Home / Blogs

Why DNS Is Broken, Part 2: DoS Target

Paul Parisi

Continuing from where we left off last time... Before we get into what DNSSEC is and the benefits of it, let's talk about some of the other potential pitfalls of DNS.

One of the most significant issues we have to deal with are denial-of-service (DoS) attacks. While DoS attacks are not specific to DNS we have seen DNS be a frequent target of these attacks. A DoS attack is when hackers target your DNS server (or any resource) with a flood of so much traffic that the server is unable to keep up and service legitimate requests. Doing this to a DNS server is relatively easy and rather difficult to prevent. Prevention is really only accomplished with border devices such as firewalls which limit the number of connections over time from any one source. However, it is much more difficult to avoid when the attack is distributed. Most current attacks are distributed. Hackers utilize armies of unsuspecting machines which have been compromised, each to do just a little bit of work for them; it is so little that it goes easily unnoticed.

The problem for the DNS administrator is how to determine which of the requests are legitimate and which are not. Not easy. A well executed distributed denial-of-service (DDoS) can be very difficult to thwart. Basically the only way to really avoid the effects of a DDoS is by having an overdesigned and over-provisioned network and servers. VeriSign solves this by having lots of bandwidth available and a small army of DNS servers.

Bottom-line is that as a DNS administrator you need to have a current understanding of how close your servers are operating to their limits; you need to diligently monitor their performance. For Microsoft Windows based DNS take a look at PerfMon for others you will need to dump the statistics and compare them over time. Good stuff. I guess we will have to talk about DNSSEC next time, I promise.

By Paul Parisi, Chief Technology Officer at DNSstuff.com

Related topics: DNS, DNSSEC, Security

WEEKLY WRAP — Get CircleID's Weekly Summary Report by Email:

Comments

Not the fault of DNS The Famous Brett Watson  –  May 22, 2009 7:47 AM PST

This isn't a pitfall of DNS: it's a pitfall of public-facing network services in general. It's safe to assume that DNSSEC will suffer this problem more than vanilla DNS simply due to its additional data overhead. Deployment of DNSSEC will thus result in the need for additional DNS server infrastructure just to maintain the status quo in relation to DoS resistance.

BCP 38 Edward Lewis  –  May 26, 2009 6:48 AM PST

The reason DDos and DNS seem to go hand in hand (they don't really, it's just a perception) is that DNS relies on UDP.  Taking UDP away from DNS is not the answer because it's UDP that gives DNS a lightweight and quick nature.  BCP 38 (aka RFC 2827, "Network Ingress Filtering: Defeating Denial of Service Attacks which employ IP Source Address Spoofing", May 2000) deployment would go a long way to stemming the impact of DDoS against DNS.

As far as what can be done within the DNS operating layer, there are a few things that can be done besides trying to "out gun" the attack.  Bringing the data topologically closer to the client (legit or not) is one strategy, for example.

To post comments, please login or create an account.

Related Blogs

Related News

Topics

Industry Updates – Sponsored Posts

.ORG COO Discusses Priorities With DailyVista, Pursuit of .NGO Domain

StarHub to Acquire '.starhub' New Top-Level Domain

ARI Registry Services Signs 21 Contracts in the First Week of New TLD Applications

MarkMonitor to Exhibit at Internet Tech Policy Exhibition and Reception to be Held on Capitol Hill

Sedari Signs With Dot Moscow Bidders

.ORG, The Public Interest Registry Welcomes Nancy Gofus As Chief Operating Officer

Minds+Machines Works with .bayern

Verisign to Award New Infrastructure Research Grants

Being a .PRO When Choosing a Registry Services Partner

UK Cabinet Office Looks to BlueCat Networks' Expertise and Best Practices for Securing PSN

dot Brand Makes Its Debut: Afilias Advises Companies to Act Now for Successful TLD Applications

BlueCat Networks Helps Organizations Transition to IPv6 with HP

BlueCat Networks to Host Webinar on DNS, DHCP and IPAM Featuring Independent Research Firm

Facets of gTLD Registry Technical Operations - Registry Services

Technology and Finance Industries to Dominate New gTLD Applications

Nixu SNS 2.5 Series Gives Fresh Views on DNS

Afilias Says "No" to SOPA

Breaking the DNS: Another Look at How SOPA Could Be Destructive

IPAM and DHCPv6 Shake Hand in Nixu NameSurfer 7.1 Series

2011: A Year in Review, from the Yes2DotAfrica Campaign

Hot Topics

Verisign

Security

Sponsored by
Verisign
dotMobi

Mobile

Sponsored by
dotMobi
Afilias

DNSSEC

Sponsored by
Afilias
Neustar UltraDNS

DNS

Sponsored by
Neustar UltraDNS
Minds + Machines

Top-Level Domains

Sponsored by
Minds + Machines