电信科学 ›› 2022, Vol. 38 ›› Issue (9): 1-17.doi: 10.11959/j.issn.1000-0801.2022248

• 综述 •    下一篇

DNS攻击检测与安全防护研究综述

章坚武1, 安彦军1, 邓黄燕2   

  1. 1 杭州电子科技大学,浙江 杭州 310018
    2 浙江宇视科技有限公司,浙江 杭州 310051
  • 修回日期:2022-08-25 出版日期:2022-09-20 发布日期:2022-09-01
  • 作者简介:章坚武(1961- ),男,博士,杭州电子科技大学通信工程学院教授、博士生导师,中国电子学会、中国通信学会高级会员,浙江省通信学会常务理事,主要研究方向为移动通信、多媒体信号处理与人工智能、通信网络与信息安全
    安彦军(1996- ),男,杭州电子科技大学通信工程学院硕士生,主要研究方向为网络安全、人工智能
    邓黄燕(1987- ),女,浙江宇视科技有限公司高级工程师、公共事务总监,主要研究方向为人工智能、物联网等
  • 基金资助:
    国家自然科学基金资助项目(U1866209);国家自然科学基金资助项目(61772162)

A survey on DNS attack detection and security protection

Jianwu ZHANG1, Yanjun AN1, Huangyan DENG2   

  1. 1 Hangzhou Dianzi University, Hangzhou 310018, China
    2 Zhejiang Uniview Technologies Co., Ltd., Hangzhou 310051, China
  • Revised:2022-08-25 Online:2022-09-20 Published:2022-09-01
  • Supported by:
    The National Natural Science Foundation of China(U1866209);The National Natural Science Foundation of China(61772162)

摘要:

随着传统互联网逐渐向“互联网+”演变,域名系统(domain name system,DNS)从基础的地址解析向全面感知、可靠传输等新模式不断扩展。新场景下的DNS由于功能的多样性和覆盖领域的广泛性,一旦受到攻击会造成严重的后果,因此DNS攻击检测与安全防护方面的研究持续进行并越来越受到重视。首先介绍了几种常见的DNS攻击,包括DNS欺骗攻击、DNS隐蔽信道攻击、DNS DDoS(distributed denial of service)攻击、DNS 反射放大攻击、恶意 DGA 域名;然后,从机器学习的角度出发对这些攻击的检测技术进行了系统性的分析和总结;接着,从DNS去中心化、DNS加密认证、DNS解析限制3个方面详细介绍了DNS的安全防护技术;最后,对未来的研究方向进行了展望。

关键词: 域名系统, DNS攻击检测, 安全防护, 机器学习

Abstract:

With the gradual evolution of the traditional Internet to “Internet+”, the domain name system (DNS) had been continuously expanding from basic address resolution to new models such as comprehensive perception and reliable transmission.Due to the diverse functions and the extensive coverage of DNS in the new scenario, it will cause serious consequences once attacked.Therefore, the research on DNS attack detection and security protection continues and attracts more and more attention.Firstly, several common DNS attacks were introduced, including DNS spoofing, DNS covert channel, DNS distributed denial of service (DDoS) attack, DNS reflection amplification attacks, and malicious DGA domain names.Subsequently, these DNS attack detection technologies were systematically analyzed and summarized from the machine learning perspective.Then, the DNS security protection technologies were sorted out in decentralization, authenticated encryption and limited resolution.Finally, some future research directions were proposed.

Key words: domain name system, DNS attack detection, security protection, machine learning

中图分类号: 

No Suggested Reading articles found!