当前位置:首页 > 报告详情

互联网如何躲过一劫:KeyTrap 针对 DNSSEC 的拒绝服务攻击.pdf

上传人: 竿*** 编号:981587 2025-11-29 73页 4.24MB

1、#BHEU BlackHatEventsHowHow thethe Internet Internet DodgedDodged a Bullet:The a Bullet:The KeyTrapKeyTrapDenialDenial-ofof-Service Service AttacksAttacks againstagainst DNSSECDNSSECSpeaker(s):Elias Heftrig,Niklas VogelContributors:Haya Schulmann,Michael Waidner#BHEU BlackHatEventsRefresher:DNS and D

2、NSSEC#BHEU BlackHatEventsInformation Classification:GeneralWhy is it always DNS?#BHEU BlackHatEventsInformation Classification:GeneralWhy is it always DNS?DNSHTTPSSMTPFTPVoIPVPNNTPSignal.#BHEU BlackHatEventsInformation Classification:General.ing.bank.ing.www.bank.ing.IN A?bank.ing.IN NS ns.bank.ing.

3、12345678www.bank.ing.IN A 1.2.3.4DNS Resolution#BHEU BlackHatEventsInformation Classification:General.ing.bank.ing.www.bank.ing.IN A 6.6.6.6 Attack on DNS Record AuthenticityDNS Poisoningwww.bank.ing.IN A?www.bank.ing.IN A 6.6.6.6#BHEU BlackHatEventsInformation Classification:General.ing.bank.ing.At

4、tack preventedDNSSEC to the Rescue!Xwww.bank.ing.IN A?www.bank.ing.IN A 1.2.3.4www.bank.ing.IN A 6.6.6.6#BHEU BlackHatEventsInformation Classification:GeneralDNSSEC Adoption on the InternetAdoption in domains is dragging#BHEU BlackHatEventsInformation Classification:GeneralDNSSEC Adoption on the Int

5、ernetBetter adoption in Resolvers#BHEU BlackHatEventsInformation Classification:GeneralHow DNSSEC Validation WorksWhat is the IP Address ofwww.ietf.org?$dig www.ietf.org-t A+dnssec#BHEU BlackHatEventsInformation Classification:GeneralHow DNSSEC Validation WorksWhat is the IP Address ofwww.ietf.org?$

6、dig www.ietf.org-t A+dnssec;ANSWER SECTION:www.ietf.org.300 IN A 104.16.45.99www.ietf.org.300 IN A 104.16.44.99www.ietf.org.300 IN RRSIG A 13 3 300 20241211 20241209 34505 ietf.org.eSTHK9qluvSgBA=#BHEU BlackHatEventsInformation Classification:GeneralHow DNSSEC Validation WorksWhat is the IP Address

word格式文档无特别注明外均可编辑修改,预览文件经过压缩,下载原文更清晰!
三个皮匠报告文库所有资源均是客户上传分享,仅供网友学习交流,未经上传用户书面授权,请勿作商用。
根据报告的内容,以下是全文关键点的概括: 1. **DNSSEC攻击**:DNSSEC(域名系统安全扩展)旨在保护DNS查询免受篡改,但存在安全漏洞,称为KeyTrap攻击。 2. **攻击原理**:通过生成大量具有相同标签的DNSKEY和RRSIG记录,攻击者可以耗尽解析器的资源,导致拒绝服务(DoS)。 3. **攻击影响**:所有测试的DNSSEC解析器都易受攻击,包括Unbound、Bind9、Knot、Akamai、PowerDNS、Windows Server、Stubby和Cloudflare。 4. **攻击效果**:一次攻击可能导致解析器停滞长达1014秒。 5. **防御措施**:需要修复DNSSEC解析器中的漏洞,并考虑资源消耗对实现的影响。 6. **修复时间**:修复KeyTrap攻击漏洞涉及超过30人,耗时3个月。
揭秘KeyTrap攻击!" "DNSSEC如何应对KeyTrap攻击?揭秘防御策略!" "DNSSEC验证器面临重大威胁,KeyTrap攻击解析!"
客服
商务合作
小程序
服务号
折叠