Cache Poisoning Defenses
2017
The primary attack vector for poisoning domain name system (DNS) cache consists of an attacker manipulating DNS responses by sending numerous answers to a given query with varying IP and DNS header parameters. A high volume of incoming DNS answers disproportionate to outgoing queries could indicate a cache poisoning attack. Upon detection of an attack, user should attempt to identify the source of the attack and if possible, block the sender. Antivirus and anti-malware defenses for end user devices can help reduce the incidence of known viruses and malware from instigating a cache poisoning attack against the recursive servers. The definitive solution to cache poisoning attacks requires the authentication of each DNS query answer as having been published by the authoritative domain owner. DNS security extensions (DNSSEC) specifications provide for query answer authentication as well as data integrity validation to assure no manipulation of query answers en route to the validating resolver.