Swamp of Reflectors: Investigating the Ecosystem of Open DNS Resolvers
摘要
DNS reflection-based DDoS attacks rely on open DNS resolvers to reflect and amplify attack traffic towards victims. While the majority of these resolvers are considered to be open because of misconfiguration, there remains a lot to be learned about the open resolver ecosystem. In this paper, we investigate and characterize open DNS resolvers from multiple angles. First, we look at indicators that likely suggest an intention behind the existence of open resolvers. To this end, we cross open resolver IP addresses with reverse DNS measurement data and show that a relatively small group of open resolvers unmistakably indicate their service in hostnames (i.e., PTR records). Second, we investigate the extent to which anycast technique is used among open resolvers and show that this is mainly driven by hypergiants. Additionally, we take a look at the exposure of the authoritative nameservers as open recursive resolvers and show that a non-negligible number of authoritative nameservers also serve as open recursors. Finally, we look at the persistency of open resolvers over time. We study open resolvers longitudinally over a three-year period and show that 1% of open resolvers persistently appear in more than 95% of the measurement snapshots.