A Proxy View of Quality of Domain Name Service, Poisoning Attacks and Survival Strategies

被引:7
|
作者
Yuan, Lihua [1 ]
Chen, Chao-Chih [2 ]
Mohapatra, Prasant [2 ]
Chuah, Chen-Nee [3 ]
Kant, Krishna [4 ]
机构
[1] Univ Calif Davis, Davis, CA 95616 USA
[2] Univ Calif Davis, Dept Comp Sci, Davis, CA 95616 USA
[3] Univ Calif Davis, Dept Elect & Comp Engn, Davis, CA 95616 USA
[4] Intel Corp, Santa Clara, CA 95051 USA
关键词
Reliability; Security; DNS; QoDNS; proxy; cache; poisoning; CACHING SYSTEMS; WEB;
D O I
10.1145/2461321.2461324
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The Domain Name System (DNS) provides a critical service for the Internet - mapping of user-friendly domain names to their respective IP addresses. Yet, there is no standard set of metrics quantifying the Quality of Domain Name Service (QoDNS), let alone a thorough evaluation of it. This article attempts to fill this gap from the perspective of a DNS proxy/cache, which is the bridge between clients and authoritative servers. We present an analytical model of DNS proxy operations that offers insights into the design trade-offs of DNS infrastructure and the selection of critical DNS parameters. Due to the critical role DNS proxies play in QoDNS, they are the focus of attacks including cache poisoning attack. We extend the analytical model to study DNS cache poisoning attacks and their impact on QoDNS metrics. This analytical study prompts us to present Domain Name Cross-Referencing (DoX), a peer-to-peer systems for DNS proxies to cooperatively defend cache poisoning attacks. Based on QoDNS, we compare DoX with the cryptography-based DNS Security Extension (DNSSEC) to understand their relative merits.
引用
收藏
页数:26
相关论文
共 7 条
  • [1] A proxy view of quality of domain name service
    Yuan, Lihua
    Kant, Krishna
    Mohapatra, Prasant
    Chuah, Chen-Nee
    INFOCOM 2007, VOLS 1-5, 2007, : 321 - +
  • [2] An Encryption Algorithm to Prevent Domain Name System Cache Poisoning Attacks
    Li, Xue Jun
    Ma, Maode
    Arjun, Narayanan
    2019 29TH INTERNATIONAL TELECOMMUNICATION NETWORKS AND APPLICATIONS CONFERENCE (ITNAC), 2019,
  • [3] Mitigating DDoS Attacks towards Top Level Domain Name Service
    Pan, Lanlan
    Yuchi, Xuebiao
    Chen, Yong
    2016 18TH ASIA-PACIFIC NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM (APNOMS), 2016,
  • [4] Analysis of domain name and customer service strategies in online marketing
    Fang, F.
    Qin, T.B.
    Shanghai Haiyun Xueyuan Xuebao/Journal of Shanghai Maritime University, 2001, 22 (02):
  • [5] Detection of Denial of Service Attacks against Domain Name System Using Machine Learning Classifiers
    Rastegari, Samaneh
    Saripan, M. Iqbal
    Rasid, Mohd Fadlee A.
    WORLD CONGRESS ON ENGINEERING, WCE 2010, VOL I, 2010, : 444 - 447
  • [6] An enhanced mechanism for detection of Domain Name System-based distributed reflection denial of service attacks depending on modified metaheuristic algorithms and adaptive thresholding techniques
    Manickam, Selvakumar
    Nuiaa, Riyadh Rahef
    Alsaeedi, Ali Hakem
    Alyasseri, Zaid Abdi Alkareem
    Mohammed, Mazin A.
    Jaber, Mustafa M.
    IET NETWORKS, 2022, 11 (05) : 169 - 181
  • [7] Defending against Distributed Denial-of-Service (DDoS) Attacks Using Routing Assignments and Resource Allocation Strategies under Quality-of-Service (QoS) Constraints
    Yeong-Sung, Frank
    Tsang, Po-Hao
    Kuo, Chen-Bin
    WMSCI 2008: 12TH WORLD MULTI-CONFERENCE ON SYSTEMICS, CYBERNETICS AND INFORMATICS, VOL III, PROCEEDINGS, 2008, : 221 - 226