Skip to main navigation Skip to search Skip to main content

Adaptive deterrence of DNS cache poisoning

  • Sze Yiu Chau
  • , Omar Chowdhury
  • , Victor Gonsalves
  • , Huangyi Ge
  • , Weining Yang
  • , Sonia Fahmy
  • , Ninghui Li
  • Purdue University
  • Alphabet Inc.

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

8 Scopus citations

Abstract

Many long-lived network protocols were not designed with adversarial environments in mind; security is often an afterthought. Developing security mechanisms for protecting such systems is often very challenging as they are required to maintain compatibility with existing implementations, minimize deployment cost and performance overhead. The Domain Name System (DNS) is one such noteworthy example; the lack of source authentication has made DNS susceptible to cache poisoning. Existing countermeasures often suffer from at least one of the following limitations: insufficient protection; modest deployment; complex configuration; dependent on domain owners’ participation. We propose CGuard which is an adaptive defense framework for caching DNS resolvers: CGuard actively tries to detect cache poisoning attempts and protect the cache entries under attack by only updating them through available high confidence channels. CGuard’s effective defense is immediately deployable by the caching resolvers without having to rely on domain owners’ assistance and is compatible with existing and future solutions. We have empirically demonstrated the efficacy of CGuard. We envision that by taking away the attacker’s incentive to launch DNS cache poisoning attacks, CGuard essentially turns the existence of high confidence channels into a deterrence. Deterrence-based defense mechanisms can be applicable to other systems beyond DNS.

Original languageEnglish
Title of host publicationSecurity and Privacy in Communication Networks - 14th International Conference, SecureComm 2018, Proceedings
EditorsBing Chang, Yingjiu Li, Raheem Beyah, Sencun Zhu
PublisherSpringer Verlag
Pages171-191
Number of pages21
ISBN (Print)9783030017033
DOIs
StatePublished - 2018
Event14th International EAI Conference on Security and Privacy in Communication Networks, SecureComm 2018 - Singapore, Singapore
Duration: Aug 8 2018Aug 10 2018

Publication series

NameLecture Notes of the Institute for Computer Sciences, Social-Informatics and Telecommunications Engineering, LNICST
Volume255
ISSN (Print)1867-8211

Conference

Conference14th International EAI Conference on Security and Privacy in Communication Networks, SecureComm 2018
Country/TerritorySingapore
CitySingapore
Period08/8/1808/10/18

Fingerprint

Dive into the research topics of 'Adaptive deterrence of DNS cache poisoning'. Together they form a unique fingerprint.

Cite this