In an advancing digital environment, the Domain Name System (DNS) serves as a significant component facilitating Internet functionality. However, it is susceptible to Man-in-the-Middle (MitM) attacks which compromise security and privacy. We investigate the MitM attacks and propose a security measure in addition to authentication to mitigate the effects of attacks. The literature review highlights the need for DNS monitoring and detection techniques to address challenges such as encrypted traffic and false positives. This study proposes novel approaches to enhance DNS security against MitM attacks. The Simulink module in MATLAB was employed to simulate and model DNS systems and network configurations, enabling the design of simulation models which replicate various attack scenarios and testing countermeasures’ effectiveness. The Detection Accuracy, Packet Drop Ratio, DNS Response time, Packet Delivery Ratio, Throughput, and Average Delay were considered for the evaluation of the proposed scheme. Results show that the Location-Based model demonstrates superior performance. The scheme performed well in detection accuracy, packet delivery ratio, average response time, and throughput compared to DNSSEC and CGUARD. The scheme is effective in mitigating MitM attacks. The Location-Based model is recommended as an effective defence mechanism against MitM attacks. Ongoing modifications and proactive measures are recommended to safeguard Internet security.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Evaluating the Effectiveness of Current Countermeasures Against Man-In-The-Middle Attack on Domain Name System

  • Phandavhudzi Rotshidzwa,
  • Moila Ramahlapane Lerato,
  • Velempini Mthulisi

摘要

In an advancing digital environment, the Domain Name System (DNS) serves as a significant component facilitating Internet functionality. However, it is susceptible to Man-in-the-Middle (MitM) attacks which compromise security and privacy. We investigate the MitM attacks and propose a security measure in addition to authentication to mitigate the effects of attacks. The literature review highlights the need for DNS monitoring and detection techniques to address challenges such as encrypted traffic and false positives. This study proposes novel approaches to enhance DNS security against MitM attacks. The Simulink module in MATLAB was employed to simulate and model DNS systems and network configurations, enabling the design of simulation models which replicate various attack scenarios and testing countermeasures’ effectiveness. The Detection Accuracy, Packet Drop Ratio, DNS Response time, Packet Delivery Ratio, Throughput, and Average Delay were considered for the evaluation of the proposed scheme. Results show that the Location-Based model demonstrates superior performance. The scheme performed well in detection accuracy, packet delivery ratio, average response time, and throughput compared to DNSSEC and CGUARD. The scheme is effective in mitigating MitM attacks. The Location-Based model is recommended as an effective defence mechanism against MitM attacks. Ongoing modifications and proactive measures are recommended to safeguard Internet security.