Design and Implementation of Domain Hijacking Detection System
1 Institute of Information Engineering, Chinese Academy of Sciences, Beijing, China
2 National Computer network Emergency Response technical Team/Coordination Center of China, Beijing, China
3 Chinese Academy of Sciences, Beijing, China
As the basement of Internet application, DNS plays a very critical role in the network running. On Jan. 21st, 2014, the occurrence of a serious DNS hijacking in Internet has aroused the attentions to the DNS security incident again. This paper comes up with a new method to detect DSN hijacking through the construction of a high-speed cache in terms of the corresponding relation between domain name and server IP. With this method, we build a cache with the domain name and the IP. With this cache, domain name can be detected if DSN hijacking happens in DNS cache server and this system can detect domain name hijacking efficiently after it happens.
Key words: DNS hijacking / domain name hijacking / hijacking incident / detection method
