Dark Side of the DNS Force

us-16-Wu-Dark-Side-Of-The-DNS-Force us-16-Wu-Dark-Side-Of-The-DNS-Force

08.08.2016 Views

Intro Subdomain Mechanism Impact Outro Operation Mitigation Impact • Attacking target domain’s authoritative name servers • Collateral damages of DNS resolvers along the path • Enablers: • Subdomain generator • (optional) Open resolvers • (optional) Spoofed sending addresses Resolver Resolver what is IP address of victim.com? victim’s name server victim.com.

Intro Subdomain Mechanism Impact Outro Operation Mitigation Operation Disruption Authoritative name server often serves more than one domain, so does DNS resolver (cache/recursive) A major ISP operation may be taken down by small-scale subdomain attacks • 2gbps vs 300gbps

Intro<br />

Subdomain<br />

Mechanism<br />

Impact<br />

Outro<br />

Operation<br />

Mitigation<br />

Operation Disruption<br />

Authoritative name server <strong>of</strong>ten serves more than one domain,<br />

so does <strong>DNS</strong> resolver (cache/recursive)<br />

A major ISP operation may be taken down by small-scale<br />

subdomain attacks<br />

• 2gbps vs 300gbps

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!