首页> 外文会议>Internet Measurement Conference >DNSSEC and Its Potential for DDoS Attacks: A Comprehensive Measurement Study
【24h】

DNSSEC and Its Potential for DDoS Attacks: A Comprehensive Measurement Study

机译:DNSSEC及其对DDOS攻击的潜力:全面的测量研究

获取原文

摘要

Over the past five years we have witnessed the introduction of DNSSEC, a security extension to the DNS that relies on digital signatures. DNSSEC strengthens DNS by preventing attacks such as cache poisoning. However, a common argument against the deployment of DNSSEC is its potential for abuse in Distributed Denial of Service (DDoS) attacks, in particular reflection and amplification attacks. DNS responses for a DNSSEC-signed domain are typically larger than those for an unsigned domain, thus, it may seem that DNSSEC could actually worsen the problem of DNS-based DDoS attacks. The potential for abuse in DNSSEC-signed domains has, however, never been assessed on a large scale. In this paper we establish ground truth around this open question. We perform a detailed measurement on a large dataset of DNSSEC-signed domains, covering 70% (2.5 million) of all signed domains in operation today, and compare the potential for amplification attacks to a representative sample of domains without DNSSEC. At first glance, the outcome of these measurements confirms that DNSSEC indeed worsens the DDoS phenomenon. Closer examination, however, gives a more nuanced picture. DNSSEC really only makes the situation worse for one particular query type (ANY), for which responses may be over 50 times larger than the original query (and in rare cases up to 179×). We also discuss a number of mitigation strategies that can have immediate impact for operators and suggest future research directions with regards to these mitigation strategies.
机译:在过去的五年中,我们目睹了DNSSEC的引入,安全扩展到DNS依赖于数字签名。 DNSSEC通过防止诸如缓存中毒等攻击来增强DNS。然而,针对DNSSEC部署的共同论证是其滥用分布式拒绝服务(DDOS)攻击的潜力,特别是反射和放大攻击。 DNS签名域的DNS响应通常大于未签​​名域的响应,因此,DNSSEC实际上可能会使基于DNS的DDOS攻击的问题恶化。然而,DNSSec签名域中的滥用可能性从未评估大规模。在本文中,我们在这个公开的问题周围建立了基础的真理。我们在DNSSEC签名域的大型数据集上进行详细测量,涵盖今天运营中的所有签名域的70%(250万),并比较放大攻击对没有DNSSEC的代表性域的潜力。乍一看,这些测量结果的结果证实,DNSSEC确实恶化了DDOS现象。然而,仔细检查,给出了更细微的差别。 DNSSEC真的只使某一个特定查询类型(任何)更糟糕的情况,其中响应可能比原始查询大超过50倍(并且在罕见情况下高达179×)。我们还讨论了许多缓解策略,可以立即对运营商产生影响,并建议未来关于这些缓解策略的研究方向。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号