Detection of DNS Cache Poisoning Attack in DNS Standard Resolution Traffic

Yasuo Musashi, Kazuya Takemori, Kubota Shinichiro, Kenichi Sugitani · 研究報告コンピュータセキュリティ(CSEC) · 2011

We statistically investigated the total A resource record (RR) based DNS query request packet traffic from the Internet to the top domain DNS server in a university campus network through January 1st to December 31st, 2010. The obtained results are: (1) We found five DNS Cache Poisoning (DNSCP) attacks in observation of rapid decrease in the unique source IP address based entropy of the DNS query packet traffic and significant increase in the unique DNS query keyword based one. (2) Also, we found five DNSCP attacks in the score changes for detection method using the calculated restricted Damerau-Levenshtein distance (restricted edit distance) between the observed query keyword and the last one by employing both threshold ranges through 1 to 40. Therefore, it is possible that the restricted Damerau-Levenshtein distance based detection technology can detect the DNSCP attacks.

Read the paper · More papers on PaperTik