Protocol Fixes for KeyTrap Vulnerabilities

Elias Heftrig, Haya Schulmann, Niklas Vogel, Michael Waidner · 2024

The security and availability of DNS are of major concern for many critical Internet services. Recently, KeyTrap algorithmic complexity Denial of Service attacks were demonstrated against DNSSEC-validating DNS resolvers [6]. The attacks exploit the validation complexity in DNSSEC to stall DNS resolvers, some for as long as 16h with just a single DNS response. Although short term patches were immediately implemented by the vendors, the attack can still produce a heavy load in some patched DNS resolvers.

Read the paper · More papers on PaperTik