DNS-over-TCP considered vulnerable

5Citations
Citations of this article
6Readers
Mendeley users who have this article in their library.
Get full text

Abstract

The research and operational communities believe that TCP provides protection against IP fragmentation attacks and recommend that servers avoid sending DNS responses over UDP but use TCP instead. In this work we show that IP fragmentation attacks also apply to servers that communicate over TCP. Our measurements indicate that in the 100K-top Alexa domains there are 393 additional domains whose nameservers can be forced to (source) fragment IP packets that contain TCP segments. In contrast, responses from these domains cannot be forced to fragment when sent over UDP. Our study not only shows that the recommendation to use TCP instead of UDP in order to avoid attacks that exploit fragmentation is risky, but it also unveils that the attack surface due to fragmentation is larger than was previously believed. We evaluate IP fragmentation-based DNS cache poisoning attacks against DNS responses over TCP.

Cite

CITATION STYLE

APA

Dai, T., Shulman, H., & Waidner, M. (2021). DNS-over-TCP considered vulnerable. In ANRW 2021 - Proceedings of the 2021 Applied Networking Research Workshop (pp. 76–81). Association for Computing Machinery, Inc. https://doi.org/10.1145/3472305.3472884

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free