Transparent Forwarders: An Unnoticed Component of the Open DNS Infrastructure
arXiv:2110.02224 · doi:10.1145/3485983.3494872
Abstract
In this paper, we revisit the open DNS (ODNS) infrastructure and, for the first time, systematically measure and analyze transparent forwarders, DNS components that transparently relay between stub resolvers and recursive resolvers. Our key findings include four takeaways. First, transparent forwarders contribute 26% (563k) to the current ODNS infrastructure. Unfortunately, common periodic scanning campaigns such as Shadowserver do not capture transparent forwarders and thus underestimate the current threat potential of the ODNS. Second, we find an increased deployment of transparent forwarders in Asia and South America. In India alone, the ODNS consists of 80% transparent forwarders. Third, many transparent forwarders relay to a few selected public resolvers such as Google and Cloudflare, which confirms a consolidation trend of DNS stakeholders. Finally, we introduce DNSRoute++, a new traceroute approach to understand the network infrastructure connecting transparent forwarders and resolvers.
Proc. of ACM CoNEXT'21, camera-ready
References in corpus (2)
Cited by in corpus (4)
- The Far Side of DNS Amplification: Tracing the DDoS Attack Ecosystem from the Internet Core
- The Age of DDoScovery: An Empirical Comparison of Industry and Academic DDoS Assessments
- SoK: A Data-driven View on Methods to Detect Reflective Amplification DDoS Attacks Using Honeypots
- Forward to Hell? On the Potentials of Misusing Transparent DNS Forwarders in Reflective Amplification Attacks