DNS Cache Poisoning Attack: Resurrections with Side Channels

DNS Cache Poisoning Attack: Resurrections with Side Channels
复制标题

DOI:
10.1145/3460120.3486219
复制
发表时间:
2021-11
期刊:
Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
通讯作者:
Keyu Man;Xin'an Zhou;Zhiyun Qian
Keyu Man;Xin'an Zhou;Zhiyun Qian
中科院分区:
其他
文献类型:
--
作者:
Keyu Man;Xin'an Zhou;Zhiyun Qian

文献摘要

被引文献

相似文献

DNS是互联网上支持许多网络应用和服务的基本和古老协议之一。不幸的是,DNS在设计时没有考虑到安全性,并且受到各种严重攻击,其中之一是众所周知的DNS缓存中毒攻击。经过几十年的发展,事实证明,将强大的安全功能改造到其中是非常具有挑战性的。迄今为止,只有基于随机化原则的较弱版本的防御被广泛部署,例如,UDP临时端口号的随机化,使得非路径攻击者很难猜测秘密。然而,正如最近所示,这种随机性受到巧妙的网络侧信道攻击的影响,这可以有效地对临时端口号进行去随机化。在本文中,我们对以前被忽视的攻击面进行了分析,并能够发现在Linux内核中存在了十多年的更强大的侧通道。侧信道不仅影响Linux,还影响运行在其上的各种DNS软件,包括BIND、Unbound和dnsmasq。我们还发现大约38%的开放解析器(按前端IP)和14%(按后端IP)存在漏洞,包括OpenDNS和Quad9等流行的DNS服务。我们已经在实际配置和网络条件下对攻击进行了广泛的实验验证,并表明它工作可靠且快速。
DNS is one of the fundamental and ancient protocols on the Internet that supports many network applications and services. Unfortunately, DNS was designed without security in mind and is subject to a variety of serious attacks, one of which is the well-known DNS cache poisoning attack. Over the decades of evolution, it has proven extraordinarily challenging to retrofit strong security features into it. To date, only weaker versions of defenses based on the principle of randomization have been widely deployed, e.g., the randomization of UDP ephemeral port number, making it hard for an off-path attacker to guess the secret. However, as it has been shown recently, such randomness is subject to clever network side channel attacks, which can effectively derandomize the ephemeral port number. In this paper, we conduct an analysis of the previously overlooked attack surface, and are able to uncover even stronger side channels that have existed for over a decade in Linux kernels. The side channels affect not only Linux but also a wide range of DNS software running on top of it, including BIND, Unbound and dnsmasq. We also find about 38% of open resolvers (by frontend IPs) and 14% (by backend IPs) are vulnerable including the popular DNS services such as OpenDNS and Quad9. We have extensively validated the attack experimentally under realistic configuration and network conditions and showed that it works reliably and fast.