Detecting DNS Amplification Attacks

11 years 8 months ago
Detecting DNS Amplification Attacks
DNS amplification attacks massively exploit open recursive DNS servers mainly for performing bandwidth consumption DDoS attacks. The amplification effect lies in the fact that DNS response messages may be substantially larger than DNS query messages. In this paper, we present and evaluate a novel and practical method that is able to distinguish between authentic and bogus DNS replies. The proposed scheme can effectively protect local DNS servers acting both proactively and reactively. Our analysis and the corresponding real-usage experimental results demonstrate that the proposed scheme offers a flexible, robust and effective solution.
Georgios Kambourakis, Tassos Moschos, Dimitris Gen
Added 26 Oct 2010
Updated 26 Oct 2010
Type Conference
Year 2007
Authors Georgios Kambourakis, Tassos Moschos, Dimitris Geneiatakis, Stefanos Gritzalis
Comments (0)