Retroactive Identification of Targeted DNS Infrastructure Hijacking

Retroactive Identification of Targeted DNS Infrastructure Hijacking
复制标题

目标 DNS 基础设施劫持的追溯识别

DOI:
10.1145/3517745.3561425
复制
发表时间:
2022
期刊:
Proceedings of the 22nd ACM Internet Measurement Conference
影响因子:
--
通讯作者:
Savage, Stefan
Savage, Stefan
中科院分区:
--
文献类型:
--
作者:
Akiwate, Gautam;Sommese, Raffaele;Jonker, Mattijs;Durumeric, Zakir;Claffy, KC;Voelker, Geoffrey M.;Savage, Stefan

文献摘要

相似文献

2019年,美国国土安全部发布了关于DNS基础设施篡改的紧急警告。这一警报是为了应对针对外国政府网站的一系列攻击,强调了老练的攻击者如何利用对关键DNS基础设施的访问,然后劫持流量并为目标组织获取有效的登录凭据。然而,即使有了这些知识,确定这类事件的存在几乎完全是通过事后法医报告(即,在通过某种其他方法发现违反之后)。事实上,这种攻击特别难以检测,因为它们可能非常短暂,绕过TLS和DNSSEC的保护,并且用户无法察觉。由于缺乏细粒度的互联网取证数据,追溯识别它们变得更加复杂。本文是第一次尝试在后一个目标取得进展。结合来自互联网范围扫描、被动DNS记录和证书透明度日志的一系列纵向数据,我们构建了一种方法来识别复杂DNS基础设施劫持的潜在受害者,并使用它来识别一系列受害者(主要是政府机构),包括先前报告中提到的受害者和其他以前未知的受害者。
In 2019, the US Department of Homeland Security issued an emergency warning aboutDNS infrastructure tampering.This alert, in response to a series of attacks against foreign government websites, highlighted how a sophisticated attacker could leverage access to key DNS infrastructure to then hijack traffic and harvest valid login credentials for target organizations. However, even armed with this knowledge, identifying the existence of such incidents has been almost entirely via post hoc forensic reports (i.e., after a breach was found via some other method). Indeed, such attacks are particularly challenging to detect because they can be very short lived, bypass the protections of TLS and DNSSEC, and are imperceptible to users. Identifying them retroactively is even more complicated by the lack of fine-grained Internet-scale forensic data. This paper is a first attempt to make progress at this latter goal. Combining a range of longitudinal data from Internet-wide scans, passive DNS records, and Certificate Transparency logs, we have constructed a methodology for identifying potential victims of sophisticated DNS infrastructure hijacking and have used it to identify a range of victims (primarily government agencies), both those named in prior reporting, and others previously unknown.