首页> 外文会议>Internet Measurement Conference >Going Wild: Large-Scale Classification of Open DNS Resolvers
【24h】

Going Wild: Large-Scale Classification of Open DNS Resolvers

机译:狂野:Open DNS resolvers的大规模分类

获取原文

摘要

Since several years, millions of recursive DNS resolvers are-deliberately or not-open to the public. This, however, is counter-intuitive, since the operation of such openly accessible DNS resolvers is necessary in rare cases only. Furthermore, open resolvers enable both amplification DDoS and cache snooping attacks, and can be abused by attackers in multiple other ways. We thus find open recursive DNS resolvers to remain one critical phenomenon on the Internet. In this paper, we illuminate this phenomenon by analyzing it from two different angles. On the one hand, we study the landscape of DNS resolvers based on empirical data we collected for over a year. We analyze the changes over time and classify the resolvers according to device type and software version. On the other hand, we take the viewpoint of a client and measure the response authenticity of these resolvers. Besides legitimate redirections (e.g., to captive portals or router login pages), we find millions of resolvers to deliberately manipulate DNS resolutions (i.e., return bogus IP address information). To understand this threat in more detail, we systematically analyze non-legitimate DNS responses and reveal open DNS resolvers that manipulate DNS resolutions to censor communication channels, inject advertisements, serve malicious files, perform phishing, or redirect to other kinds of suspicious or malicious activities.
机译:自从几年以来,数百万次递归DNS腐败者 - 故意或不向公众开放。然而,这是对抗直观的,因为在罕见的情况下,这种公开访问的DNS腐蚀剂的操作是必要的。此外,打开的解析器使放大DDOS和缓存侦听攻击能够以多种其他方式被攻击者滥用。因此,我们发现开放的递归DNS解析器在互联网上仍然是一个关键现象。在本文中,我们通过从两种不同的角度分析它来照亮这种现象。一方面,我们根据我们收集多年来的经验数据研究DNS解析器的景观。我们根据设备类型和软件版本分析随时间的变化并分类了解官。另一方面,我们采取客户的观点,并衡量这些解析器的响应真实性。除了合法的重定向(例如,捕获门户或路由器登录页面),我们发现数百万个resolvers来故意操纵DNS分辨率(即,返回虚假IP地址信息)。要更详细地了解这一威胁,我们系统地分析了非合法的DNS响应,并揭示了操作DNS分辨率的开放式DNS解析器,以审查审查通信渠道,注入广告,服务恶意文件,执行网络钓鱼或重定向到其他类型的可疑或恶意活动。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号