דילוג לניווט ראשי דילוג לחיפוש דילוג לתוכן הראשי

POPS: From History to Mitigation of DNS Cache Poisoning Attacks

פרסום מחקרי: פרק בספר / בדוח / בכנספרסום בספר כנסביקורת עמיתים

2 ציטוטים ‏(Scopus)

תקציר

We present a novel yet simple and comprehensive DNS cache POisoning Prevention System (POPS), designed to integrate as a module in Intrusion Prevention Systems (IPS). POPS addresses statistical DNS poisoning attacks-documented from 2002 to the present-and offers robust protection against similar future threats. It comprises a detection module, which employs three simple rules, and a mitigation module that leverages the TC flag in the DNS header to enhance security. Once activated, the mitigation module has zero false positives or negatives, correcting any such errors on the side of the detection module. Thus, the detection module is allowed to err on the false positive side while minimizing false negatives. We first analyze POPS against historical DNS services and attacks, showing that it would have mitigated all network-based statistical poisoning attacks. We then simulate POPS on traffic benchmarks (PCAPs) incorporating current potential network-based statistical poisoning attacks, and benign PCAPs; the simulated attacks still succeed with a probability of 0.0076%. This occurs because five malicious packets go through before POPS detects the attack and activates the mitigation module. In addition, POPS completes its task using only 20%-50% of the time required by other tools (e.g., Suricata or Snort), and after examining just 5%-10% as many packets. It successfully detects DNS cache poisoning attacks-including fragmentation-based variants-that Suricata and Snort consistently miss, highlighting POPS’s superiority.

שפה מקוריתאנגלית
כותר פרסום המארחProceedings of the 34th USENIX Security Symposium
עמודים3537-3556
מספר עמודים20
מסת"ב (אלקטרוני)9781939133526
סטטוס פרסוםפורסם - 2025
אירוע34th USENIX Security Symposium, USENIX Security 2025 - Seattle, ארצות הברית
משך הזמן: 13 אוג׳ 202515 אוג׳ 2025

סדרות פרסומים

שםProceedings of the 34th USENIX Security Symposium

כנס

כנס34th USENIX Security Symposium, USENIX Security 2025
מדינה/אזורארצות הברית
עירSeattle
תקופה13/08/2515/08/25

טביעת אצבע

להלן מוצגים תחומי המחקר של הפרסום 'POPS: From History to Mitigation of DNS Cache Poisoning Attacks'. יחד הם יוצרים טביעת אצבע ייחודית.

פורמט ציטוט ביבליוגרפי