Detecting DNS Amplification Attacks

Detecting DNS Amplification Attacks
复制标题

检测 DNS 放大攻击

DOI:
--
复制
发表时间:
2007
期刊:
Critical Information Infrastructures Security
影响因子:
--
通讯作者:
S. Gritzalis
S. Gritzalis
中科院分区:
--
文献类型:
--
作者:
G. Kambourakis;Tassos Moschos;Dimitris Geneiatakis;S. Gritzalis

文献摘要

被引文献

相似文献

DNS放大攻击大量利用开放递归DNS服务器,主要用于执行带宽消耗DDoS攻击。放大效应在于DNS响应消息可能比DNS查询消息大得多的事实。在本文中,我们提出并评估了一种新颖实用的方法,能够区分真实和虚假的DNS回复。该方案可以有效地保护本地DNS服务器的主动和被动行为。我们的分析和相应的实际使用的实验结果表明,该方案提供了一个灵活的,强大的和有效的解决方案。
DNS amplification attacks massively exploit open recursive DNS servers mainly for performing bandwidth consumption DDoS attacks. The amplification effect lies in the fact that DNS response messages may be substantially larger than DNS query messages. In this paper, we present and evaluate a novel and practical method that is able to distinguish between authentic and bogus DNS replies. The proposed scheme can effectively protect local DNS servers acting both proactively and reactively. Our analysis and the corresponding real-usage experimental results demonstrate that the proposed scheme offers a flexible, robust and effective solution.