Guardians of DNS Integrity: A Remote Method for Identifying DNSSEC Validators Across the Internet - DRAKKAR
Communication Dans Un Congrès Année : 2023

Guardians of DNS Integrity: A Remote Method for Identifying DNSSEC Validators Across the Internet

Yevheniya Nosyk
  • Fonction : Auteur
Maciej Korczyński
  • Fonction : Auteur
Andrzej Duda
  • Fonction : Auteur

Résumé

DNS Security Extensions (DNSSEC) provide the most effective way to fight DNS cache poisoning attacks. Yet, very few DNS resolvers perform DNSSEC validation. Identifying such systems is non-trivial and the existing methods are not suitable for Internet-scale measurements. In this paper, we propose a novel remote technique for identifying DNSSEC-validating resolvers. The proposed method consists of two steps. In the first step, we identify open resolvers by scanning 3.1 billion end hosts and request every non-forwarder to resolve one correct and seven deliberately misconfigured domains. We then build a classifier that discriminates validators from non-validators based on query patterns and DNS response codes. We find that while most open resolvers are DNSSEC-enabled, less than 18% in IPv4 (38% in IPv6) validate received responses. In the second step, we remotely identify closed non-forwarders in networks that do not have inbound Source Address Validation (SAV) in place. Using the classifier built in step one, we identify 37.4% IPv4 (42.9% IPv6) closed DNSSEC validators and cross-validate the results using RIPE Atlas probes. Finally, we show that the discovered (non)-validators actively send requests to DNS root servers, suggesting that we deal with operational recursive resolvers rather than misconfigured machines

Mots clés

Fichier principal
Vignette du fichier
TrustCom_2023__Guardians_of_DNS_Integrity__A_Remote_Method_for_Identifying_DNSSEC_Validators_Across_the_Internet.pdf (422.1 Ko) Télécharger le fichier
Origine Fichiers produits par l'(les) auteur(s)

Dates et versions

hal-04602223 , version 1 (05-06-2024)

Identifiants

Citer

Yevheniya Nosyk, Maciej Korczyński, Andrzej Duda. Guardians of DNS Integrity: A Remote Method for Identifying DNSSEC Validators Across the Internet. IEEE 22nd International Conference on Trust, Security and Privacy in Computing and Communications (TrustCom 2023), Nov 2023, Exeter, United Kingdom. pp.1470-1479, ⟨10.1109/TrustCom60117.2023.00201⟩. ⟨hal-04602223⟩
55 Consultations
40 Téléchargements

Altmetric

Partager

More