skip to main content
10.1145/3603165.3607438acmotherconferencesArticle/Chapter ViewAbstractPublication Pagesacm-turcConference Proceedingsconference-collections
poster

Silence is not Golden: Disrupting the Load Balancing of Authoritative DNS Servers

Published:25 September 2023Publication History

ABSTRACT

We present a new attack, the Disablance, that disrupts the load balancing for authoritative DNS servers. We discovered a prevalent misconfiguration for nameservers and an implementation decision in mainstream DNS software that an adversary can leverage to divert legitimate DNS traffic to a targeted nameserver. Through a systematic evaluation, we confirmed that Disablance is realistic, efficient, and prevalent. In total, 22.24% of the top 1M FQDNs and 3.94% of the top 1M SLDs can be victims of Disablance. Besides, a number of stable open resolvers and several well-known public DNS service providers are also exploitable. Moving forward, we provided suggestions to mitigate the threat of Disablance and responsibly disclosed this issue to service providers. As of the time of writing this paper, several renowned vendors have taken action to fix it.

References

  1. Tianxiang Dai, Haya Shulman, and Michael Waidner. 2021. Let’s Downgrade Let’s Encrypt. In Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security(CCS ’21).Google ScholarGoogle ScholarDigital LibraryDigital Library
  2. Brij B Gupta and Omkar P Badve. 2017. Taxonomy of DoS and DDoS attacks and desirable defense mechanism in a cloud computing environment. Neural Computing and Applications (2017).Google ScholarGoogle Scholar
  3. Fenglu Zhang, Chaoyi Lu, Baojun Liu, Haixin Duan, and Ying Liu. 2022. Measuring the Practical Effect of DNS Root Server Instances: A China-Wide Case Study. In Passive and Active Measurement.Google ScholarGoogle Scholar

Recommendations

Comments

Login options

Check if you have access through your login credentials or your institution to get full access on this article.

Sign in
  • Published in

    cover image ACM Other conferences
    ACM TURC '23: Proceedings of the ACM Turing Award Celebration Conference - China 2023
    July 2023
    173 pages
    ISBN:9798400702334
    DOI:10.1145/3603165

    Copyright © 2023 Owner/Author

    Permission to make digital or hard copies of part or all of this work for personal or classroom use is granted without fee provided that copies are not made or distributed for profit or commercial advantage and that copies bear this notice and the full citation on the first page. Copyrights for third-party components of this work must be honored. For all other uses, contact the Owner/Author.

    Publisher

    Association for Computing Machinery

    New York, NY, United States

    Publication History

    • Published: 25 September 2023

    Check for updates

    Qualifiers

    • poster
    • Research
    • Refereed limited

PDF Format

View or Download as a PDF file.

PDF

eReader

View online with eReader.

eReader

HTML Format

View this article in HTML Format .

View HTML Format