DNS authentication as a service: Preventing amplification attacks

Amir Herzberg, Haya Shulman

Research output: Contribution to conferencePaperpeer-review

13 Scopus citations

Abstract

We present the first defence against DNS-amplification DoS attacks, which is compatible with the common DNS servers configurations and with the (important standard) DNSSEC. We show that the proposed DNS-authentication system is efficient, and effectively prevents DNS-based amplification DoS attacks abusing DNS name servers. We present a gametheoretic model and analysis, predicting a wide-spread adoption of our design, sufficient to reduce the threat of DNS amplification DoS attacks. To further reduce costs and provide additional defences for DNS servers, we show how to deploy our design as a cloud based service.

Original languageEnglish
Pages356-365
Number of pages10
DOIs
StatePublished - 8 Dec 2014
Event30th Annual Computer Security Applications Conference, ACSAC 2014 - New Orleans, United States
Duration: 8 Dec 201412 Dec 2014

Conference

Conference30th Annual Computer Security Applications Conference, ACSAC 2014
Country/TerritoryUnited States
CityNew Orleans
Period8/12/1412/12/14

Keywords

  • DNS Amplification
  • DNS Authentication
  • DNS Reflection
  • Denial of service attacks
  • Source Authentication

Fingerprint

Dive into the research topics of 'DNS authentication as a service: Preventing amplification attacks'. Together they form a unique fingerprint.

Cite this