遇见数据集

Lar­ge-sca­le Ana­ly­sis of In­fra­struc­tu­re-lea­king DNS Ser­vers - (Dataset)

收藏
Zenodo2020-07-29 更新2026-05-25 收录
数据链接:
官方服务:

资源简介:

Dataset of the paper: "Lar­ge-sca­le Ana­ly­sis of In­fra­struc­tu­re-lea­king DNS Ser­vers", published at Con­fe­rence on De­tec­tion of In­tru­si­ons and Mal­wa­re & Vul­nerabi­li­ty As­sess­ment (DIMVA), Go­then­burg, Swe­den, June 2019. Abstract The Do­main Name Sys­tem (DNS) is a fun­da­men­tal back­bone ser­vice of the In­ter­net. In prac­tice, this in­fra­struc­tu­re often shows flaws, which in­di­ca­te that me­a­su­ring the DNS is im­portant to un­der­stand po­ten­ti­al (se­cu­ri­ty) is­su­es. Se­ver­al works deal with the DNS and pre­sent such pro­blems, miti­ga­ti­ons, and at­tack vec­tors. A so far over­look­ed issue is the fact that DNS ser­vers might an­s­wer with in­for­ma­ti­on about in­ter­nal net­work in­for­ma­ti­on (e.g., host­na­mes) to ex­ter­nal que­ries. This be­ha­vi­or re­sults in a ca­pa­bi­li­ty to per­form an ac­tive net­work re­con­nais­sance wi­thout the need for in­di­vi­du­al vul­nerabi­li­ties or ex­ploits. Ana­ly­zing how pu­blic DNS ser­vices might in­vol­un­ta­ri­ly dis­clo­se sen­si­ti­ve in­for­ma­ti­on ties in with the trust we have on In­ter­net ser­vices. To in­ves­ti­ga­te this phe­no­men­on, we con­duc­ted a sys­te­ma­tic me­a­su­re­ment study on this topic. We crawl all pu­blic re­acha­ble DNS ser­vers in 15 scans over a pe­ri­od of al­most six months and ana­ly­ze up to 574,000 DNS ser­vers per run that are con­fi­gu­red in a way that might lead to this kind of in­for­ma­ti­on le­a­ka­ge. With this lar­ge-sca­le eva­lua­ti­on, we show that the amount of this pos­si­ble in­fra­struc­tu­re lea­king DNS ser­vers is on aver­a­ge al­most 4 per­cent over all of our scans on every re­acha­ble DNS ser­vers on the In­ter­net. Based on our ne­west scan, the coun­tri­es with most of these ser­vers are Ro­ma­nia, China, and the US. In these coun­tri­es, the share of such ser­vers among of all re­acha­ble ser­vers is about 15% in Ro­ma­nia, 9% in China, and 2.9% in the US. A de­tai­led ana­ly­sis of the re­s­pon­ses re­veals that not all an­s­wers pro­vi­de use­ful in­for­ma­ti­on for an ad­versa­ry. Howe­ver, we found that up to 158,000 DNS ser­vers pro­vi­de po­ten­ti­al­ly ex­ploi­ta­ble in­for­ma­ti­on in the wild. Hence, this me­a­su­re­ment study de­mons­tra­tes that the con­fi­gu­ra­ti­on of a DNS ser­ver should be exe­cu­ted ca­re­ful­ly; other­wi­se, it may be pos­si­ble to dis­clo­se too much in­for­ma­ti­on.

提供机构:
Zenodo
创建时间:
2019-04-23
二维码
社区交流群
二维码
科研交流群
商业服务