• DocumentCode
    2243148
  • Title

    A cache-splitting scheme for DNS recursive server

  • Author

    Zhiwei Yan ; Anlei Hu ; Wei Wang

  • Author_Institution
    Comput. Network Inf. Center, China Internet Network Inf. Center, Beijing, China
  • fYear
    2012
  • fDate
    Oct. 30 2012-Nov. 1 2012
  • Firstpage
    1267
  • Lastpage
    1271
  • Abstract
    Domain Name System (DNS) cache poisoning is a kind of computer hacking attack, whereby data are introduced into a DNS name server´s cache database, causing the name server to return an incorrect IP address, diverting traffic to another computer (often controlled by the attacker). In this paper, a novel scheme is proposed in order to make the recursive server more intelligent to handle the cache poisoning attacks. The cache-splitting is adopted in the proposed scheme, in which the credible cache is used to maintain the trustful answers while the incredible cache is used to temporarily maintain the suspicious responses. After the possible attack disappears, the recursive server will resolute the names contained in the incredible cache once again and cache the new answers into the credible cache as usual. The analyzing results show that the recursive serer can handle the responses according to the actual conditions and make use of the caching to optimize the DNS resolutions at the same time.
  • Keywords
    IP networks; Internet; cache storage; computer network security; DNS cache poisoning; DNS recursive server; cache database; cache splitting scheme; computer hacking attack; domain name system; incorrect IP address; Computer crime; Computers; IP networks; Internet; Peer-to-peer computing; Servers; DNS; cache poisoning;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Cloud Computing and Intelligent Systems (CCIS), 2012 IEEE 2nd International Conference on
  • Conference_Location
    Hangzhou
  • Print_ISBN
    978-1-4673-1855-6
  • Type

    conf

  • DOI
    10.1109/CCIS.2012.6664588
  • Filename
    6664588