引用本文:张宾,杨书徒,姬东岑,张宇,张伟哲,凃唯坚,戴一娜.基于大型DNS递归服务的域名访问模式测量与分析.软件学报,2026,37(4):1801-1818
【打印本页】   【下载PDF全文】   查看/发表评论  【EndNote】   【RefMan】   【BibTex】
←前一篇|后一篇→ 过刊浏览    高级检索
本文已被:浏览 967次   下载 1965 本文二维码信息
码上扫一扫!
分享到: 微信 更多
基于大型DNS递归服务的域名访问模式测量与分析
张宾1, 杨书徒1, 姬东岑1, 张宇1,2, 张伟哲1,2, 凃唯坚1, 戴一娜1
1.鹏城实验室, 广东 深圳 518055;2.哈尔滨工业大学 网络空间安全学院, 黑龙江 哈尔滨 150001
摘要:
域名系统(domain name system, DNS)协议的性能和操作特性引起了研究和网络运营界的极大兴趣. 在这项工作中, 通过测量分析来自一个大型DNS服务商的递归服务器数据, 从一个大型DNS运营商递归服务的角度考察了用户访问模式及解析状况. 面向海量的DNS数据, 首先提供一种多机分布式并行测量机制和大数据平台存储监控方案, 实现了对DNS海量数据的高效测量分析. 然后, 从用户请求响应率、请求域名的情况、请求用户的情况和域名解析的情况多个维度系统分析了DNS数据的特征, 并呈现了多个有价值的测量结果, 对提升DNS的运维和洞察DNS的特性具有重要价值. 最后, 基于对DNS缓存命中率的测量分析, 提出一种适用于DNS大型运营商进行在线异常检测的通用框架, 并初步验证了框架方案的正确性和可行性.
关键词:  域名系统  域名系统安全  网络测量  攻击检测
DOI:10.13328/j.cnki.jos.007429
分类号:TP393
基金项目:国家重点研发计划(2024YFB31NL00105); 鹏城实验室重大攻关项目(PCL2023A05); 广东省基础与应用基础研究重大项目(2019B030302002)
Measurement and Analysis of Domain Access Patterns Based on Large-scale DNS Recursive Services
ZHANG Bin1, YANG Shu-Tu1, JI Dong-Cen1, ZHANG Yu1,2, ZHANG Wei-Zhe1,2, TU Wei-Jian1, DAI Yi-Na1
1.Pengcheng Laboratory, Shenzhen 518055, China;2.School of Cyberspace Science, Harbin Institute of Technology, Harbin 150001, China
Abstract:
The performance and operational characteristics of the domain name system (DNS) protocol continue to attract significant attention from both the research community and network operators. In this study, data collected from a large-scale DNS recursive service is measured and analyzed to examine user access patterns and resolution behavior from the perspective of a major DNS operator. To handle the massive volume of DNS data, this study proposes a distributed parallel measurement mechanism and a big data-based storage and monitoring solution, enabling efficient processing and analysis. The characteristics of DNS data are systematically examined across several dimensions, including user request response rates, domain name request patterns, user distribution, and resolution outcomes. Several valuable insights are presented, offering meaningful guidance for DNS operation optimization and improved understanding of DNS behavior. Finally, based on the analysis of DNS cache hit rates, this study proposes a general framework for online anomaly detection tailored to large-scale DNS operators. The correctness and feasibility of the proposed framework are preliminarily verified.
Key words:  domain name system (DNS)  DNS security  network measurement  attack detection