Page 360 - 《软件学报》2026年第4期
P. 360
软件学报 ISSN 1000-9825, CODEN RUXUEW E-mail: jos@iscas.ac.cn
2026,37(4):1801−1818 [doi: 10.13328/j.cnki.jos.007429] [CSTR: 32375.14.jos.007429] http://www.jos.org.cn
©中国科学院软件研究所版权所有. Tel: +86-10-62562563
*
基于大型 DNS 递归服务的域名访问模式测量与分析
张 宾 1 , 杨书徒 1 , 姬东岑 1 , 张 宇 1,2 , 张伟哲 1,2 , 凃唯坚 1 , 戴一娜 1
1
(鹏城实验室, 广东 深圳 518055)
2
(哈尔滨工业大学 网络空间安全学院, 黑龙江 哈尔滨 150001)
通信作者: 张宇 E-mail: yuzhang@hit.edu.cn
摘 要: 域名系统 (domain name system, DNS) 协议的性能和操作特性引起了研究和网络运营界的极大兴趣. 在这
项工作中, 通过测量分析来自一个大型 DNS 服务商的递归服务器数据, 从一个大型 DNS 运营商递归服务的角度
考察了用户访问模式及解析状况. 面向海量的 DNS 数据, 首先提供一种多机分布式并行测量机制和大数据平台存
储监控方案, 实现了对 DNS 海量数据的高效测量分析. 然后, 从用户请求响应率、请求域名的情况、请求用户的
情况和域名解析的情况多个维度系统分析了 DNS 数据的特征, 并呈现了多个有价值的测量结果, 对提升 DNS 的
运维和洞察 DNS 的特性具有重要价值. 最后, 基于对 DNS 缓存命中率的测量分析, 提出一种适用于 DNS 大型运
营商进行在线异常检测的通用框架, 并初步验证了框架方案的正确性和可行性.
关键词: 域名系统; 域名系统安全; 网络测量; 攻击检测
中图法分类号: TP393
中文引用格式: 张宾, 杨书徒, 姬东岑, 张宇, 张伟哲, 凃唯坚, 戴一娜. 基于大型DNS递归服务的域名访问模式测量与分析. 软件学
报, 2026, 37(4): 1801–1818. http://www.jos.org.cn/1000-9825/7429.htm
英文引用格式: Zhang B, Yang ST, Ji DC, Zhang Y, Zhang WZ, Tu WJ, Dai YN. Measurement and Analysis of Domain Access
Patterns Based on Large-scale DNS Recursive Services. Ruan Jian Xue Bao/Journal of Software, 2026, 37(4): 1801–1818 (in Chinese).
http://www.jos.org.cn/1000-9825/7429.htm
Measurement and Analysis of Domain Access Patterns Based on Large-scale DNS Recursive
Services
1
1
1
1
1,2
1,2
ZHANG Bin , YANG Shu-Tu , JI Dong-Cen , ZHANG Yu , ZHANG Wei-Zhe , TU Wei-Jian , DAI Yi-Na 1
1
(Pengcheng Laboratory, Shenzhen 518055, China)
2
(School of Cyberspace Science, Harbin Institute of Technology, Harbin 150001, China)
Abstract: The performance and operational characteristics of the domain name system (DNS) protocol continue to attract significant
attention from both the research community and network operators. In this study, data collected from a large-scale DNS recursive service
is measured and analyzed to examine user access patterns and resolution behavior from the perspective of a major DNS operator. To
handle the massive volume of DNS data, this study proposes a distributed parallel measurement mechanism and a big data-based storage
and monitoring solution, enabling efficient processing and analysis. The characteristics of DNS data are systematically examined across
several dimensions, including user request response rates, domain name request patterns, user distribution, and resolution outcomes. Several
valuable insights are presented, offering meaningful guidance for DNS operation optimization and improved understanding of DNS
behavior. Finally, based on the analysis of DNS cache hit rates, this study proposes a general framework for online anomaly detection
tailored to large-scale DNS operators. The correctness and feasibility of the proposed framework are preliminarily verified.
Key words: domain name system (DNS); DNS security; network measurement; attack detection
* 基金项目: 国家重点研发计划 (2024YFB31NL00105); 鹏城实验室重大攻关项目 (PCL2023A05); 广东省基础与应用基础研究重大项目
(2019B030302002)
收稿时间: 2024-10-28; 修改时间: 2025-01-22; 采用时间: 2025-03-17; jos 在线出版时间: 2025-07-17
CNKI 网络首发时间: 2025-07-18

