Data packet filtering method and device based on domain name
By introducing a Domain Name System (DNS) monitoring module into the vehicle firewall system, dynamic domain name resolution and filtering are achieved, solving the problems of high computational overhead, high latency, and limited coverage in existing technologies, thereby improving system performance and firewall applicability.
Patent Information
- Application Number
- CN202511120522.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-11
- Publication Date
- 2025-11-07
AI Technical Summary
Existing vehicle firewall systems suffer from problems such as high computational and memory overhead, high latency, frequent buffer overflows, and inability to monitor non-DNSmasq ECUs in packet filtering, which affect system performance and firewall coverage.
Design a domain name-based packet filtering method. Utilize an IP filtering module and a Domain Name System (DNS) monitoring module to generate firewall rules through a domain name whitelist, monitor and filter DNS response messages, dynamically update the IP set, and reduce reliance on DNSmasq.
It improves the applicability and efficiency of packet filtering, reduces CPU and memory consumption, enhances the flexibility and coverage of the firewall, and ensures network monitoring and filtering for all ECUs.
Smart Images

Figure CN120915538A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of automotive network security technology, and in particular to a domain name-based data packet filtering method and device. BACKGROUND
[0002] In a vehicle network, with the development of vehicle intelligence and vehicle-to-everything (V2X) technology, the security of the vehicle system and data packet filtering have become a key issue. In order to improve the security of the vehicle system, many vehicle firewalls use an iptables-based solution to filter network traffic and prevent malicious data packets from invading the vehicle network.
[0003] Currently, vehicle firewalls often combine IPset, DNSmasq and iptables to achieve filtering by dynamically resolving domain names to IP addresses and updating IPset. However, DNSmasq has limitations in practical applications, and many vehicle ECUs do not use DNSmasq but rely on other DNS services, which limits the applicability of this solution. In addition, deploying DNSmasq increases the computational and memory overhead, which may affect performance, especially in resource-constrained systems. DNS queries by DNSmasq can also introduce delays, affecting real-time communication. Moreover, its cache entries are limited, which can easily cause cache overflow, increasing the frequency of upstream DNS queries and increasing the burden on the system. Finally, DNSmasq cannot monitor ECUs that use other DNS servers, limiting the coverage and effectiveness of the firewall.
[0004] Therefore, how to improve the applicability, filtering performance and efficiency of data packet filtering and increase the coverage and effectiveness of the firewall is a problem that needs to be solved at present. SUMMARY
[0005] Therefore, the embodiments of the present application provide a domain name-based data packet filtering method and device to solve the problem of how to improve the widespread applicability, filtering accuracy and processing speed of data packet filtering, and enhance the protection capability and coverage of the firewall.
[0006] To achieve the above-mentioned purpose, the embodiments of the present application provide the following technical solutions:
[0007] The first aspect of the present application discloses a domain name-based data packet filtering method, which comprises:
[0008] checking the data packets received by the vehicle using firewall rules in the IP filtering module; the firewall rules are created based on the domain name whitelist included in the domain name set in the IP set module;
[0009] determining whether the data packets checked by the firewall rules meet the domain name system response filtering rules in the IP filtering module;
[0010] If the domain name system response filtering rule is met, the data packet is determined as a domain name system response message, and the domain name system response message is copied to a message queue of a domain name system monitoring module; the domain name system response message is added with a pass-through identifier by the domain name system monitoring module and sent to a kernel network protocol stack, so that the domain name system response message is routed to a corresponding destination address by the kernel network protocol stack; wherein the domain name system monitoring module is initialized in advance;
[0011] The domain name system response message is analyzed and filtered by the domain name system monitoring module, and the IP address in the domain name system response message meeting the analysis and filtering condition is added to the domain name set.
[0012] Preferably, before the data packet received by the whole vehicle is checked by the firewall rule in the IP filtering module, the method further comprises:
[0013] Obtaining a domain name system response filtering rule;
[0014] Obtaining a domain name white list from the domain name set of the IP set module, and generating a firewall rule according to the domain name white list;
[0015] Adding the domain name system response filtering rule and the firewall rule to the IP filtering module.
[0016] Preferably, the process of initializing the domain name system monitoring module comprises:
[0017] After the module information of the domain name system monitoring module is initialized, a network link socket is created;
[0018] A communication connection is established between the network link socket and an IP set module in the kernel;
[0019] A message acquisition thread is created, and a communication connection is established between the network filtering queue API interface and a network filtering queue in the kernel;
[0020] A domain name white list is obtained from a firewall configuration file, and a control message is generated according to the domain name white list;
[0021] The control message is sent to the IP set module through the network link socket, so as to create a domain name set in the IP set module, and the domain name white list is included in the domain name set.
[0022] Preferably, the method further comprises:
[0023] Registering a domain name system monitoring callback function;
[0024] monitoring the communication endpoint and thread of the domain name system monitoring module periodically through the domain name system monitoring callback function;
[0025] if the communication endpoint of the domain name system monitoring module is not in active state, re-communication connection is made to the communication endpoint of the domain name system monitoring module;
[0026] if the thread of the domain name system monitoring module is not in active state, re-creation is made to the thread of the domain name system monitoring module.
[0027] Preferably, the domain name system response message is parsed and filtered by the domain name system monitoring module, and the IP address in the domain name system response message meeting the parsing and filtering condition is added to the domain name set, which comprises:
[0028] the domain name system response message is parsed by the domain name system monitoring module to obtain the DNS data part of the domain name system response message;
[0029] the question area field in the domain name system response message is parsed according to the DNS data part, and the domain name is extracted from the question area field;
[0030] if the domain name is the domain name in the domain name white list, the answer question area field in the domain name system response message is parsed, and the IP address corresponding to the domain name is extracted from the answer question area field;
[0031] the IP address is added to the domain name set of the IP set module.
[0032] The second aspect of the present application discloses a domain name-based data packet filtering device, which comprises:
[0033] a checking unit for checking the data packet received by the whole vehicle by using the firewall rule in the IP filtering module; the firewall rule is created based on the domain name white list included in the domain name set in the IP set module;
[0034] a judging unit for judging whether the data packet checked by the firewall rule meets the domain name system response filtering rule in the IP filtering module;
[0035] The copying unit is configured to determine the data packet as a domain name system response message if the domain name system response filtering rule is met, and copy the domain name system response message to a message queue of the domain name system monitoring module; add a pass-through identifier to the domain name system response message through the domain name system monitoring module, and send the domain name system response message to a kernel network protocol stack, so that the domain name system response message is routed to a corresponding destination address through the kernel network protocol stack; wherein the domain name system monitoring module is initialized in advance.
[0036] The resolving filtering unit is configured to perform resolving filtering on the domain name system response message through the domain name system monitoring module, and add an IP address in the domain name system response message meeting the resolving filtering condition to the domain name set.
[0037] Preferably, the apparatus further comprises:
[0038] The first creating unit is configured to obtain a domain name system response filtering rule.
[0039] The second creating unit is configured to obtain a domain name white list from a domain name set of an IP set module, and generate a firewall rule according to the domain name white list.
[0040] The adding unit is configured to add the domain name system response filtering rule and the firewall rule to an IP filtering module.
[0041] Preferably, the apparatus further comprises:
[0042] The third creating unit is configured to create a network link socket after module information initialization of the domain name system monitoring module is completed.
[0043] The first communication connection unit is configured to establish a communication connection with an IP set module in a kernel through the network link socket.
[0044] The second communication connection unit is configured to create a message obtaining thread, and establish a communication connection with a network filtering queue in the kernel through a network filtering queue API interface.
[0045] The generating unit is configured to obtain a domain name white list from a firewall configuration file, and generate a control message according to the domain name white list.
[0046] The sending unit is configured to send the control message to the IP set module through the network link socket, so as to create a domain name set in the IP set module, wherein the domain name set includes the domain name white list.
[0047] Preferably, the apparatus further comprises:
[0048] The registering unit is configured to register a domain name system monitoring callback function.
[0049] a monitoring unit configured to monitor whether the communication endpoint and the thread of the domain name system monitoring module are active by the domain name system monitoring callback function periodically;
[0050] a reconnection unit configured to reconnect the communication endpoint of the domain name system monitoring module if the communication endpoint of the domain name system monitoring module is not active;
[0051] a reconstruction unit configured to recreate the thread of the domain name system monitoring module if the thread of the domain name system monitoring module is not active.
[0052] Preferably, the resolution filtering unit comprises:
[0053] a resolution module configured to resolve the domain name system response message by using the domain name system monitoring module to obtain a DNS data part of the domain name system response message;
[0054] a domain name extraction module configured to parse a question area field in the domain name system response message according to the DNS data part and extract a domain name from the question area field;
[0055] an IP address extraction module configured to parse an answer question area field in the domain name system response message and extract an IP address corresponding to the domain name from the answer question area field if the domain name is a domain name in the domain name whitelist;
[0056] an adding module configured to add the IP address to the domain name set of the IP set module.
[0057] The domain name system monitoring module is designed and implemented, the dynamic domain name resolution function is supported, the domain name-based packet filtering is implemented, DNSmasq is not needed to be enabled, the CPU and memory consumption are reduced, and the flexibility of the firewall and the platform multiplicity are improved. BRIEF DESCRIPTION OF DRAWINGS
[0058] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings needed to be used in the embodiments or prior art description. Obviously, the drawings in the following description only represent some embodiments of the present application, and for those skilled in the art, other drawings can be obtained based on the provided drawings without any creative effort.
[0059] Figure 1 A flow chart of a domain name-based data packet filtering method provided for the embodiments of the present application;
[0060] Figure 2 A starting flowchart of a domain name-based data packet filtering vehicle iptables firewall provided for the embodiments of the present application;
[0061] Figure 3 A principle diagram of ECU obtaining DNS response for analysis and IPset updating provided for the embodiments of the present application;
[0062] Figure 4 A structural block diagram of a domain name-based data packet filtering device provided for the embodiments of the present application. DETAILED DESCRIPTION
[0063] The technical solutions in the embodiments of the present application will be described clearly and completely below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments only represent some of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without any creative effort fall within the protection scope of the present application.
[0064] In the present application, the term “comprising”, “containing” or any other variant thereof is intended to cover the non-exclusive inclusion, so that the process, method, article or equipment including a series of elements not only includes those elements, but also includes other elements not explicitly listed, or includes the elements inherent to such process, method, article or equipment. Without more limitations, the element defined by the sentence “including a…” does not exclude the presence of other identical elements in the process, method, article or equipment including the element.
[0065] As can be known from the background art, the Domain Name System Masquerade (DNSmasq) in the current vehicle firewall has some problems: it increases the computing and memory overhead, affects the filtering performance, and may introduce Domain Name System (DNS) query delay, affecting real-time communication. In addition, the cache entries of DNSmasq are limited and prone to overflow, resulting in an increase in upstream DNS query frequency and increasing the system burden. At the same time, it cannot monitor Electronic Control Unit (ECU) using other DNS servers, limiting the coverage and effectiveness of the firewall.
[0066] Therefore, the embodiment of the present application provides a domain name-based packet filtering method and device. If the data packet received by the whole vehicle meets the firewall rule in the IP filtering module and the domain name system response filtering rule at the same time, it is determined that the data packet is a domain name system response message; the domain name system response message is copied to the message queue of the domain name system monitoring module; the domain name system response message is added with a pass-through identifier by the domain name system monitoring module and sent to the kernel network protocol stack so as to route the domain name system response message to its corresponding destination address; the domain name system response message is analyzed and filtered by the domain name system monitoring module, and the IP address in the domain name system response message meeting the analysis and filtering condition is added to the domain name set. The domain name system monitoring module is designed and implemented, the dynamic domain name resolution function is supported, and the domain name-based packet filtering is realized. DNSmasq is not needed to be enabled, the CPU and memory consumption are reduced, and the flexibility and platform reusability of the firewall are improved.
[0067] Referring to Figure 1 , a flowchart of a domain name-based packet filtering method provided by the embodiment of the present application is shown, which is a domain name-based packet filtering technology and a solution realized in combination with the vehicle iptables module (i.e. IP filtering module, Internet Protocol Tables). The method comprises:
[0068] It can be understood that the iptables module (i.e. IP filtering module, Internet Protocol Tables) is a firewall tool on the Linux system, which is used to configure IP packet filtering rules in the kernel space. Since these rules are set according to IP addresses rather than domain names, the iptables firewall itself does not directly support domain name-based packet filtering. Based on this, the DNSMonitor module (i.e. Domain Name System monitoring module) is designed and implemented in the vehicle-mounted iptables firewall in the embodiment of the application, which functions to monitor Domain Name System (DNS) responses, obtain DNS response messages (i.e. Domain Name System response messages), and parse these messages to update IP addresses in the IPset set (i.e. domain name set) in the IPset module (i.e. IP set module).
[0069] Step S101: checking the data packets received by the whole vehicle by using the firewall rules in the IP filtering module.
[0070] In actual application, after the TBOX system is started, the domain name-based packet filtering vehicle-mounted iptables firewall is started (i.e. the IP filtering module is started). As shown in Figure 2 , the IP filtering module startup process includes an initialization phase (such as the init phase of the iptables module as shown in Figure 2 ) and a startup phase (such as the start phase of the iptables module as shown in Figure 2 ). First, in the startup phase, the IP filtering module enables the generation of firewall rules (such as adding filtering rules based on the IPset set as shown in Figure 2 ).
[0071] It should be noted that the firewall rules in the IP filtering module are specifically obtained from the domain name set in the IP set module, and are generated according to the domain name whitelist, which includes multiple domain names that are allowed to pass through the firewall.
[0072] For example: the firewall rule is generated by the command "iptables -A OUTPUT -m set --match-set set0 dst -j ACCEPT", which is used to filter data packets with destination addresses as IP addresses corresponding to the domain names contained in the domain name set in the OUTPUT rule chain, and perform the "ACCEPT" operation on these data packets.
[0073] Among them, the OUTPUT rule chain is mounted on the LOCAL_OUT hook point of the Linux network protocol stack.
[0074] In the implementation of step S101, when the application program on all electronic control units (ECU) on the vehicle needs to query a domain name in the working process, a DNS request is initiated for query, and the request message is sent to the DNS server through Ethernet; the DNS server sends the data packet to the TBOX system. The data packet is routed at the data link layer of the TBOX protocol stack: if the destination address of the data packet is the TBOX system, it is routed to the LOCAL IN hook point; if the destination address of the data packet is other ECU, it is routed to the FORWARD hook point. At the LOCAL IN hook point or the FORWARD hook point, the IP filtering module checks the data packet through the firewall rule, and if the data packet passes the firewall rule check, step S102 is performed.
[0075] It should be noted that in the TBOX protocol stack data link layer, the data packet is routed to the LOCAL IN hook point or the FORWARD hook point according to the destination address of the data packet, and the process is as follows (process A1 to process A3):
[0076] Process A1: Determine whether the destination address of the data packet is the TBOX system.
[0077] In the implementation of process A1, the data packet is routed at the TBOX protocol stack data link layer, and it is determined whether the destination address of the data packet is the TBOX system. If the destination address of the data packet is the TBOX system, process A2 is performed; if the destination address of the data packet is not the TBOX system, process A3 is performed.
[0078] Process A2: If the destination address of the data packet is the TBOX system, route the data packet to the LOCAL IN hook point of the iptables module (i.e., the IP filtering module).
[0079] Process A3: If the destination address of the data packet is not the TBOX system, route the data packet to the FORWARD hook point of the iptables module (i.e., the IP filtering module).
[0080] Step S102: Determine whether the data packet that passes the firewall rule check meets the domain name system response filtering rule in the IP filtering module.
[0081] It should be noted that the domain name system response filtering rule is added to the iptables module in advance when the iptables module (i.e., the IP filtering module) is initialized, that is, in the initialization phase (as shown in the init phase), the domain name system response filtering rule (such as Figure 2 Figure 2 The iptables module shown adds the NFQUEUE rule.
[0082] For example, the command "iptables -A INPUT -p tcp --sport 53 -j NFQUEUE –queue_num 0 --queue-bypass" is used.
[0083] The command "iptables -A INPUT -p udp --sport 53 -j NFQUEUE –queue_num 0 --queue-bypass" is used.
[0084] The command "iptables -A FORWARD -p tcp --sport 53 -j NFQUEUE –queue_num 0 --queue-bypass" is used.
[0085] The command "iptables -A FORWARD -p udp --sport 53 -j NFQUEUE –queue_num 0 --queue-bypass" is used to add the domain name system response filtering rule to the iptables module.
[0086] It can be understood that the domain name system response filtering rule is used to filter the data packet with the source port 53 (i.e., the port opened by the DNS server) and via the LOCAL_IN hook point or the FORWARD hook point.
[0087] It can be understood that in a general vehicle network system, all the network connections of the ECUs except the TBOX need to be forwarded through the TBOX. By configuring the domain name system response filtering rule at the INPUT and FORWARD hook points, the network monitoring of all the ECUs of the vehicle can be realized, so that the DNS request of all the domain names in the vehicle can be monitored.
[0088] In the process of implementing step S102, when the data packet meets the firewall rule, it indicates that the data packet passes the firewall rule check, and then it is judged whether the data packet meets the domain name system response filtering rule.
[0089] It should be noted that if the data packet meets the domain name system response filtering rule, step S103 is executed. If the data packet does not meet the domain name system response filtering rule, the process is ended.
[0090] Step S103: If the domain name system response filtering rule is met, the data packet is determined as a domain name system response message, and the domain name system response message is copied to the message queue of the domain name system monitoring module; the domain name system response message is added with a pass-through identifier by the domain name system monitoring module, and is sent to the kernel network protocol stack, so that the domain name system response message is routed to the corresponding destination address by the kernel network protocol stack.
[0091] It should be noted that when the data packet meets the domain name system response filtering rule, the data packet is determined as a domain name system response message (i.e. a DNS response message), and the domain name system response message is stored in the Netfilter queue (such as the Netfilter queue with queue_num=0).
[0092] It should be noted that queue_num is the number of the Netfilter queue, and Netfilter is a packet filtering framework in the Linux kernel.
[0093] In actual application, the IP filtering module takes out the domain name system response message from the Netfilter queue through the message acquisition thread in the domain name system monitoring module (i.e. the DNSMonitor module). Specifically, after the domain name system response message is intercepted and stored in the Netfilter queue, the domain name system monitoring module (i.e. the DNSMonitor module) immediately takes out the domain name system response message from the Netfilter queue, copies the domain name system response message to the message queue of the DNSMonitor module, and then immediately adds a pass-through identifier (such as marked as "ACCEPT") to the domain name system response message and sends it to the kernel network protocol stack, so as to ensure that the kernel network protocol stack routes the domain name system response message to the destination application (or destination address) in the planned time.
[0094] It can be understood that the domain name system monitoring module (i.e. the DNSMonitor module) is initialized in advance, and the initialization process is as follows (process B1 to process B5) in combination with the init phase of the DNSMonitor module in the above-mentioned process A1 to process A5. Figure 2
[0095] Process B1: After the module information of the domain name system monitoring module is initialized, a network link socket is created.
[0096] Process B2: A communication connection is established between the network link socket and the IP set module in the kernel.
[0097] For example, a netlink socket_1 is created to establish a communication connection with the IP set module (i.e. the IPset module) in the kernel.
[0098] Process B3: Create a packet acquisition thread to establish a communication connection with the network filtering queue in the kernel through the network filtering queue API interface.
[0099] For example, a packet acquisition thread is created to establish a communication connection with the network filtering queue (i.e., to the Netfilter queue) in the kernel through the network filtering queue API interface (i.e., the NFQ API interface; for example, netlink socket_0).
[0100] Process B4: Obtain the domain name whitelist from the firewall configuration file, and generate a control packet according to the domain name whitelist.
[0101] It can be understood that the firewall configuration file is read, and a control packet is generated according to the domain name whitelist in the configuration file (the domain name whitelist contains domain names that need to be concerned by the firewall).
[0102] Process B5: Send the control packet to the IP set module through the network link socket to create a domain name set in the IP set module.
[0103] It can be understood that the control packet is sent to the IP set module (i.e., the IPset module) through the network link socket (netlink socket_1) to create a domain name set for the domain names that need to be concerned in the IP set module. That is, the domain name set includes the domain name whitelist.
[0104] It should be noted that the domain names that need to be concerned are, for example, if it is known that there is an application on the device that needs to access the domain name wxx.xxxx.cxx, then the domain name needs to be added to the whitelist, that is, the domain name is a domain name that needs to be concerned.
[0105] It can be understood that after the initialization of the DNSMonitor module is completed, the DNSMonitor module is started, and the DNSMonitor module is combined with Figure 2 The start phase of the DNSMonitor module corresponds to the process of actively initiating a DNS request by creating a DNS request thread, and the process of starting includes processes C1 to C3:
[0106] Process C1: Create a domain name resolution thread through the DNSMonitor module to obtain a firewall configuration file.
[0107] Process C2: Perform domain name resolution on all domain names in the firewall configuration file to obtain IP addresses.
[0108] In the specific implementation of process C2, the domain name resolution thread of the DNSMonitor module performs domain name resolution on all domain names in the firewall configuration file to obtain IP addresses.
[0109] It can be understood that the purpose of this process is to prevent other applications from performing DNS queries before the firewall is started, causing the firewall to fail to capture DNS response packets in time, and thus failing to quickly update the IPset set of domain names.
[0110] Process C3: updating the domain name set in the IPset module based on the IP address.
[0111] In the implementation of process C3, the domain name set in the IPset module is updated based on the IP address obtained through domain name resolution (such as IPset set set0).
[0112] In the application process, referring to the "start ev_loop to resolve the obtained DNS response" shown in Figure 2 The DNSMonitor module performs the process of starting, which also includes (processes D1 to D4):
[0113] Process D1: register the domain name system monitoring callback function.
[0114] In the implementation of process D1, the domain name system monitoring callback function, i.e. the DNSMonitor callback function, is registered in the ev_loop of the main process.
[0115] Among them, ev_loop refers to event loop, which is an important concept in event-driven programming, used to handle the registration, distribution and callback of events.
[0116] Process D2: periodically monitor the communication endpoint and thread of the domain name system monitoring module through the domain name system monitoring callback function.
[0117] In the implementation of process D2, the DNSMonitor callback function is used to periodically monitor whether the communication endpoint (such as the relevant socket) and thread resources of the DNSMonitor module are active.
[0118] It can be understood that if the communication endpoint and thread resources of the DNSMonitor module are not active, it is determined that an exception has occurred, and exception handling is required at this time. The specific content is described in processes D3 and D4.
[0119] Process D3: if the communication endpoint of the domain name system monitoring module is not active, re-communicate the communication endpoint of the domain name system monitoring module.
[0120] In the implementation of process D3, if it is determined that the communication endpoint of the DNSMonitor module is not active, the communication connection of the communication endpoint of the DNSMonitor module is re-established.
[0121] Process D4: If the DNS monitoring module's thread is not active, then recreate the DNS monitoring module's thread.
[0122] In the specific implementation process D4, if it is determined that the threads of the DNSMonitor module (such as the packet acquisition thread and the domain name resolution thread) are not in an active state, then the threads of the DNSMonitor module will be recreated.
[0123] In some specific embodiments, the DNSMonitor module periodically checks its message queue for unresolved DNS response messages. If any are found, they are retrieved and processed. For details of the implementation process, please refer to step S104.
[0124] It should be noted that the DNSMonitor module monitors the packet queue at millisecond intervals. If there are unresolved packets in the packet queue, they will be resolved immediately. Therefore, the packet queue usually does not contain many DNS response packets.
[0125] Step S104: Use the Domain Name System (DNS) monitoring module to parse and filter DNS response messages, and add the IP addresses in the DNS response messages that meet the parse filtering conditions to the domain name set.
[0126] In the specific implementation of step S104, the Domain Name System monitoring module (i.e., the DNSMonitor module) is used to parse and filter the Domain Name System response messages in the message queue, and the IP addresses in the Domain Name System response messages that meet the parse filtering conditions are added to the domain name set.
[0127] The specific steps for parsing and filtering Domain Name System response messages are as follows (processes E1 to E4):
[0128] Process E1: Use the Domain Name System (DNS) monitoring module to parse the DNS response message and obtain the DNS data portion of the DNS response message.
[0129] In the specific implementation process E1, the Domain Name System monitoring module (i.e., the DNSMonitor module) is used to extract the Domain Name System response message from the message queue for parsing, that is, to parse the IP header information, TCP / UDP header and DNS data parts such as the DNS packet body in sequence.
[0130] Process E2: Resolve the problem zone field in the Domain Name System response message based on the DNS data portion, and extract the domain name from the problem zone field.
[0131] It can be understood that the question area field in the domain name system response message is parsed according to the DNS data part, that is, the Questions field, wherein the Questions field represents a query part in the DNS request, that is, domain name information requested by a user to be parsed. The Questions field shows which query requests are responded by the DNS server, and usually contains a domain name, a query type (such as an A record, a CNAME record, etc.). Therefore, the domain name can be extracted by parsing the Questions field.
[0132] Process E3: If the domain name is a domain name in the domain name whitelist, the answer question area field in the domain name system response message is parsed, and the IP address corresponding to the domain name is extracted from the answer question area field.
[0133] In the implementation of process E3, if the domain name is a domain name in the domain name whitelist, it is considered that the domain name system response message is a valid request to be processed; otherwise, it is considered to be irrelevant or invalid, and the domain name system response message is discarded and not processed.
[0134] When the domain name in the domain name system response message is a domain name in the domain name whitelist, the IP address corresponding to the domain name is extracted from the answer question area field.
[0135] In some embodiments, when it is determined that the domain name in the DNS response message matches the domain name in the configuration file, the Answers field in the DNS response message is further parsed by the DNSMonitor module, the IP address corresponding to the domain name is extracted from the Answers field, the IP address is added to the domain name set of the IPset module, the domain name set of the IPset module is updated, and the domain name packet with the IP address in the domain name set as a target address can be accepted by the iptables module.
[0136] Process E4: The IP address is added to the domain name set of the IPset module.
[0137] In the implementation of process E4, the IP address is added to the domain name set of the IPset module to update the domain name set. Based on this, the domain name system response message with the IP address in the domain name set as a target address can be accepted by the iptables module.
[0138] In the embodiment of the present application, a DNSMonitor module in a vehicle iptables firewall is designed and implemented to support dynamic domain name resolution function and realize domain name-based packet filtering. The scheme does not need to enable the DNSmasq service, thereby effectively reducing the use of CPU and memory and saving system resource consumption. At the same time, this enables the firewall to be deployed in an environment that does not support DNSmasq, greatly improving the flexibility and platform reusability of the firewall. In terms of technical implementation, the embodiment of the present application configures a DNS response message capturing rule on the LOCAL_IN and FORWARD two rule chains of the TBOX, thereby realizing network monitoring of all ECUs of the vehicle and ensuring that DNS requests for all domain names can be monitored and filtered. Specifically, the DNSMonitor module copies the message in the manner of NFQ message capturing, marks the original message as "ACCEPT" and releases it back to the protocol stack. The embodiment of the present application does not affect the normal DNS request of the application, and the upper-layer application has no awareness of this process, and the original configuration does not need to be modified, having the advantage of easy deployment. In summary, the embodiment of the present application optimizes the DNS monitoring and packet filtering functions, which not only improves the system performance but also enhances the deployment flexibility.
[0139] In order to better explain the above-mentioned embodiment of the present application, a domain name-based packet filtering method, reference is made to Figure 3 , which shows the principle diagram of the ECU obtaining DNS response for analysis and updating IPset provided by the embodiment of the present application.
[0140] 1. When the application programs on all ECUs of the vehicle need to query a domain name in the working process, a DNS request is initiated for query, and the request message is sent to the DNS server through Ethernet.
[0141] 2. The DNS server sends the data packet to the TBOX system, and the data packet is routed at the data link layer of the TBOX protocol stack: if the destination address of the data packet is the TBOX system, the data packet is routed to the LOCAL_IN hook point; if the destination address of the data packet is other ECUs, the data packet is routed to the FORWARD hook point.
[0142] 3. At the LOCAL_IN hook point or the FORWARD hook point, the iptables module (i.e. IP filtering module) checks the data packet according to the firewall rule and the domain name system response filtering rule (i.e. NFQ in Figure 3 ).
[0143] 4. When the data packet meets the firewall rule and the domain name system response filtering rule, it is determined that the data packet is a domain name system response message (i.e. DNS response message), and the domain name system response message is stored in the Netfilter queue (such as Figure 3Netlink socket 0).
[0144] 5. The DNS monitoring module (e.g., DNS Monitor) immediately takes the DNS response packet from the Netfilter queue, copies the DNS response packet to the packet queue of the DNSMonitor module, and then immediately adds the DNS response packet with a pass-through identifier (e.g., marked as “ACCEPT”) and sends it to the kernel network protocol stack. Figure 3
[0145] 6. The DNS response packet is routed by the kernel network protocol stack to its destination address.
[0146] 7. The DNS response packet in the packet queue is parsed and filtered by the DNS monitoring module (i.e., DNSMonitor module) to determine whether the domain name of the DNS response packet is in the domain name whitelist (e.g., “Firewall configuration file”). Figure 3
[0147] 8. If the domain name of the DNS response packet is in the domain name whitelist, the DNSMonitor module continues to parse the Answers field in the DNS response to obtain the IP address corresponding to the domain name, and adds the IP address to the domain name set (e.g., “IPset”) in the IP set module through netlinksocket_1. Figure 3
[0148] At this point, the IPset set is updated, and when a data packet with a destination address of any domain name in the IPset set reaches the iptables module, it can be ACCEPTed by the iptables module.
[0149] In the embodiment of the application, a DNSMonitor module in the vehicle-mounted iptables firewall is designed and implemented, supporting dynamic domain name resolution function and realizing packet filtering based on domain name. In terms of technical implementation, the embodiment of the application configures DNS response packet grabbing rules on the LOCAL_IN and FORWARD two rule chains of the TBOX, thereby realizing network monitoring of all ECUs of the vehicle and ensuring that all DNS requests for domain names can be monitored and filtered. Specifically, the NFQ packet grabbing method is adopted, the DNSMonitor module copies the packet, marks the original packet as “ACCEPT” and releases it back to the protocol stack. It does not affect the normal DNS request of the application, and the upper-layer application has no awareness of this process, and the original configuration does not need to be modified, having the advantage of easy deployment. In summary, by optimizing the DNS monitoring and packet filtering functions, the system performance is improved and the deployment flexibility is enhanced.
[0150] Corresponding to the domain name-based packet filtering method provided by the embodiment of the application, refer to Figure 4 , a structure block diagram of a domain name-based packet filtering device provided by the embodiment of the application is shown, and the device comprises: a checking unit 401, a judging unit 402, a copying unit 403 and an analysis filtering unit 404.
[0151] The checking unit 401 is configured to check the data packet received by the whole vehicle by using the firewall rule in the IP filtering module; the firewall rule is created based on the domain name whitelist included in the domain name set in the IP set module.
[0152] The judging unit 402 is configured to judge whether the data packet checked by the firewall rule meets the domain name system response filtering rule in the IP filtering module.
[0153] The copying unit 403 is configured to determine the data packet as a domain name system response message if the domain name system response filtering rule is met, and copy the domain name system response message to the message queue of the domain name system monitoring module; add the pass-through identification to the domain name system response message by the domain name system monitoring module, and send to the kernel network protocol stack, so as to route the domain name system response message to the corresponding destination address by the kernel network protocol stack; wherein, the domain name system monitoring module is initialized in advance.
[0154] The analysis filtering unit 404 is configured to analyze and filter the domain name system response message by using the domain name system monitoring module, and add the IP address in the domain name system response message meeting the analysis filtering condition to the domain name set.
[0155] In the embodiment of the application, the domain name system monitoring module is designed and implemented, the dynamic domain name analysis function is supported, and the domain name-based packet filtering is realized. The CPU and memory consumption are reduced, and the flexibility and platform reusability of the firewall are improved.
[0156] In combination with the content shown in Figure 4 , the device further comprises a first creating unit, a second creating unit and an adding unit.
[0157] The first creating unit is configured to obtain the domain name system response filtering rule.
[0158] The second creating unit is configured to obtain the domain name whitelist from the domain name set in the IP set module, and generate the firewall rule according to the domain name whitelist.
[0159] The adding unit is configured to add the domain name system response filtering rule and the firewall rule to the IP filtering module.
[0160] In combination with the content shown in Figure 4The device shown also includes a third creation unit, a first communication connection unit, a second communication connection unit, a generation unit, and a sending unit.
[0161] The third creation unit is configured to create a network link socket after initialization of the module information of the domain name system monitoring module is completed.
[0162] The first communication connection unit is configured to establish a communication connection with an IP set module in the kernel through the network link socket.
[0163] The second communication connection unit is configured to create a message acquisition thread and establish a communication connection with a network filtering queue in the kernel through a network filtering queue API interface.
[0164] The generation unit is configured to acquire a domain name whitelist from a firewall configuration file and generate a control message according to the domain name whitelist.
[0165] The sending unit is configured to send the control message to the IP set module through the network link socket to create a domain name set in the IP set module, the domain name set including the domain name whitelist.
[0166] In combination Figure 4 The device shown also includes a registration unit, a monitoring unit, a reconnection unit, and a reconstruction unit.
[0167] The registration unit is configured to register a domain name system monitoring callback function.
[0168] The monitoring unit is configured to periodically monitor, through the domain name system monitoring callback function, whether a communication endpoint and a thread of the domain name system monitoring module are in an active state.
[0169] The reconnection unit is configured to perform a re-communication connection on the communication endpoint of the domain name system monitoring module if the communication endpoint of the domain name system monitoring module is not in the active state.
[0170] The reconstruction unit is configured to perform a re-creation on the thread of the domain name system monitoring module if the thread of the domain name system monitoring module is not in the active state.
[0171] In combination Figure 4 The parsing filtering unit 404 shown includes a parsing module, a domain name extraction module, an IP address extraction module, and an adding module.
[0172] The parsing module is configured to parse a domain name system response message by using the domain name system monitoring module to obtain a DNS data part of the domain name system response message.
[0173] The domain name extraction module is configured to parse a question area field in the domain name system response message according to the DNS data part and extract a domain name from the question area field.
[0174] The IP address extraction module is configured to, if the domain name is a domain name in the domain name white list, parse a question answer area field in the domain name system response message, and extract an IP address corresponding to the domain name from the question answer area field.
[0175] The adding module is configured to add the IP address into the domain name set of the IP set module.
[0176] Each of the embodiments in the specification is described in a progressive manner, and the same and similar parts of each of the embodiments can be referred to each other. Each of the embodiments mainly describes the difference from other embodiments. In particular, for the system or system embodiments, since it is basically similar to the method embodiments, the description is relatively simple, and the related parts can be referred to the part of the method embodiments. The above-described system and system embodiments are only illustrative, and the units described as separate components can be or can not be physically separated, and the components shown as units can be or can not be physical units, that is, they can be located in one place or distributed on multiple network units. Part or all of the modules can be selected to achieve the purpose of the embodiment scheme according to actual needs. Those skilled in the art can understand and implement without creative labor.
[0177] The skilled person can further realize that the units and algorithm steps of the examples described in combination with the embodiments disclosed herein can be realized by electronic hardware, computer software or a combination of both. In order to clearly illustrate the interchangeability of hardware and software, the components and steps of the examples have been described in general terms in the above description. Whether the functions are realized in hardware or software depends on the specific application and design constraints of the technical solution. The skilled person can use different methods to realize the described functions for each specific application, but such implementation should not be considered beyond the scope of the present application.
[0178] The above description of the disclosed embodiments enables a person skilled in the art to implement or use the present application. Various modifications to the embodiments will be apparent to those skilled in the art, and the general principles defined herein can be implemented in other embodiments without departing from the scope of the present application. Therefore, the present application will not be limited to the embodiments shown herein, but will conform to the widest scope consistent with the principles and novel features disclosed herein.
Claims
1. A domain name based packet filtering method, characterized by, The method comprises: checking the data packet received by the vehicle by using the firewall rule in the IP filtering module; the firewall rule is created based on the domain name whitelist included in the domain name set in the IP set module; judging whether the data packet checked by the firewall rule meets the domain name system response filtering rule in the IP filtering module; if the domain name system response filtering rule is met, determining that the data packet is a domain name system response message, and copying the domain name system response message to the message queue of the domain name system monitoring module; adding a pass-through identifier to the domain name system response message by using the domain name system monitoring module, and sending the domain name system response message to the kernel network protocol stack, so that the domain name system response message is routed to the corresponding destination address by using the kernel network protocol stack; wherein the domain name system monitoring module is initialized in advance; analyzing and filtering the domain name system response message by using the domain name system monitoring module, and adding the IP address in the domain name system response message meeting the analysis and filtering condition to the domain name set.
2. The method of claim 1, wherein, Before checking the data packet received by the vehicle by using the firewall rule in the IP filtering module, the method further comprises: obtaining the domain name system response filtering rule; obtaining the domain name whitelist from the domain name set in the IP set module, and generating the firewall rule according to the domain name whitelist; adding the domain name system response filtering rule and the firewall rule to the IP filtering module.
3. The method of claim 1, wherein, The process of initializing the domain name system monitoring module comprises: after the module information of the domain name system monitoring module is initialized, creating a network link socket; establishing a communication connection with the IP set module in the kernel through the network link socket; creating a message acquisition thread, and establishing a communication connection with the network filtering queue in the kernel through a network filtering queue API interface; obtaining the domain name whitelist from the firewall configuration file, and generating a control message according to the domain name whitelist; sending the control message to the IP set module through the network link socket, so as to create a domain name set in the IP set module, and the domain name set includes the domain name whitelist.
4. The method of claim 3, wherein, The method further comprises: registering a domain name system monitoring callback function; periodically monitoring whether the communication endpoint and thread of the domain name system monitoring module are in an active state through the domain name system monitoring callback function; if the communication endpoint of the domain name system monitoring module is not in an active state, re-establishing the communication connection of the communication endpoint of the domain name system monitoring module; if the thread of the domain name system monitoring module is not in an active state, re-creating the thread of the domain name system monitoring module.
5. The method of claim 1, wherein, The analyzing and filtering of the domain name system response message by using the domain name system monitoring module, and adding the IP address in the domain name system response message meeting the analysis and filtering condition to the domain name set, comprises: analyzing the domain name system response message by using the domain name system monitoring module, to obtain the DNS data part of the domain name system response message; According to the DNS data part, the question area field in the domain name system response message is parsed, and a domain name is extracted from the question area field; If the domain name is a domain name in the domain name white list, an answer question area field in the domain name system response message is parsed, and an IP address corresponding to the domain name is extracted from the answer question area field; The IP address is added to the domain name set of the IP set module.
6. A domain name based packet filtering apparatus, characterized by comprising: The device comprises: a checking unit configured to check a data packet received by the whole vehicle by using a firewall rule in an IP filtering module, wherein the firewall rule is created based on a domain name white list included in a domain name set in an IP set module; a judging unit configured to judge whether the data packet checked by the firewall rule meets a domain name system response filtering rule in the IP filtering module; a copying unit configured to determine that the data packet is a domain name system response message if the data packet meets the domain name system response filtering rule, and copy the domain name system response message to a message queue of a domain name system monitoring module, add a pass-through identifier to the domain name system response message by using the domain name system monitoring module, and send the domain name system response message to a kernel network protocol stack, so that the domain name system response message is routed to a corresponding destination address by using the kernel network protocol stack; wherein the domain name system monitoring module is initialized in advance; a parsing filtering unit configured to parse filter the domain name system response message by using the domain name system monitoring module, and add an IP address in the domain name system response message meeting a parsing filtering condition to the domain name set.
7. The apparatus of claim 6, wherein, The device further comprises: a first creating unit configured to obtain a domain name system response filtering rule; a second creating unit configured to obtain a domain name white list from a domain name set in an IP set module, and generate a firewall rule based on the domain name white list; an adding unit configured to add the domain name system response filtering rule and the firewall rule to an IP filtering module.
8. The apparatus of claim 6, wherein, The device further comprises: a third creating unit configured to create a network link socket when module information of the domain name system monitoring module is initialized; a first communication connection unit configured to establish a communication connection with an IP set module in a kernel by using the network link socket; a second communication connection unit configured to create a message acquisition thread, and establish a communication connection with a network filtering queue in the kernel by using a network filtering queue API interface; a generating unit configured to obtain a domain name white list from a firewall configuration file, and generate a control message based on the domain name white list; a sending unit configured to send the control message to the IP set module by using the network link socket, so as to create a domain name set in the IP set module, wherein the domain name set includes the domain name white list.
9. The apparatus of claim 8, wherein, The device further comprises: a registering unit configured to register a domain name system monitoring callback function; a monitoring unit configured to periodically monitor whether a communication endpoint and a thread of the domain name system monitoring module are in an active state by using the domain name system monitoring callback function. The reconnection unit is configured to reconnect the communication end point of the domain name system monitoring module if the communication end point of the domain name system monitoring module is not in an active state. The reconstruction unit is configured to recreate the thread of the domain name system monitoring module if the thread of the domain name system monitoring module is not in an active state.
10. The apparatus of claim 6, wherein, The parsing filtering unit comprises: The parsing module is configured to parse the domain name system response packet by using the domain name system monitoring module to obtain a DNS data part of the domain name system response packet. The domain name extraction module is configured to parse a question area field in the domain name system response packet according to the DNS data part and extract a domain name from the question area field. The IP address extraction module is configured to parse an answer question area field in the domain name system response packet and extract an IP address corresponding to the domain name from the answer question area field if the domain name is a domain name in the domain name white list. The adding module is configured to add the IP address to the domain name set of the IP set module.