Domain name hijacking detection
By collecting and comparing the real domain name resolution data of the recursive server with the configuration data of the authoritative domain name server through cloud-based domain name hijacking analysis equipment, the real-time and accuracy issues of hijacking detection during the domain name resolution process are solved, ensuring that users obtain the correct domain name resolution results.
Patent Information
- Application Number
- PCT/IB2025/055121
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-05-23
- Filing Date
- 2025-05-16
- Publication Date
- 2025-11-27
AI Technical Summary
In existing technologies, there is a risk of domain name hijacking during the domain name resolution process, which can lead to malicious tampering with the resolution results actually obtained by users, affecting normal access. Furthermore, traditional detection methods lack real-time performance and accuracy.
By collecting real domain name resolution data from recursive servers through cloud-based domain hijacking analysis equipment and obtaining configuration data from authoritative domain name servers, the actual resolution results are compared with reference resolution results to detect in real time whether a domain name has been hijacked.
It achieves high-precision, real-time domain hijacking detection, ensuring users receive correct domain name resolution results and reducing the computational load and data volume during the detection process.
Smart Images

Figure IB2025055121_27112025_PF_FP_ABST
Abstract
Description
[0001] Domain name hijacking detection
[0002]
[0001] The present disclosure relates to the field of communication technology, in particular to domain name hijacking detection. BACKGROUND
[0003]
[0002] The Domain Name System (DNS) is a system that provides identification mapping relationship query of domain names and IP addresses, etc., enables users to access the Internet more conveniently without memorizing IP addresses that can be directly read by devices. The process of ultimately obtaining an IP address corresponding to a domain name through a domain name is called domain name resolution.
[0004]
[0003] In the process of domain name resolution, two types of servers are mainly involved, one is a recursive server, and the other is an authoritative domain name server. Among them, the authoritative domain name server is a server that stores domain name configuration data of specific domain names and IP addresses, etc. The recursive server is a server that provides recursive query service for domain names, generally does not store domain name configuration data, only assists users to complete the domain name resolution process and returns the actual domain name resolution result to the user, and only caches the previous query result to improve the resolution efficiency.
[0005]
[0004] In the process of obtaining the actual domain name resolution result by the user using a certain recursive server, the user's domain name resolution request or the actual domain name resolution result may be at risk of hijacking, resulting in that the user actually obtains the resolution result that is maliciously tampered, and affecting the normal access of the user. Therefore, it is necessary to timely find the hijacking phenomenon existing in the network. SUMMAR
[0006]
[0005] Embodiments of the present disclosure provide a domain name hijacking detection method, device, storage medium and program, which can complete the hijacking detection in real time and accurately.
[0007]
[0006] In a first aspect, the embodiments of the present disclosure provide a domain name hijacking detection method, applied to a domain name hijacking analysis device, the method comprising: collecting recursive resolution data of a recursive server, the recursive server being a server providing domain name recursive query service, the recursive resolution data comprising a domain name actually requested for resolution by a user and an actual domain name resolution result fed back by the recursive server for the domain name, the recursive server obtaining the actual domain name resolution result by recursively querying an authoritative domain name server; obtaining domain name configuration data of the authoritative domain name server, the domain name configuration data comprising the domain name and a reference domain name resolution result corresponding to the domain name; and determining whether the domain name is hijacked at the recursive server according to the actual domain name resolution result and the reference domain name resolution result.
[0008]
[0007] In a second aspect, the embodiments of the present disclosure provide a domain name hijacking detection device, applied to a domain name hijacking analysis device, the device comprising: a collection module configured to collect recursive resolution data of a recursive server, the recursive server being a server providing domain name recursive query service, the recursive resolution data comprising a domain name actually requested for resolution by a user and an actual domain name resolution result fed back by the recursive server for the domain name, the recursive server obtaining the actual domain name resolution result by recursively querying an authoritative domain name server; an obtaining module configured to obtain domain name configuration data of the authoritative domain name server, the domain name configuration data comprising the domain name and a reference domain name resolution result corresponding to the domain name; and a determination module configured to determine whether the domain name is hijacked at the recursive server according to the actual domain name resolution result and the reference domain name resolution result.
[0009]
[0008] In a third aspect, the embodiments of the present disclosure provide a domain name hijacking detection method, applied to a recursive server providing domain name recursive query service, the method comprising: in response to a domain name resolution request of a user, obtaining an actual domain name resolution result corresponding to a domain name requested for resolution, the actual domain name resolution result being obtained by the recursive server by recursively querying an authoritative domain name server; generating recursive resolution data, the recursive resolution data comprising the domain name and the actual domain name resolution result; and sending the recursive resolution data to a domain name hijacking analysis device, so that the domain name hijacking analysis device obtains domain name configuration data of the authoritative domain name server, and determines whether the domain name is hijacked at the recursive server according to a reference domain name resolution result corresponding to the domain name in the domain name configuration data and the actual domain name resolution result.
[0010]
[0009] In a fourth aspect, the embodiments of the present disclosure provide a domain name hijacking detection apparatus, applied to a recursive server providing domain name recursive query service, and the apparatus comprises: an obtaining module, configured to obtain an actual domain name resolution result corresponding to a domain name to be resolved in response to a user's domain name resolution request, the actual domain name resolution result being obtained by the recursive server through recursive query of an authoritative domain name server; a generating module, configured to generate recursive resolution data, the recursive resolution data comprising the domain name and the actual domain name resolution result; and a sending module, configured to send the recursive resolution data to a domain name hijacking analysis device, so that the domain name hijacking analysis device obtains domain name configuration data of the authoritative domain name server, and determines whether the domain name is hijacked at the recursive server according to a reference domain name resolution result corresponding to the domain name in the domain name configuration data and the actual domain name resolution result.
[0011]
[0010] In a fifth aspect, the embodiments of the present disclosure provide an electronic device, comprising: a memory, a processor, and a communication interface; wherein the memory stores executable code, and when the executable code is executed by the processor, the processor can at least implement the domain name hijacking detection method according to the first aspect or the third aspect.
[0012]
[0011] In a sixth aspect, the embodiments of the present disclosure provide a non-transitory machine readable storage medium, and the non-transitory machine readable storage medium stores executable code, and when the executable code is executed by a processor of an electronic device, the processor can at least implement the domain name hijacking detection method according to the first aspect or the third aspect.
[0013]
[0012] In a seventh aspect, the embodiments of the present disclosure provide a computer program product, and the computer program product comprises a computer program, and when the computer program is executed by a processor of an electronic device, the processor can at least implement the domain name hijacking detection method according to the first aspect or the third aspect.
[0014]
[0013] The domain name hijacking detection method provided by the embodiments of the present disclosure can obtain the actual domain name requested for resolution by each user at different time points and the actual domain name resolution result fed back by the recursive server for the domain name by using the cloud-based domain name hijacking analysis device to collect recursive resolution data of the recursive server. Meanwhile, the domain name hijacking analysis device can also obtain the domain name configuration data of the authoritative domain name server to obtain the domain name and the reference domain name resolution result corresponding to the domain name, and then compare the actual domain name resolution result with the reference domain name resolution result to determine whether the domain name is hijacked in the recursive server. The embodiments of the present disclosure can accurately detect hijacking by using the real recursive resolution data and the authoritative domain name configuration data for the domain name resolution request triggered by the user in real time. BRIEF DESCRIPTION OF DRAWINGS
[0015]
[0014] In order to more clearly illustrate the technical solutions in the embodiments of the present disclosure, the drawings needed to be used in the embodiments will be briefly introduced. Obviously, the drawings in the following description are some embodiments of the present disclosure, and for those skilled in the art, other drawings can also be obtained without creative labor.
[0016]
[0015] FIG. 1 is a structural schematic diagram of a domain name hijacking detection system provided by an embodiment of the present disclosure;
[0017]
[0016] FIG. 2 is a flowchart of a domain name hijacking detection method provided by an embodiment of the present disclosure;
[0018]
[0017] FIG. 3 is an application schematic diagram of a domain name hijacking detection method provided by an embodiment of the present disclosure;
[0019]
[0018] FIG. 4 is a flowchart of a domain name hijacking detection method provided by an embodiment of the present disclosure;
[0020]
[0019] FIG. 5 is a flowchart of another domain name hijacking detection method provided by an embodiment of the present disclosure;
[0021]
[0020] FIG. 6 is a structural schematic diagram of a domain name hijacking detection apparatus provided by an embodiment of the present disclosure;
[0022]
[0021] FIG. 7 is a structural schematic diagram of another domain name hijacking detection apparatus provided by an embodiment of the present disclosure;
[0023]
[0022] FIG. 8 is a structural schematic diagram of an electronic device provided by an embodiment of the present disclosure. DETAILED DESCRIPTION
[0024]
[0023] In order to make the purposes, technical solutions and advantages of the embodiments of the present disclosure clearer, the technical solutions in the embodiments of the present disclosure will be described clearly and completely below with reference to the drawings in the embodiments of the present disclosure. Obviously, the described embodiments are only part of the embodiments of the present disclosure, rather than all the embodiments. Based on the embodiments in the present disclosure, all other embodiments obtained by a person of ordinary skill in the art without creative labor fall within the protection scope of the present disclosure.
[0025]
[0024] It should be noted that the user information (including but not limited to user equipment information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in the embodiments of the present disclosure are all information and data authorized by the user or authorized by all parties, and the collection, use and processing of the related data need to comply with the relevant laws, regulations and standards of the relevant countries and regions, and provide corresponding operation portal for the user to choose authorization or refusal.
[0026]
[0025] Some embodiments of the present disclosure will be described in detail below with reference to the drawings. The embodiments described below and the features in the embodiments can be combined with each other without conflict between the embodiments. In addition, the sequence of steps in each method embodiment described below is only an example, not a strict limitation.
[0027]
[0026] First, the terms or concepts involved in the embodiments of the present disclosure are explained.
[0028]
[0027] Domain Name System (DNS): is a system that provides domain name and IP address mapping relationship query, which can make it more convenient for users to access the Internet without memorizing IP addresses that can be directly read by devices. The process of getting the corresponding IP address and other identification information through the domain name is called domain name resolution.
[0029]
[0028] Recursive server: is a server that provides recursive query service for domain names, generally does not store domain name configuration data, only assists users to complete the domain name resolution process and returns the actual domain name resolution result to the user, and only caches the previous query result to improve the resolution efficiency.
[0030]
[0029] Authoritative domain name server: is a server that saves domain name configuration data of specific domain names and IP addresses.
[0031]
[0030] Domain name configuration server: is a server for managing domain name configuration data stored in the authoritative domain name server.
[0032]
[0031] Domain name hijacking: is a way of Internet attack, by resolving the domain name of user request to the wrong IP address so as to achieve the user can not access the target website, or malicious request user to visit the specified IP address.
[0033]
[0032] In the process of using a recursive server to obtain the actual domain name resolution result, the user's domain name resolution request or the actual domain name resolution result may be hijacked, resulting in that the user actually obtains the resolution result is maliciously tampered, affecting the normal access of the user. Therefore, it is necessary to timely find the hijacking phenomenon existing in the network.
[0034]
[0033] In the traditional scheme, a domain name resolution request for a domain name is generally simulated at a moment, and the domain name resolution request is sent to a plurality of recursive servers in different regions, so that a plurality of recursive servers return a plurality of domain name resolution results corresponding to the domain name after recursive query, that is, a plurality of IP address resolution results corresponding to the domain name. If the plurality of domain name resolution results are the same, it is considered that no hijacking occurs, and if there is an abnormal domain name resolution result different from other domain name resolution results in the plurality of domain name resolution results (for example, one of N domain name resolution results is different from the others), it is considered that the recursive server corresponding to the abnormal domain name resolution result has a hijacking problem of the domain name. However, such hijacking detection method can only simulate the visit of a domain name at a moment to determine the hijacking situation, and the real-time performance is poor, and the data used in the whole hijacking detection process is simulation data, not real data, which leads to low accuracy of the final hijacking detection result.
[0035]
[0034] In view of this, the embodiment of the present disclosure provides the following idea to solve the above problem: the embodiment of the present disclosure collects recursive resolution data of recursive servers by using a cloud domain name hijacking analysis device, obtains actual request resolution domain names of each user at different moments and actual domain name resolution results fed back by the recursive servers for the domain names, which are all real data, not simulation data. At the same time, the domain name hijacking analysis device can also obtain domain name configuration data of authoritative domain name servers, obtains domain names and reference domain name resolution results corresponding to the domain names, and then compares the actual domain name resolution results with the reference domain name resolution results, so as to determine whether the domain name is hijacked in the recursive server. The embodiment of the present disclosure uses real recursive resolution data and authoritative domain name configuration data for hijacking detection, which not only has high hijacking detection accuracy, but also has good real-time performance.
[0036]
[0035] Fig. 1 is a structural schematic diagram of a domain name hijacking detection system provided by an embodiment of the present disclosure. As shown in Fig. 1, the domain name hijacking detection system comprises a recursive server 10, an authoritative domain name server 20, a domain name hijacking analysis device 30, and a domain name configuration server 40. The domain name hijacking analysis device 30 can be arranged in the cloud. The domain name hijacking analysis device 30 is configured to collect recursive resolution data obtained by the recursive server 10, and obtain domain name configuration data of the authoritative domain name server 20 through the domain name configuration server 40, and determine whether the domain name is hijacked in the recursive server 10 according to an actual domain name resolution result and a reference domain name resolution result, and listen to a domain name configuration data update event of the domain name configuration server 40, and update the domain name configuration data based on the domain name configuration data update event. The domain name configuration server 40 is configured to manage domain name configuration data stored in the authoritative domain name server 20. The recursive resolution data comprises a domain name actually requested by a user for resolution and an actual domain name resolution result fed back by the recursive server for the domain name. The domain name configuration data comprises a domain name and a reference domain name resolution result corresponding to the domain name.
[0037]
[0036] In fact, the recursive server 10 can realize domain name query by recursively querying the authoritative domain name server 20. The recursive query process is not shown in Fig. 1 and will be described in subsequent embodiments.
[0038]
[0037] Based on the above system composition, the following specifically describes a domain name hijacking detection process.
[0039]
[0038] Fig. 2 is a flowchart of a domain name hijacking detection method provided by an embodiment of the present disclosure. The method is applied to a domain name hijacking analysis device. As shown in Fig. 2, the method comprises the following steps.
[0040]
[0039] 201. Collect recursive resolution data of a recursive server. The recursive server is a server providing recursive query service for domain names. The recursive resolution data comprises a domain name actually requested by a user for resolution and an actual domain name resolution result fed back by the recursive server for the domain name.
[0041]
[0040] 202. Obtain domain name configuration data of an authoritative domain name server. The domain name configuration data comprises a domain name and a reference domain name resolution result corresponding to the domain name.
[0042]
[0041] 203. Determine whether the domain name is hijacked in the recursive server according to an actual domain name resolution result and a reference domain name resolution result.
[0043]
[0042] In practical applications, different recursive servers can be deployed in different regions, for example, two recursive servers can be deployed in city A, one recursive server can be deployed in city B, and three recursive servers can be deployed in city C, that is, at least one recursive server can be deployed in each different region, which is not listed here. Different recursive servers deployed in the same region can correspond to different network operators. Therefore, the domain name resolution request actually triggered by a user in a region can be sent to a recursive server in the region based on the configuration information of the IP address of the recursive server on the terminal device of the user.
[0044]
[0043] In order to detect the hijacking of the domain name resolution process through the recursive servers, in the embodiments of the present disclosure, a domain name hijacking analysis service is provided in the cloud, and the device running the service is called a domain name hijacking analysis device, which is actually a cloud server. The recursive resolution data of each recursive server can be collected through the domain name hijacking analysis device.
[0045]
[0044] In the embodiments of the present disclosure, the recursive resolution data is generated by any recursive server based on the domain name resolution request triggered by any user at any time, which contains the domain name actually requested by the user for resolution and the actual domain name resolution result corresponding to the domain name. The actual domain name resolution result is obtained by the recursive server based on its own recursive query service, specifically through recursive query of the authoritative domain name server. The recursive server and the domain name actually requested by the user for resolution in the following refer to the domain name contained in any domain name resolution request actually received by any recursive server.
[0046]
[0045] In order to facilitate understanding, the scheme of the embodiments of the present disclosure is exemplified below.
[0047]
[0046] As shown in FIG. 3, it is assumed that user A sends an actual domain name resolution request containing the domain name “xxx.yyy.com” to a certain recursive server belonging to the user through a terminal device (such as a mobile phone, a computer, a tablet computer, etc.). After receiving the actual domain name resolution request, the recursive server queries whether the IP address corresponding to the domain name “xxx.yyy.com” exists in its internal cache, if it exists, the IP address corresponding to the domain name “xxx.yyy.com” is returned to user A.
[0048]
[0047] If the IP address corresponding to the domain name "xxx.yyy.com" is not found in the cache of the recursive server, the recursive server sends an actual domain name resolution request containing the domain name "xxx.yyy.com" to the authoritative domain name server. It should be noted that the authoritative domain name server includes the root domain name server, the top-level domain name server, and the second-level domain name server.
[0048] In implementation, the recursive server sends an actual domain name resolution request containing the domain name "xxx.yyy.com" to the root domain name server (the root domain name server contains configuration data of the top-level domain names such as "com", "net", and "cn"). If the IP address of the top-level domain name server corresponding to "com" is found in the root domain name server, the root domain name server sends the IP address of the top-level domain name server to the recursive server. The recursive server sends a query request to the top-level domain name server accordingly. If the IP address of the second-level domain name server corresponding to "yyy.com" is found in the top-level domain name server, the top-level domain name server sends the IP address of the second-level domain name server to the recursive server. The recursive server sends a query request to the second-level domain name server accordingly. If the domain name configuration data of the IP address corresponding to "xxx.yyy.com" is contained in the second-level domain name server, the second-level domain name server sends the IP address corresponding to "xxx.yyy.com" to the recursive server, and the recursive server can feed back the IP address corresponding to the domain name to the terminal device of user A.
[0049]
[0049] Similarly, it is assumed that user B sends an actual domain name resolution request containing the domain name "xxx.zzz.com" to the recursive server through a terminal device (such as a mobile phone, a computer, a tablet computer, etc.), and user C sends an actual domain name resolution request containing the domain name "xxx.kkk.com" to the recursive server through a terminal device (such as a mobile phone, a computer, a tablet computer, etc.). After the above recursive server and authoritative domain name server are parsed and searched, the IP addresses corresponding to the domain names are obtained, and the IP addresses are sent to the corresponding users, respectively. At the same time, the domain names and the corresponding IP addresses are cached to the recursive server, so as to avoid repeated recursive search on the parsed domain names in the future.
[0050]
[0050] In the above example, the IP address corresponding to the domain name actually requested by the user for resolution by the recursive server through recursive query is the actual domain name resolution result.
[0051]
[0051] Optionally, the recursive server can send the resulting recursive resolution data to the domain hijacking analysis device in the cloud whenever it receives the domain name actually requested by a user and the actual domain name resolution result returned by the recursive server for the domain name. Simultaneously, the domain hijacking analysis device in the cloud obtains the domain name configuration data (including the domain name and the corresponding reference domain name resolution result) from the authoritative domain name server. By comparing the actual domain name resolution result with the reference domain name resolution result, it can determine in real time whether the domain name has been hijacked on the recursive server. The domain name configuration data can be simply understood as the mapping relationship between authoritative domain names and their corresponding IP addresses (reference domain name resolution results).
[0052]
[0052] For example, suppose user A sends a domain name resolution request containing the domain name "xxx.yyy.com" to a recursive server. After recursive querying, the recursive server returns the actual domain name resolution result "IP address = 1.1.1.1" to user A, and simultaneously sends recursive resolution data "domain name = xxx.yyy.com, IP address = 1.1.1.1" to the domain name hijacking analysis device in the cloud. However, the domain name hijacking analysis device obtains the domain name "xxx.yyy.com" from the authoritative domain name server... If the domain name resolution result differs from the reference domain name resolution result, it can be determined that the domain name "xxx.yyy.com" has been hijacked on the recursive server. As an example, as shown in Figure 3, the hijacking occurs during the process of the second-level domain name server sending the domain name resolution result to the recursive server via network devices such as routers or switches. Conversely, if both the actual domain name resolution result and the reference domain name resolution result are "1.1.1.1", that is, the actual domain name resolution result and the reference domain name resolution result are the same, it can be determined that the domain name "xxx.yyy.com" has not been hijacked on the recursive server.
[0053]
[0053] Further, if it is determined that the domain name has been hijacked on the recursive server based on the comparison between the actual domain name resolution result and the reference domain name resolution result, then correction information is sent to the recursive server based on the reference domain name resolution result, so that the recursive server corrects the actual domain name resolution result and the cached domain name configuration data.
[0054]
[0054] It should be understood that if the domain name is hijacked at the recursive server, the actual resolution result obtained by the user is maliciously tampered with, affecting the normal access of the user. Therefore, in order to ensure that the user can obtain the correct domain name resolution result, the domain name hijacking analysis device sends correction information to the recursive server according to the reference domain name resolution result to make the recursive server correct the actual domain name resolution result and cache the domain name configuration data when it is determined that the domain name is hijacked at the recursive server. For example, assuming that the actual domain name resolution result of the domain name is "IP address = 1.1.1.1", and the reference domain name resolution result is "IP address = 2.222", at this time, it is determined that the domain name is hijacked at the recursive server, and the reference domain name resolution result "IP address = 2.2.2.2" is sent to the recursive server, so that the recursive server corrects the actual domain name resolution result from "IP address = 1.1.1.1" to "IP address = 2.222", and caches the corresponding relationship between the domain name and "IP address = 2.222", that is, caches the domain name configuration data.
[0055]
[0056]
[0055] In addition, it should be noted that in actual application, the same domain name "xxx.yyy.com" can correspond to different reference domain name resolution results, for example, the domain name configuration data corresponding to the domain name "xxx.yyy.com" is "domain name = xxx.yyy.com, IP address = 1.1.1.1, 2.2.2.2, 3.3.3.3". At this time, assuming that the actual domain name resolution result of the domain name "xxx.yyy.com" is "IP address = 1.1.1.1", it hits one IP address = 1.1.1.1 in the domain name configuration data, that is, it can be determined that the actual domain name resolution result meets the requirements, and the corresponding recursive server has not been hijacked. Conversely, if the actual domain name resolution result of the domain name "xxx.yyy.com" is "IP address = 0.0.0.0", which is different from "IP address = 1.1.1.1, 2.222, 3.3.3.3", it can be determined that the actual domain name resolution result does not meet the requirements, and the corresponding recursive server has been hijacked.
[0057]
[0058]
[0056] In summary, in the embodiment of the present disclosure, the real recursive resolution data and the authoritative domain name configuration data can be used to timely and accurately detect the hijacking for the domain name resolution request triggered by the user in real time.
[0059]
[0057] FIG. 4 is a flowchart of a domain name hijacking detection method provided by an embodiment of the present disclosure, which is applied to a domain name hijacking analysis device. As shown in FIG. 4, the method comprises the following steps.
[0060]
[0058] 401. Collect recursive resolution data of a recursive server. The recursive server is a server providing domain name recursive query service. The recursive resolution data comprises a domain name actually requested for resolution by a user and an actual domain name resolution result fed back by the recursive server for the domain name.
[0061]
[0059] 402. Listen to a domain name configuration data update event of a domain name configuration server, to update domain name configuration data of an authoritative domain name server. The domain name configuration data comprises a domain name and a reference domain name resolution result corresponding to the domain name. The domain name configuration server is configured to manage the domain name configuration data stored in the authoritative domain name server.
[0062]
[0060] 403. Determine whether the domain name is hijacked in the recursive server according to the actual domain name resolution result and the reference domain name resolution result.
[0063]
[0061] In this embodiment, the domain name hijacking analysis device acquires the domain name configuration data of the authoritative domain name server in the manner of a cloud-based domain name configuration server. Specifically, the domain name hijacking analysis device updates the obtained domain name configuration data after listening to a domain name configuration data update event of the domain name configuration server. It can be understood that, in the initial state, the domain name configuration data stored in the domain name hijacking analysis device is empty. At a certain time, the domain name configuration data of the authoritative domain name server stored in the domain name configuration server at the time can be obtained from the domain name configuration server. Then, if the domain name configuration server updates (such as modifies or adds, deletes) some domain name configuration data, the domain name hijacking analysis device can listen to the corresponding update event in time based on the listening to the domain name configuration server, to update the locally stored domain name configuration data correspondingly.
[0064]
[0062] In particular implementation, the domain name hijacking analysis device listens to the domain name configuration data update event of the domain name configuration server in real time. If the domain name configuration server updates the domain name configuration data corresponding to the authoritative domain name server (for example, updates the IP address corresponding to a domain name in the authoritative domain name server from "1.1.1.1" to "222.2"), the domain name configuration server sends the specific information of the update to the domain name hijacking analysis device, and then the domain name hijacking analysis device updates the domain name configuration data cached by it. The domain name configuration server has a data configuration management interface. The worker can modify the domain name configuration data corresponding to the authoritative domain name server on the data configuration management interface, and then distribute the domain name configuration data to the authoritative domain name server and the domain name hijacking analysis device through the domain name configuration server.
[0065]
[0063] By listening to the domain name configuration data update event of the domain name configuration server and updating the domain name configuration data stored in the domain name hijacking analysis device in a timely manner based on the domain name configuration data update event, the accuracy of subsequent domain name hijacking detection using the reference domain name resolution result in the domain name configuration data can be improved.
[0066]
[0064] Further, in the embodiments of the present disclosure, in order to reduce the data volume of the recursive resolution data reported by the recursive server to the domain name hijacking analysis device, optionally, the domain name hijacking analysis device can also send a domain name whitelist to the recursive server, the domain name whitelist containing a plurality of domain names for which the domain name hijacking analysis device has management authority. Thus, the domain name hijacking analysis device obtaining the recursive resolution data of the recursive server includes: obtaining the recursive resolution data reported by the recursive server based on the domain name whitelist, the domain name contained in the recursive resolution data being contained in the plurality of domain names in the domain name whitelist.
[0065] In actual application, there can be many domain names corresponding to the authoritative domain name server, but the domain name configuration server can have management authority for only part of them, so that the domain name hijacking analysis device can obtain only part of the domain names for which it has management authority from the domain name configuration server. If the recursive resolution data reported by the recursive server contains a domain name for which the domain name hijacking analysis device does not have management authority, the domain name hijacking analysis device cannot obtain the domain name configuration data corresponding to the domain name, and thus cannot perform domain name hijacking analysis. In view of this, in order to reduce the reporting of useless recursive resolution data by the recursive server, the embodiments of the present disclosure add a domain name whitelist, that is, the domain name hijacking analysis device generates a domain name whitelist with a plurality of domain names for which it has management authority, and sends it to the recursive server. In this way, if the recursive server resolves a certain domain name based on an actual request of a user, and after obtaining the corresponding actual domain name resolution result, finds that the domain name is contained in the whitelist, the recursive server can generate corresponding recursive resolution data and report it to the domain name hijacking analysis device.
[0067]
[0066] Further, in the embodiments of the present disclosure, in order to reduce the data volume of the recursive resolution data reported by the recursive server to the domain name hijacking analysis device, and reduce the computing load of the domain name hijacking analysis device, optionally, the domain name hijacking analysis device can also: obtain the domain name resolution request traffic of the recursive server, adjust the cache time window of the recursive server according to the domain name resolution request traffic, so that the recursive server combines a plurality of actual domain name resolution data corresponding to the domain name into recursive resolution data according to the adjusted cache time window, the plurality of actual domain name resolution data being generated within the same adjusted cache time window.
[0068]
[0067] That is, after obtaining the corresponding actual domain name resolution result based on a domain name resolution request, the recursive server can determine the cache time window corresponding to the actual domain name resolution result based on the cache time window set by the domain name hijacking analysis device, combine a plurality of actual domain name resolution results corresponding to the same domain name in the same adjusted cache time window, obtain the combined recursive resolution data, and report the recursive resolution data to the domain name hijacking analysis device.
[0069]
[0068] In implementation, the domain name hijacking analysis device can obtain the domain name resolution request flow of the recursive server every set time, that is, obtain from the recursive server how many domain name resolution requests it has received in the past set time length. If the domain name resolution request flow is greater than the set flow value, the cache time window is reduced. If the domain name resolution request flow is less than or equal to the set flow value, the cache time window is increased. The recursive server combines the multiple actual domain name resolution data corresponding to the same domain name in the adjusted cache time window into recursive resolution data according to the adjusted cache time window. Optionally, the domain name hijacking analysis device can set an initial cache time window. The above increasing and decreasing can be enlarging or reducing the set time length based on the size of the initial cache time window.
[0070]
[0069] For example, it is assumed that the recursive server obtains the actual domain name resolution data of the domain name xxx.yyy.com at T1 as IP address = 1.1.1.1. The recursive server obtains the actual domain name resolution data of the domain name xxx.yyy.com at T2 as IP address = 1.1.1.1. The recursive server obtains the actual domain name resolution data of the domain name xxx.yyy.com at T3 as IP address = 2.2.2.2. It is assumed that the current cache time window includes the time period of T1-T3. The combination result of the above three actual domain name resolution data is: “domain name = xxx.yyy.com, IP address = 1.1.1.1 (2 times), IP address = 2.2.2.2 (1 time), recursive server identifier = 22, time range = T1-T3”. By combining the multiple actual domain name resolution results of the same domain name based on the cache time window, one recursive resolution data is obtained, which can reduce the data amount transmitted between the recursive server and the domain name hijacking analysis device, and reduce the calculation load of the domain name hijacking analysis device.
[0071]
[0070] In another optional implementation, the domain name hijacking analysis device can also send indication information indicating to reduce the cache time window to the recursive server when it is determined that the domain name is hijacked in the recursive server according to the comparison result of the actual domain name resolution result of the domain name and the reference domain name resolution result, so that the recursive server combines the multiple actual domain name resolution data corresponding to the same domain name in the same reduced cache time window into recursive resolution data according to the reduced cache time window based on the indication information.
[0072]
[0071] It should be understood that in actual application, in the case that hijacking of a certain domain name at a certain recursive server is determined at a certain time, the hijacking of the domain name can be reported more quickly by adjusting the cache time window, so that the hijacking of the domain name can be processed in time subsequently.
[0073]
[0072] It should be noted that in the above embodiment, the indication information can carry a domain name for which the domain name hijacking problem is determined, so that the recursive server can only combine the actual domain name resolution result of the domain name received subsequently with the adjusted cache time window, and combine the actual domain name resolution result of other domain names with the previous cache time window.
[0074]
[0073] FIG. 5 is a flowchart of another domain name hijacking detection method provided by an embodiment of the present disclosure, which is applied to a recursive server providing domain name recursive query service. As shown in FIG. 5, the method comprises the following steps.
[0075]
[0074] 501, in response to a domain name resolution request of a user, obtaining an actual domain name resolution result corresponding to the domain name requested to be resolved, the actual domain name resolution result being obtained by the recursive server through recursive query of an authoritative domain name server.
[0076]
[0075] 502, generating recursive resolution data, the recursive resolution data comprising the domain name and the actual domain name resolution result.
[0077]
[0076] 503, sending the recursive resolution data to a domain name hijacking analysis device in the cloud, so that the domain name hijacking analysis device obtains domain name configuration data of the authoritative domain name server, and determines whether the domain name is hijacked at the recursive server according to a reference domain name resolution result corresponding to the domain name in the domain name configuration data and the actual domain name resolution result.
[0078]
[0077] In actual application, it is assumed that a user A sends an actual domain name resolution request comprising a domain name “xxx.yyy.com” to a recursive server through a terminal device (such as a mobile phone, a computer, a tablet computer, etc.), and the recursive server will locally cache whether there is an IP address corresponding to the domain name “xxx.yyy.com” (i.e. the actual domain name resolution result) after receiving the actual domain name resolution request, and if there is, the IP address corresponding to the domain name “xxx.yyy.com” will be returned to the user A.
[0079]
[0078] If the IP address corresponding to the domain name "xxx.yyy.com" is not found in the cache of the recursive server, the recursive server sends an actual domain name resolution request containing the domain name "xxx.yyy.com" to the authoritative domain name server, and receives the actual domain name resolution result fed back by the authoritative domain name server. For the specific recursive query process, refer to the above embodiment, which will not be described here.
[0080]
[0079] After obtaining the actual domain name resolution result, the recursive server can form recursive resolution data containing the domain name and the actual domain name resolution result, and send it to the cloud-side domain name hijacking analysis device. At the same time, the cloud-side domain name hijacking analysis device obtains the domain name configuration data of the authoritative domain name server, and compares the actual domain name resolution result with the reference domain name resolution result of the domain name in the domain name configuration data, to determine whether the domain name is hijacked in the recursive server.
[0081]
[0080] It should be noted that, in this process, if the recursive server receives the hijacking indication message sent by the domain name hijacking analysis device within a set time, the recursive server can feed back the user after correcting the actual domain name resolution result according to the reference domain name resolution result contained in the message. If the recursive server does not receive the hijacking indication message sent by the domain name hijacking analysis device within a set time, the actual domain name resolution result is sent to the user. If it is received after the set time, the corresponding relationship between the reference domain name resolution result in the hijacking indication message and the domain name is cached.
[0082]
[0081] In addition, in the embodiments of the present disclosure, as described above: the recursive server can receive the domain name whitelist sent by the domain name hijacking analysis device, which contains a plurality of domain names that the domain name hijacking analysis device has management authority over. Therefore, after receiving the domain name resolution request containing the domain name, if the recursive server finds that the domain name is contained in the domain name whitelist, the recursive server generates recursive resolution data after obtaining the actual domain name resolution result, and reports it to the domain name hijacking analysis device.
[0083]
[0082] In another optional embodiment, the recursive server generates recursive resolution data, including: determining the current cache time window, determining a plurality of actual domain name resolution results corresponding to the domain name in the cache time window, merging the plurality of actual domain name resolution results corresponding to the domain name in the cache time window into recursive resolution data, and reporting it to the domain name hijacking analysis device.
[0084]
[0083] The above-mentioned generation of recursive resolution data based on the domain name whitelist, and the merging of the multiple actual domain name resolution results corresponding to the domain name within the cache time window into the recursive resolution data can refer to the descriptions in the above embodiments, and will not be repeated here.
[0085]
[0084] The domain name hijacking detection device of one or more embodiments of the present disclosure will be described in detail below. Those skilled in the art can understand that these devices can be configured using commercially available hardware components through the steps taught by the present solution.
[0086]
[0085] FIG. 6 is a structural schematic diagram of a domain name hijacking detection device provided by an embodiment of the present disclosure. The device is applied to a cloud-side domain name hijacking analysis equipment. As shown in FIG. 6, the device includes a collection module 61, an acquisition module 62, and a determination module 63.
[0087]
[0086] The collection module 61 is configured to collect recursive resolution data of a recursive server. The recursive server is a server providing domain name recursive query service. The recursive resolution data includes a domain name actually requested for resolution by a user and an actual domain name resolution result fed back by the recursive server for the domain name. The recursive server obtains the actual domain name resolution result by recursively querying an authoritative domain name server.
[0088]
[0087] The acquisition module 62 is configured to acquire domain name configuration data of the authoritative domain name server. The domain name configuration data includes the domain name and a reference domain name resolution result corresponding to the domain name.
[0089]
[0088] The determination module 63 is configured to determine whether the domain name is hijacked at the recursive server according to the actual domain name resolution result and the reference domain name resolution result.
[0090]
[0089] Optionally, the device further includes a correction module configured to, if it is determined that the domain name is hijacked at the recursive server according to a comparison result of the actual domain name resolution result and the reference domain name resolution result, send correction information to the recursive server according to the reference domain name resolution result, so that the recursive server corrects the actual domain name resolution result and caches the domain name configuration data.
[0091]
[0090] Optionally, the device further includes an update module. The update module is configured to listen to a domain name configuration data update event of a domain name configuration server. The domain name configuration server is configured to manage the domain name configuration data stored in the authoritative domain name server. The update module updates the domain name configuration data based on the domain name configuration data update event.
[0092]
[0091] wherein, optionally, the apparatus further comprises a sending module configured to send a domain name white list to the recursive server, the domain name white list comprising a plurality of domain names for which the domain name hijacking analysis device has administrative rights.
[0093]
[0092] wherein, optionally, the apparatus further comprises a first merging module configured to obtain domain name resolution request traffic of the recursive server, and adjust a cache time window of the recursive server according to the domain name resolution request traffic, so that the recursive server merges a plurality of actual domain name resolution data corresponding to the domain name within a same cache time window into the recursive resolution data according to the adjusted cache time window.
[0094]
[0093] wherein, optionally, the apparatus further comprises a second merging module configured to, if it is determined that the domain name is hijacked at the recursive server according to the comparison result of the actual domain name resolution result and the reference domain name resolution result, send indication information indicating to reduce the cache time window to the recursive server, so that the recursive server merges a plurality of actual domain name resolution data corresponding to the domain name within a same cache time window into the recursive resolution data according to the reduced cache time window.
[0095]
[0094] The apparatus shown in FIG. 6 can perform the steps performed by the domain name hijacking analysis device of the cloud in the foregoing embodiments, and the detailed execution process and technical effects are described in the foregoing embodiments, which will not be described here again.
[0096]
[0095] FIG. 7 is a structural schematic diagram of another domain name hijacking detection apparatus provided by the embodiment of the present disclosure, which is applied to a recursive server providing domain name recursive query service. As shown in FIG. 7, the apparatus comprises an obtaining module 71, a generating module 72 and a sending module 73.
[0097]
[0096] The obtaining module 71 is configured to, in response to a domain name resolution request of a user, obtain an actual domain name resolution result corresponding to a domain name requested to be resolved, the actual domain name resolution result being obtained by the recursive server through recursive query to an authoritative domain name server.
[0098]
[0097] The generating module 72 is configured to generate recursive resolution data, the recursive resolution data comprising the domain name and the actual domain name resolution result.
[0099]
[0098] The sending module 73 is configured to send the recursive resolution data to the domain name hijacking analysis device, so that the domain name hijacking analysis device acquires domain name configuration data of an authoritative domain name server, and determines whether the domain name is hijacked at the recursive server according to a reference domain name resolution result corresponding to the domain name in the domain name configuration data and an actual domain name resolution result.
[0100]
[0099] Optionally, the apparatus further includes a receiving module configured to receive a domain name white list sent by the domain name hijacking analysis device, the domain name white list including a plurality of domain names for which the domain name hijacking analysis device has management authority; and the generating module 72 is specifically configured to generate the recursive resolution data if the domain name is included in the plurality of domain names.
[0101]
[0100] The generating module 72 is specifically further configured to determine a current cache time window, determine a plurality of actual domain name resolution results corresponding to the domain name in the cache time window, and combine the plurality of actual domain name resolution results corresponding to the domain name in the cache time window into the recursive resolution data.
[0102]
[0101] The apparatus shown in FIG. 7 can perform the steps in the foregoing embodiments, and detailed execution processes and technical effects can be referred to the descriptions in the foregoing embodiments, which will not be repeated here.
[0103]
[0102] In one possible design, the structure of the apparatus shown in FIG. 7 can be implemented as an electronic device. As shown in FIG. 8, the electronic device can include a processor 81, a memory 82, and a communication interface 83. The memory 82 stores executable code, which, when executed by the processor 81, causes the processor 81 to at least implement the domain name hijacking detection method provided in the foregoing embodiments.
[0104]
[0103] In addition, the disclosure provides a non-transitory machine readable storage medium, which stores executable code. When the executable code is executed by a processor of an electronic device, the processor can at least implement the domain name hijacking detection method provided in the foregoing embodiments.
[0105]
[0104] The disclosure provides a computer program product, which includes a computer program. When the computer program is executed by a processor of an electronic device, the processor can at least implement the domain name hijacking detection method provided in the foregoing embodiments.
[0106]
[0105] The apparatus embodiments described above are merely illustrative, wherein the network elements described as separate components can or can not be physically separated. Part or all of the modules can be selected to achieve the purposes of the embodiments according to actual needs. Those skilled in the art can understand and implement without creative labor.
[0107]
[0106] Those skilled in the art can clearly understand the embodiments by the description of the above embodiments, which can be implemented by means of general hardware platforms as required, and can also be implemented by means of combination of hardware and software. Based on such understanding, the above technical solutions can be embodied in the form of computer products, and the disclosure can be embodied in the form of computer program products implemented on one or more computer usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer usable program codes.
[0108]
[0107] Finally, it should be noted that: the above embodiments are used to illustrate the technical solutions of the disclosure, rather than limit them; although the disclosure has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that: the technical solutions recorded in the foregoing embodiments can still be modified, or some technical features can be replaced by equivalents; and these modifications or replacements do not make the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the disclosure.
Claims
CLAIM 1. A domain name hijacking detection method, applied to a domain name hijacking analysis device, the method comprising: Collecting recursive resolution data of a recursive server, the recursive server being a server providing domain name recursive query service, the recursive resolution data including a domain name actually requested to be resolved by a user and an actual domain name resolution result fed back by the recursive server for the domain name, the recursive server obtaining the actual domain name resolution result by recursively querying an authoritative domain name server; Obtaining domain name configuration data of the authoritative domain name server, the domain name configuration data including the domain name and a reference domain name resolution result corresponding to the domain name; and determining whether the domain name is hijacked at the recursive server according to the actual domain name resolution result and the reference domain name resolution result.
2. The method of claim 1, further comprising: If it is determined that the domain name is hijacked at the recursive server according to a comparison result of the actual domain name resolution result and the reference domain name resolution result, sending correction information to the recursive server according to the reference domain name resolution result, so that the recursive server corrects the actual domain name resolution result and caches the domain name configuration data.
3. The method of claim 1, further comprising: Listening to a domain name configuration data update event of a domain name configuration server, the domain name configuration server being configured to manage the domain name configuration data stored in the authoritative domain name server; Updating the domain name configuration data based on the domain name configuration data update event.
4. The method of claim 1, further comprising: Sending a domain name whitelist to the recursive server, the domain name whitelist including a plurality of domain names for which the domain name hijacking analysis device has management authority. The collecting of the recursive resolution data of the recursive server includes: obtaining recursive resolution data reported by the recursive server based on the domain name whitelist, the domain name included in the recursive resolution data being included in the plurality of domain names.
5. The method of any one of claims 1-4, further comprising: Obtaining domain name resolution request traffic of the recursive server; Adjusting a cache time window of the recursive server according to the domain name resolution request traffic, so that the recursive server combines a plurality of actual domain name resolution data corresponding to the domain name into the recursive resolution data according to the adjusted cache time window, the plurality of actual domain name resolution data being generated within the same adjusted cache time window.
6. The method of any one of claims 1-4, further comprising: If it is determined that the domain name is hijacked at the recursive server according to a comparison result of the actual domain name resolution result and the reference domain name resolution result, sending correction information to the recursive server according to the reference domain name resolution result, so that the recursive server corrects the actual domain name resolution result and caches the domain name configuration data. In response to a domain name resolution request of a user, obtaining an actual domain name resolution result corresponding to a domain name requested to be resolved, the actual domain name resolution result being obtained by the recursive server by recursively querying an authoritative domain name server; 7. A domain name hijacking detection method, applied to a recursive server providing domain name recursive query service, the method comprising: The recursive resolution data is generated, and the recursive resolution data includes the domain name and the actual domain name resolution result.
8. The method of claim 7, further comprising: The domain name white list sent by the domain name hijacking analysis device is received, and the domain name white list includes a plurality of domain names for which the domain name hijacking analysis device has management authority. The recursive resolution data is generated, and the recursive resolution data includes the domain name and the actual domain name resolution result.
9. The method according to claim 7, wherein, The recursive resolution data is generated, and the recursive resolution data includes the domain name and the actual domain name resolution result.
10. An electronic device, comprising: The recursive resolution data is generated, and the recursive resolution data includes the domain name and the actual domain name resolution result.
11. A non-transitory machine-readable storage medium, wherein, The memory, the processor, and the communication interface are provided, and the executable code is stored on the memory.
12. A computer program product, comprising: The non-transitory machine-readable storage medium stores the executable code, and when the executable code is executed by the processor of the electronic device, the processor executes the domain name hijacking detection method. The computer program is executed by the processor of the electronic device, and the processor executes the domain name hijacking detection method.
Citation Information
Patent Citations
Method for resolving with public DNS (Domain Name System) server, system and server
CN106453685A
Detection method and system for target domain name hijacking
CN107135236A
Domain name hijacking detection method and device, computer equipment and storage medium
CN110572390A
Domain name detection method, domain name analyzer, electronic equipment and storage medium
CN116938875A