Measuring the Impact of a Successful DDoS Attack on the Customer Behaviour of Managed DNS Service Providers

Measuring the Impact of a Successful DDoS Attack on the Customer Behaviour of Managed DNS Service Providers
复制标题

衡量成功的 DDoS 攻击对托管 DNS 服务提供商的客户行为的影响

DOI:
10.1145/3229598.3229599
复制
发表时间:
2018
期刊:
Proceedings of the 2018 Workshop on Traffic Measurements for Cybersecurity
影响因子:
--
通讯作者:
L. Nieuwenhuis
L. Nieuwenhuis
中科院分区:
--
文献类型:
--
作者:
Abhishta Abhishta;R. V. Rijswijk;L. Nieuwenhuis

文献摘要

被引文献

相似文献

分布式拒绝服务(DDoS)攻击继续对Internet服务的可用性构成严重威胁。域名系统(DNS)是互联网核心的一部分,也是成功提供互联网服务的关键因素。由于DNS的重要性,专业服务提供商如雨后春笋般出现在市场上,提供托管DNS服务。它们的主要卖点之一是保护域名的DNS免受DDoS攻击。但是,如果这样的服务成为DDoS攻击的目标,并且攻击成功了怎么办?在本文中,我们分析了两个这样的事件,2016年5月对NS1的攻击和2016年10月对Dyn的攻击。我们通过分析服务客户行为的变化来做到这一点。对于我们的分析,我们利用来自OpenINTEL主动DNS测量系统的数据,该系统涵盖了全球DNS的大部分。我们的结果显示,使用NS1或Dyn作为DNS服务提供商的域的行为几乎立即发生了统计学上显著的变化。我们观察到,专门使用NS1或Dyn作为托管DNS服务提供商的域名数量有所下降,并看到通过使用多个提供商来分散风险的转变。虽然大型托管DNS提供商可以更好地防范攻击,但这两个案例研究表明,它们并非不受攻击的影响。这就对使用单一提供商管理DNS是否明智提出了质疑。我们的研究结果表明,通过使用多个供应商来分散风险是一种有效的对策,尽管成本可能更高。
Distributed Denial-of-Service (DDoS) attacks continue to pose a serious threat to the availability of Internet services. The Domain Name System (DNS) is part of the core of the Internet and a crucial factor in the successful delivery of Internet services. Because of the importance of DNS, specialist service providers have sprung up in the market, that provide managed DNS services. One of their key selling points is that they protect DNS for a domain against DDoS attacks. But what if such a service becomes the target of a DDoS attack, and that attack succeeds? In this paper we analyse two such events, an attack on NS1 in May 2016, and an attack on Dyn in October 2016. We do this by analysing the change in the behaviour of the service's customers. For our analysis we leverage data from the OpenINTEL active DNS measurement system, which covers large parts of the global DNS over time. Our results show an almost immediate and statistically significant change in the behaviour of domains that use NS1 or Dyn as a DNS service provider. We observe a decline in the number of domains that exclusively use NS1 or Dyn as a managed DNS service provider, and see a shift toward risk spreading by using multiple providers. While a large managed DNS provider may be better equipped to protect against attacks, these two case studies show they are not impervious to them. This calls into question the wisdom of using a single provider for managed DNS. Our results show that spreading risk by using multiple providers is an effective countermeasure, albeit probably at a higher cost.