bk99.de entertain the web since 1997

DNS dampening: Slowing attacks, keeping resolvers alive

Summary

Lutz Donnerhacke tests DNS dampening under real load and shows how measurements refute several dangerous assumptions in the first draft. An internal check script produced around 40,000 legitimate queries within minutes. Attacks were detected and blocked after about 40 packets.

Ideas

  • Dampening collects penalty points and temporarily suppresses conspicuous DNS queries.
  • Early publication uncovers concept and memory errors more quickly.
  • Internal consistency tests can mistakenly look like attack traffic.
  • Local networks need exceptions as long as source address spoofing is ruled out there.
  • Penalty points must decay over time instead of growing exponentially.
  • Fixed resource limits prevent self-overload when attack detection goes wrong.

Insights

  • Without production data, defence logic easily becomes an availability problem itself.
  • Good telemetry separates harmful repetition from legitimate peaks.
  • A failed algorithm can still produce valuable load tests.

Quotes

  • Release often, release early – Lutz Donnerhacke

Habits

  • Donnerhacke extends the instrumentation as soon as measurements show inexplicable effects.

Facts

  • The experiment modified BIND 9.9.1-P3 directly in the query path.

References

Critique

  • The experimental patch does not yet have mature configuration or ACL management.
  • Shared resolvers can be blocked completely by mistake through source-based scoring.

Remarks

  • The article documents mistakes as openly as the later improvements.
  • The specific query types reflect the DNS ecosystem of 2012.

Recommendations

  • Test adaptive defences in observation mode first instead of suppressing immediately.
  • Score at least by source, destination and query type separately.
  • Define hard memory limits and automatic release times.

Read the original article

Search the Web Archive