2016
DOI: 10.1109/jsac.2016.2558918
|View full text |Cite
|
Sign up to set email alerts
|

A High-Performance, Scalable Infrastructure for Large-Scale Active DNS Measurements

Abstract: The domain name system (DNS) is a core component of the Internet. It performs the vital task of mapping human readable names into machine readable data (such as IP addresses, which hosts handle e-mail, and so on). The content of the DNS reveals a lot about the technical operations of a domain. Thus, studying the state of large parts of the DNS over time reveals valuable information about the evolution of the Internet. We collect a unique long-term data set with daily DNS measurements for all the domains under … Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
1

Citation Types

0
76
0

Year Published

2018
2018
2022
2022

Publication Types

Select...
5
3

Relationship

3
5

Authors

Journals

citations
Cited by 90 publications
(88 citation statements)
references
References 18 publications
0
76
0
Order By: Relevance
“…Based on previous considerations on the actual temporary loss of use of the victim IP address, in some cases even beyond the attack duration, we explore the impact blackholing may have on the availability of services by considering data from OpenINTEL 18 . OpenINTEL is an active DNS measurements platform [20] that measures daily snapshots of the DNS by querying all domain names under Top-Level Domains (TLDs) for their Resource Records (RRs). This includes IP addresses of: (i) www labels, (ii) mail exchanger (MX), and (iii) authoritative name servers (NS).…”
Section: Blackholed Attacksmentioning
confidence: 99%
See 2 more Smart Citations
“…Based on previous considerations on the actual temporary loss of use of the victim IP address, in some cases even beyond the attack duration, we explore the impact blackholing may have on the availability of services by considering data from OpenINTEL 18 . OpenINTEL is an active DNS measurements platform [20] that measures daily snapshots of the DNS by querying all domain names under Top-Level Domains (TLDs) for their Resource Records (RRs). This includes IP addresses of: (i) www labels, (ii) mail exchanger (MX), and (iii) authoritative name servers (NS).…”
Section: Blackholed Attacksmentioning
confidence: 99%
“…Of unique MX and NS names, 154 k (0.40% of 38.76 M) and 9994 (0.13% of 7.62 M) map to blackholed prefixes. 20 Infrastructure can be redundantly hosted, i.e., have multiple IP addresses. We investigate this by studying the presence of nonblackholed IP address records and find that, respectively, 87.4%, 98.0% and 98.6% of the names found (cf., ratio in Table 6) do not have an alternative IP address at the time of blackholing.…”
Section: Blackholed Attacksmentioning
confidence: 99%
See 1 more Smart Citation
“…We analysed the impact of domain names that have the terms stresser, booter or ddos in their composition, and are registered within .com, using a large-scale active DNS measurement dataset [95]. We found that of all 2,721 domains names in .com containing one of the three terms, only 61 domain names (less than 3%) are not related to booters.…”
Section: Tlds Operators Domain Registrars Web Hostingmentioning
confidence: 99%
“…To evaluate the potential impact of attacks using Web sites as a measure we need a historical mapping between IP addresses and Web sites hosted. To obtain this mapping we use active DNS measurement data from the OpenINTEL project[20,107].OpenINTEL is a large-scale, active DNS measurement platform that collects daily snapshots of the content of the DNS. It builds snapshots by structurally querying all the domain names under a full zone, i.e., Top-Level Domain (TLD), a set of Resource Records (RRs).…”
mentioning
confidence: 99%