The invention discloses a mimic security method and a device for a recursive DNS
server, overcoming the security threatening problem of the recursive DNS
server. The method comprises the following steps: 1) receiving the inquiry requests of users; guiding the inquiry requests through a DNS switch to a
security service chain where screening, filtering and
attack detecting are performed to the requests; and obtaining the
attack detecting data by a parameter manager followed by the delivering of corresponding parameter information to a transferring device; 2) for each inquiry request in the
request queue of the transferring device, selecting by the transferring device a plurality of inquiry requests by the DNS
server according to the parameter manager delivered parameters, the state information of various DNS servers and the transferring strategy; and 3) receiving the responding information of the DNS servers by a determining module; making the
majority decision to the result; and updating the state information of the various servers in the DNS server
pool. The method and the device of the invention solve the
virus attacks to the cache of a recursive server without the modification of the DNS protocol or DNS inquiry responding procedure.