###
计算机系统应用英文版:2022,31(3):129-135
本文二维码信息
码上扫一扫!
DNS的RPZ安全防护系统的构建、配置与验证
(1.江苏省未来网络创新研究院, 南京 211111;2.南京师范大学 商学院, 南京 210023)
Construction, Configuration and Verification of DNS RPZ Protection System
(1.Jiangsu Future Networks Innovation Institute, Nanjing 211111, China;2.Business School, Nanjing Normal University, Nanjing 210023, China)
摘要
图/表
参考文献
相似文献
本文已被:浏览 691次   下载 1110
Received:May 13, 2021    Revised:June 14, 2021
中文摘要: DNS (domain name system)作为网络的重要基础服务设施, 是终端访问互联网必要的一环. 近年来, 越来越多尝试将用户通过DNS系统引入恶意服务器的攻击, 对互联网安全产生重要威胁. 防范与化解针对恶意域名或IP的访问, 如钓鱼网站、垃圾邮件、勒索软件、色情网站等, 无论是对于运营商还是网络监管机构都具有重要的现实意义. 论文阐述RPZ (response policy zones)的工作原理, 构建DNS的RPZ安全防护系统, 再进行相关核心软件的配置, 最后通过实验验证, 检验系统针对恶意域名和IP的防护效果.
中文关键词: DNS  RPZ  域名攻击  互联网安全
Abstract:As an important network infrastructure for service, the domain name system (DNS) is a necessary link for terminals to access the Internet. In recent years, more and more attempts have been made to trick users into malicious servers through DNS, posing a huge threat to Internet security. It is of great practical significance for both operators and network regulators to prevent and resolve access to malicious domains or IPs, including phishing websites, spam, ransomware, and pornographic websites. Therefore, this paper describes the working principle of Response Policy Zones (RPZ), builds a DNS RPZ security protection system, and then configures the related core software. Then, experiments are conducted on the system to verify the protection effect against malicious domains and IPs.
文章编号:     中图分类号:    文献标志码:
基金项目:国家自然科学基金青年项目(71903096)
引用文本:
戴云伟,沈春苗.DNS的RPZ安全防护系统的构建、配置与验证.计算机系统应用,2022,31(3):129-135
DAI Yun-Wei,SHEN Chun-Miao.Construction, Configuration and Verification of DNS RPZ Protection System.COMPUTER SYSTEMS APPLICATIONS,2022,31(3):129-135