Arming the Defenseless: An Incentive-based Approach to DNS Reflection Prevention
Casey Deccio, Brigham Young University AIMS 2017 CAIDA, UCSD, La Jolla, CA March 1, 2017
Arming the Defenseless: An Incentive-based Approach to DNS - - PowerPoint PPT Presentation
Arming the Defenseless: An Incentive-based Approach to DNS Reflection Prevention Casey Deccio, Brigham Young University AIMS 2017 CAIDA, UCSD, La Jolla, CA March 1, 2017 Reflection/Amplification-based DDoS Attack Queries Responses
Casey Deccio, Brigham Young University AIMS 2017 CAIDA, UCSD, La Jolla, CA March 1, 2017
Attackers (Globally distributed) Servers (Address B) Victim (Address A) Queries ((spoofed)A → B) Responses (B → A)
RRL
DNS Client DNS server
www.example.com (NOCOOKIE) COOKIE: 1234 www.example.com (COOKIE:1234) 192.0.2.1
Attackers (Globally distributed) Servers (Address B) Victim (Address A) Queries ((spoofed)A → B)
BCP38 DNS RRL Increase Resources
Attackers (Globally distributed) Servers (Address B) Victim (Address A) Queries ((spoofed)A → B)
arpa 192 2 in-addr 191 193 … …