IT Pro confession: I contributed to the DDOS attack against Spamhaus
theregister.co.uk
theregister.co.uk
This explanation is skipping a key component of a DNS reflection attack. When the attacker makes a DNS request, they spoof their source address so it is the address of the host they want to attack. Thus they send a small request to your DNS server, and your DNS server returns a large response not to them, but to the host they're attacking.
Couldn't you perform the same attack by querying a whole bunch of authoritative name servers for zones they serve with forged source addresses?
Also, you can definitely do this with authoritative servers only, which is why only egress filtering by ISPs is a permanent solution to the problem. However, there are way fewer authoritative DNS servers out there than there are open recursors and they are better managed. So an attack would never grow to the scale this one has grown to using only authoritative servers.
The attack works by sending a recursive DNS server a request with a spoofed source IP. Namely, you make the recursive DNS server think your target is making the request. While a typical DNS query consists of a 64byte UDP packet, a reply can be much much lengthier(it can go well over 1KB).
So say you have a botnet with a total bandwidth of 1Gb/s. Each request you make(64bytes) will result in, say, 1KB being sent by the DNS server to your target although the server thinks it is sending it to you. That results in a 16x amplification of the amount of data you are sending the target's way. So instead of flooding your target with 1Gb/s of data, you are flooding it with 16Gb/s of DNS replies.
The only permanent solution to this problem(though it is discussed elsewhere in this thread why this is impractical) is for all(or almost all) ISPs to have egress filtering. That is, that they would drop all packets sent from their networks with a source IP that is not on their networks. This would make it impossible to fool a recursive DNS server into sending the reply to the wrong IP.
Since this is very hard to do(ISPs have zero incentive to do egress filtering, and we can't even locate the ones from whose networks these attacks are originating to shame them into doing it) the pursued solution is the easier one of locating and closing publicly open DNS recursors. This would still allow DNS amplification attacks using authoritative servers, but they would be much more limited in scope.
So if I understand correctly, the problems with the DNS amplification attack using only authoritative nameservers are:
a) You have to keep track of which name to request from which server
b) You can't optimize for a particularly large response
c) Operators of authoritative name servers are likely to be more sophisticated and therefore have egress filtering.
d) There aren't as many authoritative nameservers as open recursive servers (?)
But since operators of authoritative name servers are more likely to be sophisticated they could notice an ongoing attack and throttle down the replies without negatively affect anything else. In fact, that protection could be built into the server code. Simply throttle consecutive replies to the same requester to a sane amount. There is no legitimate use-case where the same person would make a humongous amount of consecutive requests from an authoritative server as responses are usually cached. If that's done, an attacker wouldn't be able to coerce authoritative servers into flooding a target, they would just send replies at a slow rate(after an initial speedy response) and no significant amplification would occur.
As you state in d) there are a lot of open recursive servers out there that are unlikely to be updated or managed by someone sophisticated enough to respond to attacks like this. Whereas this is less likely with authoritative servers.
A normal A record lookup results in 1-2x amplification
$ dig www.ripe.net. in a | grep SIZE
;; MSG SIZE rcvd: 46
Asking for DNSSEC records specifically yields a 10x+ amplification $ dig www.ripe.net. in RRSIG | grep SIZE
;; MSG SIZE rcvd: 534
According to research by DJB[1] over 2000 DNSSEC enabled zones provide >30x amplification for incoming UDP queries.1. cr.yp.to/talks/2012.06.04/slides.pdf
$ dig google.com. ANY | grep SIZE
;; MSG SIZE rcvd: 546
If you want more amplification than that gives, just host one yourself. The recursive resolver will hit your DNS server once, then send out replies based on the cache.There seems to be lots of fearmongering about DNSSEC amplification, but you can get just the same amount of amplification out of regular DNS, so it seems that fixing DNS amplification in other ways would be more effective than trying to avoid adopting DNSSEC.
There is also a 300+ Gbps DDoS attack making use of it right now. This was foreseen as a huge amplification vector in a stateless protocol during the design phase, but was ignored. Now we get to reap the benefits of that decision.
Normal DNS responses don't often grow to the size of google.com/IN/ANY. You have a very limited number of authoritative sources to use (and hosting yourself creates a bottleneck as well as a path back to you). With widespread DNSSEC adoption every zone becomes a good amplification source, which nullifies the current best practices for mitigation (rate limiting responses per zone/source).
If DNSSEC adoption becomes the norm, open recursive resolvers no longer become the problem and direct to authoritative becomes a viable attack vector.
| There is also a 300+ Gbps DDoS attack
| making use of it right now
I have yet to see anyone state authoritatively that DNSSEC is being used in this attack. Could you provide a reference for this?If this attack right now is able to reach 30x amplification without DNSSEC, then what's the point of of decrying DNSSEC amplification as a huge issue?
Other discussion: https://news.ycombinator.com/item?id=5451299
You can read CloudFlare's own explanation of how these attacks work http://blog.cloudflare.com/deep-inside-a-dns-amplification-d...
E.g. make a UDP DNS request to an open resolver with the source IP forged to be your target, then the response is sent to your target (rather than to the real source of the request).
My understanding is that the problem people have with DNSSEC in this regard is that the data returned in those responses increases by a lot (allowing for a 30x increase?). But if attackers are able to accomplish this without DNSSEC, then what's the point of talking about how horrible DNSSEC will make things in this regard?
http://dnsknowledge.com/bind/howto-test-bind-open-recursive-...
The reason not to do this at layer 4 is because I, in the several minutes of pondering it, think it could break lots of security devices that track connection state across lots of computers in a network. Make some kind of
C -> S request
C <- S ack
C -> S yes
C <- S lots of data
done
C -> S request
C <- S ack
C -> S no
doneI even like to think I know this stuff well, but still got burned. I'm sure at the time my security analysis (if I even thought of the externally-facing issue) was "who cares if I expose a caching nameserver with no sensitive content to the rest of the internet?".
Blacklists are pure evil, and nothing will ever change my opinion of that. They cause far more problems than they solve. Granted, it's usually by idiot, over-zealous mail admins who block on merely being listed anywhere, rather than by weighted score.
Sure, large and entrenched authorities pose risks. There's not much that can be done about that as long as they're large and entrenched. The best way to ensure their power stays in check is to try to have their customers put pressure on them to clean up their act. And the end-user (you and me) is not their customer. We are customers of the businesses and organizations implementing their block lists. I understand your frustration, and as security professional I have my own beef with Spamhaus ratings, but the answer to that problem lies in comparing their ratings with those of other organizations and a bit of common sense.
I see SpamHaus as akin to a the Microsoft monopoly in the 90's. If your interests are aligned with them, great. And for most people they do a great job. But there a lots of small businesses who get caught up and nearly crushed. Because a listing on a blacklist can be murder for a business that depends on communicating with people over email.
I rented a server, and when I decided to use it for sending emails, I found out the IPs were blacklisted. I tried appealing to Microsoft and they claimed the IP was blacklisted after I rented it. This was ridiculous since I had just installed Postfix for a few days and barely sent any emails out.
So I decided to relay all my emails to another server and haven't had any problems with it for a year except now I am stuck with a server with blacklisted IPs.
Some messages still randomly get blocked by Hotmail while Gmail happily accepts them. This whole email delivery problem is a mess and the fact that people are paying to have someone else send their emails is proof of how bad Email is failing.