The Wolf of Name Street: Hijacking Domains Through Their Nameservers

The Wolf of Name Street: Hijacking Domains Through Their Nameservers
复制标题

DOI:
10.1145/3133956.3133988
复制
发表时间:
2017-10
期刊:
Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
通讯作者:
T. Vissers;Timothy Barron;Tom van Goethem;W. Joosen;Nick Nikiforakis
T. Vissers;Timothy Barron;Tom van Goethem;W. Joosen;Nick Nikiforakis
中科院分区:
其他
文献类型:
--
作者:
T. Vissers;Timothy Barron;Tom van Goethem;W. Joosen;Nick Nikiforakis

文献摘要

被引文献

相似文献

所有域名的功能和安全性都取决于其名称服务器。当这些名称服务器或对它们的请求受到损害时,依赖它们的所有域都会受到影响。在本文中,我们研究了利用配置问题(拼写错误和过时的WHOIS记录)和硬件错误(位抢注)来控制域名服务器劫持域名的请求。我们对10,000个流行的域名服务器域进行了大规模分析,其中我们绘制了现有的滥用和脆弱的实体。我们通过真实世界的测量来确认这些攻击的能力。总的来说,我们发现超过12,000个域名容易受到近乎立即的危害,而5280万个域名正成为域名服务器比特抢注者的目标,这些域名服务器比特抢注者使用流氓IP地址进行响应。此外,我们确定128万个域名由于依赖过时的名称服务器而面临拒绝服务攻击的风险。
The functionality and security of all domain names are contingent upon their nameservers. When these nameservers, or requests to them, are compromised, all domains that rely on them are affected. In this paper, we study the exploitation of configuration issues (typosquatting and outdated WHOIS records) and hardware errors (bitsquatting) to seize control over nameservers' requests to hijack domains. We perform a large-scale analysis of 10,000 popular nameserver domains, in which we map out existing abuse and vulnerable entities. We confirm the capabilities of these attacks through real-world measurements. Overall, we find that over 12,000 domains are susceptible to near-immediate compromise, while 52.8M domains are being targeted by nameserver bitsquatters that respond with rogue IP addresses. Additionally, we determine that 1.28M domains are at risk of a denial-of-service attack by relying on an outdated nameserver.