A Comprehensive Measurement-based Investigation of DNS Hijacking

A Comprehensive Measurement-based Investigation of DNS Hijacking
复制标题

DOI:
10.1109/srds53918.2021.00029
复制
发表时间:
2021-09
期刊:
2021 40th International Symposium on Reliable Distributed Systems (SRDS)
影响因子:
--
通讯作者:
Rebekah Houser;Shuai Hao;Zhou Li;Daiping Liu;Chase Cotton;Haining Wang
Rebekah Houser;Shuai Hao;Zhou Li;Daiping Liu;Chase Cotton;Haining Wang
中科院分区:
其他
文献类型:
--
作者:
Rebekah Houser;Shuai Hao;Zhou Li;Daiping Liu;Chase Cotton;Haining Wang

文献摘要

被引文献

相似文献

针对域名系统(DNS)的攻击长期以来一直困扰着互联网,需要持续调查和警惕,以防止滥用这一关键基础设施。在这些攻击中,DNS劫持一再声称自己是最严重的威胁之一。近年来,DNS劫持的严重性激发了人们对开发更强大防御的兴趣。DNS生态系统的规模、动态性和多样性对构建有效且可扩展的防御提出了不小的挑战。此外,有记录的DNS劫持攻击相对较少,因此很难深入研究。在本文中,我们试图解决两个推力的挑战。我们首先根据已确认的DNS劫持攻击报告和被动DNS记录进行分析,以描述已知的DNS劫持攻击,并确定用于构建防御机制的特征。然后,我们探讨了在何种程度上的特征可以用来建立一个DNS劫持检测机制,并从网络网关的角度来评估其有效性。
Attacks against the domain name system (DNS) have long plagued the Internet, requiring continual investigation and vigilance to prevent the abuse of this critical infrastructure. Among these attacks, DNS hijacking has repeatedly asserted itself as one of the most serious threats. In recent years, the severity of DNS hijacking has motivated renewed interest in developing more robust defenses. The size, dynamism, and diversity of the DNS ecosystem present nontrivial challenges to crafting an effective and scalable defense. Further, the relative rarity of documented DNS hijacking attacks makes them difficult to study in-depth. In this paper, we attempt to address the challenges in two thrusts. We first conduct an analysis based on the reports of confirmed DNS hijacking attacks and passive DNS records to characterize known DNS hijacking attacks and identify features for building defense mechanisms. Then we explore the extent to which the characteristic features can be used to build a DNS hijacking detection mechanism and evaluate its effectiveness from the perspective of a network gateway.