Ghost Domain Reloaded: Vulnerable Links in Domain Name Delegation and Revocation

Ghost Domain Reloaded: Vulnerable Links in Domain Name Delegation and Revocation
复制标题

DOI:
10.14722/ndss.2023.23005
复制
发表时间:
2023
期刊:
Proceedings 2023 Network and Distributed System Security Symposium
影响因子:
--
通讯作者:
Xiang Li;Baojun Liu;Xuesong Bai;Mingming Zhang;Qifan Zhang;Zhou Li;Haixin Duan;Qi Li
Xiang Li;Baojun Liu;Xuesong Bai;Mingming Zhang;Qifan Zhang;Zhou Li;Haixin Duan;Qi Li
中科院分区:
其他
文献类型:
--
作者:
Xiang Li;Baojun Liu;Xuesong Bai;Mingming Zhang;Qifan Zhang;Zhou Li;Haixin Duan;Qi Li

文献摘要

被引文献

相似文献

在本文中,我们提出了P HOENIX D OMAIN,一种通用的新型攻击,允许对手保持撤销的恶意域在规模上连续可解析,这使得旧的,减轻的攻击,幽灵域。P HOENIX D OMAIN有两个变体,影响所有主流DNS软件和公共DNS解析器,因为它不违反任何DNS规范和最佳安全实践。通过系统地“逆向工程“8个DNS实现的缓存该高速缓存操作,攻击成为可能,新的攻击面在域名授权过程中被揭示。我们选择了41个知名的公共DNS解析器,并证明所有被调查的DNS服务都容易受到P HOENIX D OMAIN的攻击,包括Google Public DNS和Cloudflare DNS。对210k个稳定的分布式DNS递归解析器进行了大量的测量研究,结果表明,即使在域名撤销和缓存过期一个月后,仍有超过25%的递归解析器能够解析域名。我们已经向所有受影响的供应商报告了发现的漏洞,并建议了6种缓解方法。到目前为止,包括BIND,Unbound,Google和Cloudflare在内的7家DNS软件提供商和15家解析器供应商已经确认了漏洞,其中一些正在根据我们的建议实施和发布缓解补丁。此外,还分配了9个CVE编号。该研究呼吁标准化,以解决如何安全地撤销域名和维护缓存一致性的问题。
—In this paper, we propose P HOENIX D OMAIN , a general and novel attack that allows adversaries to maintain the revoked malicious domain continuously resolvable at scale, which enables an old, mitigated attack, Ghost Domain. P HOENIX D OMAIN has two variations and affects all mainstream DNS software and public DNS resolvers overall because it does not violate any DNS specifications and best security practices. The attack is made possible through systematically “ reverse engineer ” the cache operations of 8 DNS implementations, and new attack surfaces are revealed in the domain name delegation processes. We select 41 well-known public DNS resolvers and prove that all surveyed DNS services are vulnerable to P HOENIX D OMAIN , including Google Public DNS and Cloudflare DNS. Extensive measurement studies are performed with 210k stable and distributed DNS recursive resolvers, and results show that even after one month from domain name revocation and cache expiration, more than 25% of recursive resolvers can still resolve it. The proposed attack provides an opportunity for adversaries to evade the security practices of malicious domain take-down. We have reported discovered vulnerabilities to all affected vendors and suggested 6 types of mitigation approaches to them. Until now, 7 DNS software providers and 15 resolver vendors, including BIND, Unbound, Google, and Cloudflare, have confirmed the vulnerabilities, and some of them are implementing and publishing mitigation patches according to our suggestions. In addition, 9 CVE numbers have been assigned. The study calls for standardization to address the issue of how to revoke domain names securely and maintain cache consistency.