A wrinkle in time: A case study in DNS poisoning

06/26/2019
by   Harel Berger, et al.
0

The Domain Name System (DNS) provides a translation between readable domain names and IP addresses. The DNS is a key infrastructure component of the Internet and a prime target for a variety of attacks. One of the most significant threat to the DNS's wellbeing is a DNS poisoning attack, in which the DNS responses are maliciously replaced, or poisoned, by an attacker. To identify this kind of attack, we start by an analysis of different kinds of response times. We present an analysis of typical and atypical response times, while differentiating between the different levels of DNS servers' response times, from root servers down to internal caching servers. We successfully identify empirical DNS poisoning attacks based on a novel method for DNS response timing analysis. We then present a system we developed to validate our technique that does not require any changes to the DNS protocol or any existing network equipment. Our validation system tested data from different architectures including LAN and cloud environments and real data from an Internet Service Provider (ISP). Our method and system differ from most other DNS poisoning detection methods and achieved high detection rates exceeding 99 they can considerably enhance the accuracy of these methods.

READ FULL TEXT

page 1

page 5

page 10

research
05/18/2020

NXNSAttack: Recursive DNS Inefficiencies and Vulnerabilities

The Domain Name System (DNS) infrastructure, a most critical system the ...
research
06/08/2021

DNS attack mitigation Using OpenStack Isolation

The Domain Name System (DNS) is essential for the Internet, giving a mec...
research
03/30/2020

Analysis of an Extension Dynamic Name Service – A discussion on DNS compliance with RFC 6891

Domain Name Service (DNS) resolution is a mechanism that resolves the sy...
research
11/12/2019

A Reproducibility Study of "IP Spoofing Detection in Inter-Domain Traffic"

IP spoofing enables reflection and amplification attacks, which cause ma...
research
01/18/2022

Analyzing Enterprise DNS Traffic to Classify Assets and Track Cyber-Health

The Domain Name System (DNS) is a critical service that enables domain n...
research
07/12/2023

Evaluating DNS Resiliency and Responsiveness with Truncation, Fragmentation DoTCP Fallback

Since its introduction in 1987, the DNS has become one of the core compo...
research
05/16/2021

Low-Complexity PIR Using Subfield Subcodes

A major drawback of many PIR schemes is the highcomputational cost at th...

Please sign up or login with your details

Forgot password? Click here to reset