Defending Root DNS Servers Against DDoS Using Layered Defenses

by   A S M Rizvi, et al.

Distributed Denial-of-Service (DDoS) attacks exhaust resources, leaving a server unavailable to legitimate clients. The Domain Name System (DNS) is a frequent target of DDoS attacks. Since DNS is a critical infrastructure service, protecting it from DoS is imperative. Many prior approaches have focused on specific filters or anti-spoofing techniques to protect generic services. DNS root nameservers are more challenging to protect, since they use fixed IP addresses, serve very diverse clients and requests, receive predominantly UDP traffic that can be spoofed, and must guarantee high quality of service. In this paper we propose a layered DDoS defense for DNS root nameservers. Our defense uses a library of defensive filters, which can be optimized for different attack types, with different levels of selectivity. We further propose a method that automatically and continuously evaluates and selects the best combination of filters throughout the attack. We show that this layered defense approach provides exceptional protection against all attack types using traces of ten real attacks from a DNS root nameserver. Our automated system can select the best defense within seconds and quickly reduces traffic to the server within a manageable range, while keeping collateral damage lower than 2 noticeable operational overhead.


A Survey of Distributed Denial of Service Attacks and Defenses

A distributed denial-of-service (DDoS) attack is an attack wherein multi...

DeTorrent: An Adversarial Padding-only Traffic Analysis Defense

While anonymity networks like Tor aim to protect the privacy of their us...

Changing proxy-server identities as a proactive moving-target defense against reconnaissance for DDoS attacks

We consider a cloud based multiserver system consisting of a set of repl...

Layered Cost-Map-Based Traffic Management for Multiple Automated Mobile Robots via a Data Distribution Service

This letter proposes traffic management for multiple automated mobile ro...

SoK: Analysis of Root Causes and Defense Strategies for Attacks on Microarchitectural Optimizations

Microarchitectural optimizations are expected to play a crucial role in ...

Chhoyhopper: A Moving Target Defense with IPv6

Services on the public Internet are frequently scanned, then subject to ...

Rethinking the Defense Against Free-rider Attack From the Perspective of Model Weight Evolving Frequency

Federated learning (FL) is a distributed machine learning approach where...

Please sign up or login with your details

Forgot password? Click here to reset