Skip to main navigation Skip to search Skip to main content

Preventing DNS amplification attacks using the history of DNS queries with SDN

  • Sungkyunkwan University

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Domain Name System (DNS) amplification attack is a sophisticated Distributed Denial of Service (DDoS) attack by sending a huge volume of DNS name lookup requests to open DNS servers with the source address spoofed as a victim host. However, from the point of view of an individual network resource such as DNS server and switch, it is not easy to mitigate such attacks because a distributed attack could be performed with multiple DNS servers and/or switches. To overcome this limitation, we propose a novel security framework using Software-Defined Networking (SDN) to store the history of DNS queries as an evidence to distinguish normal DNS responses from attack packets. Our evaluation results demonstrate that the network traffic for DNS amplification attack can completely be blocked under various network conditions without incurring a significant communication overhead.

Original languageEnglish
Title of host publicationComputer Security – ESORICS 2017 - 22nd European Symposium on Research in Computer Security, Proceedings
EditorsSimon N. Foley, Dieter Gollmann, Einar Snekkenes
PublisherSpringer Verlag
Pages135-152
Number of pages18
ISBN (Print)9783319663982
DOIs
StatePublished - 2017
Event22nd European Symposium on Research in Computer Security, ESORICS 2017 - Oslo, Norway
Duration: 11 Sep 201715 Sep 2017

Publication series

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume10493 LNCS
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference22nd European Symposium on Research in Computer Security, ESORICS 2017
Country/TerritoryNorway
CityOslo
Period11/09/1715/09/17

Keywords

  • Distributed Denial of Service (DDoS)
  • DNS amplification attack
  • Domain Name System (DNS)
  • Software-Defined Networking (SDN)

Fingerprint

Dive into the research topics of 'Preventing DNS amplification attacks using the history of DNS queries with SDN'. Together they form a unique fingerprint.

Cite this