A Comprehensive Measurement-based Investigation of DNS Hijacking
A Comprehensive Measurement-based Investigation of DNS Hijacking
复制标题
DOI:
10.1109/srds53918.2021.00029
复制
发表时间:
2021-09
期刊:
影响因子:
--
通讯作者:
Rebekah Houser;Shuai Hao;Zhou Li;Daiping Liu;Chase Cotton;Haining Wang
中科院分区:
文献类型:
--
作者:
Rebekah Houser;Shuai Hao;Zhou Li;Daiping Liu;Chase Cotton;Haining Wang
Attacks against the domain name system (DNS) have long plagued the Internet, requiring continual investigation and vigilance to prevent the abuse of this critical infrastructure. Among these attacks, DNS hijacking has repeatedly asserted itself as one of the most serious threats. In recent years, the severity of DNS hijacking has motivated renewed interest in developing more robust defenses. The size, dynamism, and diversity of the DNS ecosystem present nontrivial challenges to crafting an effective and scalable defense. Further, the relative rarity of documented DNS hijacking attacks makes them difficult to study in-depth. In this paper, we attempt to address the challenges in two thrusts. We first conduct an analysis based on the reports of confirmed DNS hijacking attacks and passive DNS records to characterize known DNS hijacking attacks and identify features for building defense mechanisms. Then we explore the extent to which the characteristic features can be used to build a DNS hijacking detection mechanism and evaluate its effectiveness from the perspective of a network gateway.