120 likes | 285 Views
Corrupted DNS Resolution Paths: The Rise of a Malicious Resolution Authority. Reporter: Jing Chiu Adviser: Yuh-Jye Lee. Reference. Corrupted DNS Resolution Paths: The Rise of a Malicious Resolution Authority Authors: David Dagon, Niels Provos, Christopher P. Lee, and Wenke Lee.
E N D
Corrupted DNS Resolution Paths: The Rise of a Malicious Resolution Authority Reporter: Jing Chiu Adviser: Yuh-Jye Lee Data Mining & Machine Learning Lab
Reference • Corrupted DNS Resolution Paths: The Rise of a Malicious Resolution Authority • Authors: David Dagon, Niels Provos, Christopher P. Lee, and Wenke Lee. • Conference: Network and Distributed Security Symposium (NDSS )2008. Data Mining & Machine Learning Lab
Outline • Introduction • Methodology • Analysis • Conclusion Data Mining & Machine Learning Lab
Introduction • DNS resolution path corruption • Rogue DNS service Data Mining & Machine Learning Lab
Methodology • Organizing IPv4 into a series of classful addresses • Using bogons list published by Team Cymru • Exclude U.S. Military and U.S. government • Design Query Pattern • Blowfish(IP).parentzone.example.com • Select 600,000 resolvers • 200,000 uniformly randomly from all resolvers • 200,000 from resolvers overlapped with contacting Google • 200,000 from IP addresses known infected by Storm bot • Ask these resolvers to resolve 84 different domains during 4 days Data Mining & Machine Learning Lab
Methodology (cont.) Data Mining & Machine Learning Lab
Analysis • Open resolvers found • 10.4 million – late August 2007 • 10.5 million – early September 2007 • Union of two sets: 17,365,759 • 634,941 – January 2006 Data Mining & Machine Learning Lab
Analysis (cont) Data Mining & Machine Learning Lab
Analysis (cont.) Data Mining & Machine Learning Lab
Analysis Data Mining & Machine Learning Lab
Conclusion • DNSSEC • DNS with authority • Blocking • Block the remote DNS traffic • Recovery • After blocking or take down the Rogue DNS? Data Mining & Machine Learning Lab
Thanks for attension • Questions? Data Mining & Machine Learning Lab