A DNS risk quantitative evaluation model capable of dynamically adapting to attack scenes

CN122764553APending Publication Date: 2026-09-15BEIJING UNIV OF POSTS & TELECOMM
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202610730312.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-05-26
Publication Date
2026-09-15

AI Technical Summary

Technical Problem

[0007]本发明的目的在于克服现有技术存在的指标体系不统一、评估结果不量化、无法动态适配攻击场景、权重分配片面、评估维度缺失等缺陷,提供一种可动态适配攻击场景的DNS 风险量化评估方法

Benefits of technology

[0007] The purpose of this invention is to overcome the shortcomings of existing technologies, such as inconsistent indicator systems, non-quantifiable evaluation results, inability to dynamically adapt to attack scenarios, one-sided weight allocation, and lack of evaluation dimensions. This invention provides a DNS risk quantification assessment method that can dynamically adapt to attack scenarios. It constructs a three-level, multi-dimensional indicator system covering the entire DNS resolution process, combines subjective weighting using AHP with objective weighting using CRITIC, and introduces game theory equilibrium concepts to solve for the optimal weight combination. A dynamic weight adaptation algorithm for real-time attack scenarios is designed, and fuzzy comprehensive evaluation is used to achieve risk quantification scoring. Finally, it outputs DNS security risk assessment results that can be compared horizontally and tracked vertically.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122764553A_ABST
    Figure CN122764553A_ABST
Patent Text Reader

Abstract

This invention discloses a DNS risk quantification assessment model that can dynamically adapt to attack scenarios, relating to the fields of network security and risk assessment technology. Addressing the problems of inconsistent indicator systems, one-sided weight allocation, inability to dynamically adapt to attack scenarios, and lack of quantification in existing DNS security assessments, this invention constructs a three-level measurement indicator system across five dimensions of DNS. It employs the Analytic Hierarchy Process (AHP) to obtain subjective expert weights, combines this with the CRITIC method to obtain objective data weights, and introduces game theory equilibrium concepts to solve for the optimal combination coefficients, forming a baseline comprehensive weight that considers both experience and data. Simultaneously, it identifies different attack types in different scenarios through real-time traffic monitoring, assigning dynamic adjustment factors to core risk indicators, enabling dynamic updates of assessment weights according to attack scenarios. Finally, it utilizes fuzzy comprehensive evaluation and defuzzification processing to transform the DNS security status into a quantitative score of 0–100. This invention achieves full-process coverage of DNS risk, integration of subjective and objective weights, dynamic attack adaptation, and quantifiable and comparable results, effectively improving the standardization and timeliness of risk assessment.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of domain name system security assessment, specifically to a dynamic quantitative measurement method for DNS security based on game theory combined weighting and fuzzy comprehensive evaluation. Background Technology

[0002] The Domain Name System (DNS) is an indispensable core infrastructure of the internet, responsible for mapping and resolving domain names to network addresses. With the increasing complexity of the network environment, a series of attack methods targeting DNS have emerged, including cache poisoning, domain hijacking, DDoS attacks, and tunneling attacks. These security threats can easily lead to network service interruptions, business anomalies, and data leaks. How to achieve proactive DNS security risk warnings and quantitative assessments based on the multi-dimensional and massive traffic characteristics, and identify potential malicious tendencies and vulnerable nodes hidden within legitimate traffic, has become an important research direction for improving the resilience and proactive defense capabilities of network infrastructure.

[0003] Existing DNS security assessments divide DNS measurement into four dimensions: components, structure, traffic, and security. They address aspects such as DNSSEC, encrypted DNS, and malicious domains, but only measure DNS indicators, failing to establish a quantitative assessment system for DNS security risks and thus unable to yield a quantitative evaluation result. DNS security assessments based on the analytic hierarchy process (AHP) construct multi-indicator assessment problems hierarchically into comparison matrices to calculate indicator weights, achieving a comprehensive subjective score for DNS security status. However, this method relies excessively on subjective human judgment, lacks integration with actual measurement data characteristics, and suffers from insufficient objectivity, low stability, and low reliability. Quantitative analysis-based DNS risk assessments calculate risks from three dimensions: threat frequency, vulnerability level, and asset value. Combining large-scale probing data with vulnerability correlation analysis, they normalize risk probability and impact consequences, outputting a risk value in the 0-1 range, achieving an objective assessment of DNS security risks. While this provides a quantitative score, it lacks a standardized indicator system, professional experience-based judgment, dynamic adaptability, and is unsuitable for various environments.

[0004] The above-mentioned problems stem from an inconsistent indicator system: the evaluation dimensions are scattered, focusing on a single risk point or local service, failing to cover the entire DNS resolution process, and lacking systematic integration of availability, completeness, operation management, protocol data, and client security.

[0005] The evaluation methods are not quantitative: existing evaluation methods do not propose a quantitative standard for evaluation results, resulting in vague evaluation outcomes. They rely solely on a single subjective or objective evaluation method, failing to achieve an optimal fusion of subjective and objective weights.

[0006] The adaptability is not dynamic: it uses fixed indicators and calculation methods, and cannot adjust the assessment focus according to real-time attack scenarios such as DDoS, cache poisoning, and DNS tunneling, making it difficult to reflect the real risks under real-time threats. Summary of the Invention

[0007] The purpose of this invention is to overcome the shortcomings of existing technologies, such as inconsistent indicator systems, non-quantifiable evaluation results, inability to dynamically adapt to attack scenarios, one-sided weight allocation, and lack of evaluation dimensions. This invention provides a DNS risk quantification assessment method that can dynamically adapt to attack scenarios. It constructs a three-level, multi-dimensional indicator system covering the entire DNS resolution process, combines subjective weighting using AHP with objective weighting using CRITIC, and introduces game theory equilibrium concepts to solve for the optimal weight combination. A dynamic weight adaptation algorithm for real-time attack scenarios is designed, and fuzzy comprehensive evaluation is used to achieve risk quantification scoring. Finally, it outputs DNS security risk assessment results that can be compared horizontally and tracked vertically.

[0008] This invention can comprehensively cover the entire evaluation dimension of DNS server, client, protocol layer, data layer and operation management layer, realize the optimal weight fusion of subjective experience and objective data, automatically adjust the evaluation focus according to the real-time attack type, and output a precise quantitative score of 0-100 points and four risk levels. It has the advantages of comprehensive evaluation, scientific weight, quantifiable results and strong dynamic adaptability.

[0009] According to one embodiment of the present invention, the construction of the five-dimensional index system for DNS security specifically includes:

[0010] Availability and Resilient Security: DNS resolution availability, response jitter, DDoS attack resistance, DNS amplification attack protection, and peak load capacity;

[0011] DNS resolution integrity and security: domain hijacking rate, cache poisoning detection rate, DNSSEC verification success rate, resolution data consistency, and channel encryption protocol compatibility;

[0012] Operational and management security: system vulnerability exposure, security baseline compliance, service port exposure and access control strength, security audit coverage and tracing capabilities;

[0013] Protocol and Data Security: DNS tunnel detection capabilities, data leakage prevention capabilities, and compliance of recursive query behavior;

[0014] Client and user security: detection of abnormal DNS behavior on the terminal, effectiveness of malicious domain name blocking, DNS redirection auditing capabilities, and matching degree between resolution results and certificates.

[0015] According to one embodiment of the present invention, the data preprocessing includes normalizing the positive and negative indices to the [0,1] interval, with the positive indices adopting a standardization method that the higher the value, the safer the standardization method, and the negative indices adopting a standardization method that the lower the value, the safer the standardization method, thereby eliminating dimensional differences and unifying the calculation caliber.

[0016] According to one embodiment of the present invention, the AHP (Analytic Hierarchy Process) method for calculating subjective weights specifically includes: constructing a three-level hierarchical structure based on the indicator system; experts constructing a judgment matrix using the 1-9 scale method; performing a consistency check on the constructed matrix; indicating that the matrix is ​​usable when CR is less than 0.1; and using the square root method to calculate the weight vector to obtain the effective subjective weights.

[0017] According to one embodiment of the present invention, the CRITIC objective weighting specifically includes calculating the standard deviation of the indicators, the correlation coefficient between the indicators, the information content of the indicators, the comprehensive information content, and normalizing to obtain objective weights that reflect the characteristics of the data based on the standardized data.

[0018] According to one embodiment of the present invention, the game theory combination weighting specifically includes constructing a combination weight model based on subjective weights and objective weights, treating the subjective and objective weights as the two sides of the game, solving for the optimal combination coefficients by establishing a least squares optimization model, and obtaining the final weights by normalization and weighted calculation.

[0019] According to one embodiment of the present invention, the fuzzy comprehensive evaluation method specifically includes constructing a factor set, a comment set, and a weight set. The factor set is a three-level indicator in the indicator system, and the comment set is the level set of all evaluation sets. All risk levels are fuzzily described into four levels: high-risk threat, medium-risk threat, low-risk threat, and acceptable threat. The combined weight result obtained using game theory algorithm is denoted as the weight set. The membership degree of each indicator to the four risk levels is calculated by piecewise trapezoidal / triangular membership function. A fuzzy relation matrix is ​​constructed. The baseline comprehensive weight and the fuzzy relation matrix are combined by fuzzy matrix synthesis to obtain a fuzzy evaluation vector. A score is assigned to each evaluation level, and the matrix and the fuzzy evaluation vector are synthesized to obtain a quantitative scalar score.

[0020] According to one embodiment of the present invention, the dynamic adaptation mechanism specifically includes: dynamically adjusting the weight of each indicator according to the different scenarios in which the DNS system is located and the specific attack types it is suffering, thereby focusing the evaluation on the most urgent and critical risk points at present. Attached Figure Description

[0021] To more clearly illustrate the technical solutions in this invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced one by one below. Obviously, the drawings described below are some embodiments of this invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0022] Figure 1 This is the DNS risk quantification assessment index system tree provided by the present invention.

[0023] Figure 2 This is a flowchart of the DNS risk quantification assessment provided by the present invention. Detailed Implementation

[0024] To make the objectives, technical solutions, and advantages of this invention clearer, the technical solutions of this invention will be clearly and completely described below with reference to the accompanying drawings. All other embodiments obtained by those skilled in the art based on the embodiments of this invention without creative effort are within the scope of protection of this invention. To more clearly explain how this invention solves the above problems, the specific execution flow, key steps, and application logic of the data lifecycle usage control method of this invention will be described in detail below with reference to the accompanying drawings.

[0025] The assessment service takes a comprehensive evaluation of the DNS system's security status as its top-level objective and establishes a three-tiered hierarchical indicator system. The objective layer represents the comprehensive security assessment results of the DNS system; the criteria layer includes five assessment domains: availability and resilience security, resolution integrity and trustworthiness security, operational and management security, protocol and data security, and client and user security; the factor layer breaks down each criteria domain into directly measurable and quantifiable underlying indicators.

[0026] Availability and resilience security aim to comprehensively measure the stable operation and service recovery capabilities of the DNS system under extreme conditions such as high concurrency requests, DDoS attacks, or network failures. As the "nerve center" of network infrastructure, the DNS system's service continuity is fundamental to supporting the access scheduling of over 90% of network applications. Therefore, it is necessary not only to focus on the simple availability of DNS services but also to deeply evaluate its service carrying capacity and rapid recovery capabilities under attack. By quantifying indicators such as resolution availability, response jitter rate, DDoS attack resistance, and peak load capacity, the system's resilience under different pressures can be accurately reflected, providing a scientific basis for ensuring the reliability of network services. The calculation method is as follows:

[0027] DNS resolution availability: The percentage of DNS resolution requests that are responded to normally within a specific time period out of the total number of requests.

[0028] Response jitter rate: The proportion of requests with a response time greater than a threshold out of the total number of requests.

[0029] DDoS attack resistance: The percentage of requests that were successfully resolved after an attack out of the total number of requests.

[0030] DNS amplification attack protection capability: The percentage of amplification attack requests that are blocked out of the total number of requests.

[0031] Peak load capacity: The percentage of successfully resolved requests out of the total peak requests.

[0032] DNS resolution integrity and trustworthiness assessment aims to deeply evaluate the correctness and trustworthiness of DNS resolution results, and is core to addressing advanced threats such as domain hijacking and cache poisoning. Traditional assessment methods often overlook this crucial dimension, but erroneous resolution results can directly redirect users to malicious websites, severely impacting data security. By quantifying indicators such as domain hijacking rate, cache poisoning detection rate, and DNSSEC verification success rate, vulnerabilities in system data integrity can be effectively revealed, ensuring that the resolution information obtained by users is authentic and untampered, thereby fundamentally protecting the security of network services. The calculation method is as follows:

[0033] Domain hijacking rate: The percentage of hijacked DNS resolution requests out of the total number of DNS resolution requests.

[0034] Cache poisoning detection rate: The proportion of detected cache poisoning events to the actual number of poisoning events.

[0035] DNSSEC Validation Success Rate: The percentage of DNSSEC-validated resolutions out of the total number of resolutions requiring validation.

[0036] Data consistency: The proportion of nodes with consistent parsing results to the total number of nodes participating in the verification.

[0037] Channel encryption protocol compatibility: the proportion of encryption parsing requests (DoH / DoT) to the total number of parsing requests.

[0038] Operational and management security measures the protection level of the underlying operating system, management interface, and security baseline configuration of the DNS server. This is the cornerstone of ensuring the stable and secure operation of the DNS system. A poorly configured or vulnerable DNS system is highly susceptible to attack. This guideline focuses on indicators such as system vulnerability exposure, security baseline compliance, service port exposure, and access control strength to ensure that the system has sufficient security hardening at the foundational level. Simultaneously, by estimating security audit coverage and attribution capabilities, critical support can be provided for post-incident investigations and accountability, improving system controllability and recoverability. The calculation method is as follows:

[0039] System vulnerability exposure: number of high-risk vulnerabilities × 3 + number of medium-risk vulnerabilities × 2 + number of low-risk vulnerabilities × 1.

[0040] Security baseline compliance: The percentage of configuration items that comply with the baseline out of the total number of configuration items.

[0041] Service port exposure and access control strength: Service port exposure = the proportion of open non-essential ports to the total number of open ports; Access control strength = the proportion of effective access control rules to the total number of rules.

[0042] Security audit coverage and traceability: Security audit coverage = the proportion of audited DNS operations to the total number of DNS operations; traceability = the proportion of security events that can be successfully traced to the total number of security events.

[0043] Protocol and data security measures the security hardening capabilities of the DNS protocol itself and the confidentiality of data during transmission. Attackers exploit the characteristics of the DNS protocol for more covert attacks, such as DNS tunneling, to bypass the detection of traditional security devices. This criterion assesses the system's ability to protect against these emerging threats by introducing indicators such as DNS tunneling detection capabilities and data leakage prevention capabilities. Furthermore, it examines the system's support for encrypted DNS protocols (such as DoH / DoT) to ensure that sensitive DNS query data is not eavesdropped on during transmission, protecting user privacy and communication security. The calculation method is as follows:

[0044] DNS tunnel detection capability: The proportion of detected DNS tunnel traffic to the actual tunnel traffic.

[0045] Data leakage prevention capability: The percentage of critical nodes that have implemented data leakage prevention measures out of the total number of critical nodes.

[0046] Compliance of recursive query behavior: The proportion of compliant recursive queries to the total number of recursive queries.

[0047] Client and user security aims to assess the security risks posed by client devices and user behavior within the DNS resolution chain. Many network attacks, such as botnets, utilize DNS queries as the basis for their command and control (C2) operations. Therefore, monitoring endpoint DNS behavior is crucial. This guideline assesses the system's ability to perceive and defend against endpoint threats by quantifying metrics such as anomaly detection of endpoint DNS behavior, effectiveness of malicious domain name blocking, and DNS redirection auditing capabilities. This extends DNS security assessment beyond the server side to the entire network environment, forming a comprehensive security protection loop. The calculation method is as follows:

[0048] Terminal DNS Behavior Anomaly Detection Rate: The proportion of detected terminal abnormal behavior to the actual number of abnormal behaviors.

[0049] Domain blocking effectiveness: The proportion of blocked malicious domain requests to the total number of malicious domain requests.

[0050] DNS redirection auditing capability: The percentage of audited DNS redirection actions out of the total number of redirection actions.

[0051] Parsing result matching degree: The proportion of parsing results that match the certificate to the total number of parsing results that require certificate verification.

[0052] Step 2: Indicator Data Collection and Standardization Preprocessing

[0053] Because the original data has problems such as different dimensions, large differences in numerical range, and a mixture of positive and negative indicators, it is necessary to perform standardized preprocessing operations to map all data to the interval between 0 and 1, eliminate the influence of dimensions, and unify the calculation method.

[0054] For positive indicators (the higher the value, the safer), use the following calculation formula:

[0055]

[0056] For contrarian indicators (lower values ​​indicate greater safety), use the calculation formula.

[0057]

[0058] Step 3: Assign weights based on a combination of subjective and objective factors using game theory and determine baseline weights.

[0059] 3.1 Using AHP to calculate subjective weights

[0060] The system invites no fewer than three experts in the field of DNS security to conduct pairwise importance comparisons of indicators at the same level using the 1–9 scaling method, construct a judgment matrix, calculate the weight vector using the square root method, and perform a consistency test to calculate the maximum eigenvalue, consistency index CI, and consistency ratio CR. When CR is less than 0.1, the judgment matrix is ​​valid, thus obtaining subjective weights that conform to expert experience.

[0061] 3.1.1 Construct a three-level hierarchical structure: target layer, criterion layer, and factor layer.

[0062] 3.1.2 Constructing the judgment matrix: Invite 3 or more experts in the field of DNS security to compare the importance of each pair of indicators at the same level using the 1-9 scaling method to generate a judgment matrix.

[0063] 3.1.3 Calculate the weight vector using the square root method.

[0064]

[0065] 3.1.4 Consistency Test: Calculate the maximum eigenvalue and the consistency ratio. If the CR is less than 0.1, the judgment matrix is ​​valid, and the subjective weights are obtained. .

[0066]

[0067] 3.2 Calculating Objective Weights Using the CRITIC Method: Based on standardized measured data, the standard deviation of each indicator, the correlation coefficient between indicators, the information content of indicators, and the comprehensive information content are calculated. Objective weights are calculated through indicator variability and conflict, so that the weight allocation fully reflects the distribution characteristics and distinguishing ability of the data itself.

[0068] 3.2.1 Calculate the standard deviation of the indicators. The standard deviation measures the magnitude of the differences between the evaluation indicators. The calculation formula is:

[0069]

[0070] 3.2.2 Calculate the amount of information in the indicators The amount of information is represented by the correlation between indicators. The larger the value, the higher the overlap in evaluation content between the evaluation indicators, and the smaller the weight assigned to the two indicators. The calculation formula is:

[0071]

[0072] Here are the Pearson correlation coefficients between indicators i and j, and the Pearson correlation coefficients between two indicators X and Y:

[0073]

[0074] 3.2.3 Calculate the information content of the indicators and normalize them to obtain objective weights.

[0075]

[0076] 3.3 Game Theory Optimal Combination Weighting

[0077] After obtaining the subjective and objective weights, the system enters the game theory optimal combination weighting process, constructs a combination weight model, establishes the least squares optimization matrix equation with the goal of minimizing the deviation between subjective and objective weights, solves the optimal combination coefficients α and β, satisfying α+β=1, and optimally integrates the subjective and objective weights to obtain a baseline comprehensive weight that takes into account both expert experience and data characteristics, avoiding the one-sidedness and bias brought about by a single weighting method.

[0078] 3.3.1 Setting Combination Rules: Overall Weight: constraint

[0079] 3.3.2 The problem is transformed into a least squares optimization model to calculate the optimal combination coefficients that minimize the sum of squared deviations between subjective and objective weights:

[0080]

[0081] 3.3.3 Solving for the optimal coefficients: The optimal values ​​of α and β are calculated, and substituted into the equation to obtain the baseline composite weight. .

[0082] Step 4: Fuzzy Comprehensive Evaluation and Risk Quantification Score Output

[0083] After the baseline weights are determined, the system enters the fuzzy comprehensive evaluation process. First, a four-level risk assessment set is constructed, including high-risk, medium-risk, low-risk, and acceptable levels, with corresponding scores of 0, 35, 65, and 100. Based on the standardized values ​​of each indicator, the system calculates the membership degree of each indicator to the four risk levels using a piecewise trapezoidal membership function or a triangular membership function, forming a complete fuzzy relation matrix. The baseline comprehensive weights and the fuzzy relation matrix are then fuzzily synthesized to obtain a fuzzy evaluation vector. This vector is then defuzzified using a weighted average method, transforming it into a precise quantitative score within the 0–100 range. Finally, a quantitative assessment result of DNS security risk is output, which can be compared horizontally, tracked vertically, and used for early warning decision-making.

[0084] 4.1 Constructing the evaluation set

[0085] Risk Assessment Set (Risk Level): V = [v1 (High Risk), v2 (Medium Risk), v3 (Low Risk), v4 (Acceptable)]

[0086] Grade score: S=[0,35,65,100]

[0087] 4.2 Constructing the fuzzy relation matrix R

[0088] Based on the measured values ​​of the indicators, the membership degree of each indicator to the four risk levels is calculated using piecewise trapezoidal / triangular membership functions, forming a matrix:

[0089]

[0090] 4.3 Perform fuzzy matrix synthesis operation on the baseline composite weights A and the fuzzy relation matrix R:

[0091]

[0092] The fuzzy evaluation vector B = [b1, b2, b3, b4] is obtained.

[0093] 4.4 Deblurring output quantization score

[0094]

[0095] Step 5: Real-time attack identification and dynamic weight adaptation

[0096] While outputting baseline assessment results, the system initiates a real-time attack identification and dynamic weight adaptation process. Through the real-time DNS traffic monitoring module, it continuously analyzes and detects resolution requests, response packets, traffic characteristics, behavioral patterns, abnormal frequencies, packet lengths, query types, response statuses, source IPs, and request frequencies. This identifies whether the system is currently under attack, including DDoS attacks, cache poisoning attacks, DNS tunneling attacks, NXDOMAIN attacks, DNS amplification attacks, and malicious domain abuse, and assesses the attack intensity and scope of impact. When a specific attack type is identified, the system automatically matches preset dynamic adjustment rules, assigning an adjustment factor greater than 1 to core indicators highly correlated with the current attack, increasing their weight. For example, when under DDoS attack, the weight of resolution availability, DDoS resistance, and peak load capacity is increased; when cache poisoning is detected, the weight of cache poisoning detection rate and resolution data consistency is increased; when DNS tunneling is discovered, the weight of DNS tunneling detection capability and recursive query compliance is increased; and when a large number of NXDOMAIN abnormal responses occur, the weight of response jitter rate and resolution availability is increased. The system weights and corresponding adjustment factors, then re-normalizes them to generate dynamic weights suitable for the current attack scenario. These dynamic weights are then used to re-execute fuzzy comprehensive evaluation and defuzzification calculations, outputting real-time, accurate, and current threat-appropriate dynamic risk assessment results. This allows the assessment model to automatically focus on core risks as the attack scenario changes, significantly improving the timeliness, accuracy, and practical value of the assessment. The formula for the dynamic weight adjustment is provided below:

[0097]

[0098] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A DNS risk quantitative evaluation method capable of dynamically adapting to an attack scene, characterized in that, Includes the following steps: Construct a five-dimensional quantifiable indicator system for DNS security, including five secondary domains: availability and resilience security, resolution integrity and trust security, operation and management security, protocol and data security, and client and user security, as well as corresponding quantifiable tertiary indicators; Subjective weights were calculated using the Analytic Hierarchy Process (AHP), and objective weights were calculated using the CRITIC method. By introducing the concept of equilibrium in game theory, a least squares optimization model is established to solve for the optimal combination coefficients of subjective and objective weights, and thus obtain the comprehensive weights. A fuzzy comprehensive evaluation model is constructed to determine the factor set, evaluation set, and fuzzy relation matrix. After fuzzy synthesis and defuzzification, the DNS security quantification score and level are output. Based on real-time threat monitoring, attack types are identified, dynamic adjustment factors are generated, and baseline weights are weighted and fused to achieve dynamic scenario adaptation.

2. The method of claim 1, wherein, The aforementioned five-dimensional indicator system for DNS security specifically includes: Availability and Resilient Security: DNS resolution availability, response jitter, DDoS attack resistance, DNS amplification attack protection, and peak load capacity; DNS resolution integrity and security: domain hijacking rate, cache poisoning detection rate, DNSSEC verification success rate, resolution data consistency, and channel encryption protocol compatibility; Operational and management security: system vulnerability exposure, security baseline compliance, service port exposure and access control strength, security audit coverage and tracing capabilities; Protocol and Data Security: DNS tunnel detection capabilities, data leakage prevention capabilities, and compliance of recursive query behavior; Client and user security: detection of abnormal DNS behavior on the terminal, effectiveness of malicious domain name blocking, DNS redirection auditing capabilities, and matching degree between resolution results and certificates.

3. The method according to claim 1, characterized in that, Data preprocessing includes normalizing positive and negative indices to the [0,1] interval, with higher values ​​for positive indices being more secure and lower values ​​for negative indices being more secure, thus eliminating dimensional differences and unifying the calculation method.

4. The method of claim 1, wherein, The AHP (Analytical Hierarchy Process) method for calculating subjective weights specifically includes: constructing a three-level hierarchical structure based on the indicator system; experts constructing a judgment matrix using the 1-9 scale method; performing a consistency check on the constructed matrix; indicating that the matrix is ​​usable when CR is less than 0.1; and using the square root method to calculate the weight vector to obtain the effective subjective weights.

5. The method of claim 1, wherein, The CRITIC objective weighting specifically includes calculating the standard deviation of indicators, the correlation coefficient between indicators, the information content of indicators, the comprehensive information content, and normalizing to obtain objective weights that reflect the characteristics of the data based on the standardized data.

6. The method of claim 1, wherein, The game theory combination weighting specifically includes constructing a combination weight model based on subjective and objective weights, treating subjective and objective weights as two sides of the game, solving for the optimal combination coefficients by establishing a least squares optimization model, and obtaining the final weights by normalization and weighted calculation.

7. The method of claim 1, wherein, The fuzzy comprehensive evaluation method specifically includes constructing a factor set, a comment set, and a weight set. The factor set consists of three-level indicators in the indicator system, and the comment set is the set of levels of all evaluation sets. All risk levels are fuzzily described into four levels: high-risk threat, medium-risk threat, low-risk threat, and acceptable threat. The combined weight result obtained using game theory algorithm is denoted as the weight set. The membership degree of each indicator to the four risk levels is calculated using piecewise trapezoidal and triangular membership functions. A fuzzy relation matrix is ​​constructed. The baseline comprehensive weights and the fuzzy relation matrix are combined using fuzzy matrix synthesis to obtain a fuzzy evaluation vector. A score is assigned to each evaluation level, and the matrix and the fuzzy evaluation vector are synthesized to obtain a quantitative scalar score.

8. The method according to claim 1, characterized in that, The dynamic adaptation mechanism specifically includes dynamically adjusting the weight of each indicator according to the different scenarios in which the DNS system is located and the specific types of attacks it is suffering, thereby focusing the assessment on the most urgent and critical risk points.