TsuNAME: exploiting misconfiguration and vulnerability to DDoS DNS

TsuNAME: exploiting misconfiguration and vulnerability to DDoS DNS
复制标题

TsuNAME:利用 DDoS DNS 的错误配置和漏洞

DOI:
10.1145/3487552.3487824
复制
发表时间:
2021
期刊:
ACM Internet Measurements Conference
影响因子:
--
通讯作者:
Hardaker, Wes
Hardaker, Wes
中科院分区:
--
文献类型:
--
作者:
Moura, Giovane C.;Castro, Sebastian;Heidemann, John;Hardaker, Wes

文献摘要

参考文献

被引文献

相似文献

互联网的域名系统(DNS)是每个网络请求和电子邮件交换的一部分,因此DNS故障可能是灾难性的,会导致主要网站和服务中断。本文确定了TsuNAME,这是一个漏洞,一些递归解析程序可以极大地放大查询,可能导致DNS服务拒绝服务。TsuNAME是由DNS记录中的循环依赖关系引起的。递归解析器重复地遵循这些循环,再加上不充分的缓存和应用程序级重试,极大地放大了初始查询,给权威服务器带来了压力。虽然循环依赖性的问题并不新鲜,但放大的规模以前并没有被理解。我们记录了.nz(国家级域名)中的真实事件,其中两个错误配置的域名导致整体流量增加了50%。我们通过实验重现并记录了这一事件的根本原因,并演示了500倍的放大系数。作为对我们披露的回应,一些DNS软件供应商已经记录了他们的缓解措施,包括Google公共DNS和Cisco OpenDNS。对于权威DNS服务的运营商,我们开发并发布了CycleHunter,这是一款开源工具,可以检测循环依赖并防止攻击。我们使用CycleHunter评估了7个大型顶级域名(TLD)中的大约1.84亿个域名,发现1.4k个域名使用了44个循环依赖NS记录。TsuNAME漏洞是可武器化的,因为攻击者可以很容易地创建循环来攻击父域的基础设施。记录这一威胁及其解决方案是确保其得到充分解决的重要一步。
TheInternet's Domain Name System (DNS) is a part of every web request and e-mail exchange, so DNS failures can be catastrophic, taking out major websites and services. This paper identifies TsuNAME, a vulnerability where some recursive resolvers can greatly amplify queries, potentially resulting in a denial-of-service to DNS services. TsuNAME is caused by cyclical dependencies in DNS records. A recursive resolver repeatedly follows these cycles, coupled with insufficient caching and application-level retries greatly amplify an initial query, stressing authoritative servers. Although issues with cyclic dependencies are not new, the scale of amplification has not previously been understood. We document real-world events in .nz (a country-level domain), where two misconfigured domains resulted in a 50% increase on overall traffic. We reproduce and document root causes of this event through experiments, and demostrate a 500× amplification factor. In response to our disclosure, several DNS software vendors have documented their mitigations, including Google public DNS and Cisco OpenDNS. For operators of authoritative DNS services we have developed and released CycleHunter, an open-source tool that detects cyclic dependencies and prevents attacks. We use CycleHunter to evaluate roughly 184 million domain names in 7 large, top-level domains (TLDs), finding 44 cyclic dependent NS records used by 1.4k domain names. The TsuNAME vulnerability is weaponizable, since an adversary can easily create cycles to attack the infrastructure of a parent domains. Documenting this threat and its solutions is an important step to ensuring it is fully addressed.
DOI: 10.1145/1015467.1015503
发表时间: 2004-08
影响因子: 16.4
作者:
V. Pappas;D. Wessels;D. Massey;Songwu Lu;A. Terzis;Lixia Zhang
通讯作者: V. Pappas;D. Wessels;D. Massey;Songwu Lu;A. Terzis;Lixia Zhang
互联网云化:DNS 流量变得多么集中?
DOI: 10.1145/3419394.3423625
发表时间: 2020
期刊: Proceedings of the ACM Internet Measurement Conference
影响因子: --
作者:
G. Moura;Sebastian Castro;W. Hardaker;M. Wullink;Cristian Hesselman
通讯作者: Cristian Hesselman
对 DNS 稳健性的评论
DOI: 10.1145/3278532.3278541
发表时间: 2018
期刊: Proceedings of the Internet Measurement Conference 2018
影响因子: --
作者:
M. Allman
通讯作者: M. Allman
识别名称服务器实例的机制的要求
DOI: --
发表时间: 2007
期刊: Request for Comments
影响因子: --
作者:
Suzanne Woolf;David Conrad
通讯作者: David Conrad
未解决的问题:蹩脚代表团的普遍性、持续性和危险
DOI: 10.1145/3419394.3423623
发表时间: 2020
期刊: IMC '20: Proceedings of the ACM Internet Measurement Conference
影响因子: --
作者:
Akiwate, Gautam;Jonker, Mattijs;Sommese, Raffaele;Foster, Ian;Voelker, Geoffrey M.;Savage, Stefan;Claffy, KC
通讯作者: Claffy, KC