A Multi-Path Approach to Protect DNS Against DDoS Attacks

被引:0
|
作者
Alouneh S. [1 ,2 ]
机构
[1] German Jordanian University, Amman
[2] Al Ain University, Abu Dhabi
来源
Journal of Cyber Security and Mobility | 2023年 / 12卷 / 04期
关键词
DNS; DoS; MPLS; multipath routing; security;
D O I
10.13052/jcsm2245-1439.1246
中图分类号
学科分类号
摘要
Domain Name System (DNS) is considered a vital service for the internet and networks operations, and practically this service is configured and accessible across networks’ firewall. Therefore, attackers take advantage of this open configuration to attack a network’s DNS server in order to use it as a reflector to achieve Denial of Service (DoS) attacks. Most of protection methods such as intrusion prevention and detection systems use blended tactics such as blocked-lists for suspicious sources, and thresholds for traffic volumes to detect and defend against DoS flooding attacks. However, these protection methods are not often successful. In this paper, we propose a new method to sense and protect DNS systems from DoS and Distributed DoS (DDoS) attacks. The main idea in our approach is to distribute the DNS request mapping into more than one DNS resolver such that an attack on one server should not affect the entire DNS services. Our approach uses the Multi-Protocol Label Switching (MPLS) along with multi-path routing to achieve this goal. Also, we use threshold secret sharing to code the distributed DNS requests. Our findings and results show that this approach performs better when compared with the traditional DNS structure. © 2023 River Publishers.
引用
收藏
页码:569 / 588
页数:19
相关论文
共 50 条
  • [1] An Approach of DNS Protection Against DDoS Attacks
    Georgiev, Ivan
    Nikolova, Kamelia
    2017 13TH INTERNATIONAL CONFERENCE ON ADVANCED TECHNOLOGIES, SYSTEMS AND SERVICES IN TELECOMMUNICATIONS (TELSIKS), 2017, : 140 - 143
  • [2] A Packet Marking Approach To Protect Cloud Environment Against DDoS Attacks
    Anitha, E.
    Malliga, S.
    2013 INTERNATIONAL CONFERENCE ON INFORMATION COMMUNICATION AND EMBEDDED SYSTEMS (ICICES), 2013, : 367 - 370
  • [3] A Distributed Mechanism to Protect Against DDoS Attacks
    Mosharraf, Negar
    Jayasumana, Anura P.
    Ray, Indrakshi
    DATA AND APPLICATIONS SECURITY AND PRIVACY XXXI, DBSEC 2017, 2017, 10359 : 529 - 540
  • [4] Resilience Evaluation of Multi-Path Routing against Network Attacks and Failures
    An, Hyok
    Na, Yoonjong
    Lee, Heejo
    Perrig, Adrian
    ELECTRONICS, 2021, 10 (11)
  • [5] DoubleCheck: Multi-path Verification Against Man-in-the-Middle Attacks
    Alicherry, Mansoor
    Keromytis, Angelos D.
    ISCC: 2009 IEEE SYMPOSIUM ON COMPUTERS AND COMMUNICATIONS, VOLS 1 AND 2, 2009, : 556 - 562
  • [6] An Overview of DDoS attacks based on DNS
    Alieyan, Kamal
    Kadhum, Mohammed M.
    Anbar, Mohammed
    Ul Rehman, Shafiq
    Alajmi, Naser K. A.
    2016 INTERNATIONAL CONFERENCE ON INFORMATION AND COMMUNICATION TECHNOLOGY CONVERGENCE (ICTC 2016): TOWARDS SMARTER HYPER-CONNECTED WORLD, 2016, : 276 - 280
  • [7] Dynamic countermeasures selection for multi-path attacks
    Li, Fenghua
    Li, Yongjun
    Leng, Siyuan
    Guo, Yunchuan
    Geng, Kui
    Wang, Zhen
    Fang, Liang
    COMPUTERS & SECURITY, 2020, 97
  • [8] Defending against spoofed DDoS attacks with path fingerprint
    Lee, FY
    Shieh, S
    COMPUTERS & SECURITY, 2005, 24 (07) : 571 - 586
  • [9] The Management of Path Identifier Scheme against DDoS Attacks
    Zheng, Jun
    Jin, Guang
    Jiang, Xianliang
    Xie, Zhijun
    2ND INTERNATIONAL SYMPOSIUM ON COMPUTER NETWORK AND MULTIMEDIA TECHNOLOGY (CNMT 2010), VOLS 1 AND 2, 2010, : 85 - 88
  • [10] Capability-Based Defenses Against DoS Attacks in Multi-path MANET Communications
    Quan Jia
    Kun Sun
    Angelos Stavrou
    Wireless Personal Communications, 2013, 73 : 127 - 148