首页> 外文会议>IEEE/IFIP Network Operations and Management Symposium >Never say never: Authoritative TLD nameserver-powered DNS amplification
【24h】

Never say never: Authoritative TLD nameserver-powered DNS amplification

机译:永远不要说永远不会:权威的TLD名称服务器供电的DNS放大

获取原文

摘要

DNS amplification attack is a significant and persistent threat to the Internet. Authoritative name servers (ANSes) of popular domains, especially the DNSSEC-enabled ones, give attractive leverage for attackers in distributed denial-of-service (DDoS) attacks. Particularly, the ANS list of top-level domains (TLD) is publicly accessible, including by would-be attackers, in the form of a root.zone file. In this work, we examine the potential of TLD ANSes to be exploited as unknowing agents in DNS amplification attacks. Specifically, over a period of 12 months that covers two different versions of the root.zone file, we assess the amplification factor (AF) that these servers may provide to attackers when replying to both individual and multiple queries. Also, we measure the degree of actual adoption of the recommended response rate limiting (RRL) countermeasure for the ANSes. Our major findings are that (i) 70% of the distinct ANSes and 47% of the possible DNS queries for the TLDs produce a large AF that exceeds 60, (ii) 10% of the distinct ANSes reflect inbound network traffic and magnify it by a factor that exceeds 50, (iii) the number of most useful ANSes for the attacker, in terms of their role as amplifiers, appears increasing during the monitoring period, and (iv) there still exists a significant number of ANSes that do not implement the RRL or leave it inactive.
机译:DNS扩增攻击是对互联网的显着且持续的威胁。受权威名称服务器(ANSES)的流行域,尤其是启用了DNSSEC的域,为分布式拒绝服务(DDOS)攻击的攻击者提供了有吸引力的杠杆。特别地,顶级域(TLD)的ANS列表可公开访问,包括root.zone文件的形式的攻击者。在这项工作中,我们检查TLD ANSES在DNS扩增攻击中被开发为未知剂的潜力。具体而言,在12个月的时间内涵盖了两个不同版本的root.zone文件,我们评估了这些服务器在回复个人和多个查询时可以向攻击者提供的放大因子(AF)。此外,我们衡量了ANSES推荐的响应率限制(RRL)对策的实际采用程度。我们的主要发现是(i)70 %的DIST anes和47 %的TLD可能的DNS查询产生了超过60,(ii)10 %DISTINCT ANS的大量AF,反映了入站网络流量和通过超过50,(iii)攻击者的最有用ANS的数量的因素,在其作为放大器的角色方面,在监测期间出现增加,并且(iv)仍然存在大量的ANSES请勿实施RRL或将其留下无效。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号