摘要
IPv6环境下的域名系统(DNS,domain name system)服务发展迅速,开展IPv6环境下DNS服务发现方法研究,对分析DNS服务在IPv6环境下的全球发展态势,提升服务可靠性具有非常重要的意义。基于IPv4和IPv6的合作解析关系,通过跨栈服务关联发现IPv6 DNS服务是一种有效的方法。然而,现有基于跨栈服务关联的IPv6 DNS服务发现方法受DNS探测包长度限制,探测能力有限。针对此问题,提出一种基于动态域名水印的IPv6 DNS服务发现方法。该方法利用自建权威服务器构建动态域名资源记录,绕过探测包长度限制。相比传统方法,该方法发现的IPv6 DNS服务数量提升接近98%;同时,通过解析水印日志记录,发现了解析器间存在大量解析依赖和集中化现象。
DNS(domain name system)services in the IPv6 environment experienced rapid development.Research on methods for discovering DNS services in an IPv6 environment was of paramount importance in order to analyze the global developmental trends of DNS services in IPv6 and enhance their reliability.Based on the cooperative resolution relationship between IPv4 and IPv6,associating IPv6 DNS services through inter-stack services was an effective approach.However,existing methods for discovering IPv6 DNS services based on inter-stack service association were limited by the length of DNS probe packets.In response to this issue,a novel approach was proposed for discovering IPv6 DNS services based on dynamic domain name watermarks.By constructing dynamic domain name resource records using self-established authoritative servers,the limitations imposed by probe packet length were circumvented.Comparative analysis indicated that the number of discovered IPv6 DNS services using this method increased by nearly 98%compared to traditional methods.Moreover,through the analysis of watermark logs,a plethora of resolver dependencies and centralization phenomena were identified.
作者
韩丁康
朱宇佳
赵蕾
焦亮
刘庆云
HAN Dingkang;ZHU Yujia;ZHAO Lei;JIAO Liang;LIU Qingyun(Institute of Information Engineering,Chinese Academy of Sciences,Beijing 100085,China;School of Cyberspace Security,University of Chinese Academy of Sciences,Beijing 100049,China)
出处
《网络与信息安全学报》
2024年第5期56-70,共15页
Chinese Journal of Network and Information Security
关键词
域名系统
IPV6
服务测绘
域名水印
domain name system
IPv6
service measurement
domain name watermark