A domain name anomaly determination method based on multi-source detection and related equipment

CN122845240APending Publication Date: 2026-09-29CHINA INTERNET NETWORK INFORMATION CENTER
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202611051850.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-07-15
Publication Date
2026-09-29

AI Technical Summary

Technical Problem

[0004]有鉴于此,本申请提供一种基于多源探测的域名异常确定方法及相关设备,以解决域名系统异常状态难以确定的问题,从而有益于域名系统的维护

Benefits of technology

本申请实施例提供了一种基于多源探测的域名异常确定方法,该方法一方面实现了对于域名的多源探测,克服了单一维度指标监测的局限性;另一方面,该方法实现了不同协议之间的特征的有效关联,并对目标域名在链路可信度、时延表现以及协议能力等多维度的综合量化评估,在逻辑上建立了多指标间的协同机制,有效提升了域名异常检测的准确性。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122845240A_ABST
    Figure CN122845240A_ABST
Patent Text Reader

Abstract

This application discloses a method and related equipment for determining domain name anomalies based on multi-source probing. The method includes: a computing device obtaining link credibility based on a set of authoritative servers querying the target domain name; performing multi-source probing on the target domain name based on the set of authoritative servers, obtaining multi-source probing indicators and the average probing latency of the target domain name; determining the credibility of the target domain name based on the multi-source probing indicators and link credibility, and determining the protocol association value of the target domain name based on the protocol capability indicators corresponding to N protocols and the correlation between every two protocols among the N protocols; determining a comprehensive score for the target domain name based on the credibility, average probing latency, and protocol association value; and determining that the target domain name is anomaly when its comprehensive score is lower than or equal to a first threshold. Thus, this method achieves multi-source probing of domain names and performs a multi-dimensional comprehensive quantitative evaluation of the target domain name, effectively improving the accuracy of domain name anomaly detection.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of communication technology, and in particular to a method for determining domain name anomalies based on multi-source detection, a device for determining domain name anomalies based on multi-source detection, a computing device, a computer-readable storage medium, and a computer program product. Background Technology

[0002] As a crucial infrastructure of the Internet, the Domain Name System (DNS) plays a vital role in resolving domain names into Internet Protocol (IP) addresses, and its service performance directly impacts the access experience of Internet applications.

[0003] As the internet continues to expand, the number of domain names is growing exponentially, making domain name resolution links, protocol support, and service deployment environments increasingly complex. Currently, most domain name detection methods focus on single indicators and lack holistic collaborative modeling of global information. Therefore, it is difficult to form a comprehensive understanding of the overall operational status of domain names, and consequently, it is difficult to determine whether there are any anomalies in the domain name system. Summary of the Invention

[0004] In view of this, this application provides a method and related equipment for determining domain name anomalies based on multi-source detection, so as to solve the problem of difficulty in determining the abnormal state of the domain name system, thereby benefiting the maintenance of the domain name system.

[0005] Firstly, this application provides a method for determining abnormal links, the method comprising: The link credibility is obtained based on the set of authoritative servers for the target domain name. The link credibility is determined based on the deviation between the set of authoritative servers obtained from the query and the theoretical set of authoritative servers for the target domain name, as well as the deviation between the number of successful queries and the total number of queries. Based on the set of authoritative servers, multi-source probing is performed on the target domain name to obtain multi-source probing indicators and the average probing latency of the target domain name. The multi-source probing indicators include protocol capability indicators corresponding to N protocols, where N is a positive integer greater than 1. The credibility of the target domain name is determined based on the multi-source detection indicators and the link credibility. The protocol association value of the target domain name is determined based on the protocol capability indicators corresponding to the N protocols and the correlation between every two protocols among the N protocols; A comprehensive score for the target domain name is determined based on the target domain name's credibility, average probe latency, and protocol association value. If the overall score of the target domain name is lower than or equal to the first threshold, it is determined that the target domain name is abnormal.

[0006] In some possible implementations, the overall score of the target domain name is determined according to the following expression: ; in, The overall score is as follows. For the stated credibility, The associated value of the protocol. The average detection delay is... , and These are the weighting coefficients.

[0007] In some possible implementations, performing multi-source probing on the target domain name and obtaining multi-source probing metrics and the average probing latency of the target domain name includes: Perform multi-source concurrent probing on the target domain name; Obtain the multi-source detection indicators and multi-source detection delay; The average detection latency of the target domain name is obtained based on the maximum value among the multi-source detection latency and the time overhead for detection scheduling.

[0008] In some possible implementations, the N protocols include at least two of the following: DNS protocol, HTTP or HTTPS protocol, TCP / IP protocol, DNSSEC protocol, NSEC3 protocol, or EDNS0 protocol.

[0009] In some possible implementations, the multi-source detection metrics may also include at least one of network availability metrics, registration attribute metrics, or host-side fingerprint metrics.

[0010] In some possible implementations, the set of authoritative servers for the target domain name includes: If the target domain name has no historical records, the query is reconstructed from top to bottom according to the domain name hierarchy of the target domain name, starting from the root name server, until the set of authoritative servers of the target domain name is obtained.

[0011] In some possible implementations, the method further includes: Store the multi-source detection indicators obtained for the target domain name in the first detection period as a historical snapshot; Calculate the feature differences of the multi-source probing indicators obtained by the target domain name in the second probing period compared with the historical snapshot, wherein the feature differences include at least one of the following: changes in the authoritative DNS service software version, changes in the resolved IP address, and changes in protocol support; The dynamic anomaly score of the target domain name is calculated based on the feature differences. When the dynamic anomaly score is greater than or equal to the second threshold, it is determined that the target domain name is abnormal.

[0012] Secondly, this application provides an abnormal link determination apparatus, which includes modules for performing the method in the first aspect or any possible implementation of the first aspect, specifically including: The query module is used to obtain the link credibility based on the set of authoritative servers of the target domain name. The link credibility is determined based on the deviation between the set of authoritative servers obtained by the query and the theoretical set of authoritative servers of the target domain name, and the deviation between the number of successful queries and the total number of queries. The detection module is used to perform multi-source detection on the target domain name based on the set of authoritative servers, and obtain multi-source detection indicators and the average detection latency of the target domain name. The multi-source detection indicators include protocol capability indicators corresponding to N protocols, where N is a positive integer greater than 1. A calculation module is used to determine the credibility of the target domain name based on the multi-source detection indicators and the link credibility. The calculation module is also used to determine the protocol association value of the target domain name based on the protocol capability indicators corresponding to the N protocols and the correlation between every two protocols among the N protocols; The calculation module is also used to determine a comprehensive score for the target domain name based on the credibility of the target domain name, the average detection latency, and the protocol association value; The anomaly determination module is used to determine that the target domain name is abnormal when the comprehensive score of the target domain name is lower than or equal to a first threshold.

[0013] Thirdly, this application provides a computing device. The computing device includes a processor and a memory. The memory stores computer instructions; the processor executes the methods described in the first aspect of this application or any possible implementation thereof, according to the computer instructions.

[0014] Fourthly, this application provides a computer-readable medium storing instructions that, when executed on a computer device, cause the computer device to perform the method described in the first aspect of this application or any possible implementation thereof.

[0015] Fifthly, this application provides a computer program product containing instructions that, when run on a computer, cause the computer to perform the method described in the first aspect of this application or any possible implementation thereof.

[0016] Based on the implementation methods provided in the above aspects, this application can be further combined to provide more implementation methods.

[0017] As can be seen from the above technical solutions, the embodiments of this application have the following advantages: This application provides a method for determining domain name anomalies based on multi-source detection. On the one hand, this method achieves multi-source detection of domain names, overcoming the limitations of monitoring single-dimensional indicators. On the other hand, this method realizes the effective correlation of features between different protocols and comprehensively quantifies the target domain name in multiple dimensions such as link credibility, latency performance, and protocol capabilities. Logically, it establishes a collaborative mechanism among multiple indicators, effectively improving the accuracy of domain name anomaly detection. Attached Figure Description

[0018] Figure 1 This is a flowchart of a domain name anomaly determination method based on multi-source detection disclosed in an embodiment of this application; Figure 2 This is a schematic diagram illustrating a scenario of a domain name anomaly determination method based on multi-source detection disclosed in an embodiment of this application; Figure 3 This is a schematic diagram of a domain name anomaly determination device based on multi-source detection disclosed in an embodiment of this application. Detailed Implementation

[0019] To make the above-mentioned objectives, features and advantages of this application more apparent and understandable, the embodiments of this application will be further described in detail below with reference to the accompanying drawings and specific implementation methods.

[0020] The terminology used in the following embodiments is for the purpose of describing specific embodiments only and is not intended to be a limitation of this application. The terms "first" and "second" in the embodiments of this application are for descriptive purposes only and should not be construed as indicating or implying relative importance, chronological order of operations, or implicitly specifying the number of indicated technical features. Therefore, a feature defined with "first" and "second" may explicitly or implicitly include one or more of that feature.

[0021] First, a brief introduction to the technical background involved in this application will be given.

[0022] The Domain Name System (DNS), as an important infrastructure of the Internet, is a distributed hierarchical database system that plays a crucial role in resolving domain names into Internet Protocol (IP) addresses.

[0023] As the internet continues to expand, the number of domain names is growing exponentially, making domain name resolution links, protocol support, and service deployment environments increasingly complex. Currently, most domain name detection methods focus on single indicators, such as website accessibility testing, obtaining domain name system resolution results, querying domain name registration information (WHOIS) protocols, or single-point protocol detection.

[0024] However, while such methods can reflect the operational status of a certain dimension, they lack a comprehensive understanding of the overall operational status of the domain name system due to the lack of holistic collaborative modeling of information such as the domain name system's resolution environment, protocol capabilities, registration attributes, security configurations, and host-side characteristics. Consequently, it is difficult to determine whether there are any anomalies in the domain name system.

[0025] In addition, for large-scale key domain names, traditional serial probing methods face problems such as low efficiency, high resource consumption and high latency. Furthermore, the output formats of different probing tools vary greatly, making it difficult to achieve unified standardized storage and subsequent statistical analysis.

[0026] In view of this, this application provides a method for determining domain name anomalies based on multi-source detection, in order to solve the problem of difficulty in determining the abnormal state of the domain name system, thereby benefiting the maintenance of the domain name system.

[0027] Specifically, the method includes: a computing device obtaining link credibility based on the set of authoritative servers querying the target domain name. Link credibility is determined based on the deviation between the obtained set of authoritative servers and the theoretical set of authoritative servers for the target domain name, as well as the deviation between the number of successful queries and the total number of queries. Then, based on the set of authoritative servers, the computing device performs multi-source probing on the target domain name, obtaining multi-source probing indicators and the average probing latency of the target domain name. The multi-source probing indicators include protocol capability indicators corresponding to N protocols, where N is a positive integer greater than 1. Next, the credibility of the target domain name is determined based on the multi-source probing indicators and link credibility, and the protocol association value of the target domain name is determined based on the protocol capability indicators corresponding to the N protocols and the correlation between every two protocols among the N protocols. Finally, a comprehensive score of the target domain name is determined based on its credibility, average probing latency, and protocol association value. When the comprehensive score of the target domain name is lower than or equal to a first threshold, the target domain name is determined to be abnormal.

[0028] Thus, this method achieves multi-source detection of domain names, overcoming the limitations of single-dimensional indicator monitoring. On the other hand, it enables effective correlation of features between different protocols and provides a comprehensive quantitative evaluation of target domain names in multiple dimensions such as link credibility, latency performance, and protocol capabilities. Logically, it establishes a collaborative mechanism among multiple indicators, effectively improving the accuracy of domain name anomaly detection.

[0029] To make the solution provided in this application clearer, the method provided in this application will be described below with reference to specific embodiments.

[0030] Figure 1 This is a flowchart of a domain name anomaly determination method based on multi-source detection disclosed in an embodiment of this application. The method includes: S101: The computing device obtains the link trustworthiness based on the set of authoritative servers for the target domain name.

[0031] Computing devices can determine link trustworthiness based on the set of authoritative servers querying the target domain name. In other words, computing devices can quantitatively evaluate the basic configuration and resolution interaction status of the target domain name at the network and resolution path level, providing a link-level trustworthiness benchmark for subsequent heterogeneous data exploration.

[0032] Existing methods typically rely on recursive resolution results when performing probing. When nameservers (NS) are missing, there are abnormal records, or some domain name system levels fail, it becomes difficult to continue to complete accurate probing.

[0033] Therefore, when a computing device performs an operation to query the set of authoritative servers for a target domain name, it can first configure multiple recursive DNS servers as initial resolution nodes to form a recursive server set, and then sequentially perform DNS service (NS) record resolution operations for each target domain name to be probed. When the target domain name has no historical records, or when it is found during the normal resolution process that the target domain name does not have a valid NS record, or when its associated glue record is missing, the computing device will automatically trigger a recursive fallback mechanism.

[0034] At this point, the computing device will start from the root name server and perform a step-by-step reconstruction query according to the domain name hierarchy of the target domain, from top to bottom, until it obtains the set of authoritative servers for the target domain. For example, the domain name hierarchy of the target domain can be defined as a hierarchical sequence from the root domain to the target domain. The computing device will initiate query requests step by step from top to bottom according to this hierarchical sequence until it successfully restores and reconstructs the complete resolution path of the target domain, thereby obtaining a valid set of authoritative servers.

[0035] After successfully obtaining the set of authoritative servers, the computing device can further resolve the IPv4 address set and IPv6 address set corresponding to each authoritative server, thereby providing complete infrastructure network layer address support for subsequent multi-source probing.

[0036] After obtaining the set of authoritative servers for the target domain, the computing device can calculate the corresponding link credibility based on this set and various statistical indicators during the query interaction process. The link credibility is determined by the deviation between the obtained set of authoritative servers and the theoretical set of authoritative servers for the target domain, and the deviation between the number of successful queries and the total number of queries. For example, the deviation between the obtained set of authoritative servers and the theoretical set of authoritative servers for the target domain can be characterized by the ratio or difference between the number of successfully obtained valid authoritative servers and the theoretical number of authoritative servers that the domain should have; while the deviation between the number of successful queries and the total number of queries can be characterized by the ratio or difference between the number of successful responses during query reconstruction and the total number of queries initiated. In other words, the link credibility can be determined with reference to the following expression: ; in, For link credibility, The number of valid authoritative servers obtained from the query. The theoretical number of authoritative servers for the target domain. To query the number of successful queries, This represents the total number of queries. The weighting coefficient is not limited in the embodiments of this application.

[0037] In this way, by calculating the credibility of this link, we can not only accurately reflect the completeness of the domain name resolution path restoration, but also effectively demonstrate the robustness of the network link and the stability of the service response, thereby achieving a precise quantitative assessment of the true state of the domain name resolution link.

[0038] S102: The computing device performs multi-source probing on the target domain name based on a set of authoritative servers, and obtains multi-source probing indicators and the average probing latency of the target domain name.

[0039] The computing device, based on a set of authoritative servers, performs multi-source probing on the target domain name, obtaining multi-source probing metrics and the average probing latency of the target domain name. The multi-source probing metrics include protocol capability metrics corresponding to N protocols, where N is a positive integer greater than 1.

[0040] Specifically, for obtaining protocol capability indicators, the N protocols may include at least two of the following: DNS protocol, Hypertext Transfer Protocol (HTTP) or Hypertext Transfer Protocol Secure (HTTPS), Transmission Control Protocol / Internet Protocol (TCP / IP), Domain Name System Security Extensions (DNSSEC) protocol, Next Secure 3 (NSEC3) protocol or Extension Mechanisms for DNS 0 (EDNS0) protocol.

[0041] Among them, the DNSSEC protocol is a security extension mechanism that provides source verification and data integrity checks for Domain Name System (DNS) data. Computing devices can determine whether a target domain name supports the DNSSEC protocol by querying resource records such as Delegation Signer (DS) records and DNSKEY records, thereby assessing the domain name's security defense capabilities against DNS spoofing and cache poisoning. The NSEC3 protocol, as an enhanced extension of the DNSSEC protocol, is a hash-based negative response mechanism that provides proof of non-existence and is resistant to dictionary attacks. Computing devices can determine its deployment status by detecting whether the authoritative server's response contains an NSEC3 record, thus quantifying the target domain name's security attributes against zone enumeration attacks. The EDNS0 protocol is an extended transmission mechanism that allows DNS messages to exceed the traditional 512-byte size limit. Computing devices can determine its support by sending extended query messages and counting the number of successful responses. This protocol support effectively reflects whether the target domain name's underlying infrastructure has the basic transmission capability to handle large-capacity security payload messages.

[0042] Correspondingly, each protocol capability indicator reflects the current target domain's support for it. For example, if the target domain does not support the protocol, the corresponding protocol capability indicator value is 0; if the target domain supports the protocol, the corresponding protocol capability indicator value is 1.

[0043] In this way, we can obtain the actual support performance of the target domain name for multiple protocols in a real heterogeneous resolution environment.

[0044] In some possible implementations, in addition to including the protocol capability indicators corresponding to N protocols, multi-source detection indicators may also include at least one of network availability indicators, registration attribute indicators, or host-side fingerprint indicators.

[0045] Network availability metrics are quantitative parameters used to characterize the actual reachability and service quality of a target domain name at the network and transport layers. Computing devices can collect this metric by sending specific probe messages (such as ICMP echo request messages or TCP handshake synchronization messages) to the set of authoritative servers for the target domain name or the business servers bound to that domain name. For example, this metric can be specifically reflected by packet loss rate or connection success rate. Thus, by introducing network availability metrics, the network health status of the underlying infrastructure of the target domain name can be reflected in real time, avoiding interference from occasional network congestion or link disconnections in subsequent anomaly detection.

[0046] Registration attribute metrics refer to data used to characterize the compliance, stability, and historical sustainability of a target domain name throughout its administrative lifecycle. Computing devices can obtain the registration configuration text of a target domain name by invoking domain registration data access protocols (such as RDAP) or sending query requests to WHOIS servers, and extract key time points and institutional attributes from it. For example, registration attribute metrics can be specifically represented as the domain name's duration of existence, i.e., the difference between the current timestamp during the current multi-source probe and the timestamp when the target domain name was initially created at the registry. Similarly, registration attribute metrics can also include the expiration threshold duration, obtained from the difference between the target domain name's preset expiration timestamp and the current timestamp. Thus, by introducing registration attribute metrics, the attributes of a target domain name can be determined from its duration of existence, because malicious domain names or temporarily constructed attack domain names typically exhibit statistical characteristics such as extremely short durations, near expiration, and frequent changes in registrars.

[0047] Host-side fingerprinting refers to the unique behavioral characteristics of the operating system, software version identifiers, and encryption suite configuration attributes exposed by the backend server mapped to the target domain when interacting with the probe node at the application layer. Computing devices can use fingerprint similarity for quantitative characterization. For example, it's the ratio of the number of elements in the intersection to the number of elements in the union between the currently detected set of application layer features (such as component names and version number strings returned by the web server) and the set of known security service features pre-stored in a local benchmark database. Thus, by introducing host-side fingerprinting, the system can deeply understand the software stack architecture on the server side. If this similarity indicator undergoes an abnormally drastic change, it often means that the backend server of the target domain may have been hijacked, maliciously tampered with, or its services migrated.

[0048] In some possible implementations, computing devices can perform multi-source probing on the target domain name concurrently. This not only saves runtime latency but also allows for the acquisition of various metrics under relatively stable network conditions, resulting in more accurate determinations.

[0049] Based on concurrent probing, the computing device can also obtain the multi-source probing latency corresponding to each concurrent probing task, and obtain the average probing latency of the target domain name based on the maximum value among the multi-source probing latencies and the time overhead used for probing scheduling. That is, the average probing latency can be determined with reference to the following mathematical expression: ; in, To detect the average latency, The time taken by each concurrent probe. This refers to the time overhead used for detection scheduling.

[0050] Thus, by introducing a multi-source concurrent detection mechanism, S102 can break the limitations of single-dimensional indicator monitoring and logically establish a comprehensive feature structure covering multiple dimensions such as basic resolution, protocol support, and network availability. By binding the calculation of the average detection latency with the maximum latency and scheduling overhead of each concurrent task, it can not only accurately quantify the real response performance of the target domain name in the actual heterogeneous resolution environment, but also effectively reflect the comprehensive time cost of the system processing multi-source data in high-concurrency scenarios.

[0051] S103: The computing device determines the credibility of the target domain name based on multi-source detection indicators and link credibility.

[0052] Computing devices can determine the trustworthiness of a target domain name based on multi-source detection indicators and link trustworthiness, thus providing a comprehensive and multi-dimensional reflection of whether the domain name is trustworthy. For example, the trustworthiness of a target domain name can be expressed using the following formula: ; in, To assess the credibility of the target domain name, Indicates the first The weight of each indicator This represents the indicator value, which can be a normalized value. This indicates the reliability of the parsing link (refer to the description in S101). This represents network availability metrics (see description in S102). , This indicates an adjustment coefficient, but the embodiments of this application do not limit the adjustment coefficient. It should be noted that... One indicator was proposed separately because network availability is considered important; its essence is also a weighted average of indicators, and it can also be categorized under... In the item.

[0053] S104: The computing device determines the protocol association value of the target domain name based on the protocol capability indicators corresponding to the N protocols and the correlation between each pair of protocols among the N protocols.

[0054] The computing device can determine the protocol association value of the target domain name based on the protocol capability indicators corresponding to N protocols and the correlation between every two protocols among the N protocols. In this way, the inherent symbiotic or exclusive relationships between different network protocols in actual deployment can be determined, logically constructing a feature quantity that can quantitatively evaluate the rationality and degree of synergy of multi-source heterogeneous protocol configuration.

[0055] The computing device determines the protocol association value of the target domain name based on the protocol capability indicators corresponding to N protocols and the correlation between every two protocols among the N protocols. This value can be determined using the following calculation expression: ; in, For protocol-associated values, Indicates the protocol support status. This indicates the correlation between the capabilities of different protocols. To enhance the weight of associations.

[0056] For example, this expression can be used to determine the synergistic enhancement relationships between protocol combinations such as DNSSEC and NSEC3; IPv6 and EDNS0; TCP and DNSSEC.

[0057] In this way, by performing matrix-style collaborative calculations based on the capability indicators of N protocols and the statistical correlation between protocols, the correlation of domain names at the application layer protocol cluster level can be captured. This provides more robust and discriminative quantitative feature support for constructing a comprehensive and in-depth domain name profile score by combining link credibility and latency indicators.

[0058] S105: The computing device determines a comprehensive score for the target domain name based on its credibility, average probe latency, and protocol association value.

[0059] Computing devices can determine a comprehensive score for a target domain name based on its credibility, average probe latency, and protocol correlation value. This allows for the construction of a high-level, multi-dimensional collaborative profiling and scoring model that integrates link / feature credibility, network resolution performance, and application layer protocol configuration correlation across dimensions in a standardized manner, thereby providing a final quantitative evaluation of the target domain name's operational status from a global network space perspective.

[0060] In some possible implementations, the overall score of the target domain name is determined according to the following expression: ; in, For comprehensive scoring, For credibility (see description in S103). This is a protocol-associated value (see description in S104). To detect the average latency (see description in S102). , and This is a weighting coefficient, and its value is not limited in the embodiments of this application.

[0061] Credibility Associated values ​​with the protocol As a positive gain feature, a higher score indicates a more robust overall compliance and security extension protection deployment for the domain name, thus boosting the overall score; while the normalized average detection latency... As a negative deduction feature of the model, it indicates that the worse the domain name resolution link performance or authoritative response efficiency, the lower the overall score will be due to the subtraction of points after weighting in the formula.

[0062] S106: When the overall score of the target domain name is lower than or equal to the first threshold, the computing device determines that the target domain name is abnormal.

[0063] When the overall score of a target domain name is lower than or equal to a first threshold, the computing device determines that the target domain name is abnormal. This enables automated and accurate identification of high-risk or degraded target domain names in cyberspace. It should be noted that the specific value of the first threshold is not limited in this embodiment.

[0064] In some possible implementations, in order to further enhance the system's ability to detect anomalies in domain name evolution over time, the computing device can also dynamically compare multi-source detection indicators based on historical data.

[0065] For example, a computing device can store the multi-source probing metrics obtained for a target domain in the first probing period as a historical snapshot. Then, it can calculate in real time the feature differences between the multi-source probing metrics obtained for the target domain in the second probing period and the historical snapshot.

[0066] The key differences include at least one of the following: changes in the authoritative DNS service software version, changes in the resolved IP address, and changes in protocol support. Changes in the authoritative DNS service software version refer to the computing device comparing the authoritative server text obtained through host-side fingerprinting; if the software brand or specific version number strings do not match between two periods, a version change is determined. Changes in the resolved IP address refer to the intersection of the IP addresses of the computing device over two periods, determining the degree of Autonomous System (AS) topology shift of the IP address. Changes in protocol support, such as a decrease in security protocol support capabilities, refer to the computing device comparing the protocol capability indicators between two periods to see if it changes from supported to unsupported. This decrease in protocol capability usually indicates that the domain name has been subjected to malicious attacks or underlying key management problems.

[0067] Finally, the computing device calculates a dynamic anomaly score for the target domain name based on the feature differences. When the dynamic anomaly score is greater than or equal to a second threshold, it is determined that the target domain name is abnormal. It should be noted that this embodiment does not limit the specific value of the second threshold. For example, the dynamic anomaly score can be determined according to the following expression: ; in, For dynamic anomaly scoring, This indicates a change in DNS software. To resolve address changes, This indicates that the protocol supports changes. , , As for the weight, the embodiments of this application do not limit this.

[0068] Thus, by introducing historical snapshot comparisons across detection cycles, computing devices can capture in real time the coordinated mutation behavior of target domain names in three key dimensions: "authoritative software version, network layer topology space, and application layer protocol," thereby providing more rigorous, dynamic, and robust technical support for ensuring the overall credibility of the underlying infrastructure of the domain name system.

[0069] In some possible implementations, the computing device can also achieve structured data storage. For example, the computing device can uniformly store the results of multi-source detection as a JSON structure, or use a graph database, time-series database, or relational database for storage. At the same time, the following datasets are generated: (1) data on the resolution status of key domain names; (2) data on the discovery of anomalies in the resolution of key domain names; (3) data on the monitoring and analysis of key domain names; (4) data on the monitoring and analysis of key domain names.

[0070] In some possible implementations, the computing device can also construct different indicator systems based on the indicators of multi-source detection results. For example: (1) domain name resolution delay comparison analysis; (2) NS name format standardization ratio analysis; (3) NS record redundancy analysis; (4) NS record pointing to CNAME anomaly analysis; (5) authoritative server DNSSEC support ratio analysis; (6) registry domain name lock status analysis; (7) domain name validity period exceeding 90 days statistical analysis; (8) domain name resolution data change statistics; (9) IPv6 protocol support analysis; (10) NSEC3 protocol support analysis; (11) domain name home country ranking analysis; (12) domain name corresponding IP operating system type statistics; (13) TCP protocol support analysis; (14) domain name resolution software and version distribution analysis; (15) EDNS0 protocol support analysis; (16) domain name website access status statistical analysis. This further expands the indicator system and more accurately determines the status of the target domain name.

[0071] Based on the above description, this application provides a method for determining domain name anomalies based on multi-source detection. On the one hand, this method achieves multi-source detection of domain names, overcoming the limitations of monitoring single-dimensional indicators. On the other hand, this method achieves effective correlation between features of different protocols and comprehensively quantifies the target domain name in multiple dimensions such as link credibility, latency performance, and protocol capabilities. Logically, it establishes a collaborative mechanism among multiple indicators, effectively improving the accuracy of domain name anomaly detection.

[0072] To make the above method embodiments more specific and intuitive, this application also provides a scenario example of a domain name anomaly determination method based on multi-source detection. It should be noted that this example is merely an illustrative illustration of the method provided in this application and does not represent all implementations of the method provided in this application.

[0073] See Figure 2 This is a schematic diagram illustrating a method for determining domain name anomalies based on multi-source detection, provided in an embodiment of this application. The method includes the following steps, where the dashed lines represent optional steps: S201: The computing device performs environment settings and queries the set of authoritative servers for the target domain name.

[0074] This embodiment uses 1 million key domain names as the detection targets and adopts a distributed detection node deployment method to build a large-scale domain name multi-source heterogeneous collaborative detection and profiling system.

[0075] The system includes: (1) Domain Name Task Scheduling Module; (2) Recursive DNS detection module; (3) Authoritative server detection module; (4) WHOIS information detection module; (5) Website status detection module; (6) Host fingerprint recognition module; (7) Abnormal change detection module; (8) Structured portrait data storage module.

[0076] The system employs a multi-threaded concurrent scheduling approach to coordinate tasks such as domain name resolution, protocol detection, WHOIS query, website status detection, and host fingerprinting, thereby improving the efficiency of large-scale domain name detection.

[0077] In actual deployment, the system divides the 1 million key domain names into groups of 50,000. The average processing time for a single group (50,000 domain names) is approximately 10 to 15 hours, which can stably support data collection and profile building tasks for millions of domain names.

[0078] S202: The computing device obtains the detection results.

[0079] Taking the domain name "myslpolska.info" as an example, the system detection results are as follows, including multi-source detection indicators, network availability indicators, registration attribute indicators, host-side fingerprint indicators, average detection latency, etc. Record A: 185.208.164.145; NS records: ns1.cyberfolks.pl., ns2.cyberfolks.pl., ns3.cyberfolks.pl.; DNSSEC support: 0; NSEC3 supports: 1; TCP support: 1; EDNS0 supports: 1; IPv6 support: 0; Website status: 200; Average DNS response time: 85ms; WHOIS country: PL; DNS software type: Served by PowerDNS - https: / / www.powerdns.com / ; Operating system type: Linux 4.4.

[0080] S203: The computing device determines the credibility of the target domain name.

[0081] First, the various indicators are normalized to obtain the domain name feature vector: ; The indicators respectively represent: DNSSEC support; NSEC3 support; TCP support; EDNS0 is supported; IPv6 support; Website status; Reliability of the analysis; WHOIS credibility; Host fingerprint stability.

[0082] During the probe, a total of 25 DNS queries were performed, of which 20 resulted in successful responses. According to the formula Confidence of the analysis ; WHOIS credibility is based on domain registration information, such as a registration duration of 8 years, a reference duration of 10 years, 210 remaining expiration days, and a security reference period of 365 days. These parameters are set accordingly. Then, we can refer to a similar formula for calculating the reliability of the analysis to obtain: Based on the statistical information, the minimum value is 0.20 and the maximum value is 0.73. Therefore, the normalized WHOIS confidence level is calculated as follows: .

[0083] Host fingerprint stability detection obtains eight host fingerprint characteristics, such as operating system version and type, DNS software version, host access encryption protocol, and open ports. If there is only one difference based on historical information comparison, then the host fingerprint stability is determined. Let the minimum value be 0 and the maximum value be 1. Based on information normalization, we obtain... .

[0084] Set weight parameters: ; in: ; set up: , ; ; Continue calculation: ; Website access: =1; ; According to the credibility expression in S103: ; Conclusion: .

[0085] S204: The computing device determines the protocol association value of the target domain name.

[0086] Calculate the associated value of the protocol: ; There are five supported protocols: DNSSEC, NSEC3, TCP, EDNS0, and IPv6, corresponding to (0, 1, 1, 1, 0). ; in: The correlation between DNSSEC and the TCP protocol is 0.71; The correlation between EDNS0 and IPv6 is 0.63; Average correlation: ; set up: ; but: .

[0087] S205: The computing device determines the overall score of the target domain name and determines the status of the target domain name.

[0088] Finally, a comprehensive score is constructed by combining the analysis latency: ; set up: , ; Assuming the resolution delay of 85ms is normalized to 0.18, The final result is: .

[0089] If the system defines 0.65 to 0.80 as stable operation, the target domain name will be marked as abnormal.

[0090] S206: Computing device provides a comprehensive profile of the target domain name.

[0091] The computing device can automatically generate profile tags based on the comprehensive score, including: (1) A profile of DNS protocol capabilities; (2) IPv6 supports portraits; (3) Website usability profile; (4) Infrastructure stability profile; (5) Analyze performance portraits.

[0092] For the above domain names, the following profile tags are ultimately generated: "Supports EDNS0 / TCP protocol, supports NSEC3, IPv6 missing, website status is normal, medium to low latency, Linux host environment."

[0093] S207: The computing device dynamically determines abnormal situations of the target domain name.

[0094] Suppose the system continuously probes the target domain name within different time periods and detects the following changes: The DNS software version has changed from Power DNS 4.9 to BIND 9.18, and the resolved address has also changed. The address 185.208.164.145 changed to 185.208.123.19, and the DNSSEC status was detected to have changed from "off" to "on".

[0095] According to the expression: ; set up: , ; in: DNS software change rating: ; IP Change Score: ; Protocol change rating: ; The final anomaly score is: ; If the computing device is set with an abnormal threshold: ; This will automatically trigger a "high-risk analysis environment change alarm" and record it in the abnormal change database.

[0096] In some possible implementations, the computing device can also store the above detection results as structured JSON profile data and further generate statistical analysis results and records of abnormal changes.

[0097] Based on the above description, this application provides a possible implementation of a domain name anomaly determination method based on multi-source detection, which more intuitively demonstrates the advantages of this method in improving the accuracy and comprehensiveness of domain name anomaly determination.

[0098] This application also provides a domain name anomaly determination device based on multi-source detection. The device of this application will be described in detail below with reference to the accompanying drawings.

[0099] See Figure 3The diagram shows a structural schematic of a domain name anomaly determination device based on multi-source detection. The domain name anomaly determination device 300 based on multi-source detection may include: The query module 301 is used to obtain the link credibility based on the set of authoritative servers of the target domain name. The link credibility is determined based on the deviation between the set of authoritative servers obtained by the query and the theoretical set of authoritative servers of the target domain name, as well as the deviation between the number of successful queries and the total number of queries. The detection module 302 is used to perform multi-source detection on the target domain name based on the set of authoritative servers, and obtain multi-source detection indicators and the average detection latency of the target domain name. The multi-source detection indicators include the protocol capability indicators corresponding to N protocols, where N is a positive integer greater than 1. The calculation module 303 is used to determine the credibility of the target domain name based on multi-source detection indicators and link credibility; The calculation module 303 is also used to determine the protocol association value of the target domain name based on the protocol capability indicators corresponding to the N protocols and the correlation between each pair of protocols in the N protocols; The calculation module 303 is also used to determine the comprehensive score of the target domain name based on the credibility of the target domain name, the average probe latency, and the protocol association value; The anomaly determination module 304 is used to determine that the target domain name is abnormal when the comprehensive score of the target domain name is lower than or equal to the first threshold.

[0100] In some possible implementations, the overall score of the target domain name is determined according to the following expression: ; in, For comprehensive scoring, For credibility, For protocol-associated values, To detect the average latency, 、 and These are the weighting coefficients.

[0101] In some possible implementations, the detection module 302 performs multi-source probing on the target domain name, obtains multi-source probing metrics and the average probing latency of the target domain name, specifically for: Perform multi-source concurrent probing on the target domain name; obtain multi-source probing metrics and multi-source probing latency; obtain the average probing latency of the target domain name based on the maximum value of the multi-source probing latency and the time overhead used for probing scheduling.

[0102] In some possible implementations, the N protocols include at least two of the following: DNS protocol, HTTP or HTTPS protocol, TCP / IP protocol, DNSSEC protocol, NSEC3 protocol, or EDNS0 protocol.

[0103] In some possible implementations, multi-source detection metrics may also include at least one of network availability metrics, registration attribute metrics, or host-side fingerprint metrics.

[0104] In some possible implementations, when query module 301 queries the set of authoritative servers for the target domain name, it is specifically used for: When the target domain name has no historical records, the query is reconstructed from top to bottom according to the domain name hierarchy of the target domain name, starting from the root name server, until the set of authoritative servers of the target domain name is obtained.

[0105] In some possible implementations, the device also includes a storage module for storing the multi-source detection indicators of the target domain name obtained in the first detection period as a historical snapshot; At this time, the calculation module 303 is also used for: The characteristic differences of the target domain name obtained in the second probing period compared with the historical snapshot are calculated. The characteristic differences include at least one of the following: changes in the authoritative DNS service software version, changes in the resolved IP address, and changes in protocol support. The exception determination module 304 is also used for: The dynamic anomaly score of the target domain name is calculated based on the feature differences. When the dynamic anomaly score is greater than or equal to the second threshold, it is determined that the target domain name is abnormal.

[0106] Based on the foregoing method and apparatus, this application also provides a computing device. The computing device includes a processor and a memory. The memory stores computer-readable instructions, and the processor executes these computer-readable instructions to perform the foregoing method. In some examples, the computing device is used to implement the functions of the foregoing apparatus.

[0107] This application provides a computer-readable storage medium storing instructions that, when executed on a computer device, cause the computer device to perform the above-described method.

[0108] This application provides a computer program product containing instructions that, when run on a computer device, cause the computer device to perform the above-described method.

[0109] It should also be noted that the device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. In addition, in the device embodiment drawings provided in this application, the connection relationship between modules indicates that they have a communication connection, which can be implemented as one or more communication buses or signal lines.

[0110] Through the above description of the embodiments, those skilled in the art can clearly understand that this application can be implemented by means of software plus necessary general-purpose hardware, or it can be implemented by special-purpose hardware including application-specific integrated circuits, special-purpose CPUs, special-purpose memory, special-purpose components, etc. Generally, any function performed by a computer program can be easily implemented by corresponding hardware, and the specific hardware structure used to implement the same function can also be diverse, such as analog circuits, digital circuits, or special-purpose circuits. However, for this application, software program implementation is more often a better implementation method. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a readable storage medium, such as a computer floppy disk, USB flash drive, mobile hard disk, ROM, RAM, magnetic disk, or optical disk, etc., and includes several instructions to cause a computer device (which may be a personal computer, training equipment, or network device, etc.) to execute the methods described in the various embodiments of this application.

[0111] In the above embodiments, implementation can be achieved, in whole or in part, through software, hardware, firmware, or any combination thereof. When implemented in software, it can be implemented, in whole or in part, as a computer program product.

[0112] The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of this application are generated. The computer may be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions may be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions may be transmitted from one website, computer, training device, or data center to another website, computer, training device, or data center via wired (e.g., coaxial cable, fiber optic, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium may be any available medium that a computer can store or a data storage device such as a training device or data center that integrates one or more available media. The available media may be magnetic media (e.g., floppy disks, hard disks, magnetic tapes), optical media (e.g., DVDs), or semiconductor media (e.g., solid-state drives (SSDs)).

[0113] The above description of the disclosed embodiments enables those skilled in the art to make or use this application. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of this application. Therefore, this application is not to be limited to the embodiments shown herein, but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.

Claims

1. A method for determining domain name anomalies based on multi-source detection, characterized in that, The method includes: The link credibility is obtained based on the set of authoritative servers for the target domain name. The link credibility is determined based on the deviation between the set of authoritative servers obtained from the query and the theoretical set of authoritative servers for the target domain name, as well as the deviation between the number of successful queries and the total number of queries. Based on the set of authoritative servers, multi-source probing is performed on the target domain name to obtain multi-source probing indicators and the average probing latency of the target domain name. The multi-source probing indicators include protocol capability indicators corresponding to N protocols, where N is a positive integer greater than 1. The credibility of the target domain name is determined based on the multi-source detection indicators and the link credibility. The protocol association value of the target domain name is determined based on the protocol capability indicators corresponding to the N protocols and the correlation between every two protocols among the N protocols; A comprehensive score for the target domain name is determined based on the target domain name's credibility, average probe latency, and protocol association value. If the overall score of the target domain name is lower than or equal to the first threshold, it is determined that the target domain name is abnormal.

2. The method according to claim 1, characterized in that, The overall score of the target domain name is determined according to the following expression: ; in, For the aforementioned comprehensive score, For the stated credibility, The associated value of the protocol. The average detection delay is... , and These are the weighting coefficients.

3. The method according to claim 1, characterized in that, The step of performing multi-source probing on the target domain name and obtaining multi-source probing metrics and the average probing latency of the target domain name includes: Perform multi-source concurrent probing on the target domain name; Obtain the multi-source detection indicators and multi-source detection delay; The average detection latency of the target domain name is obtained based on the maximum value among the multi-source detection latency and the time overhead for detection scheduling.

4. The method according to claim 1, characterized in that, The N protocols include at least two of the following: DNS protocol, HTTP or HTTPS protocol, TCP / IP protocol, DNSSEC protocol, NSEC3 protocol, or EDNS0 protocol.

5. The method according to claim 1, characterized in that, The multi-source detection metrics also include at least one of network availability metrics, registration attribute metrics, or host-side fingerprint metrics.

6. The method according to any one of claims 1 to 5, characterized in that, The set of authoritative servers for the target domain name being queried includes: If the target domain name has no historical records, the query is reconstructed from top to bottom according to the domain name hierarchy of the target domain name, starting from the root name server, until the set of authoritative servers of the target domain name is obtained.

7. The method according to any one of claims 1 to 5, characterized in that, The method further includes: Store the multi-source detection indicators obtained for the target domain name in the first detection period as a historical snapshot; Calculate the feature differences of the multi-source probing indicators obtained by the target domain name in the second probing period compared with the historical snapshot, wherein the feature differences include at least one of the following: changes in the authoritative DNS service software version, changes in the resolved IP address, and changes in protocol support; The dynamic anomaly score of the target domain name is calculated based on the feature differences. When the dynamic anomaly score is greater than or equal to the second threshold, it is determined that the target domain name is abnormal.

8. A domain name anomaly determination device based on multi-source detection, characterized in that, The device includes: The query module is used to obtain the link credibility based on the set of authoritative servers of the target domain name. The link credibility is determined based on the deviation between the set of authoritative servers obtained by the query and the theoretical set of authoritative servers of the target domain name, and the deviation between the number of successful queries and the total number of queries. The detection module is used to perform multi-source detection on the target domain name based on the set of authoritative servers, and obtain multi-source detection indicators and the average detection latency of the target domain name. The multi-source detection indicators include protocol capability indicators corresponding to N protocols, where N is a positive integer greater than 1. A calculation module is used to determine the credibility of the target domain name based on the multi-source detection indicators and the link credibility. The calculation module is also used to determine the protocol association value of the target domain name based on the protocol capability indicators corresponding to the N protocols and the correlation between every two protocols among the N protocols; The calculation module is also used to determine a comprehensive score for the target domain name based on the credibility of the target domain name, the average detection latency, and the protocol association value; The anomaly determination module is used to determine that the target domain name is abnormal when the comprehensive score of the target domain name is lower than or equal to a first threshold.

9. A computing device, characterized in that, The computing device includes: Memory is used to store computer programs or computer instructions; A processor for executing a computer program or computer instructions stored in the memory, causing the computing device to perform the method as described in any one of claims 1 to 7.

10. A computer program product, characterized in that, When the computer program product is run on a computer, it causes the computer to perform the method as described in any one of claims 1 to 7.