Security and Stability Advisory Committee (SSAC)

The SSAC is a volunteer group of specialists in the technical security field that provides advice and insight to the ICANN community and the Board.

Contenido disponible solo en los siguientes idiomas

  • English

SAC065 | Executive Summary for SSAC Advisory on DDoS Attacks Leveraging DNS Infrastructure

[PDF, 422.97 KB]

This advisory explores several unresolved critical design and deployment issues that have enabled increasingly large and severe Distributed Denial of Service (DDoS) attacks using the DNS. The report also makes recommendations for DNS and network operators to mitigate large-scale DDoS attacks leveraging DNS infrastructure.

Distributed Denial of Service (DDoS) attacks cause both service outages for attack targets and collateral damage to other systems. In these types of attacks, malicious actors generate queries using an IP address forged to appear as the victim’s, impacting both authoritative and open recursive DNS servers. The result is a potentially massive DDoS attack that is difficult or impossible for a victim to mitigate. These types of attacks can lead to significant or total service outages for victims, as well as collateral damage to other systems. The scale of these attacks will continue to grow and requires urgent action to mitigate this problem.

Recommendations

  • Recommendation 1: ICANN should help facilitate an Internet-wide community effort to reduce the number of open resolvers and networks that allow network spoofing.
  • Recommendation 2: All types of network operators should take immediate steps to prevent network address spoofing.
  • Recommendation 3: Recursive DNS server operators should take immediate steps to secure open recursive DNS servers.
  • Recommendation 4: Authoritative DNS server operators should investigate deploying authoritative response rate limiting.
  • Recommendation 5: DNS operators should put in place operational processes to ensure that their DNS software is regularly updated and communicate with their software vendors to keep abreast of latest developments.
  • Recommendation 6: Manufacturers and/or configurators of customer premise networking equipment, including home networking equipment, should take immediate steps to secure these devices and ensure that they are field upgradable when new software is available to fix security vulnerabilities, and aggressively replacing the installed base of non-upgradeable devices with upgradeable devices.