CN111131285B - 一种针对随机域名攻击的主动防护方法 - Google Patents
一种针对随机域名攻击的主动防护方法 Download PDFInfo
- Publication number
- CN111131285B CN111131285B CN201911392970.XA CN201911392970A CN111131285B CN 111131285 B CN111131285 B CN 111131285B CN 201911392970 A CN201911392970 A CN 201911392970A CN 111131285 B CN111131285 B CN 111131285B
- Authority
- CN
- China
- Prior art keywords
- domain name
- zone
- index
- domain
- names
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Active
Links
- 238000000034 method Methods 0.000 title claims abstract description 33
- 238000007619 statistical method Methods 0.000 claims abstract description 10
- 238000001514 detection method Methods 0.000 claims abstract description 9
- 230000004931 aggregating effect Effects 0.000 claims abstract description 5
- 239000006185 dispersion Substances 0.000 claims description 9
- 230000002776 aggregation Effects 0.000 claims description 5
- 238000004220 aggregation Methods 0.000 claims description 5
- 238000004364 calculation method Methods 0.000 claims description 5
- 230000008569 process Effects 0.000 claims description 4
- 238000004422 calculation algorithm Methods 0.000 claims description 3
- 230000003247 decreasing effect Effects 0.000 description 2
- 238000010586 diagram Methods 0.000 description 2
- 238000005192 partition Methods 0.000 description 2
- 230000004044 response Effects 0.000 description 2
- 230000006378 damage Effects 0.000 description 1
- 230000007123 defense Effects 0.000 description 1
- 238000012986 modification Methods 0.000 description 1
- 230000004048 modification Effects 0.000 description 1
- 238000012216 screening Methods 0.000 description 1
- 230000009528 severe injury Effects 0.000 description 1
- 238000006467 substitution reaction Methods 0.000 description 1
Images
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
- H04L63/1441—Countermeasures against malicious traffic
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L61/00—Network arrangements, protocols or services for addressing or naming
- H04L61/45—Network directories; Name-to-address mapping
- H04L61/4505—Network directories; Name-to-address mapping using standardised directories; using standardised directory access protocols
- H04L61/4511—Network directories; Name-to-address mapping using standardised directories; using standardised directory access protocols using domain name system [DNS]
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/02—Network architectures or network communication protocols for network security for separating internal from external traffic, e.g. firewalls
- H04L63/0227—Filtering policies
- H04L63/0236—Filtering by address, protocol, port number or service, e.g. IP-address or URL
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/10—Network architectures or network communication protocols for network security for controlling access to devices or network resources
- H04L63/101—Access control lists [ACL]
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Computer Hardware Design (AREA)
- Computing Systems (AREA)
- General Engineering & Computer Science (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
Abstract
Description
Claims (8)
Priority Applications (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN201911392970.XA CN111131285B (zh) | 2019-12-30 | 2019-12-30 | 一种针对随机域名攻击的主动防护方法 |
Applications Claiming Priority (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN201911392970.XA CN111131285B (zh) | 2019-12-30 | 2019-12-30 | 一种针对随机域名攻击的主动防护方法 |
Publications (2)
Publication Number | Publication Date |
---|---|
CN111131285A CN111131285A (zh) | 2020-05-08 |
CN111131285B true CN111131285B (zh) | 2022-03-01 |
Family
ID=70504870
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
CN201911392970.XA Active CN111131285B (zh) | 2019-12-30 | 2019-12-30 | 一种针对随机域名攻击的主动防护方法 |
Country Status (1)
Country | Link |
---|---|
CN (1) | CN111131285B (zh) |
Families Citing this family (1)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN114726625B (zh) * | 2022-04-08 | 2024-08-20 | Oppo广东移动通信有限公司 | 检测方法及装置、服务器及存储介质 |
Citations (6)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN104079421A (zh) * | 2013-03-27 | 2014-10-01 | 中国移动通信集团北京有限公司 | 一种域名系统防护的方法和系统 |
CN104253796A (zh) * | 2013-06-27 | 2014-12-31 | 北京快网科技有限公司 | 域名系统中基于网络地址绑定区层级的快速区识别方法 |
CN104506538A (zh) * | 2014-12-26 | 2015-04-08 | 北京奇虎科技有限公司 | 机器学习型域名系统安全防御方法和装置 |
CN108737439A (zh) * | 2018-06-04 | 2018-11-02 | 上海交通大学 | 一种基于自反馈学习的大规模恶意域名检测系统及方法 |
CN109284613A (zh) * | 2018-09-30 | 2019-01-29 | 北京神州绿盟信息安全科技股份有限公司 | 标识检测及仿冒站点检测方法、装置、设备及存储介质 |
CN109756480A (zh) * | 2018-11-30 | 2019-05-14 | 中国互联网络信息中心 | 一种DDoS攻击防御方法、装置、电子设备及介质 |
Family Cites Families (1)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
US10623425B2 (en) * | 2017-06-01 | 2020-04-14 | Radware, Ltd. | Detection and mitigation of recursive domain name system attacks |
-
2019
- 2019-12-30 CN CN201911392970.XA patent/CN111131285B/zh active Active
Patent Citations (6)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN104079421A (zh) * | 2013-03-27 | 2014-10-01 | 中国移动通信集团北京有限公司 | 一种域名系统防护的方法和系统 |
CN104253796A (zh) * | 2013-06-27 | 2014-12-31 | 北京快网科技有限公司 | 域名系统中基于网络地址绑定区层级的快速区识别方法 |
CN104506538A (zh) * | 2014-12-26 | 2015-04-08 | 北京奇虎科技有限公司 | 机器学习型域名系统安全防御方法和装置 |
CN108737439A (zh) * | 2018-06-04 | 2018-11-02 | 上海交通大学 | 一种基于自反馈学习的大规模恶意域名检测系统及方法 |
CN109284613A (zh) * | 2018-09-30 | 2019-01-29 | 北京神州绿盟信息安全科技股份有限公司 | 标识检测及仿冒站点检测方法、装置、设备及存储介质 |
CN109756480A (zh) * | 2018-11-30 | 2019-05-14 | 中国互联网络信息中心 | 一种DDoS攻击防御方法、装置、电子设备及介质 |
Also Published As
Publication number | Publication date |
---|---|
CN111131285A (zh) | 2020-05-08 |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
US20200244689A1 (en) | Detection and mitigation of recursive domain name system attacks | |
US9769035B2 (en) | Domain popularity scoring | |
JP6510040B2 (ja) | 不審なホストネームを識別するシステム及び方法 | |
Villamarín-Salomón et al. | Identifying botnets using anomaly detection techniques applied to DNS traffic | |
Hao et al. | Understanding the domain registration behavior of spammers | |
US8141157B2 (en) | Method and system for managing computer security information | |
US20140143825A1 (en) | Reputation-Based In-Network Filtering of Client Event Information | |
US20080320119A1 (en) | Automatically identifying dynamic Internet protocol addresses | |
US20060130147A1 (en) | Method and system for detecting and stopping illegitimate communication attempts on the internet | |
CN112532598B (zh) | 一种用于实时入侵检测系统的过滤方法 | |
CN112019533A (zh) | 一种缓解CDN系统被DDoS攻击的方法及系统 | |
CN110765374A (zh) | 风险链接识别方法、装置及计算机设备 | |
CN114301700B (zh) | 调整网络安全防御方案的方法、装置、系统及存储介质 | |
CN111131285B (zh) | 一种针对随机域名攻击的主动防护方法 | |
Hasegawa et al. | FQDN-based whitelist filter on a DNS cache server against the DNS water torture attack | |
CN116760649B (zh) | 基于大数据的数据安全保护及预警方法 | |
CN112839005B (zh) | Dns域名异常访问监控方法及装置 | |
Fejrskov et al. | Detecting DNS hijacking by using NetFlow data | |
CN105871891B (zh) | 一种dns隐私泄露风险评估方法及系统 | |
CN110650157A (zh) | 基于集成学习的Fast-flux域名检测方法 | |
CN106027516B (zh) | 一种域名服务安全事件评价方法及系统 | |
CN109951811B (zh) | 一种服务号码短信监控方法、装置及系统 | |
CN113556342A (zh) | 一种dns缓存服务器前缀变化攻击防护方法及装置 | |
CN109617925B (zh) | 一种针对网络攻击的防护、区间标记的设置方法及系统 | |
Alayoff et al. | Optimizing DNS Resolvers for High Loads |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
PB01 | Publication | ||
PB01 | Publication | ||
SE01 | Entry into force of request for substantive examination | ||
SE01 | Entry into force of request for substantive examination | ||
TA01 | Transfer of patent application right |
Effective date of registration: 20220112 Address after: 518001 710 Ludan building, No. 1011 Binhe Road, Ludan village community, Guiyuan street, Luohu District, Shenzhen, Guangdong Province Applicant after: Shenzhen Wangji Technology Co.,Ltd. Address before: Room 322, building 1, yard 3, Xingke south 2nd Street, Yanqi Economic Development Zone, Huairou District, Beijing Applicant before: INTERNET DOMAIN NAME SYSTEM BEIJING ENGINEERING RESEARCH CENTER |
|
TA01 | Transfer of patent application right | ||
GR01 | Patent grant | ||
GR01 | Patent grant | ||
TR01 | Transfer of patent right |
Effective date of registration: 20240529 Address after: 518001 710 Ludan building, No. 1011 Binhe Road, Ludan village community, Guiyuan street, Luohu District, Shenzhen, Guangdong Province Patentee after: Shenzhen Wangji Technology Co.,Ltd. Country or region after: China Patentee after: INTERNET DOMAIN NAME SYSTEM BEIJING ENGINEERING RESEARCH CENTER Address before: 518001 710 Ludan building, No. 1011 Binhe Road, Ludan village community, Guiyuan street, Luohu District, Shenzhen, Guangdong Province Patentee before: Shenzhen Wangji Technology Co.,Ltd. Country or region before: China |
|
TR01 | Transfer of patent right |