Prevention of DNS Amplification Attacks
Josip Stanešić, Zlatan Morić, Vedran Dakić and Matej Bašić. Prevention of DNS Amplification Attacks. Proceedings of the 34th DAAAM International Symposium, 82–87, 2023.
Abstract
The Domain Name System (DNS) is a critical internet infrastructure component, that translates domain names to IP addresses. This study examines the persistent threat of DNS amplification attacks, which exploit certain DNS servers to magnify query responses, causing network congestion. Despite existing mitigations like Response Rate Limiting (RRL) and DNS Security Extensions (DNSSEC), these attacks remain prevalent. Our comprehensive analysis of over 1.7 million IP addresses reveals that approximately 14.77% of Internet DNS servers support recursive queries without access controls. Notably, vulnerable servers are distributed globally, with Asia, Africa, and South America showing the highest vulnerability rates. This research underscores the urgency of enhancing DNS server security. Recommendations include disabling recursion or implementing strict access controls, deploying rate-limiting measures, and restricting "ANY" queries to mitigate DNS amplification attacks. Collaboration between regulatory bodies and network operators is crucial, especially for government infrastructure. In conclusion, this study provides crucial insights into the state of public DNS servers, their vulnerabilities, and the ongoing threat of DNS amplification attacks. As the internet evolves, vigilance and proactive measures are essential to protect DNS service integrity and availability.
My contribution
Joint work with Josip Stanešić, Zlatan Morić and Vedran Dakić on the state of public DNS servers and how amplification attacks can be prevented. The proceedings carry no author contribution statement, so I have not put a claim here yet.