can derive other drawings based on these drawings without inventive effort.
[0052] Figure 1 A schematic diagram of the structure of a domain name resolution protection system according to an embodiment of the present disclosure is shown;
[0053] Figure 2 A flowchart of a domain name resolution protection method according to an embodiment of the present disclosure is shown;
[0054] Figure 3 A flowchart of another domain name resolution protection method according to an embodiment of the present disclosure is shown;
[0055] Figure 4 A flowchart of another domain name resolution protection method according to an embodiment of the present disclosure is shown;
[0056] Figure 5 A flowchart of another domain name resolution protection method according to an embodiment of the present disclosure is shown;
[0057] Figure 6A flowchart of another domain name resolution protection method according to an embodiment of the present disclosure is shown;
[0058] Figure 7 An interactive diagram of another domain name resolution protection method according to an embodiment of the present disclosure is shown;
[0059] Figure 8 A diagram showing another method and apparatus for domain name resolution protection according to an embodiment of the present disclosure is shown;
[0060] Figure 9 A structural block diagram of an electronic device in an embodiment of the present disclosure is shown. DETAILED DESCRIPTION
[0061] Example embodiments will now be described more fully with reference to the accompanying drawings. However, example embodiments can be embodied in many forms and should not be construed as limited to the examples set forth herein; rather, these embodiments are provided so that this disclosure will be thorough and complete and will fully convey the concepts of the example embodiments to those skilled in the art. The described features, structures, or characteristics may be combined in any suitable manner in one or more embodiments.
[0062] In addition, the accompanying drawings are merely schematic illustrations of the present disclosure and are not necessarily drawn to scale. Identical reference numerals in the figures denote identical or similar parts, and thus repetitive descriptions thereof will be omitted. Some of the block diagrams shown in the accompanying drawings are functional entities that do not necessarily correspond to physically or logically separate entities. These functional entities may be implemented in software, in one or more hardware modules or integrated circuits, or in different networks and / or processor devices and / or microcontroller devices.
[0063] It should be understood that the various steps described in the method embodiments of the present disclosure may be performed in different orders and / or in parallel. In addition, the method embodiments may include additional steps and / or omit the steps shown. The scope of the present disclosure is not limited in this respect.
[0064] It should be noted that the concepts of "first" and "second" mentioned in this disclosure are only used to distinguish different devices, modules or units, and are not used to limit the order or interdependence of the functions performed by these devices, modules or units.
[0065] It should be noted that the modifications of "one" and "multiple" mentioned in the present disclosure are illustrative rather than restrictive, and those skilled in the art should understand that unless otherwise clearly indicated in the context, they should be understood as "one or more".
[0066] It should be pointed out that, in the absence of conflict, the embodiments of the present disclosure and the technical features therein may be combined with each other.
[0067] The specific implementation of the embodiment of the present disclosure is described in detail below with reference to the accompanying drawings.
[0068] Figure 1 A schematic diagram of the structure of a domain name resolution protection system in an embodiment of the present disclosure is shown. The system can apply the domain name resolution protection method or domain name resolution protection device in various embodiments of the present disclosure.
[0069] like Figure 1 As shown, the domain name resolution protection system 10 may include a user terminal 101 and a bearer server 102 for users to access domain names. The user terminal 101 and the domain name server 102 may be located on two different devices. The user terminal 101 may be a module on an electronic device with data acquisition capabilities, such as a recording device with sound collection capabilities, a photographic device with image collection capabilities, and a computer with text information collection capabilities. The domain name server 102 may be a module on an electronic device with processing capabilities, such as a computer. The user terminal 101 and the domain name server 102 may be located on the same device. For example, the user terminal 101 and the domain name server 102 may be an input module and a processing module on a computer or a mobile phone.
[0070] The user terminal 101 and the domain name server 102 are connected to each other via a network, which may be a wired network or a wireless network.
[0071] Optionally, the wireless network or wired network described above uses standard communication technologies and / or protocols. The network is typically the Internet, but may be any network, including but not limited to a local area network (LAN), a metropolitan area network (MAN), a wide area network (WAN), a mobile, wired or wireless network, a private network, or any combination of a virtual private network. In some embodiments, technologies and / or formats including Hypertext Markup Language (HTML) and Extensible Markup Language (XML) are used to represent data exchanged over the network. In addition, conventional encryption technologies such as Secure Sockets Layer (SSL), Transport Layer Security (TLS), Virtual Private Network (VPN), and Internet Protocol Security (IPsec) may be used to encrypt all or some links. In other embodiments, customized and / or dedicated data communication technologies may be used to replace or supplement the above-mentioned data communication technologies.
[0072] The following describes a case where the user terminal 101 and the domain name server 102 are located on two different devices.
[0073] The user terminal 101 may be located on a terminal device, which may be various electronic devices, including but not limited to smart phones, tablet computers, laptop computers, desktop computers, wearable devices, augmented reality devices, virtual reality devices, etc.
[0074] Optionally, the client of the application installed in different terminal devices is the same, or the client of the same type of application based on different operating systems. Based on the different terminal platforms, the specific form of the client of the application can also be different, for example, the application client can be a mobile phone client, a PC client, etc.
[0075] The domain name server 102 can be located on a domain name server. The domain name server can be a domain name server that provides various services, such as a background management domain name server that provides support for devices operated by users using terminal devices. The background management domain name server can analyze and process received requests and other data, and feed back the processing results to the terminal device.
[0076] Optionally, the domain name server can be an independent physical domain name server, or a domain name server cluster or distributed system composed of multiple physical domain name servers. It can also be a cloud domain name server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN (Content Delivery Network), and big data and artificial intelligence platforms.
[0077] Those skilled in the art will know that Figure 1 The number of data acquisition modules and domain name resolution protection modules is merely illustrative, and any number of user terminals and servers may be provided based on actual needs. This disclosure does not limit this.
[0078] In order to solve the above problems, the embodiments of the present disclosure provide a domain name resolution protection method, apparatus, device and storage medium.
[0079] Figure 2 A flow chart of a domain name resolution protection method in an embodiment of the present disclosure is shown.
[0080] like Figure 2 As shown, the method may include:
[0081] S210: Receive a first domain name access request from a user, where the first domain name access request includes a domain name tag and a first domain name.
[0082] In some embodiments, the first domain name access request may be used by a user to access a target domain name.
[0083] In some embodiments, the domain name tag can be a tag corresponding to subsequent processing. Exemplarily, the domain name tag can include: a recursive tag and a cache tag. Exemplarily, the recursive tag can be recursion, which indicates that domain name resolution requires recursion to a designated authoritative server. The cache tag can be cache, which indicates that domain name resolution data is cached locally by the Local DNS.
[0084] It should be noted that the domain name tag can be a tag consisting of a triple. The triple can include the tag category, the tag domain name, and the IP address. An exemplary tag can be: (Tag, Domain, IP Address).
[0085] For example, the following table shows examples of triple labels:
[0086]
[0087]
[0088] S220: Determine whether there is cached resolution data corresponding to the first domain name.
[0089] In some embodiments, determining whether cached resolution data corresponding to the first domain name exists may include determining whether cached resolution data corresponding to the first domain name exists when the domain name tag is a cache class tag.
[0090] In some embodiments, determining whether cached resolution data corresponding to the first domain name exists may include:
[0091] In the absence of the domain name tag, it is determined whether cached resolution data corresponding to the first domain name exists.
[0092] In some embodiments, it may be determined whether cached resolution data is stored in a local domain name system (Local DNS).
[0093] For example, Local DNS (LDNS) is the domain name resolution service infrastructure closest to the user, providing fast DNS resolution. When a user accesses a website, they first request the local DNS to resolve the domain name. If the local DNS has already cached the resolution result for the domain name, it returns the result directly; otherwise, it requests resolution from the public DNS.
[0094] S230: If no cached resolution data exists, determine whether the domain name label matches a preset domain name label.
[0095] In some embodiments, matching a preset domain name tag may include the domain name tag being the same as any one of a plurality of preset domain name tags.
[0096] In some embodiments, a hash algorithm can be used to load and accurately and quickly match domain name labels. A match is determined. If a match is found, the authoritative resolution service is maintained; if a match is found, the normal existing authoritative resolution service is used.
[0097] S240: When the domain name tag matches the preset domain name tag, the first domain name is sent to the authoritative security server, so that the authoritative security server resolves the first domain name.
[0098] In some embodiments, the authoritative server can provide a backup of the resolution resources for certain protected domain names, and can take over the server with the domain name resolution authority when a risk occurs. The authoritative server often requires the cooperation of the protected domain name resolution data system to provide resolution data resources.
[0099] The domain name resolution protection method provided by the embodiment of the present disclosure receives a user's first access domain name request, determines whether there is cached resolution data corresponding to the first domain name, and if there is no cached resolution data, determines whether the domain name label matches the preset domain name label. If the domain name label matches the preset domain name label, the first domain name is sent to the preservation authority server so that the preservation authority server resolves the first domain name. By setting labels, different domain names are processed in different ways, thereby improving the efficiency of Internet domain name resolution protection.
[0100] Figure 3 A flow chart of another domain name resolution protection method in an embodiment of the present disclosure is shown.
[0101] like Figure 3 As shown, the method may include:
[0102] S310: Receive a first domain name access request from a user, where the first domain name access request includes a domain name tag and a first domain name.
[0103] S320, determining whether there is cached resolution data corresponding to the first domain name;
[0104] S330, if no cached resolution data exists, determining whether the domain name label matches a preset domain name label;
[0105] S340: If the domain name tag does not match the preset domain name tag, determine whether the first domain name is a protected domain name.
[0106] In some embodiments, protected domain names may include domain names whose resolution security requirements are technically protected by authoritative servers or DNS service providers to prevent malicious tampering or hijacking.
[0107] S350: When the first domain name is a protected domain name, the first domain name is sent to a domain name preservation and resolution data system, so that the domain name preservation and resolution data system resolves the first domain name and constructs a domain name label corresponding to the first domain name.
[0108] In some embodiments, a trained intelligent model may be used to determine domain name labels.
[0109] For example, the domain name may be parsed first, and after the parsing is completed, the parsed result is input into the intelligent model, and the intelligent model determines the domain name label.
[0110] The domain name resolution protection method provided by the embodiment of the present disclosure receives a user's first access domain name request, determines whether there is cached resolution data corresponding to the first domain name, and if there is no cached resolution data, determines whether the domain name label matches the preset domain name label. If the domain name label matches the preset domain name label, the first domain name is sent to the preservation authority server so that the preservation authority server resolves the first domain name. By setting labels, different domain names are processed in different ways, thereby improving the efficiency of Internet domain name resolution protection.
[0111] Figure 4 A flow chart of another domain name resolution protection method in an embodiment of the present disclosure is shown.
[0112] like Figure 4 As shown, the method may include:
[0113] S410: Receive a first domain name access request from a user, where the first domain name access request includes a domain name tag and a first domain name.
[0114] S420, determining whether there is cached resolution data corresponding to the first domain name;
[0115] S430, if no cached resolution data exists, determining whether the domain name label matches a preset domain name label;
[0116] S440: If the domain name tag does not match the preset domain name tag, determine whether the first domain name is a protected domain name.
[0117] In some embodiments, protected domain names may include domain names whose resolution security requirements are technically protected by authoritative servers or DNS service providers to prevent malicious tampering or hijacking.
[0118] S450: If the first domain name is a protected domain name, send the first domain name to a domain name preservation and resolution data system, so that the domain name preservation and resolution data system resolves the first domain name and constructs a domain name label corresponding to the first domain name.
[0119] S460: Receive the domain name label sent by the first domain name preservation and resolution data system;
[0120] S470, build a preservation view based on domain name tags.
[0121] In some embodiments, the preservation view may be a view constructed for multiple domain name tags for users to search for domain name tags.
[0122] In some embodiments, determining whether cached resolution data corresponding to the first domain name exists includes:
[0123] Based on the comparison between the domain name label and the preservation view, it is determined whether there is cached resolution data corresponding to the first domain name.
[0124] In some embodiments, the domain name tag and the preservation view can be input into the intelligent model to obtain the resolution cache data corresponding to the first domain name.
[0125] The domain name resolution protection method provided by the embodiment of the present disclosure receives a user's first access domain name request, determines whether there is cached resolution data corresponding to the first domain name, and if there is no cached resolution data, determines whether the domain name label matches the preset domain name label. If the domain name label matches the preset domain name label, the first domain name is sent to the preservation authority server so that the preservation authority server resolves the first domain name. By setting labels, different domain names are processed in different ways, thereby improving the efficiency of Internet domain name resolution protection.
[0126] Figure 5 A flow chart of another domain name resolution protection method in an embodiment of the present disclosure is shown.
[0127] like Figure 5 As shown, the method may include:
[0128] S510: Receive a second access domain name request from a user, where the second access domain name request includes a second domain name.
[0129] In some embodiments, the second access domain name may be the same as the first access domain name, and may be two domain names sent by the user at different time points.
[0130] In some embodiments, the second access domain name request may not include a domain name tag.
[0131] S520: If the second domain name is a domain name protected by resolution, the second domain name is sent to a domain name preservation and resolution data system, so that the domain name preservation and resolution data system resolves the second domain name and constructs a domain name label corresponding to the second domain name.
[0132] In some embodiments, before S520, the method may further include:
[0133] For the second domain name resolution, the second domain name cannot access the existing authoritative server.
[0134] S530: Determine a domain name label corresponding to the second domain name based on a preset intelligent model and a resolution result obtained by resolving the second domain name.
[0135] In some embodiments, after obtaining the domain name label, the domain name label may be distributed to multiple local DNSs through an automated script.
[0136] In some embodiments, before S530, the method may further include:
[0137] The intelligent model is trained based on historical parsing results and historical domain name labels to obtain a trained intelligent model.
[0138] Determining a domain name label corresponding to the second domain name based on a preset intelligent model and a resolution result obtained by resolving the second domain name may include:
[0139] The domain name label corresponding to the second domain name is determined based on the resolution result obtained by resolving the second domain name using the trained intelligent model.
[0140] In some embodiments, Local DNS can receive tags and classify matches through a tag matching collaboration module. For cached tags, the cache system loads the tag data into the preservation view. Adaptive sampling technology is used to update cached data, and preservation is automated based on resolution success rate and latency strategies.
[0141] S540: Receive a first domain name access request from a user, where the first domain name access request includes a domain name tag and a first domain name.
[0142] S550, determining whether there is cached resolution data corresponding to the first domain name;
[0143] S560: If no cached resolution data exists, determine whether the domain name label matches a preset domain name label.
[0144] S570: When the domain name tag matches the preset domain name tag, the first domain name is sent to the authoritative security server, so that the authoritative security server resolves the first domain name.
[0145] The domain name resolution protection method provided by the embodiment of the present disclosure receives a user's first access domain name request, determines whether there is cached resolution data corresponding to the first domain name, and if there is no cached resolution data, determines whether the domain name label matches the preset domain name label. If the domain name label matches the preset domain name label, the first domain name is sent to the preservation authority server so that the preservation authority server resolves the first domain name. By setting labels, different domain names are processed in different ways, thereby improving the efficiency of Internet domain name resolution protection.
[0146] Figure 6 A flow chart of another domain name resolution protection method in an embodiment of the present disclosure is shown.
[0147] like Figure 6 As shown, the method may include:
[0148] S610: Receive a first domain name access request from a user, where the first domain name access request includes a domain name tag and a first domain name.
[0149] S620, determining whether there is cached resolution data corresponding to the first domain name;
[0150] S630: If no cached resolution data exists, determine whether the domain name label matches a preset domain name label.
[0151] S640: When the domain name tag matches the preset domain name tag, the first domain name is sent to the authoritative security server, so that the authoritative security server resolves the first domain name.
[0152] S650: If cached resolution data corresponding to the first domain name exists, determine the cached resolution data corresponding to the first domain name;
[0153] S660: Send the cached parsed data to the user.
[0154] In some embodiments, the first access domain name request may include a user identifier, and the cached resolution data may be sent to the user based on the user identifier.
[0155] The domain name resolution protection method provided by the embodiment of the present disclosure receives a user's first access domain name request, determines whether there is cached resolution data corresponding to the first domain name, and if there is no cached resolution data, determines whether the domain name label matches the preset domain name label. If the domain name label matches the preset domain name label, the first domain name is sent to the preservation authority server so that the preservation authority server resolves the first domain name. By setting labels, different domain names are processed in different ways, thereby improving the efficiency of Internet domain name resolution protection.
[0156] In order to explain the present disclosure in detail, the present disclosure also provides an exemplary embodiment.
[0157] Figure 7 An interactive diagram of a domain name resolution protection method in an embodiment of the present disclosure is shown.
[0158] like Figure 7 As shown, the method may include:
[0159] S701: A user initiates a domain name access request corresponding to a first domain name to the Local DNS.
[0160] S702: Local DNS determines that the existing authoritative server cannot be accessed.
[0161] S703: Local DNS sends a resolution failure response to the user.
[0162] S704: When the local DNS determines that the domain name corresponding to the domain name request is a protected domain name, it applies for label data from the domain name preservation and resolution data system.
[0163] S705, the domain name preservation and resolution data system performs resolution based on the domain name and constructs label data.
[0164] S706, the domain name preservation and resolution data system sends the label data to the Local DNS.
[0165] S707, Local DNS completes importing the resolution cache data based on the label data.
[0166] S708: The user again initiates a domain name access request corresponding to the first domain name to the Local DNS.
[0167] S709: Local DNS determines whether there is resolution cache data corresponding to the first domain name based on the first domain name.
[0168] S710: If there is no corresponding resolution cache data, send the first domain name to the security authority server.
[0169] S711: If corresponding parsing cache data exists, return the parsing result.
[0170] Based on the same inventive concept, the present disclosure also provides a domain name resolution protection device, such as the following embodiment. Since the principle of solving the problem in the device embodiment is similar to that in the above method embodiment, the implementation of the device embodiment can refer to the implementation of the above method embodiment, and the repeated parts will not be repeated.
[0171] Figure 8 A structural diagram of a domain name resolution protection device in an embodiment of the present disclosure is shown.
[0172] like Figure 8 As shown, the apparatus 800 may include:
[0173] A first receiving module 810 is configured to receive a first domain name access request from a user, where the first domain name access request includes a domain name tag and a first domain name;
[0174] A first determination module 820 is configured to determine whether there is cached resolution data corresponding to the first domain name;
[0175] A second determination module 830 is configured to determine whether the domain name label matches a preset domain name label when no cached resolution data exists;
[0176] The first sending module 840 is configured to send the first domain name to the security authority server when the domain name tag matches the preset domain name tag, so that the security authority server resolves the first domain name.
[0177] In one embodiment of the present disclosure, the apparatus further comprises:
[0178] a third determining module, configured to determine whether the first domain name is a protected domain name if the domain name label does not match the preset domain name label;
[0179] The second sending module is used to send the first domain name to the domain name preservation and resolution data system when the first domain name is a protected domain name, so that the domain name preservation and resolution data system resolves the first domain name and constructs a domain name label corresponding to the first domain name.
[0180] In one embodiment of the present disclosure, the apparatus further comprises:
[0181] A second receiving module is configured to receive the domain name label sent by the first domain name preservation and resolution data system;
[0182] Building blocks for constructing holds views based on domain labels.
[0183] In one embodiment of the present disclosure, the first determining module includes:
[0184] The determination unit is configured to determine whether there is cached resolution data corresponding to the first domain name based on the comparison between the domain name label and the preservation view.
[0185] In one embodiment of the present disclosure, the apparatus further comprises:
[0186] a third receiving module, configured to receive a second access domain name request from a user, where the second access domain name request includes a second domain name;
[0187] The third sending module is used to send the second domain name to the domain name preservation and resolution data system when the second domain name is a domain name protected by resolution, so that the domain name preservation and resolution data system resolves the second domain name and constructs a domain name label corresponding to the second domain name.
[0188] In one embodiment of the present disclosure, the third sending module includes:
[0189] The construction unit is configured to determine a domain name label corresponding to the second domain name based on a preset intelligent model and a resolution result obtained by resolving the second domain name.
[0190] In one embodiment of the present disclosure, the apparatus further comprises:
[0191] a third determining module, configured to determine the cached resolution data corresponding to the first domain name if there is cached resolution data corresponding to the first domain name;
[0192] The fourth sending module is used to send the cached parsed data to the user.
[0193] The domain name resolution protection device provided by the embodiment of the present disclosure receives a user's first access domain name request, determines whether there is cached resolution data corresponding to the first domain name, and if there is no cached resolution data, determines whether the domain name label matches the preset domain name label. If the domain name label matches the preset domain name label, the first domain name is sent to the preservation authority server so that the preservation authority server resolves the first domain name. By setting labels, different domain names are processed in different ways, thereby improving the efficiency of Internet domain name resolution protection.
[0194] The domain name resolution protection device provided in the embodiment of the present disclosure can be used to execute the domain name resolution protection method provided in the above-mentioned method embodiments. Its implementation principles and technical effects are similar and will not be described here for the sake of simplicity.
[0195] Those skilled in the art will appreciate that various aspects of the present disclosure may be implemented as systems, methods, or program products. Therefore, various aspects of the present disclosure may be implemented in the following forms: a complete hardware implementation, a complete software implementation (including firmware, microcode, etc.), or a combination of hardware and software implementations, which may be collectively referred to herein as "circuits," "modules," or "systems."
[0196] Refer to the following Figure 9 1 and 2 to describe the electronic device 900 according to this embodiment of the present disclosure. Figure 9 The electronic device 900 shown is merely an example and should not limit the functions and scope of use of the embodiments of the present disclosure.
[0197] like Figure 9 As shown, electronic device 900 is implemented as a general-purpose computing device. Components of electronic device 900 may include, but are not limited to, at least one processing unit 99, at least one storage unit 920, and a bus 930 connecting various system components (including storage unit 920 and processing unit 99).
[0198] The storage unit stores program code, which can be executed by the processing unit 99, so that the processing unit 99 performs the steps described in the "Exemplary Method" section above according to various exemplary embodiments of the present disclosure. For example, the processing unit 99 can perform the following steps of the above method embodiment:
[0199] receiving a first access domain name request from a user, where the first access domain name request includes a domain name label and a first domain name;
[0200] Determining whether there is cached resolution data corresponding to the first domain name;
[0201] In the absence of cached resolution data, determining whether the domain name label matches a preset domain name label;
[0202] When the domain name tag matches the preset domain name tag, the first domain name is sent to the security authority server so that the security authority server resolves the first domain name.
[0203] The storage unit 920 may include a readable medium in the form of a volatile storage unit, such as a random access memory unit (RAM) 9201 and / or a cache memory unit 9202 , and may further include a read-only memory unit (ROM) 9203 .
[0204] The storage unit 920 may also include a program / utility 9204 having a set (at least one) of program modules 9205, such program modules 9205 including but not limited to: an operating system, one or more application programs, other program modules, and program data, each of which or some combination may include an implementation of a network environment.
[0205] Bus 930 may represent one or more of several types of bus structures, including a memory bus or memory controller, a peripheral bus, an accelerated graphics port, a processing unit, or a local bus using any of a variety of bus architectures.
[0206] The electronic device 900 can also communicate with one or more external devices 940 (e.g., a keyboard, a pointing device, a Bluetooth device, etc.), one or more devices that enable a user to interact with the electronic device 900, and / or any device that enables the electronic device 900 to communicate with one or more other computing devices (e.g., a router, a modem, etc.). Such communication can occur via an input / output (I / O) interface 950. Furthermore, the electronic device 900 can communicate with one or more networks (e.g., a local area network (LAN), a wide area network (WAN), and / or a public network such as the Internet) via a network adapter 990. As shown, the network adapter 990 communicates with other modules of the electronic device 900 via a bus 930. It should be understood that, although not shown in the figure, other hardware and / or software modules can be used in conjunction with the electronic device 900, including but not limited to microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data backup storage systems.
[0207] Through the description of the above embodiments, it is easy for those skilled in the art to understand that the example embodiments described herein can be implemented by software or by combining software with necessary hardware. Therefore, the technical solution according to the embodiments of the present disclosure can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (such as a CD-ROM, a USB flash drive, a mobile hard disk, etc.) or on a network, and includes several instructions to enable a computing device (such as a personal computer, a server, a terminal device, or a network device, etc.) to execute the method according to the embodiments of the present disclosure.
[0208] In exemplary embodiments of the present disclosure, a computer-readable storage medium is also provided. The computer-readable storage medium may be a readable signal medium or a readable storage medium. A program product capable of implementing the above-described method of the present disclosure is stored thereon. In some possible implementations, various aspects of the present disclosure may also be implemented in the form of a program product comprising program code. When the program product is executed on a terminal device, the program code is used to cause the terminal device to execute the steps according to various exemplary embodiments of the present disclosure described in the "Exemplary Methods" section above of this specification.
[0209] More specific examples of computer-readable storage media in the present disclosure may include, but are not limited to, an electrical connection having one or more conductors, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), optical fibers, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0210] In the present disclosure, a computer-readable storage medium may include a data signal propagated in baseband or as part of a carrier wave, which carries readable program code. Such propagated data signals may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. A readable signal medium may also be any readable medium other than a readable storage medium that can transmit, propagate, or transfer a program for use by or in conjunction with an instruction execution system, apparatus, or device.
[0211] Alternatively, the program code contained on the computer-readable storage medium may be transmitted using any appropriate medium, including but not limited to wireless, wired, optical cable, RF, etc., or any suitable combination thereof.
[0212] In a specific implementation, the program code for performing the operations of the present disclosure may be written in any combination of one or more programming languages, including object-oriented programming languages such as Java, C++, and the like, as well as conventional procedural programming languages such as "C" or similar programming languages. The program code may be executed entirely on the user's computing device, partially on the user's device, as a standalone software package, partially on the user's computing device and partially on a remote computing device, or entirely on a remote computing device or server. In the case of a remote computing device, the remote computing device may be connected to the user's computing device via any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computing device (e.g., via the Internet using an Internet service provider).
[0213] It should be noted that although several modules or units of the device for action execution are mentioned in the detailed description above, this division is not mandatory. In fact, according to the embodiments of the present disclosure, the features and functions of two or more modules or units described above can be concretized in one module or unit. Conversely, the features and functions of one module or unit described above can be further divided into multiple modules or units to be concretized.
[0214] Furthermore, although the steps of the method of the present disclosure are described in a particular order in the accompanying drawings, this does not require or imply that the steps must be performed in this particular order, or that all steps shown must be performed to achieve the desired results. Additionally or alternatively, some steps may be omitted, multiple steps may be combined into one step, and / or one step may be decomposed into multiple steps.
[0215] Through the description of the above embodiments, it is easy for those skilled in the art to understand that the example embodiments described herein can be implemented by software or by combining software with necessary hardware. Therefore, the technical solution according to the embodiments of the present disclosure can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (such as a CD-ROM, a USB flash drive, a mobile hard disk, etc.) or on a network, and includes a number of instructions to enable a computing device (such as a personal computer, a server, a mobile terminal, or a network device, etc.) to execute the method according to the embodiments of the present disclosure.
[0216] Other embodiments of the present disclosure will readily occur to those skilled in the art after considering the specification and practicing the invention disclosed herein. This disclosure is intended to cover any variations, uses, or adaptations of the present disclosure that follow the general principles of the present disclosure and include common knowledge or customary techniques in the art not disclosed herein. The description and examples are to be considered as exemplary only, with the true scope and spirit of the present disclosure being indicated by the appended claims.
Claims
1. A domain name resolution protection method, characterized in that: include: receiving a first domain name access request from a user, where the first domain name access request includes a domain name tag and a first domain name; Determining whether there is cached resolution data corresponding to the first domain name; In the absence of the cached resolution data, determining whether the domain name label matches a preset domain name label; In a case where the domain name tag matches the preset domain name tag, the first domain name is sent to a security authority server so that the security authority server resolves the first domain name.
2. The method according to claim 1, characterized in that The method further comprises: If the domain name label does not match the preset domain name label, determining whether the first domain name is a protected domain name; In the case that the first domain name is a protected domain name, the first domain name is sent to a domain name preservation and resolution data system, so that the domain name preservation and resolution data system resolves the first domain name and constructs a domain name label corresponding to the first domain name.
3. The method according to claim 2, characterized in that The method further comprises: receiving a domain name label sent by the first domain name preservation and resolution data system; A preservation view is constructed based on the domain name label.
4. The method according to claim 3, characterized in that The determining whether cached resolution data corresponding to the first domain name exists includes: Based on the comparison between the domain name tag and the preservation view, it is determined whether there is cached resolution data corresponding to the first domain name.
5. The method according to claim 1, wherein The method further comprises: receiving a second access domain name request from a user, where the second access domain name request includes a second domain name; In the case that the second domain name is a domain name protected by resolution, the second domain name is sent to a domain name preservation and resolution data system so that the domain name preservation and resolution data system resolves the second domain name and constructs a domain name label corresponding to the second domain name.
6. The method according to claim 5, characterized in that The constructing the domain name label corresponding to the second domain name includes: The domain name label corresponding to the second domain name is determined based on a preset intelligent model and a resolution result obtained by resolving the second domain name.
7. The method according to claim 1, characterized in that The method further comprises: If cached resolution data corresponding to the first domain name exists, determining the cached resolution data corresponding to the first domain name; The cached parsed data is sent to the user.
8. A domain name resolution protection device, characterized in that: include: A first receiving module is configured to receive a first domain name access request from a user, where the first domain name access request includes a domain name tag and a first domain name; A first determining module, configured to determine whether there is cached resolution data corresponding to the first domain name; a second determining module, configured to determine whether the domain name label matches a preset domain name label when the cached resolution data does not exist; The first sending module is configured to send the first domain name to a security authority server when the domain name label matches the preset domain name label, so that the security authority server resolves the first domain name.
9. An electronic device, characterized in that: include: processor; as well as a memory for storing executable instructions of the processor; The processor is configured to execute the domain name resolution protection method according to any one of claims 1 to 7 by executing the executable instructions.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the domain name resolution protection method according to any one of claims 1 to 7 is implemented.