[Dshield] DNS Amplification Attacks

Johannes B. Ullrich jullrich at sans.org
Fri Mar 17 23:33:06 GMT 2006


-----BEGIN PGP SIGNED MESSAGE-----
Hash: RIPEMD160


Gadi Evron asked me to forward this note about a paper Randy Vaughn
published with him about the DNS Aplilification Attacks. Lots of details
for the packet heads among us.

- -----------


In this paper we address in detail how the recent DNS DDoS attacks work.
How they abuse name servers, EDNS, the recursive feature and UDP packet
spoofing, as well as how the amplification effect works.

Our study is based on packet captures (we provide with samples) and logs
from attacks on different networks reported to have a volume of 2.8Gbps.
One of these networks indicated some attacks have reached as high as
10Gbps and used as many as 140,000 exploited name servers.

In the conclusions we also discuss some remediation suggestions.

Given recent events, we have been encouraged to make this text available
at this time.

URL: http://www.isotf.org/news/DNS-Amplification-Attacks.pdf

Please note that this version of this paper is prior to submission for
publication and that the final version may see significant revisions.

Thanks,

Randy Vaughn and Gadi Evron.

- --

- -------------------
Johannes B. Ullrich, Ph.D
Chief Research Officer
SANS Institute
http://isc.sans.org
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.1 (Darwin)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD8DBQFEG0cePNuXYcm/v/0RAyozAJ92c3BCzEB1oHy7HnfTdFXjf+4SfwCfRqZk
vshL4nrGX1xmI9Cf7GWqq8o=
=PDWt
-----END PGP SIGNATURE-----


More information about the list mailing list