Authoritative DNS configuration abnormity identification method and device, electronic equipment and storage medium
By acquiring recursive DNS memory snapshot data, extracting and structuring key information, and combining database storage and abnormal domain name judgment rules, the problems of poor real-time performance and low efficiency in authoritative DNS configuration anomaly identification are solved, achieving fast and accurate anomaly identification and location.
Patent Information
- Application Number
- CN202511722383.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-11-21
- Publication Date
- 2026-01-09
AI Technical Summary
Traditional methods struggle to efficiently identify authoritative DNS configuration anomalies, exhibiting poor real-time performance and low efficiency, especially in large-scale DNS data processing where they lack real-time capability and coverage.
By acquiring recursive DNS memory snapshot data, extracting key field information and performing structured processing, and storing it in the target database, the system automatically identifies abnormal domain names based on preset abnormal domain name judgment rules. Combining single NS configuration risks, consistency between parent domain NS and child domain NS, and domain name tampering judgment rules, it achieves rapid identification of abnormal configurations.
It enables real-time identification of authoritative DNS configuration anomalies, improving identification efficiency, reducing human error, and providing reliable support for rapid location and rectification, while balancing the accuracy of data processing with practical applicability.
Smart Images

Figure CN121309348A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of data processing technology, and in particular to a method, apparatus, electronic device, and storage medium for identifying authoritative DNS configuration anomalies. Background Technology
[0002] The robustness of authoritative DNS (Domain Name System) servers is crucial to the stability and security of network services. Within the service area of a carrier's DNS, authoritative DNS servers are distributed covertly and generate massive amounts of data. Traditional traversal methods struggle to efficiently identify potential vulnerabilities. For example, while probing key domains can identify domain faults, this method can only deploy probing tasks on a small number of popular domains. With hundreds of thousands of second-level domains, the sampling rate is too low, the workload is enormous, and fault identification is not timely. Another approach is to analyze large amounts of DNS log data. Although this method has broad coverage, analyzing authoritative DNS services across the entire province, it consumes significant computing resources and results in delayed analysis, typically generating reports on a daily basis. Therefore, traditional recursive log analysis techniques are limited by large data volumes and slow processing speeds, usually only able to detect problems a considerable time after an authoritative server failure, lacking real-time capability. Summary of the Invention
[0003] This invention provides a method, apparatus, electronic device, and storage medium for identifying authoritative DNS configuration anomalies, in order to solve the problems of poor real-time performance and low efficiency in identifying authoritative DNS configuration anomalies.
[0004] According to one aspect of the present invention, a method for identifying authoritative DNS configuration anomalies is provided, comprising:
[0005] Obtain recursive DNS memory snapshot data, which includes at least one set of resource records;
[0006] Extract key field information and perform structured processing on at least one set of resource records to obtain structured processing results, and store the structured processing results in the target database;
[0007] Based on the target database, abnormal domain names are identified according to preset abnormal domain name judgment rules to determine the authoritative DNS configuration anomaly identification results.
[0008] Optionally, obtaining recursive DNS memory snapshot data includes: determining the target snapshot data sampling period based on the domain name lifetime in the recursive DNS memory history information, combined with server caching policies and / or system resource thresholds; and collecting recursive DNS memory snapshot data based on the target snapshot data sampling period.
[0009] Optionally, the target snapshot data sampling period is determined based on the domain name lifetime in the recursive DNS memory history information, combined with server caching policies and / or system resource thresholds. This includes: classifying and statistically analyzing the target record types in the recursive DNS memory history information to determine the basic sampling period; determining the first sampling period correction data based on the server caching policy, and / or determining the second sampling period correction data based on system resource thresholds; and correcting the basic sampling period based on the first sampling period correction data and / or the second sampling period correction data to obtain the target snapshot data sampling period.
[0010] Optionally, key field information extraction and structuring processing are performed on at least one set of resource record sets to obtain structuring processing results, and the structuring processing results are stored in the target database. This includes: for each set of resource record sets, field information identification is performed on the resource record sets, and key field information is extracted to obtain key field information extraction results corresponding to the resource record sets; wherein, the key field information includes domain name, resource record type, domain name trust level, authoritative DNS information, and record time; the key field information extraction results corresponding to each resource record set are grouped and summarized based on domain name, resource record type, and record time to obtain at least one grouping result; for each grouping result, the grouping result is generated into a target record according to a preset record generation rule, and the target record is added to the corresponding field in the target database, wherein the target record includes at least a domain name field, a resource record type field, a domain name resolution result field, an authoritative parent domain NS field, an authoritative child domain NS field, and a record time field, and the fields in the target record correspond one-to-one with the fields in the target database.
[0011] Optionally, the grouping results are generated into a target record according to preset record generation rules, and the target record is added to the corresponding fields in the target database. This includes: if there is one domain trust level in the grouping results, the authoritative DNS information in the grouping results is assigned to the domain name resolution result field, the authoritative parent domain NS field, and the authoritative child domain NS field respectively; if there are two domain trust levels in the grouping results, the authoritative DNS information corresponding to the first domain trust level is assigned to the domain name resolution result field and the authoritative child domain NS field, and the authoritative DNS information corresponding to the second domain trust level is assigned to the authoritative parent domain NS field, wherein the first domain trust level is higher than the second domain trust level; the target record is generated based on the domain name, resource record type, domain trust level, assigned domain name resolution result field, assigned authoritative parent domain NS field, assigned authoritative child domain NS field, and record time in the grouping results.
[0012] Optionally, the preset abnormal domain name judgment rules include one or more of the following: single NS configuration vulnerability judgment rules, parent domain NS and child domain NS consistency judgment rules, and domain name tampering judgment rules. Based on the target database, abnormal domain names are judged according to the preset abnormal domain name judgment rules to determine the authoritative DNS configuration anomaly identification result. This includes: creating corresponding database query statements based on one or more of the preset abnormal domain name judgment rules (single NS configuration vulnerability judgment rules, parent domain NS and child domain NS consistency judgment rules, and domain name tampering judgment rules), executing the query statements to filter abnormal domain names in the target database, and obtaining the abnormal domain name filtering result; if the abnormal domain name filtering result is not empty, the authoritative DNS configuration anomaly identification result is determined based on the abnormal domain name filtering result.
[0013] Optionally, the method further includes: for any record in the target database, counting the number of domain names in the domain name resolution result field of the record; if the number of domain names is less than or equal to a first preset threshold, then determining the authoritative DNS configuration anomaly identification result as an anomaly indicating that the record has a single NS configuration vulnerability, and identifying the domain name corresponding to the domain name field in the record as an abnormal domain name; and / or, if the authoritative subdomain NS field in the record does not fully contain or does not contain the authoritative parent domain NS field, then determining the authoritative DNS configuration anomaly identification result as an anomaly indicating that the record has a parent domain NS and subdomain NS that do not meet consistency, and identifying the domain name corresponding to the domain name field in the record as an abnormal domain name; and / or If a preset character feature exists in the domain name resolution result field of a record, the authoritative DNS configuration anomaly identification result is determined to be an anomaly indicating that the record has been tampered with, and the domain name corresponding to the domain name field in the record is identified as an abnormal domain name; and / or, based on the domain name, resource record type, and domain name resolution result field, group deduplication statistical processing is performed to obtain the group deduplication statistical processing result. If the group deduplication statistical processing result contains domain names with a statistical number greater than or equal to the second preset threshold, the authoritative DNS configuration anomaly identification result is determined to be an anomaly indicating that the record has been tampered with, and the domain names with a statistical number greater than or equal to the second preset threshold in the group deduplication statistical processing result are identified as abnormal domain names.
[0014] According to another aspect of the present invention, an authoritative DNS configuration anomaly identification device is provided, comprising:
[0015] The memory snapshot data determination module is used to obtain recursive DNS memory snapshot data, which includes at least one set of resource records.
[0016] The resource record set storage module is used to extract key field information and perform structured processing on at least one set of resource record sets to obtain structured processing results, and store the structured processing results in the target database.
[0017] The Authoritative DNS Configuration Anomaly Identification Result Determination Module is used to identify abnormal domain names based on the target database according to preset abnormal domain name judgment rules, and determine the authoritative DNS configuration anomaly identification result.
[0018] According to another aspect of the present invention, an electronic device is provided, the electronic device comprising:
[0019] At least one processor; and
[0020] A memory that is communicatively connected to at least one processor; wherein,
[0021] The memory stores a computer program that can be executed by at least one processor, such that the at least one processor is able to perform the authoritative DNS configuration anomaly identification method according to any embodiment of the present invention.
[0022] According to another aspect of the present invention, a computer-readable storage medium is provided, which stores computer instructions for causing a processor to execute and implement the authoritative DNS configuration anomaly identification method of any embodiment of the present invention.
[0023] The technical solution of this invention involves acquiring recursive DNS memory snapshot data, which includes at least one set of resource record sets; extracting key field information and performing structured processing on the at least one set of resource record sets to obtain structured processing results, and storing the structured processing results in a target database; and determining the authoritative DNS configuration anomaly identification result based on the target database according to preset abnormal domain name judgment rules. This solution directly acquires data from recursive DNS memory snapshot data, accurately reflecting the real-time resolution status and ensuring the authenticity and timeliness of the original data. Structured processing transforms the scattered and disordered resource record sets into standardized data, and combined with database storage, achieves centralized data management, reducing the difficulty of subsequent analysis. Automated anomaly judgment of records in the data based on preset abnormal domain name judgment rules replaces manual verification, reducing human error, improving identification efficiency, and comprehensively covering core configuration anomaly scenarios. This solves the problems of poor real-time performance and low efficiency in authoritative DNS configuration anomaly identification. The final output identification result provides reliable support for the rapid location and rectification of authoritative DNS configuration problems, balancing the accuracy of data processing with practical application.
[0024] It should be understood that the description in this section is not intended to identify key or essential features of the embodiments of the present invention, nor is it intended to limit the scope of the invention. Other features of the invention will become readily apparent from the following description. Attached Figure Description
[0025] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0026] Figure 1 This is a flowchart of an authoritative DNS configuration anomaly identification method provided in Embodiment 1 of the present invention;
[0027] Figure 2 This is a flowchart of an authoritative DNS configuration anomaly identification method provided in Embodiment 2 of the present invention;
[0028] Figure 3 This is a schematic diagram of the structure of an authoritative DNS configuration anomaly identification device provided in Embodiment 3 of the present invention;
[0029] Figure 4 This is a schematic diagram of the structure of an electronic device that implements the authoritative DNS configuration anomaly identification method according to embodiments of the present invention. Detailed Implementation
[0030] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.
[0031] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of the invention described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover a non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.
[0032] Example 1
[0033] Figure 1This is a flowchart of an authoritative DNS configuration anomaly identification method provided in Embodiment 1 of the present invention. This embodiment is applicable to situations where authoritative DNS configuration anomalies are identified. This method can be executed by an authoritative DNS configuration anomaly identification device, which can be implemented in hardware and / or software. This authoritative DNS configuration anomaly identification device can be configured in electronic devices such as computers and servers. Figure 1 As shown, the method includes:
[0034] S110. Obtain recursive DNS memory snapshot data, which includes at least one set of resource records.
[0035] Specifically, recursive DNS memory snapshot data refers to real-time memory image data captured during the operation of a recursive DNS server. This includes currently cached domain name resolution information and is used to accurately capture the DNS resolution state at a specific moment. Recursive DNS memory snapshot data can be obtained by executing preset commands; for example, these preset commands could be memory information retrieval commands within the recursive software. Resource record sets are the core component of recursive DNS memory snapshot data. Each resource record set contains one or more associated DNS resource records, recording key resolution information such as the domain name and its corresponding IP address, TTL (Time to Live), and resource record type (e.g., NS record). These sets are the fundamental data units supporting subsequent domain name resolution analysis and anomaly detection.
[0036] Specifically, by triggering a memory snapshot collection mechanism during the operation of the recursive DNS server, such as by calling the system memory dump tool or using the snapshot interface built into the DNS service, the domain name resolution data cached in the server's current memory is captured, forming recursive DNS memory snapshot data. This recursive DNS memory snapshot data contains at least one set of resource records that record key information such as domain name, resolution address, and TTL, thus completely preserving the real-time associated data of domain name resolution.
[0037] For example, the recursive software unbound can be invoked. Unbound can use the "dump_cache" command to export the current memory information, obtaining a snapshot of the recursive DNS memory at the current moment. The memory message mainly contains two parts: RRSET_CACHE and MSG_CACHE. RRSET_CACHE stores DNS resource record sets (Resource Record Sets), such as cached records of record types A, AAAA, NS, and MX. MSG_CACHE stores simplified DNS response messages. The recursive DNS can refer to this information to quickly respond to repeated DNS queries. In this embodiment, the content of RRSET_CACHE is used for analysis to subsequently determine the authoritative DNS configuration anomaly identification results.
[0038] In this embodiment, data is collected directly from the recursive DNS memory without relying on network transmission or log recording, which can avoid data loss or delay issues to the greatest extent and ensure the authenticity and real-time nature of the resource record set. At the same time, the resource record set contained in the snapshot completely covers the current resolution-related data, providing comprehensive and reliable raw data support for subsequent extraction of key information and identification of authoritative DNS configuration anomalies.
[0039] Optionally, obtaining recursive DNS memory snapshot data includes: determining the target snapshot data sampling period based on the domain name lifetime in the recursive DNS memory history information, combined with server caching policies and / or system resource thresholds; and collecting recursive DNS memory snapshot data based on the target snapshot data sampling period.
[0040] The Time-to-Live (TTL) of a Domain Name System (DNS) specifically represents an attribute of a DNS resource record. It specifies the validity period of a domain name resolution result in the recursive DNS server cache, determining the expiration and update frequency of cached data. The TTL of the corresponding resource dataset can be obtained by identifying information at a specific location in the recursive DNS memory snapshot data. Server caching strategies can be understood as the rules established by the recursive DNS to manage cached data, such as the LRU eviction mechanism and cache capacity limits, used to optimize cache resource allocation and data validity. System resource thresholds can be understood as the resource usage limits set to ensure stable server operation, such as memory usage, CPU load, and disk I / O thresholds, avoiding excessive resource consumption that could impact service. Determining the target snapshot data sampling period can be achieved by combining historical TTL information (ensuring that snapshots capture valid, unexpired data), server caching strategies (matching the lifecycle of cached data), and system resource thresholds (controlling sampling resource consumption) for comprehensive evaluation and dynamic calculation. The resulting snapshot collection interval is one that neither misses valid parsed data nor consumes excessive system resources. For example, algorithms for comprehensive evaluation and dynamic calculation include, but are not limited to, statistical median weighted algorithms, resource threshold reverse derivation algorithms, interval clustering algorithms, and multi-objective optimization algorithms.
[0041] Specifically, by combining historical domain name time-to-live (TTL) data in the recursive DNS memory with the server's preset cache eviction policy and system resource thresholds, a comprehensive evaluation is conducted according to a preset evaluation algorithm to determine the target snapshot data sampling period that can fully capture valid resolution data without consuming excessive system resources. Then, according to this sampling period, the real-time memory image of the recursive DNS server is periodically collected through methods such as calling memory dump tools and triggering DNS service interfaces, ultimately obtaining recursive DNS memory snapshot data containing at least one set of resource record sets.
[0042] In this embodiment, the sampling period for collecting recursive DNS memory snapshot data is dynamically determined by using TTL history information, caching strategies, and system resource thresholds, avoiding data redundancy or omission of valid data caused by fixed-period sampling. In addition, periodic collection ensures that the snapshot data can continuously reflect the real-time status of DNS resolution, and reduces the resource consumption of the recursive DNS server through reasonable period control, thus balancing data validity and system stability.
[0043] Optionally, the target snapshot data sampling period is determined based on the domain name lifetime in the recursive DNS memory history information, combined with server caching policies and / or system resource thresholds. This includes: classifying and statistically analyzing the target record types in the recursive DNS memory history information to determine the basic sampling period; determining the first sampling period correction data based on the server caching policy, and / or determining the second sampling period correction data based on system resource thresholds; and correcting the basic sampling period based on the first sampling period correction data and / or the second sampling period correction data to obtain the target snapshot data sampling period.
[0044] The basic sampling period is an initial sampling interval determined by classifying and statistically analyzing the recursive DNS memory history information according to the target record type, combined with the domain name lifetime distribution characteristics of each type of record. Its core function is to ensure that the effective lifecycle of different types of resolved data is covered, providing a benchmark for subsequent sampling period adjustments. In this embodiment, the target record type refers to the NS record type. The first sampling period correction data refers to the upper limit threshold of the sampling period derived based on the server caching strategy. It is used to constrain the basic sampling period, making the sampling period conform to the management logic of cached data, and avoiding the omission of effective data due to cache eviction or expiration. Specifically, it can be obtained by acquiring the configuration rules of the server caching strategy, extracting the maximum cache retention time, the old cache reuse time, and the active update trigger interval, and calculating the adaptation value according to the constraint logic of each parameter (such as 1 / 2 of the active update trigger interval, 1 / 3 of the old cache reuse time, and the original value of the maximum cache retention time). Then, the minimum (or average) value of these adaptation values is taken as the first sampling period correction data, and finally the basic sampling period is adjusted to a value no greater than this correction data. The second sampling period correction data refers to the minimum threshold for the sampling period determined after evaluating system resource thresholds. It is used to control resource consumption during the sampling process, ensuring that sampling operations do not affect the stable operation of the server. Specifically, it can be calculated backwards from system resource thresholds (such as daily storage quotas and CPU usage limits) to determine the maximum allowable number of snapshots, and then the time interval is derived to obtain the second sampling period correction data. These three elements together constitute the "baseline-correction" system for the sampling period, ultimately forming a scientifically reasonable target snapshot data sampling period.
[0045] Specifically, domain name time-to-live (TTL) data can be extracted from recursive DNS memory history information, and key indicators can be statistically analyzed according to the target record type to determine the basic sampling period; then, the first sampling period correction data can be derived based on the server caching strategy, and / or the second sampling period correction data can be calculated in reverse based on the system resource threshold; finally, one or two of the correction data are used to adjust the basic sampling period to obtain the target snapshot data sampling period.
[0046] In this embodiment, the basic period is determined by classifying and statistically analyzing records by type, ensuring full coverage of the target type parsing data by sampling. Combined with the correction logic of caching strategy and / or system resource threshold, the sampling period not only fits the life cycle of cached data and avoids missing valid data, but also adapts to the server resource carrying capacity and reduces additional consumption. This achieves a balance between the validity of basic data, the adaptability of cache management, and the stability of the system, and is more scientific and flexible than sampling schemes determined by a fixed period or a single dimension.
[0047] S120. Extract key field information and perform structured processing on at least one set of resource records to obtain the structured processing result, and store the structured processing result in the target database.
[0048] The key field information specifically refers to the set of information set used to extract valid information, which can be pre-set according to the needs of authoritative DNS configuration anomaly identification. Specifically, it is used to selectively extract core data from the resource record set in the recursive DNS memory snapshot data, supporting key content for subsequent anomaly judgment and analysis, including but not limited to domain name, resource record type, domain name trust level, authoritative DNS information, and record time. The structured processing result is a well-organized data form generated after processing the extracted key field information according to a preset structured processing method. Its data format is uniform, logically clear, and conforms to the target database storage specifications, directly meeting the needs of subsequent querying, analysis, and anomaly judgment. It is a key intermediate data form connecting the original resource record set with database storage and subsequent business applications.
[0049] Specifically, for at least one set of resource records in the recursive DNS memory snapshot, the core key fields such as domain name, resource record type, domain name trust level, authoritative DNS information, and record time are extracted first. Then, the data is processed using a structured processing method to form regular and unified structured data. Finally, the structured processing results are batch stored in the target database according to a preset table structure through the database write interface to ensure that the data is traceable and queryable.
[0050] In this embodiment, key fields are extracted to focus on core information, reduce interference from irrelevant data, and improve the efficiency of subsequent analysis. Structured processing transforms scattered and disordered resource record sets into standardized data, lowering the threshold for data use. Data is stored in the target database to achieve centralized data management, ensuring data security and integrity, and providing efficient data query and retrieval support for subsequent abnormal domain name judgment, thus balancing the accuracy and practicality of data processing.
[0051] Optionally, key field information extraction and structuring processing are performed on at least one set of resource record sets to obtain structuring processing results, and the structuring processing results are stored in the target database. This includes: for each set of resource record sets, field information identification is performed on the resource record sets, and key field information is extracted to obtain key field information extraction results corresponding to the resource record sets; wherein, the key field information includes domain name, resource record type, domain name trust level, authoritative DNS information, and record time; the key field information extraction results corresponding to each resource record set are grouped and summarized based on domain name, resource record type, and record time to obtain at least one grouping result; for each grouping result, the grouping result is generated into a target record according to a preset record generation rule, and the target record is added to the corresponding field in the target database, wherein the target record includes at least a domain name field, a resource record type field, a domain name resolution result field, an authoritative parent domain NS field, an authoritative child domain NS field, and a record time field, and the fields in the target record correspond one-to-one with the fields in the target database.
[0052] Specifically, for each set of resource records in the recursive DNS memory snapshot data, key fields such as domain name, resource record type, domain name trust level, authoritative DNS information, and record time are first accurately located and extracted using field recognition technology to form key field extraction results for a single set of resource records. Then, all extraction results are categorized and summarized using domain name, resource record type, and record time as grouping dimensions to obtain at least one grouping result. Finally, for each grouping result, according to preset record generation rules, target records are integrated to form a target record containing domain name field, resource record type field, domain name resolution result field, authoritative parent domain NS field, authoritative child domain NS field, and record time field. The target record fields correspond one-to-one with the target database fields. All target records are then added in batches to the corresponding positions in the target database through the database writing mechanism.
[0053] In this embodiment, key fields are extracted by group to focus on core value information, ensuring the accuracy of data extraction; multi-dimensional grouping and summarization avoid data fragmentation and achieve aggregation of similar parsed data; standardized target records are generated according to preset rules and accurately matched with database fields to ensure the regularity and consistency of data storage; finally, the structured storage of target data facilitates rapid subsequent querying and retrieval, and provides a complete and standardized analytical basis for anomaly judgment, balancing the rigor of data processing with the efficiency of subsequent applications.
[0054] Specifically, during the target record generation stage, the number of domain trust levels in the grouping results is first determined. If only one domain trust level exists, the authoritative DNS information in the grouping results is directly assigned to the domain name resolution result field, authoritative parent domain NS field, and authoritative child domain NS field of the target record. If two trust levels exist, the authoritative DNS information corresponding to the first domain trust level is assigned to the domain name resolution result field and authoritative child domain NS field according to the principle of prioritizing higher trust levels, and the authoritative DNS information corresponding to the second domain trust level is assigned to the authoritative parent domain NS field. Subsequently, the domain name, resource record type, domain trust level in the grouping results, as well as the resolution result, parent / child domain NS field, and record time assigned above are integrated to generate a complete target record according to a preset format, and then written into the matching field of the target database.
[0055] For example, the structured processing results obtained by extracting key field information and structuring the recursive DNS memory snapshot data are stored in batches into the target database according to a preset table structure, resulting in the table information shown below:
[0056]
[0057] In this embodiment, by assigning values differently based on the number and priority of domain name trust levels, the accuracy and logical rationality of authoritative DNS-related field data are ensured, avoiding confusion of information from different trust levels. The target record integrates core key fields and standardized key resolution information, with a unified structure that is precisely adapted to database fields. This not only ensures the consistency of data storage but also provides clear and reliable structured data support for subsequent anomaly judgment based on parent / child domain NS fields and resolution results, improving the efficiency and accuracy of subsequent analysis.
[0058] S130. Based on the target database, judge the abnormal domain name according to the preset abnormal domain name judgment rules, and determine the authoritative DNS configuration abnormal identification result.
[0059] The preset abnormal domain name judgment rules can be standardized judgment criteria based on the authoritative DNS configuration logic and domain name resolution characteristics. These rules cover specific judgment conditions such as the potential risks of configuring only a single NS, mismatches between authoritative parent domain NS and child domain NS configurations, and domain name tampering. They are used to accurately filter domain name data with configuration problems in the target database. The preset abnormal domain name judgment rules include, but are not limited to, rules for judging potential risks of single NS configuration, rules for judging consistency between parent and child domain NS, and rules for judging domain name tampering. The authoritative DNS configuration anomaly identification result refers to the final output result formed after verification using the above preset rules based on the structured data of the target database. Optionally, the authoritative DNS configuration anomaly identification result includes, but is not limited to, the abnormal domain name name, the specific anomaly type (such as NS configuration mismatch, domain name tampering, etc.), the associated authoritative parent / child domain NS information, and the record time. This provides a clear overview of authoritative DNS configuration problems and direct evidence for subsequent investigation and rectification.
[0060] Specifically, based on the structured data stored in the target database, target analysis data can be retrieved through database queries and batch traversal. Each data point can be verified and logically judged against the preset abnormal domain name judgment rules to filter out domain name data that meets the abnormal rules. Finally, the results are summarized to form an authoritative DNS configuration anomaly identification result containing abnormal domain names, anomaly types, and associated authoritative DNS configuration information. Alternatively, a corresponding database query statement can be constructed based on the preset abnormal domain name judgment rules. By executing the database query statement, a fast full query can be performed on the database, thereby filtering out domain names with authoritative DNS configuration problems.
[0061] In this embodiment, judgment is made based on standardized stored structured data, avoiding judgment errors caused by messy raw data and improving the accuracy of anomaly identification. Preset rules realize the automation and standardization of anomaly judgment, replacing manual verification one by one, greatly improving judgment efficiency, and the rules can be flexibly iterated to adapt to different scenarios. The identification results clearly associate anomaly details with authoritative DNS configuration information, providing a clear basis for subsequent problem location and investigation, helping to quickly resolve authoritative DNS configuration problems and ensuring the stability of domain name resolution services.
[0062] The technical solution of this embodiment acquires recursive DNS memory snapshot data, which includes at least one set of resource record sets; extracts key field information and performs structured processing on at least one set of resource record sets to obtain structured processing results, and stores the structured processing results in a target database; based on the target database, it judges abnormal domain names according to preset abnormal domain name judgment rules to determine the authoritative DNS configuration anomaly identification result. This solution obtains data directly from recursive DNS memory snapshot data, which can truly reflect the real-time resolution status and ensure the authenticity and timeliness of the original data; the structured processing transforms the scattered and disordered resource record sets into standardized data, and combined with database storage, it achieves centralized data management and reduces the difficulty of subsequent analysis; based on preset abnormal domain name judgment rules, it automatically judges the records in the data, replacing manual verification, which not only reduces human error and improves identification efficiency, but also comprehensively covers core configuration anomaly scenarios, solving the problems of poor real-time performance and low efficiency in authoritative DNS configuration anomaly identification. The final output identification result provides reliable support for the rapid location and rectification of authoritative DNS configuration problems, taking into account both the accuracy of data processing and practical application.
[0063] Example 2
[0064] Figure 2 This is a flowchart of an authoritative DNS configuration anomaly identification method provided in Embodiment 2 of the present invention. The method in this embodiment is a further optimization of the method in the above embodiments. Optionally, the preset abnormal domain name judgment rules include one or more of the following: single NS configuration vulnerability judgment rules, parent domain NS and child domain NS consistency judgment rules, and domain name tampering judgment rules. Based on one or more of the preset abnormal domain name judgment rules, corresponding database query statements are created. By executing the query statements, abnormal domain names are filtered in the target database to obtain abnormal domain name filtering results. If the abnormal domain name filtering results are not empty, the authoritative DNS configuration anomaly identification result is determined based on the abnormal domain name filtering results. Figure 2 As shown, the method includes:
[0065] S210. Obtain recursive DNS memory snapshot data, which includes at least one set of resource records.
[0066] S220. Extract key field information and perform structured processing on at least one set of resource records to obtain the structured processing result, and store the structured processing result in the target database.
[0067] S230. Based on one or more of the single NS configuration vulnerability judgment rule, parent domain NS and child domain NS consistency judgment rule and domain name tampering judgment rule in the preset abnormal domain name judgment rules, create a corresponding database query statement, and perform abnormal domain name filtering in the target database by executing the query statement to obtain the abnormal domain name filtering results.
[0068] The single NS configuration vulnerability assessment rule is used to identify domains with only a single NS record, primarily preventing resolution failures caused by a single NS configuration. The parent domain NS and child domain NS consistency assessment rule verifies whether the child domain NS records declared by the parent domain match the child domain's own configured NS records and whether there is an inheritance relationship, avoiding resolution anomalies caused by inconsistent hierarchical NS configurations. The domain name tampering assessment rule identifies illegally modified domain name resolution data by comparing resolution results with high-trust-level authoritative DNS information and monitoring abnormal changes in record content. The abnormal domain name filtering result is the result set obtained by converting one or more of the above rules into database query statements and executing the query in the target database. It includes domains that match the abnormal rules, associated NS configuration information, record time, and the specific abnormal rule type matched, serving as crucial preliminary data for accurately locating authoritative DNS configuration problems.
[0069] Specifically, based on one or more of the pre-defined abnormal domain name judgment rules, such as single NS configuration risks, consistency between parent and child domain NS, and domain name tampering, a query statement adapted to the target database syntax can be generated, specifying the query fields, filtering conditions, and logical relationships. Then, the query statement is run through the database execution engine to accurately filter out domain name-related data that match the corresponding abnormal rules from the structured data of the target database, ultimately forming an abnormal domain name filtering result that includes abnormal domain names, associated configuration information, and matching abnormal rule types.
[0070] In this embodiment, abstract anomaly judgment rules are transformed into directly executable database query statements, thereby automating and increasing the efficiency of anomaly screening and significantly reducing the cost of manual screening. It supports single-rule or multi-rule combination queries, flexibly adapting to different anomaly investigation scenarios. Relying on the efficient retrieval capabilities of the database, it can quickly locate abnormal domain names from massive structured data. The screening results are accurately associated with anomaly rules and core configuration information, providing accurate and reliable preliminary data support for subsequent authoritative DNS configuration anomaly identification.
[0071] S240. If the abnormal domain name filtering result is not empty, the authoritative DNS configuration anomaly identification result is determined based on the abnormal domain name filtering result.
[0072] Specifically, the abnormal domain name filtering results can be checked for non-emptiness. If the result is not empty, indicating the presence of abnormal data matching rules such as single NS configuration vulnerabilities, inconsistencies between parent and child NS domains, or domain name tampering, the abnormal domain names, associated NS configuration information, record times, and matching abnormal rule types from the filtering results are further integrated and summarized according to a preset output format. This clarifies the specific configuration problem category corresponding to each abnormal domain name, ultimately forming a clear and complete authoritative DNS configuration anomaly identification result. If the result is empty, it confirms that there are no authoritative DNS configuration anomalies in the currently acquired recursive DNS memory snapshot data.
[0073] In this embodiment, subsequent result integration is triggered only when the filtering result is not empty, avoiding invalid processing and improving process efficiency; identification results are generated based on the accurately filtered abnormal data, ensuring the accuracy and relevance of the results; the identification results are fully associated with abnormal details and judgment criteria, eliminating the need for additional secondary verification, directly providing a clear direction for the investigation and rectification of authoritative DNS configuration problems, and simplifying subsequent workflows.
[0074] Optionally, the method further includes: for any record in the target database, counting the number of domain names in the domain name resolution result field of the record; if the number of domain names is less than or equal to a first preset threshold, then determining the authoritative DNS configuration anomaly identification result as an anomaly indicating that the record has a single NS configuration vulnerability, and identifying the domain name corresponding to the domain name field in the record as an abnormal domain name; and / or, if the authoritative subdomain NS field in the record does not fully contain or does not contain the authoritative parent domain NS field, then determining the authoritative DNS configuration anomaly identification result as an anomaly indicating that the record has a parent domain NS and subdomain NS that do not meet consistency, and identifying the domain name corresponding to the domain name field in the record as an abnormal domain name; and / or If a preset character feature exists in the domain name resolution result field of a record, the authoritative DNS configuration anomaly identification result is determined to be an anomaly indicating that the record has been tampered with, and the domain name corresponding to the domain name field in the record is identified as an abnormal domain name; and / or, based on the domain name, resource record type, and domain name resolution result field, group deduplication statistical processing is performed to obtain the group deduplication statistical processing result. If the group deduplication statistical processing result contains domain names with a statistical number greater than or equal to the second preset threshold, the authoritative DNS configuration anomaly identification result is determined to be an anomaly indicating that the record has been tampered with, and the domain names with a statistical number greater than or equal to the second preset threshold in the group deduplication statistical processing result are identified as abnormal domain names.
[0075] Specifically, the judgment process for the single NS configuration vulnerability judgment rule, the parent domain NS and child domain NS consistency judgment rule, and the domain name tampering judgment rule includes: For each record in the target database, anomaly judgment is carried out through multi-dimensional parallel verification. For the single NS configuration vulnerability judgment rule, the number of domain names in the domain name resolution result field is counted. If the number is less than or equal to a first preset threshold, it is judged that there is a single NS configuration vulnerability, and the corresponding domain name is an abnormal domain name. The first preset threshold is set to 1. For the parent domain NS and child domain NS consistency judgment rule, it is specifically verified whether the authoritative child domain NS field does not completely contain or does not contain the authoritative parent domain NS field. If it does not completely contain or does not contain the authoritative parent domain NS field, it is judged that the parent domain and child domain NS do not meet the consistency requirement, and the corresponding domain name is an abnormal domain name. The domain name tampering detection rules are specifically implemented by checking for the presence of preset character features in the domain name resolution result fields. If these features are found, the domain name is identified as tampered and the corresponding domain name is identified as an abnormal domain. Alternatively, deduplication and statistical processing can be performed by grouping domain names, resource record types, and domain name resolution result fields. If the number of domain names with a count greater than or equal to a second preset threshold is found, the authoritative DNS configuration anomaly identification result is confirmed as indicating domain name tampering. Furthermore, domain names with a count greater than or equal to the second preset threshold (set to 2) in the group deduplication and statistical processing results are identified as abnormal domain names. Finally, all verification results are integrated to form a complete authoritative DNS configuration anomaly identification result.
[0076] In this embodiment, a multi-rule verification mode is adopted to comprehensively cover three core anomaly scenarios: single NS configuration risks, NS consistency issues, and domain name tampering, ensuring the comprehensiveness of anomaly identification. Each judgment rule is directly verified based on specific fields of database records, with clear logic and accurate judgment, reducing human intervention and errors. It supports the flexible combination of multiple rules to adapt to different investigation needs, and the abnormal domain name is directly associated with the specific anomaly type, providing a clear basis for subsequent problem location and rectification, balancing identification efficiency and practicality.
[0077] The technical solution of this embodiment obtains real-time memory snapshot data of the recursive DNS server through memory snapshot acquisition technology. Then, it extracts key fields such as domain name, authoritative DNS information, and record type from the resource record set in the real-time memory snapshot data, and stores them in the target database after structured processing. Subsequently, based on one or more of the three types of rules—single NS configuration risks, consistency between parent and child domain NS, and domain name tampering—it transforms them into a query statement adapted to the database. The execution statement filters abnormal domain names from the target database to obtain abnormal domain name filtering results. If the filtering results are not empty, it integrates abnormal domain names, associated configuration information, and matching abnormal rule types to finally determine the authoritative DNS configuration anomaly identification result. This solution utilizes recursive DNS memory snapshots to ensure the authenticity and real-time nature of the original data; structured processing and database storage make the data organized and searchable, laying the foundation for anomaly screening; multiple anomaly rules can be flexibly combined into query statements to achieve automated and accurate screening, replacing manual verification, improving efficiency and reducing errors; identification results are generated only when the screening results are not empty to avoid invalid processing, and the results clearly relate to anomaly details and judgment criteria, providing reliable support for the rapid investigation and rectification of authoritative DNS configuration problems, taking into account data validity, comprehensive identification, and practical applicability.
[0078] Example 3
[0079] Figure 3 This is a schematic diagram of the structure of an authoritative DNS configuration anomaly identification device provided in Embodiment 3 of the present invention. Figure 3 As shown, the device includes:
[0080] The memory snapshot data determination module 310 is used to obtain recursive DNS memory snapshot data, which includes at least one set of resource records.
[0081] The resource record set storage module 320 is used to extract key field information and perform structured processing on at least one set of resource record sets to obtain structured processing results and store the structured processing results in the target database.
[0082] The Authoritative DNS Configuration Anomaly Identification Result Determination Module 330 is used to determine the authoritative DNS configuration anomaly identification result based on the target database according to the preset abnormal domain name judgment rules.
[0083] The technical solution of this embodiment obtains recursive DNS memory snapshot data through a memory snapshot data determination module. This recursive DNS memory snapshot data includes at least one set of resource record sets. A resource record set storage module extracts key field information and performs structured processing on the at least one set of resource record sets to obtain a structured processing result, which is then stored in a target database. An authoritative DNS configuration anomaly identification result determination module determines the authoritative DNS configuration anomaly identification result based on the target database and according to preset anomaly domain name judgment rules. This solution directly obtains data from recursive DNS memory snapshot data, accurately reflecting the real-time resolution status and ensuring the authenticity and timeliness of the original data. Structured processing transforms the scattered and disordered resource record sets into standardized data, and combined with database storage, enables centralized data management, reducing the difficulty of subsequent analysis. Automated anomaly judgment is performed on records in the data based on preset anomaly domain name judgment rules, replacing manual verification. This reduces human error, improves identification efficiency, and comprehensively covers core configuration anomaly scenarios, solving the problems of poor real-time performance and low efficiency in authoritative DNS configuration anomaly identification. The final output identification result provides reliable support for the rapid location and rectification of authoritative DNS configuration problems, balancing the accuracy of data processing with practical applicability.
[0084] Based on the above embodiments, optionally, the memory snapshot data determination module 310 is specifically used to determine the target snapshot data sampling period based on the domain name lifetime in the recursive DNS memory history information, combined with the server caching strategy and / or system resource threshold; and to collect recursive DNS memory snapshot data based on the target snapshot data sampling period.
[0085] Optionally, the memory snapshot data determination module 310 is specifically used to classify and statistically analyze the target record type in the recursive DNS memory history information to determine the basic sampling period; determine the first sampling period correction data based on the server caching strategy, and / or determine the second sampling period correction data based on the system resource threshold; and correct the basic sampling period based on the first sampling period correction data and / or the second sampling period correction data to obtain the target snapshot data sampling period.
[0086] Optionally, the resource record set storage module 320 is specifically used to identify field information for each resource record set and extract key field information to obtain the key field information extraction results corresponding to the resource record set. The key field information includes domain name, resource record type, domain name trust level, authoritative DNS information, and record time. Based on the domain name, resource record type, and record time, the key field information extraction results corresponding to each resource record set are grouped and summarized to obtain at least one grouping result. For each grouping result, the grouping result is generated into a target record according to a preset record generation rule, and the target record is added to the corresponding field in the target database. The target record includes at least a domain name field, a resource record type field, a domain name resolution result field, an authoritative parent domain NS field, an authoritative child domain NS field, and a record time field. The fields in the target record correspond one-to-one with the fields in the target database.
[0087] Optionally, the resource record set storage module 320 is specifically used to: if there is one domain name trust level in the grouping result, assign the authoritative DNS information in the grouping result to the domain name resolution result field, the authoritative parent domain NS field, and the authoritative child domain NS field respectively; if there are two domain name trust levels in the grouping result, assign the authoritative DNS information corresponding to the first domain name trust level to the domain name resolution result field and the authoritative child domain NS field, and assign the authoritative DNS information corresponding to the second domain name trust level to the authoritative parent domain NS field, wherein the first domain name trust level is higher than the second domain name trust level; and generate the target record based on the domain name, resource record type, domain name trust level, assigned domain name resolution result field, assigned authoritative parent domain NS field, assigned authoritative child domain NS field, and record time in the grouping result.
[0088] Optionally, the preset abnormal domain name judgment rules include one or more of the following: single NS configuration vulnerability judgment rules, parent domain NS and child domain NS consistency judgment rules, and domain name tampering judgment rules; the authoritative DNS configuration anomaly identification result determination module 330 is specifically used to create corresponding database query statements based on one or more of the preset abnormal domain name judgment rules: single NS configuration vulnerability judgment rules, parent domain NS and child domain NS consistency judgment rules, and domain name tampering judgment rules. By executing the query statements, abnormal domain names are filtered in the target database to obtain abnormal domain name filtering results; if the abnormal domain name filtering results are not empty, the authoritative DNS configuration anomaly identification result is determined based on the abnormal domain name filtering results.
[0089] Optionally, the authoritative DNS configuration anomaly identification result determination module 330 is specifically used to, for any record in the target database, count the number of domain names in the domain name resolution result field of the record. If the number of domain names is less than or equal to a first preset threshold, the authoritative DNS configuration anomaly identification result is determined to be an anomaly indicating that the record has a single NS configuration vulnerability, and the domain name corresponding to the domain name field in the record is determined to be an abnormal domain name; and / or, if the authoritative subdomain NS field in the record does not completely contain or does not contain the authoritative parent domain NS field, the authoritative DNS configuration anomaly identification result is determined to be an anomaly indicating that the record has a parent domain NS and subdomain NS that do not meet consistency, and the domain name corresponding to the domain name field in the record is determined to be an abnormal domain name. If the domain name resolution result field in the record contains a preset character feature, the authoritative DNS configuration anomaly identification result is determined to be an anomaly indicating that the record has been tampered with, and the domain name corresponding to the domain name field in the record is determined to be an abnormal domain name; and / or, based on the domain name, resource record type and domain name resolution result field, group deduplication statistical processing is performed to obtain the group deduplication statistical processing result. If the group deduplication statistical processing result contains domain names with a statistical number greater than or equal to the second preset threshold, the authoritative DNS configuration anomaly identification result is determined to be an anomaly indicating that the record has been tampered with, and the domain names with a statistical number greater than or equal to the second preset threshold in the group deduplication statistical processing result are determined to be abnormal domain names.
[0090] The authoritative DNS configuration anomaly identification device provided in the embodiments of the present invention can execute the authoritative DNS configuration anomaly identification method provided in any embodiment of the present invention, and has the corresponding functional modules and beneficial effects of the execution method.
[0091] Example 4
[0092] Figure 4 This is a schematic diagram of the structure of an electronic device provided in Embodiment 4 of the present invention. The electronic device 10 is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device may also represent various forms of mobile devices, such as personal digital processors, cellular phones, smartphones, wearable devices (such as helmets, glasses, watches, etc.), and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the invention described and / or claimed herein.
[0093] like Figure 4As shown, the electronic device 10 includes at least one processor 11 and a memory, such as a read-only memory (ROM) 12 or a random access memory (RAM) 13, communicatively connected to the at least one processor 11. The memory stores computer programs executable by the at least one processor. The processor 11 can perform various appropriate actions and processes based on the computer program stored in the ROM 12 or loaded into the RAM 13 from storage unit 18. The RAM 13 can also store various programs and data required for the operation of the electronic device 10. The processor 11, ROM 12, and RAM 13 are interconnected via a bus 14. An input / output (I / O) interface 15 is also connected to the bus 14.
[0094] Multiple components in electronic device 10 are connected to I / O interface 15, including: input unit 16, such as keyboard, mouse, etc.; output unit 17, such as various types of displays, speakers, etc.; storage unit 18, such as disk, optical disk, etc.; and communication unit 19, such as network card, modem, wireless transceiver, etc. Communication unit 19 allows electronic device 10 to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks.
[0095] Processor 11 can be a variety of general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special-purpose artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. Processor 11 performs the various methods and processes described above, such as authoritative DNS configuration anomaly detection methods.
[0096] In some embodiments, the authoritative DNS configuration anomaly detection method may be implemented as a computer program tangibly contained in a computer-readable storage medium, such as storage unit 18. In some embodiments, part or all of the computer program may be loaded and / or installed on electronic device 10 via ROM 12 and / or communication unit 19. When the computer program is loaded into RAM 13 and executed by processor 11, one or more steps of the authoritative DNS configuration anomaly detection method described above may be performed. Alternatively, in other embodiments, processor 11 may be configured to perform the authoritative DNS configuration anomaly detection method by any other suitable means (e.g., by means of firmware).
[0097] Various embodiments of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-a-chip (SoCs), payload-programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments may include implementations in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a dedicated or general-purpose programmable processor, capable of receiving data and instructions from a storage system, at least one input device, and at least one output device, and transmitting data and instructions to the storage system, the at least one input device, and the at least one output device.
[0098] Computer programs used to implement the authoritative DNS configuration anomaly identification method of the present invention can be written in any combination of one or more programming languages. These computer programs can be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when executed by the processor, the computer programs cause the functions / operations specified in the flowcharts and / or block diagrams to be implemented. The computer programs can be executed entirely on the machine, partially on the machine, as a standalone software package partially on the machine and partially on a remote machine, or entirely on a remote machine or server.
[0099] Example 5
[0100] Embodiment 5 of the present invention also provides a computer-readable storage medium storing computer instructions for causing a processor to execute an authoritative DNS configuration anomaly identification method, the method comprising:
[0101] Obtain recursive DNS memory snapshot data, which includes at least one set of resource records;
[0102] Extract key field information and perform structured processing on at least one set of resource records to obtain structured processing results, and store the structured processing results in the target database;
[0103] Based on the target database, abnormal domain names are identified according to preset abnormal domain name judgment rules to determine the authoritative DNS configuration anomaly identification results.
[0104] In the context of this invention, a computer-readable storage medium can be a tangible medium that may contain or store a computer program for use by or in conjunction with an instruction execution system, apparatus, or device. A computer-readable storage medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination thereof. Alternatively, a computer-readable storage medium may be a machine-readable signal medium. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof.
[0105] To provide interaction with an object, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the object; and a keyboard and pointing device (e.g., a mouse or trackball) through which the object provides input to the electronic device. Other types of devices can also be used to provide interaction with the object; for example, feedback provided to the object can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the object can be received in any form (including sound input, voice input, or tactile input).
[0106] The systems and technologies described herein can be implemented in computing systems that include backend components (e.g., as data servers), or middleware components (e.g., application servers), or frontend components (e.g., a computer with a graphical user interface or web browser through which an item can interact with the implementations of the systems and technologies described herein), or any combination of such backend, middleware, or frontend components. The components of the system can be interconnected via digital data communication of any form or medium (e.g., a communication network). Examples of communication networks include local area networks (LANs), wide area networks (WANs), blockchain networks, and the Internet.
[0107] A computing system can include clients and servers. Clients and servers are generally located far apart and typically interact through communication networks. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship with each other. The server can be a cloud server, also known as a cloud computing server or cloud host, which is a hosting product within the cloud computing service system to address the shortcomings of traditional physical hosts and VPS services, such as high management difficulty and weak business scalability.
[0108] It should be understood that the various forms of processes shown above can be used, with steps reordered, added, or deleted. For example, the steps described in this invention can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution of this invention can be achieved, and this is not limited herein.
[0109] The specific embodiments described above do not constitute a limitation on the scope of protection of this invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this invention should be included within the scope of protection of this invention.
Claims
1. A method for identifying authoritative DNS configuration anomalies, characterized in that, include: Obtain recursive DNS memory snapshot data, wherein the recursive DNS memory snapshot data includes at least one set of resource records; The key field information of the at least one set of resource records is extracted and structured to obtain the structured processing result, and the structured processing result is stored in the target database; Based on the target database, abnormal domain names are identified according to preset abnormal domain name judgment rules to determine the authoritative DNS configuration anomaly identification result.
2. The method according to claim 1, characterized in that, The acquisition of recursive DNS memory snapshot data includes: The target snapshot data sampling period is determined based on the domain name lifetime information in the recursive DNS memory history information, combined with server caching strategies and / or system resource thresholds. The recursive DNS memory snapshot data is collected based on the target snapshot data sampling period.
3. The method according to claim 2, characterized in that, The determination of the target snapshot data sampling period based on the domain name lifetime in recursive DNS memory history information, combined with server caching strategies and / or system resource thresholds, includes: Based on the target record types in the recursive DNS memory history information, a classification and statistical analysis is performed to determine the basic sampling period; The first sampling period correction data is determined based on the server caching strategy, and / or the second sampling period correction data is determined based on the system resource threshold; The base sampling period is corrected based on the first sampling period correction data and / or the second sampling period correction data to obtain the target snapshot data sampling period.
4. The method according to claim 1, characterized in that, The step of extracting key field information and performing structured processing on the at least one set of resource record sets to obtain structured processing results, and storing the structured processing results in the target database, includes: For each set of resource records, field information is identified and key field information is extracted to obtain the key field information extraction result corresponding to the resource record set; wherein, the key field information includes domain name, resource record type, domain name trust level, authoritative DNS information, and record time; Based on the domain name, the resource record type, and the record time, the key field information extraction results corresponding to each resource record set are grouped and summarized to obtain at least one grouping result; For each grouping result, the grouping result is generated into a target record according to a preset record generation rule, and the target record is added to the corresponding field in the target database. The target record includes at least a domain name field, a resource record type field, a domain name resolution result field, an authoritative parent domain NS field, an authoritative child domain NS field, and a record time field. The fields in the target record correspond one-to-one with the fields in the target database.
5. The method according to claim 4, characterized in that, The step of generating a target record from the grouping results according to a preset record generation rule, and adding the target record to the corresponding field in the target database, includes: If a domain trust level exists in the grouping results, the authoritative DNS information in the grouping results will be assigned to the domain name resolution result field, the authoritative parent domain NS field, and the authoritative child domain NS field, respectively. If there are two domain trust levels in the grouping results, the authoritative DNS information corresponding to the first domain trust level is assigned to the domain name resolution result field and the authoritative subdomain NS field, and the authoritative DNS information corresponding to the second domain trust level is assigned to the authoritative parent domain NS field, wherein the first domain trust level is higher than the second domain trust level. The target record is generated based on the domain name, resource record type, domain trust level, assigned domain name resolution result field, assigned authoritative parent domain NS field, assigned authoritative child domain NS field, and record time in the grouping result.
6. The method according to claim 1, characterized in that, The preset abnormal domain name judgment rules include one or more of the following: single NS configuration risk judgment rules, parent domain NS and child domain NS consistency judgment rules, and domain name tampering judgment rules; The step of determining the authoritative DNS configuration anomaly identification result based on the target database according to preset abnormal domain name judgment rules includes: Based on one or more of the single NS configuration vulnerability judgment rule, parent domain NS and child domain NS consistency judgment rule and domain name tampering judgment rule in the preset abnormal domain name judgment rule, create a corresponding database query statement, and perform abnormal domain name filtering in the target database by executing the query statement to obtain abnormal domain name filtering results. If the abnormal domain name filtering result is not empty, then the authoritative DNS configuration anomaly identification result is determined based on the abnormal domain name filtering result.
7. The method according to claim 6, characterized in that, The method also includes: For any record in the target database, count the number of domain names in the domain name resolution result field of the record. If the number of domain names is less than or equal to a first preset threshold, then determine that the authoritative DNS configuration anomaly identification result indicates that the record has a single NS configuration vulnerability, and identify the domain name corresponding to the domain name field in the record as an abnormal domain name; and / or, If the authoritative subdomain NS field in the record does not fully contain or does not contain the authoritative parent domain NS field, then the authoritative DNS configuration anomaly identification result is determined to be an anomaly where the parent domain NS and subdomain NS do not satisfy consistency, and the domain name corresponding to the domain name field in the record is determined to be an abnormal domain name; and / or, If the domain name resolution result field in the record contains a preset character feature, then the authoritative DNS configuration anomaly identification result is determined to be an anomaly indicating that the record has been tampered with, and the domain name corresponding to the domain name field in the record is identified as an abnormal domain name; and / or, Based on the domain name, resource record type, and domain name resolution result fields, group deduplication statistics are performed to obtain group deduplication statistics results. If the group deduplication statistics results contain domain names with a statistical number greater than or equal to a second preset threshold, then the authoritative DNS configuration anomaly identification result is determined to be an anomaly of domain name tampering, and the domain names with a statistical number greater than or equal to the second preset threshold in the group deduplication statistics results are determined to be abnormal domain names.
8. A device for identifying authoritative DNS configuration anomalies, characterized in that, include: A memory snapshot data determination module is used to obtain recursive DNS memory snapshot data, wherein the recursive DNS memory snapshot data includes at least one set of resource records; The resource record set storage module is used to extract key field information and perform structured processing on the at least one set of resource record sets to obtain structured processing results, and store the structured processing results in the target database; The authoritative DNS configuration anomaly identification result determination module is used to determine the authoritative DNS configuration anomaly identification result based on the target database according to the preset abnormal domain name judgment rules.
9. An electronic device, characterized in that, The electronic device includes: At least one processor; and A memory communicatively connected to the at least one processor; wherein, The memory stores a computer program executable by the at least one processor, which enables the at least one processor to perform the authoritative DNS configuration anomaly identification method according to any one of claims 1-7.
10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions that, when executed by a processor, implement the authoritative DNS configuration anomaly identification method according to any one of claims 1-7.