Zone Poisoning: The How and Where of Non-Secure DNS Dynamic Updates

Zone Poisoning: The How and Where of Non-Secure DNS Dynamic Updates
复制标题

区域中毒:非安全 DNS 动态更新的方式和地点

DOI:
--
复制
发表时间:
2016
期刊:
ACM/SIGCOMM Internet Measurement Conference
影响因子:
--
通讯作者:
M. V. Eeten
M. V. Eeten
中科院分区:
--
文献类型:
--
作者:
Maciej Korczyński;M. Król;M. V. Eeten

文献摘要

被引文献

相似文献

本文阐述了非安全DNS动态更新的问题,该问题允许不法分子操纵权威域名服务器区域文件中的DNS条目。我们把这种攻击称为区域中毒。本文首次对脆弱性进行了测量研究。我们分析了290万个域名和Alexa前100万个域名的随机样本,发现分别至少有1,877个(0.065%)和587个(0.062%)域名是脆弱的。易受攻击的领域包括政府、医疗保健提供者和银行,这表明该威胁影响了重要的服务。通过这项研究和随后对受影响方的通知,我们的目标是提高DNS生态系统的安全性。
This paper illuminates the problem of non-secure DNS dynamic updates, which allow a miscreant to manipulate DNS entries in the zone files of authoritative name servers. We refer to this type of attack as to zone poisoning. This paper presents the first measurement study of the vulnerability. We analyze a random sample of 2.9 million domains and the Alexa top 1 million domains and find that at least 1,877 (0.065%) and 587 (0.062%) of domains are vulnerable, respectively. Among the vulnerable domains are governments, health care providers and banks, demonstrating that the threat impacts important services. Via this study and subsequent notifications to affected parties, we aim to improve the security of the DNS ecosystem.