Location via proxy:   [ UP ]  
[Report a bug]   [Manage cookies]                
skip to main content
10.1145/3232755.3232765acmconferencesArticle/Chapter ViewAbstractPublication PagescommConference Proceedingsconference-collections
abstract

Practical Challenge-Response for DNS

Published: 16 July 2018 Publication History

Abstract

Authoritative DNS nameservers are vulnerable to being used in denial of service attacks whereby an attacker sends DNS queries while masquerading as a victim---hence coaxing the DNS server to send the responses to the victim. Reflecting off innocent DNS servers both hides the attackers identity and often amplifies the attackers traffic by turning small DNS requests sent to the nameserver into large DNS answers sent to the victim. In this poster we discuss a practical challenge-response technique that establishes a requester's identity before sending a full answer. Unlike previous schemes, our work deals with so-called "resolver pools"---or groups of DNS resolvers that work together to lookup records in the DNS. In these cases a challenge transmitted to a resolver N1 may be dealt with by a different resolver N2, thus leaving an authoritative DNS server wondering whether N2 is another resolver in the pool or a victim. We propose a technique called "challenge chains" to establish identity in the face of resolver pools. We show that the cost of our scheme in terms of added delay is small. This work appears in [1].
[1] Rami Al-Dalky, Michael Rabinovich, Mark Allman. Practical Challenge-Response for DNS. ACM Computer Communication Review, 48(3), July 2018.

Cited By

View all

Recommendations

Comments

Information & Contributors

Information

Published In

cover image ACM Conferences
ANRW '18: Proceedings of the 2018 Applied Networking Research Workshop
July 2018
102 pages
ISBN:9781450355858
DOI:10.1145/3232755
Permission to make digital or hard copies of part or all of this work for personal or classroom use is granted without fee provided that copies are not made or distributed for profit or commercial advantage and that copies bear this notice and the full citation on the first page. Copyrights for third-party components of this work must be honored. For all other uses, contact the Owner/Author.

Sponsors

Publisher

Association for Computing Machinery

New York, NY, United States

Publication History

Published: 16 July 2018

Check for updates

Author Tags

  1. DNS
  2. measurement
  3. performance
  4. security

Qualifiers

  • Abstract
  • Research
  • Refereed limited

Conference

ANRW '18
Sponsor:
ANRW '18: Applied Networking Research Workshop
July 16, 2018
QC, Montreal, Canada

Acceptance Rates

Overall Acceptance Rate 34 of 58 submissions, 59%

Contributors

Other Metrics

Bibliometrics & Citations

Bibliometrics

Article Metrics

  • Downloads (Last 12 months)10
  • Downloads (Last 6 weeks)6
Reflects downloads up to 30 Aug 2024

Other Metrics

Citations

Cited By

View all

View Options

Get Access

Login options

View options

PDF

View or Download as a PDF file.

PDF

eReader

View online with eReader.

eReader

Media

Figures

Other

Tables

Share

Share

Share this Publication link

Share on social media