• DocumentCode
    3688401
  • Title

    Reducing DNS cache poisoning attacks

  • Author

    Jayashree Mohan;Shruthi Puranik;K Chandrasekaran

  • Author_Institution
    Department of Computer Science and Engineering, National Institute of Technology, Karnataka, Surathkal, India
  • fYear
    2015
  • Firstpage
    1
  • Lastpage
    6
  • Abstract
    The increasing attacks on The Domain Name System (DNS) and the problems faced in deploying Domain Name System Security Extensions (DNSSEC) on a large scale, result in the need of a simple, and a practical approach to safeguard the DNS. In this paper, we present an efficient approach to significantly reduce the success rate of DNS cache poisoning attacks. The proposed Shift Key(S-Key) based domain name encoding scheme considerably raises the entropy of the DNS packet by encoding the domain name, using the randomly generated 4 bit S-Keys. To successfully poison a DNS cache, the attacker must now guess the 4 bit S-key as well as the encoded domain name, in addition to the port number and the transaction ID. The Bi-Query scheme captures the malicious reply packets by initiating a re-query or pairing up two consecutive requests to resolve the same domain name, thereby validating the Internet Protocol (IP) address retrieved for each domain name, before caching it. The first method proposed makes it difficult for the attacker to guess the DNS packet fields, while the latter detects and discards any packet that has been forged.
  • Keywords
    "Servers","IP networks","Electronic mail","Computer crime","Encoding","Arrays"
  • Publisher
    ieee
  • Conference_Titel
    Advanced Computing and Communication Systems, 2015 International Conference on
  • Type

    conf

  • DOI
    10.1109/ICACCS.2015.7324091
  • Filename
    7324091