Zone Poisoning: The How and Where of Non-Secure DNS Dynamic Updates
Zone Poisoning: The How and Where of Non-Secure DNS Dynamic Updates
复制标题
区域中毒:非安全 DNS 动态更新的方式和地点
DOI:
--
复制
发表时间:
2016
期刊:
影响因子:
--
通讯作者:
M. V. Eeten
中科院分区:
文献类型:
--
作者:
Maciej Korczyński;M. Król;M. V. Eeten
This paper illuminates the problem of non-secure DNS dynamic updates, which allow a miscreant to manipulate DNS entries in the zone files of authoritative name servers. We refer to this type of attack as to zone poisoning. This paper presents the first measurement study of the vulnerability. We analyze a random sample of 2.9 million domains and the Alexa top 1 million domains and find that at least 1,877 (0.065%) and 587 (0.062%) of domains are vulnerable, respectively. Among the vulnerable domains are governments, health care providers and banks, demonstrating that the threat impacts important services. Via this study and subsequent notifications to affected parties, we aim to improve the security of the DNS ecosystem.