what is all that crap
play

What is all that crap? Analysis of DNS root server bogus queries - PowerPoint PPT Presentation

RIPE Network Coordination Centre What is all that crap? Analysis of DNS root server bogus queries Authors: Danil Snchez & Joost Pijnaker Education: System & Network Engineering Supervisors: Cees de Laat (UvA) Daniel


  1. RIPE Network Coordination Centre “What is all that crap?” Analysis of DNS root server bogus queries Authors: Daniël Sánchez & Joost Pijnaker Education: System & Network Engineering Supervisors: Cees de Laat (UvA) Daniel Karrenberg (RIPE NCC) Date: 07-02-2007 14:00 http://www.ripe.net

  2. RIPE Network Coordination Centre Agenda ● Organisation ● Project introduction ● Research ● Conclusion ● Questions http://www.ripe.net

  3. RIPE Network Coordination Centre Agenda ● Organisation ● Project introduction ● Research ● Conclusion ● Questions http://www.ripe.net

  4. RIPE Network Coordination Centre Organisation: RIPE NCC http://www.ripe.net http://www.ripe.net

  5. RIPE Network Coordination Centre Organisation: K-Root server http://k.root-servers.org http://www.ripe.net

  6. RIPE Network Coordination Centre Organisation: DNS Root server http://faq.oneandone.co.uk http://www.ripe.net

  7. RIPE Network Coordination Centre Agenda ● Organisation ● Project introduction ● Research ● Conclusion ● Questions http://www.ripe.net

  8. RIPE Network Coordination Centre Agenda ● Organisation ● Project introduction ● Research ● Conclusion ● Questions http://www.ripe.net

  9. RIPE Network Coordination Centre Project introduction ● Problem definition ● Research question ● Research scope ● Capture data ● Tools http://www.ripe.net

  10. RIPE Network Coordination Centre Project introduction: Capture data http://www.ripe.net

  11. RIPE Network Coordination Centre Project introduction: Tools ● Tcpdump ● Ethereal ● dnstop ● Scripts (awk, Ruby) http://www.ripe.net

  12. RIPE Network Coordination Centre Agenda ● Organisation ● Project introduction ● Research ● Conclusion ● Questions http://www.ripe.net

  13. RIPE Network Coordination Centre Agenda ● Organisation ● Project introduction ● Research ● Conclusion ● Questions http://www.ripe.net

  14. RIPE Network Coordination Centre Research ● Determine bogus categories ● Filter capture data ● Statistics ● Determine possible causes ● Determine possible solutions http://www.ripe.net

  15. RIPE Network Coordination Centre Research ● Determine bogus categories ● Filter capture data ● Statistics ● Determine possible causes ● Determine possible solutions http://www.ripe.net

  16. RIPE Network Coordination Centre Research: Bogus categories ● A for A queries ● Private IP reverse queries ● Reserved IP reverse queries ● Local domain queries ● Invalid TLD queries ● Identical query IDs queries ● Repeated queries ● TLD not cached queries http://www.ripe.net

  17. RIPE Network Coordination Centre A for A queries A? x.y.80.66. http://www.ripe.net

  18. RIPE Network Coordination Centre Private IP reverse queries PTR? 1.0.0.127.in-addr.arpa. http://www.ripe.net

  19. RIPE Network Coordination Centre Reserved IP reverse queries PTR? 192.168.253.241.in-addr.arpa. http://www.ripe.net

  20. RIPE Network Coordination Centre Local domain queries A? svr004.network.local. http://www.ripe.net

  21. RIPE Network Coordination Centre Invalid TLD queries A? Maschult1.Speedport_W_700V. http://www.ripe.net

  22. RIPE Network Coordination Centre Same query IDs queries id 5134, A? www.google.com. id 5134, A? www.os3.nl. http://www.ripe.net

  23. RIPE Network Coordination Centre Repeated queries IP x.y.96.200 A? www.os3.nl. IP x.y.96.200 A? www.os3.nl. IP x.y.96.200 A? www.os3.nl. IP x.y.96.200 A? www.os3.nl. http://www.ripe.net

  24. RIPE Network Coordination Centre TLD not cached queries IP x.y.96.200 A? www.os3.nl. IP x.y.96.200 A? www.google.nl. http://www.ripe.net

  25. RIPE Network Coordination Centre Research ● Determine bogus categories ● Filter capture data ● Statistics ● Determine possible causes ● Determine possible solutions http://www.ripe.net

  26. RIPE Network Coordination Centre Research ● Determine bogus categories ● Filter capture data ● Statistics ● Determine possible causes ● Determine possible solutions http://www.ripe.net

  27. RIPE Network Coordination Centre Research: Filter capture data http://www.ripe.net

  28. RIPE Network Coordination Centre Research: Filter capture data 17:10:34.283465 A? A-1FREEMAN.COM.INBOUND10.MXLOGIC.NET. 17:10:34.933914 A? A-1FREEMAN.COM.INBOUND10.MXLOGIC.NET. 17:10:35.203961 A? A-1FREEMAN.COM.INBOUND10.MXLOGIC.NET. 17:10:35.498391 A? A-1FREEMAN.COM.INBOUND10.MXLOGIC.NET. 17:10:34.283465 A? A-1FREEMAN.COM.INBOUND10.MXLOGIC.NET. http://www.ripe.net

  29. RIPE Network Coordination Centre Research ● Determine bogus categories ● Filter capture data ● Statistics ● Determine possible causes ● Determine possible solutions http://www.ripe.net

  30. RIPE Network Coordination Centre Research ● Determine bogus categories ● Filter capture data ● Statistics ● Determine possible causes ● Determine possible solutions http://www.ripe.net

  31. RIPE Network Coordination Centre Research: Statistics http://www.ripe.net

  32. RIPE Network Coordination Centre Research: Statistics http://www.ripe.net

  33. RIPE Network Coordination Centre Research: Statistics http://www.ripe.net

  34. RIPE Network Coordination Centre Research ● Determine bogus categories ● Filter capture data ● Statistics ● Determine possible causes ● Determine possible solutions http://www.ripe.net

  35. RIPE Network Coordination Centre Research ● Determine bogus categories ● Filter capture data ● Statistics ● Determine possible causes ● Determine possible solutions http://www.ripe.net

  36. RIPE Network Coordination Centre Research: Causes ● Software bugs • A for A, Private IP reverse ● Not updated software • A for A ● Misconfigured software • Private IP reverse, TLD not cached ● Firewalls • Repeated http://www.ripe.net

  37. RIPE Network Coordination Centre Research ● Determine bogus categories ● Filter capture data ● Statistics ● Determine possible causes ● Determine possible solutions http://www.ripe.net

  38. RIPE Network Coordination Centre Research ● Determine bogus categories ● Filter capture data ● Statistics ● Determine possible causes ● Determine possible solutions http://www.ripe.net

  39. RIPE Network Coordination Centre Research: Solutions “Client” side: ● Install and use stable software ● Update software ● Configure software appropriatly http://www.ripe.net

  40. RIPE Network Coordination Centre Research: Solutions “Server” side: ● Access lists ● u(RPF) ● Contact software vendors ● Contact the owners of “big” sources ● Add additional servers http://www.ripe.net

  41. RIPE Network Coordination Centre Agenda ● Organisation ● Project introduction ● Research ● Conclusion ● Questions http://www.ripe.net

  42. RIPE Network Coordination Centre Agenda ● Organisation ● Project introduction ● Research ● Conclusion ● Questions http://www.ripe.net

  43. RIPE Network Coordination Centre Conclusion Statistics: ● Total % of bogus: AMS-IX: 80.70% NAP: 14.65% ● Top 10 IP addresses responsible: AMS-IX: 10.75% NAP: 42.40% ● Sources: 3 or 4 octets? http://www.ripe.net

  44. RIPE Network Coordination Centre Conclusion Solutions: ● Contact software vendors ● Contact owners big sources ● Add additional servers http://www.ripe.net

  45. RIPE Network Coordination Centre Agenda ● Organisation ● Project introduction ● Research ● Conclusion ● Questions http://www.ripe.net

  46. RIPE Network Coordination Centre Agenda ● Organisation ● Project introduction ● Research ● Conclusion ● Questions http://www.ripe.net

  47. RIPE Network Coordination Centre Questions? http://www.ripe.net

Download Presentation
Download Policy: The content available on the website is offered to you 'AS IS' for your personal information and use only. It cannot be commercialized, licensed, or distributed on other websites without prior consent from the author. To download a presentation, simply click this link. If you encounter any difficulties during the download process, it's possible that the publisher has removed the file from their server.

Recommend


More recommend