Detecting DNS Amplification Attacks
Detecting DNS Amplification Attacks
复制标题
检测 DNS 放大攻击
DOI:
--
复制
发表时间:
2007
期刊:
影响因子:
--
通讯作者:
S. Gritzalis
中科院分区:
文献类型:
--
作者:
G. Kambourakis;Tassos Moschos;Dimitris Geneiatakis;S. Gritzalis
DNS amplification attacks massively exploit open recursive DNS servers mainly for performing bandwidth consumption DDoS attacks. The amplification effect lies in the fact that DNS response messages may be substantially larger than DNS query messages. In this paper, we present and evaluate a novel and practical method that is able to distinguish between authentic and bogus DNS replies. The proposed scheme can effectively protect local DNS servers acting both proactively and reactively. Our analysis and the corresponding real-usage experimental results demonstrate that the proposed scheme offers a flexible, robust and effective solution.