DNS Cache Poisoning Attack Reloaded: Revolutions with Side Channels

DNS Cache Poisoning Attack Reloaded: Revolutions with Side Channels
复制标题

DOI:
10.1145/3372297.3417280
复制
发表时间:
2020-10
期刊:
Proceedings of the 2020 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
通讯作者:
Keyu Man;Zhiyun Qian;Zhongjie Wang;Xiaofeng Zheng;Youjun Huang;Haixin Duan
Keyu Man;Zhiyun Qian;Zhongjie Wang;Xiaofeng Zheng;Youjun Huang;Haixin Duan
中科院分区:
其他
文献类型:
--
作者:
Keyu Man;Zhiyun Qian;Zhongjie Wang;Xiaofeng Zheng;Youjun Huang;Haixin Duan

文献摘要

被引文献

相似文献

在本文中,我们报告了软件堆栈中的一系列缺陷,这些缺陷导致DNS缓存中毒的强烈复兴-这是一种经典的攻击,在实践中可以通过简单有效的基于随机化的防御(如随机化源端口)来缓解。为了成功地在典型服务器上毒害DNS缓存,偏离路径的攻击者需要发送不切实际的2^32 $欺骗响应,同时猜测正确的源端口(16位)和事务ID(16位)。令人惊讶的是,我们发现了一些弱点,这些弱点允许对手通过首先猜测源端口,然后猜测交易ID来“分割和征服”空间(导致只有2^16 + 2^16 $欺骗响应)。更糟糕的是,我们展示了对手可以延长攻击窗口的多种方法,从而大大提高了成功的几率。该攻击影响DNS基础架构中的所有缓存层,例如DNS转发器和解析器缓存,以及广泛的DNS软件堆栈,包括最流行的BIND,Unbound和dnsmasq,运行在Linux和其他操作系统上。受害者易受攻击的主要条件是操作系统及其网络被配置为允许应答错误。从我们的测量中,我们发现互联网上超过34%的开放解析器人口是脆弱的(特别是85%的流行DNS服务,包括谷歌的8.8.8.8)。此外,我们在受控实验和生产DNS解析器(具有授权)中针对可能影响攻击成功的各种服务器配置和网络条件全面验证了拟议的攻击,并获得了积极的结果。
In this paper, we report a series of flaws in the software stack that leads to a strong revival of DNS cache poisoning --- a classic attack which is mitigated in practice with simple and effective randomization-based defenses such as randomized source port. To successfully poison a DNS cache on a typical server, an off-path adversary would need to send an impractical number of $2^32 $ spoofed responses simultaneously guessing the correct source port (16-bit) and transaction ID (16-bit). Surprisingly, we discover weaknesses that allow an adversary to "divide and conquer'' the space by guessing the source port first and then the transaction ID (leading to only $2^16 +2^16 $ spoofed responses). Even worse, we demonstrate a number of ways an adversary can extend the attack window which drastically improves the odds of success. The attack affects all layers of caches in the DNS infrastructure, such as DNS forwarder and resolver caches, and a wide range of DNS software stacks, including the most popular BIND, Unbound, and dnsmasq, running on top of Linux and potentially other operating systems. The major condition for a victim being vulnerable is that an OS and its network is configured to allow ICMP error replies. From our measurement, we find over 34% of the open resolver population on the Internet are vulnerable (and in particular 85% of the popular DNS services including Google's 8.8.8.8). Furthermore, we comprehensively validate the proposed attack with positive results against a variety of server configurations and network conditions that can affect the success of the attack, in both controlled experiments and a production DNS resolver (with authorization).