Proceedings of the Applied Networking Research Workshop 2020
DOI: 10.1145/3404868.3406668
|View full text |Cite
|
Sign up to set email alerts
|

Inferring the Deployment of Inbound Source Address Validation Using DNS Resolvers

Abstract: This paper reports on the first Internet-wide active measurement study to enumerate networks not filtering incoming packets based on their source address. Our method identifies closed and open DNS resolvers handling requests from the outside of the network with the source address in the prefix of the tested network. The study gives the most complete picture of the inbound Source Address Validation deployment at network providers: 32,673 IPv4 ASes and 197,641 IPv4 BGP prefixes are vulnerable to spoofing of inbo… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
1
1
1

Citation Types

0
2
0

Year Published

2021
2021
2023
2023

Publication Types

Select...
4
2

Relationship

3
3

Authors

Journals

citations
Cited by 6 publications
(3 citation statements)
references
References 8 publications
0
2
0
Order By: Relevance
“…This method allows for fast scanning with pre-built DNS queries and also limits the traffic at our authoritative nameserver since forwarders using the same resolver will return a cached entry. The relation between forwarders and resolvers has been measured before, but the previous methodologies [6,25,56] embed the IP address of each target into the subdomain. This embedding requires the analysis of queries at the authoritative nameserver, which impedes reproducibility.…”
Section: Cache Snooping To Check Name Popularitymentioning
confidence: 99%
“…This method allows for fast scanning with pre-built DNS queries and also limits the traffic at our authoritative nameserver since forwarders using the same resolver will return a cached entry. The relation between forwarders and resolvers has been measured before, but the previous methodologies [6,25,56] embed the IP address of each target into the subdomain. This embedding requires the analysis of queries at the authoritative nameserver, which impedes reproducibility.…”
Section: Cache Snooping To Check Name Popularitymentioning
confidence: 99%
“…Open DNS resolvers also received substantial attention from the research community. In 2015, Kührer et al [46] enumerated more than 26 million open IPv4 resolvers but the collective remediation efforts decreased this number to several million by 2021-2022 [43], [44], [56], [58], [60], [78]. Hendriks et al [28] specifically focused on the IPv6 address space and discovered 1,038 IPv6 resolvers by traversal from IPv4-only to IPv6-only zones.…”
Section: Related Workmentioning
confidence: 99%
“…It happens when SAV for incoming traffic drops the packet from the outside with the source IP belonging to the inner network. However, recent work showed that inbound SAV is not widely deployed [25,12,23,24].…”
Section: Threat Modelmentioning
confidence: 99%