Systems and methods for mitigating domain name system amplification attacks
A threat intelligence system detects and mitigates DNS amplification attacks by analyzing network traffic and filtering oversized responses, ensuring legitimate queries are not disrupted.
Patent Information
- Application Number
- JP2025503192
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2022-08-02
- Filing Date
- 2023-07-28
- Publication Date
- 2025-08-07
AI Technical Summary
DNS amplification attacks overwhelm target servers by sending small queries with spoofed IP addresses, causing large responses that consume bandwidth and render systems inaccessible.
A threat intelligence system analyzes network traffic to detect DNS amplification attacks by monitoring request rates and payload sizes, initiating threat mitigation actions, and deploying filtering rules in routers or DNS servers to discard oversized responses.
Effectively filters out malicious DNS responses while allowing legitimate queries, preventing denial-of-service attacks by dynamically adjusting threshold payload sizes using machine learning models.
Smart Images

Figure 2025525750000001_ABST
Abstract
Description
[Technical Field]
[0001] [CROSS-REFERENCE TO RELATED APPLICATIONS] This application claims the benefit of U.S. Provisional Patent Application No. 63 / 370,135, filed August 2, 2022, entitled "Systems and Methods for Mitigating Domain Name System Amplification Attacks," which is incorporated herein by reference in its entirety.
[0002] One or more aspects of embodiments according to the present disclosure relate to mitigating distributed denial of service attacks, and more particularly, to mitigating Domain Name System amplification attacks. [Background technology]
[0003] Communications networks are becoming increasingly complex. For example, large communications networks may process millions (or more) of queries per second. Malicious actors routinely attempt to circumvent communications network security measures and / or cause communications network failures. For example, denial-of-service (DoS) attacks and distributed denial-of-service (DDoS) attacks have become commonplace. A DDoS attack attempts to overwhelm a network component or application by flooding it with excessive requests, overloading a network, network component (such as a Domain Name System (DNS) server), or application to prevent legitimate requests from being fulfilled.
[0004] In a Domain Name System (DNS) amplification attack, an attacker may send relatively small queries to a DNS server that contain a spoofed Internet Protocol (IP) address of a target server, causing the response to the query to be sent to the target server instead of the attacker. These responses may be significantly larger or amplified, which can overwhelm the target server or network, rendering the target server and its surrounding infrastructure inaccessible.
[0005] The information disclosed in this Background section above is intended to enhance understanding of the context of the present disclosure only, and therefore may include information that does not constitute prior art. Summary of the Invention
[0006] In one aspect, the technology includes a method comprising: analyzing network traffic information; identifying a Domain Name System (DNS) amplification attack based on the network traffic information; invoking a threat mitigation action in response to identifying the DNS amplification attack; receiving a Domain Name System (DNS) query from a source address; determining, by a DNS server, that a payload size of a response to the DNS query exceeds a threshold payload size; and discarding the response to the DNS query based on the threat mitigation action.
[0007] In one embodiment, and in combination with any of the above aspects and embodiments, detecting a DNS amplification attack includes determining a rate of traffic from a source address over a period of time; and determining that the rate of traffic exceeds a threshold rate.
[0008] In another embodiment, and in combination with any of the above aspects and embodiments, detecting a DNS amplification attack includes examining payloads of multiple first responses generated by the DNS server over a period of time; and determining that one or more payloads of the multiple first responses exceed a threshold payload size.
[0009] In another embodiment, and in combination with any of the above aspects and embodiments, detecting a DNS amplification attack includes determining a past ratio based on one or more past DNS queries and one or more past responses; determining a current ratio based on recent DNS queries and associated DNS responses in a particular time period; and determining that a difference between the current ratio and the past ratio exceeds a threshold.
[0010] In another embodiment, and in combination with any of the above aspects and embodiments, the threat mitigation measures include deploying filtering rules to filter responses to the DNS queries.
[0011] In another embodiment, and in combination with any of the above aspects and embodiments, filtering rules are deployed in routers to filter responses to DNS queries.
[0012] In another embodiment, and in combination with any of the above aspects and embodiments, filtering rules are deployed in a DNS server to filter responses to DNS queries.
[0013] In another embodiment, and in combination with any of the above aspects and embodiments, the filtering rules include a source address and a threshold payload size.
[0014] In another embodiment, and in combination with any of the above aspects and embodiments, the method further includes dynamically determining the threshold payload size based on the machine learning model and previous responses to DNS queries within the specified period.
[0015] In another embodiment, and in combination with any of the above aspects and embodiments, the DNS server calculates an expected payload size of the response before generating the response, wherein discarding the response to the DNS query includes not generating the response.
[0016] In another aspect, the technology includes a system having the following elements: at least one processor; and a memory storing instructions that, when executed by the at least one processor, cause the system to perform a method. In one embodiment, the method includes analyzing network traffic information; identifying a Domain Name System (DNS) amplification attack based on the network traffic information; invoking a threat mitigation action in response to identifying the DNS amplification attack; receiving a Domain Name System (DNS) query from a source address; determining, by a DNS server, that a payload size of the response to the DNS query exceeds a threshold payload size; and discarding the response to the DNS query based on the threat mitigation action.
[0017] In another embodiment, and in combination with any of the above aspects and embodiments, detecting a DNS amplification attack includes determining a rate of traffic from a source address over a period of time; and determining that the rate of traffic exceeds a threshold rate.
[0018] In another embodiment, and in combination with any of the above aspects and embodiments, detecting a DNS amplification attack includes examining payloads of multiple first responses generated by the DNS server over a period of time; and determining that one or more payloads of the multiple first responses exceed a threshold payload size.
[0019] In another embodiment, and in combination with any of the above aspects and embodiments, detecting a DNS amplification attack includes determining a past ratio based on one or more past DNS queries and one or more past responses; determining a current ratio based on recent DNS queries and associated DNS responses in a particular time period; and determining that a difference between the current ratio and the past ratio exceeds a threshold.
[0020] In another embodiment, and in combination with any of the above aspects and embodiments, the threat mitigation measures include deploying filtering rules to filter responses to the DNS queries.
[0021] In another embodiment, and in combination with any of the above aspects and embodiments, filtering rules are deployed in routers to filter responses to DNS queries.
[0022] In another embodiment, and in combination with any of the above aspects and embodiments, filtering rules are deployed in a DNS server to filter responses to DNS queries.
[0023] In another embodiment, and in combination with any of the above aspects and embodiments, the filtering rules include a source address and a threshold payload size.
[0024] In another embodiment, and in combination with any of the above aspects and embodiments, the method further comprises dynamically determining the threshold payload size based on the machine learning model and previous responses to DNS queries within the specified period.
[0025] In another aspect, the present technology includes a system comprising: at least one processor; and a memory storing instructions that, when executed by the at least one processor, cause the system to perform a method. In one embodiment, the method includes the steps of: the method includes: analyzing network traffic information; identifying a Domain Name System (DNS) amplification attack based on the network traffic information; dynamically determining a threshold payload size based on the machine learning model and network traffic information received within a specified first period of time; invoking threat mitigation measures including distributing a filtering notice to at least one network device in response to identifying the DNS amplification attack, wherein the filtering notice includes instructions to the at least one network device to receive a current DNS query from a source address; receive a response to the current DNS query; determine that the payload size of the response to the current DNS query exceeds a threshold payload size; and, based on the determination that the payload size of the response to the current DNS query exceeds the threshold payload size, discard the response to the DNS query; dynamically determining an updated threshold payload size based on the machine learning model and network traffic information received within a specified second period of time; and distributing an updated filtering notice including the updated threshold payload size to the at least one network device.
[0026] These and other features, aspects, and advantages of the embodiments of the present disclosure will become more fully understood when considered in conjunction with the following detailed description, the appended claims, and the accompanying drawings, in which: The actual scope of the present invention is, of course, defined by the appended claims. [Brief explanation of the drawings]
[0027] Non-limiting and non-exhaustive examples of the present embodiments are described with reference to the following figures, in which like reference numerals refer to like parts throughout the various views unless otherwise specified:
[0028] [Figure 1] FIG. 1 is a block diagram of an example networking environment for mitigating DNS amplification attacks, according to one embodiment.
[0029] [Figure 2] FIG. 1 is a block diagram of a threat intelligence system for mitigating DNS amplification attacks, according to one embodiment.
[0030] [Figure 3] FIG. 1 is a flow diagram of a process for mitigating a DNS amplification attack, according to one embodiment.
[0031] [Figure 4] FIG. 1 is a block diagram of a computing device according to one embodiment. DETAILED DESCRIPTION OF THE INVENTION
[0032] The embodiments will now be described in more detail with reference to the accompanying drawings. In the accompanying drawings, like reference numerals refer to like elements throughout. However, the present disclosure may be embodied in a variety of different forms and should not be construed as limited to only the embodiments illustrated herein. Rather, these embodiments are provided so that the disclosure will be thorough and complete, and will fully convey the aspects and features of the present disclosure to those skilled in the art. Therefore, processes, elements, and techniques that are not necessary for a complete understanding of the aspects and features of the present disclosure to those skilled in the art may not be described. Unless otherwise specified, like reference numerals refer to like elements throughout the accompanying drawings and written description, and therefore, descriptions thereof may not be repeated. Additionally, in the drawings, the relative sizes of elements, layers, and regions may be exaggerated and / or simplified for clarity.
[0033] DoS and DDoS attacks (collectively referred to herein as DDoS attacks) that attempt to overwhelm an organization's network components (such as Domain Name System (DNS) servers, web or content servers, and the like) have become commonplace. A DNS amplification attack may be launched by an attacker sending requests to a DNS server / resolver using a spoofed IP address. The spoofed IP address in the request may point to the victim's (e.g., the targeted system or network) true IP address. These requests may be crafted to generate significantly larger responses from the DNS resolver that are sent to the targeted system, potentially consuming the targeted system's bandwidth. While a small number of malicious requests may not be enough to bring the targeted system to a halt, when these requests multiply across multiple DNS resolvers, the amplification of data received by the targeted system can become enormous, potentially causing a denial of service by the targeted system.
[0034] Generally, embodiments of the present disclosure relate to systems and methods for mitigating DNS amplification attacks. In one embodiment, a threat intelligence system collects data regarding requests received by and / or responses generated by a DNS server. This data may include details regarding DNS queries and details regarding DNS responses generated in response to the queries. Such details may include, for example, IP source addresses included in the queries, query sizes, query and response timestamps, DNS response payload sizes, and / or the like.
[0035] Threat intelligence systems may also collect information about traffic entering and leaving the network (e.g., DNS and requests and responses) from traffic monitoring systems. Network flow information (e.g., collected via the NetFlow protocol) may include details about the traffic's IP source and destination addresses, the size of the packets being sent, the source port, the destination port, Layer 3 headers, protocol type, class of service, router or switch interface, and / or the like. Network flow information may also include information about source and target autonomous systems (ASs) and routing details.
[0036] In one example, the threat intelligence system analyzes collected data for characteristics indicative of a DNS amplification attack. For example, the threat intelligence system can analyze this data to determine the rate of requests received from a source IP address. A rate (or an increase in rate) exceeding a threshold rate (or a threshold rate of increase) over a specific period of time (e.g., a sliding time window) can be evidence of a DNS amplification attack. The threat intelligence system can also analyze the size of DNS responses generated by DNS resolvers for corresponding DNS queries. For example, a DNS response packet payload size exceeding a threshold payload size can be evidence of a DNS amplification attack. Thus, the threat intelligence system can monitor metrics such as the average or median payload size of DNS response packets over a specific period of time, such as a sliding time window. Another possible evidence of a DNS amplification attack is when the ratio of the DNS response size to the corresponding DNS request size (called the amplification factor) exceeds a threshold amplification factor.
[0037] In one embodiment, when a threat intelligence system detects evidence (in one or more forms) of a DNS amplification attack, it initiates threat mitigation actions. Threat mitigation actions may include filtering DNS responses generated by DNS servers. This filtering may be performed by filtering rules configured on routers that forward the generated DNS responses to the source IP address. The filtering rules may indicate that DNS responses targeted to an IP address with a payload size greater than a threshold payload size should be discarded.
[0038] In some embodiments, filtering may be performed by a DNS server that generates the DNS response. The DNS server may be configured with filtering rules that indicate a source IP address and a threshold payload size, similar to filtering rules for a router. The filtering rules may be triggered when a DNS response generated by the DNS server contains a source IP address (of the corresponding DNS request) listed in the rule and has a payload size greater than the threshold payload size indicated in the rule. In one embodiment, triggering the rule causes the DNS server to stop providing the DNS response to a router for forwarding to the target system that issued the query. In some embodiments, the DNS server may determine that the DNS response (if generated) would exceed the threshold size and first stop generating the DNS response.
[0039] In one embodiment, the payload threshold size is dynamically set by the threat intelligence system using a machine learning model. The machine learning model can be, for example, one or more deep neural networks trained using supervised learning and / or unsupervised learning. In this regard, the machine learning model can receive as input one or more characteristics of network traffic (e.g., rate of DNS queries from a particular source IP address, payload size of DNS responses sent to a particular source IP address, ratio of payload size of DNS requests to DNS responses, responses containing unexpected data for the query type, large responses with significantly long time-to-live (TTL) values, etc.) and be trained to output an optimal payload threshold size. The optimal payload threshold can be one that minimizes filtering of DNS responses to legitimate DNS queries while maximizing filtering of DNS responses to malicious DNS queries.
[0040] In some embodiments, the payload threshold size is manually set by a system administrator. In some embodiments, different payload threshold sizes are set based on the characteristics of the DNS server generating the DNS response.
[0041] 1 is a block diagram of an example networking environment 101 for mitigating DNS amplification attacks, according to one embodiment. Networking environment 101 may include any type of telecommunications network that utilizes IP addresses to connect one or more components of the network.
[0042] In one embodiment, a networking environment 101 includes one or more impersonation devices 100a, 100b (collectively referred to as 100) configured to send malicious DNS queries to DNS servers / resolvers 102a, 102b (collectively referred to as 102) during a DNS amplification attack. The DNS resolvers 102 may be configured to receive the DNS queries and generate DNS responses. The DNS responses may include address records corresponding to the DNS queries, such as the IP address of a domain name provided in the DNS queries. The address records may be retrieved from the cache of the DNS resolver 102 or obtained from an authoritative DNS server 114 (or another server within a particular DNS server hierarchy).
[0043] If the query received by the DNS resolver 102 is a malicious DNS query, the query size may be relatively small (e.g., 20 bytes), but the DNS response generated in response may be significantly larger (e.g., 2000 bytes or larger). For example, to cause the DNS resolver to output a significantly larger response, the impersonated device 100 may not only request IP address resolution of a domain name, but may also request information about the entire domain, such as information about subdomains, backup servers, mail servers, and the like (e.g., via an “arbitrary” DNS query). In another example, a threat actor operating the impersonated device 100 may issue a query for a maliciously inserted significantly larger record to the DNS resolver 102 via a malicious zone that the threat actor operates on the authoritative DNS server 114, resulting in the malicious DNS record being returned in response to the DNS query.
[0044] In one embodiment, an overly large DNS response is returned to the compromised target system 104a, 104b (collectively 104) rather than to the requesting impersonated device 100. In this regard, a DNS query sent to the DNS resolver 102 includes a source IP address of the target system 104 under attack rather than the Internet Protocol (IP) address of the impersonated device 100. The DNS resolver 102 returns the DNS response to the source IP address included in the DNS query rather than the IP address of the impersonated device 100. If multiple malicious requests generate overly large DNS responses to the target system 104 and / or if the malicious requests multiply across various DNS resolvers, the resources (e.g., computation, bandwidth, etc.) of the target system may be overwhelmed, causing denial of service of legitimate requests by the target system 104.
[0045] Of course, the DNS resolver 102 may also receive legitimate DNS queries from the targeted system 104. Legitimate DNS queries may or may not require significantly larger responses from the DNS resolver 102. Even during a DNS amplification attack, it may be desirable to generate and send DNS responses to legitimate DNS queries.
[0046] In one embodiment, the network environment includes one or more traffic monitoring systems 106. The traffic monitoring systems 106 may be coupled to one or more routers 108a, 108b (collectively 108) to collect data on network flows entering and leaving the routers 108. In some embodiments, the network data is collected using the NetFlow protocol (also known as Internet Protocol Flow Information eXport, or IPFIX). In some embodiments, the traffic monitoring systems 106 may include one or more NetFlow cache devices and / or NetFlow collectors (reporting servers that collect and process traffic and export data to facilitate analysis). The traffic monitoring systems 106 may also include one or more software agents that operate on the routers 108 to analyze individual packets and forward network data to the NetFlow caches and / or NetFlow collectors. Network data may include, for example, data contained in packets, including source IP addresses, destination IP addresses, protocol types, timestamps of data packets in the flow, source ports, destination ports, and bytes sent or received in the sampled traffic.
[0047] In one embodiment, the router 108 is configured to statistically sample data packets in a network flow. For example, the router 108 may be configured to sample 1 in N packets, where N may be set by the manufacturer or by a network administrator. The sampling rate may be configurable, for example, by the NetFlow protocol, although embodiments are not limited in this respect.
[0048] The traffic monitoring system 106 may receive and aggregate sampled network data from the routers 108. In this regard, the traffic monitoring system 106 may generate a traffic flow summary based on the sampled data, for example, using the NetFlow protocol. This summary may include, for example, source addresses (including spoofed source addresses), destination addresses, query size information, response size information, packet size information, and / or the like.
[0049] In one embodiment, traffic monitoring system 106 and DNS resolver 102 are coupled to a threat intelligence system 112. Threat intelligence system 112 may be implemented as a standalone device or may be incorporated into one or more components of the networking environment of FIG. 1 (e.g., traffic monitoring system 106, etc.).
[0050] In one embodiment, the threat intelligence system 112 receives information regarding network flow summaries and DNS responses generated by one or more of the DNS resolvers 102 from the traffic monitoring system 106 to detect possible DNS amplification attacks. In some embodiments, the threat intelligence system 112 receives traffic information from the routers 108 in addition to or instead of the flow summaries from the traffic monitoring system 106. The information provided by the DNS resolvers 102 may include, for example, the identity of the affected DNS resolver, the size of the received query, the timestamp of the received query, and the payload size of the DNS response generated in response to the query.
[0051] In one example, the threat intelligence system 112 can detect a DNS amplification attack in which a significantly larger response from the DNS resolver 102 is generated in response to detecting a significantly increased rate of traffic from a particular IP source address within a certain time window. For example, the threat intelligence system 112 can determine that a particular IP source address sends an average of 100 queries per second based on historical analysis of queries received from the particular IP source address. If the number of queries spikes above a threshold (e.g., 10,000 queries per second), the threat intelligence system 112 may re-examine the size of the DNS responses generated for these queries. If a large number of queries (e.g., 90% of the queries) generate DNS responses with payloads higher than a threshold payload, a DNS amplification attack can be inferred. Other algorithms for detecting DNS amplification attacks are possible and contemplated.
[0052] In some embodiments, a DNS amplification attack may be detected in response to determining that the amplification factor of a DNS response for a particular IP source address is higher than the average amplification factor for that IP source address. The average amplification factor may be determined based on historical data collected by the traffic monitoring system 106. In one embodiment, the amplification factor may be the ratio of DNS response size to DNS query size. For example, if, based on historical data, the (e.g., average) amplification factor for a particular IP address is typically 1.5 (e.g., a 20-byte request produces a 30-byte response), but the (e.g., average) current amplification factor detected by the threat intelligence system 112 is 100 (e.g., a 20-byte request produces a 2000-byte response), a DNS amplification attack may be predicted. In an embodiment, the amplification factor may be determined as an average or median value based on packets sampled during a sampling period.
[0053] In response to detecting a DNS amplification attack, the threat intelligence system 112 may be configured to take (or initiate) threat mitigation actions. In the illustrated embodiment, the threat intelligence system 112 may include an integrated threat mitigation system. In some other embodiments, the threat intelligence system 112 may identify a threat and communicate the threat to another threat mitigation system to implement mitigation actions. The threat mitigation actions may include, for example, deploying a filtering notification 110 that includes filtering rules. In an embodiment, the filtering notification 110 may be a FlowSpec notification defined in Internet Engineering Task Force (IETF) REC8955 and related specifications.
[0054] In one embodiment, the filtering notification 110 is sent to the router 108 to dynamically configure filtering rules on the router. The filtering rules may indicate criteria that a data packet must meet to be filtered (e.g., discarded) by the router. For example, the criteria may be a specific IP address (e.g., a spoofed IP source address of the target system 104) and a maximum threshold payload size before filtering the data packet. If a DNS response packet received by the router matches a specific IP address while the filtering rule is in effect and the packet's payload size exceeds the maximum threshold payload size, the packet is filtered and not sent to the specific IP address. In this way, rather than rate-limiting all responses to a specific IP address during a DNS amplification attack and also disabling responses to legitimate DNS queries, only oversized responses are blocked, preventing such packets from affecting the victim's IP address in a destructive manner.
[0055] In one embodiment, instead of configuring filtering rules in router 108, filtering rules may be configured in DNS resolver 102. Similar to filtering rules in router 108, filtering rules configured in DNS resolver 102 can cause the DNS resolver to discard a generated DNS response (or reject a request to generate a response) if the generated (or requested) response is intended for an IP address specified in the filtering rule and the payload size of the generated response exceeds (or would exceed) a threshold payload size indicated in the rule.
[0056] In one embodiment, the threat intelligence system 112 dynamically sets the threshold payload size based on network conditions. In this regard, the threat intelligence system 112 may be configured with one or more machine learning models that can receive network traffic conditions as input and output a recommended or optimal threshold payload size. The recommended threshold payload size may be intended to filter oversized DNS responses generated in response to malicious queries while minimizing filtering of DNS responses generated in response to legitimate DNS queries. For example, the machine learning model may be trained using, as training data, features of packets whose payloads exceed a threshold size (e.g., 1000 bytes). These packet features may include source information, destination information, and / or the like.
[0057] In instances where there is not enough training data to train the machine learning model, the threat intelligence system 112 may be configured to start with a significantly higher payload threshold. The payload threshold may be adjusted periodically or continuously based on machine learning. For example, the system may iteratively modify the function and / or weights of the machine learning model based on feedback of the results of the current threshold to generate an optimal payload threshold, which may be updated periodically or continuously as new network traffic information is received.
[0058] Dynamically adjusting the payload threshold can help thwart filtering evasion attempts by attackers. For example, an attacker may cause DNS resolvers to generate responses slightly below the current payload threshold in order to prevent the threat intelligence system 112 from detecting a DNS amplification attack. In this case, the machine learning model can lower the payload threshold based on current network conditions and filter DNS responses generated based on malicious queries identified by other means (e.g., feedback from network operators to the threat intelligence system 112).
[0059] In some embodiments, the payload threshold used to filter DNS responses from one DNS resolver (e.g., DNS resolver 102a) may be different from the payload threshold used to filter DNS responses from another DNS resolver (e.g., DNS resolver 102b). This difference may be based on an analysis of queries processed by the different DNS resolvers and / or an analysis of the sizes of DNS responses generated by the different DNS resolvers. For example, if analysis of historical data indicates that queries from a first IP source address are most often processed by DNS resolver 102a rather than DNS resolver 102b, the threshold for DNS resolver 102a may be set higher than the threshold for DNS resolver 102b. In another embodiment, if analysis of historical data indicates that the size of DNS responses from DNS resolver 102a is larger than the size of DNS responses from DNS resolver 102b, the threshold for DNS resolver 102a may be set higher than the threshold for DNS resolver 102b.
[0060] In some embodiments, the machine learning model may be configured to predict whether a generated response will exceed a threshold based on characteristics of the DNS request itself. In this case, the DNS resolver need not bother generating a response and the DNS request may simply be ignored. For example, the filtering notification may include an instruction that the DNS resolver 102 refuse to generate a DNS response for any DNS query that is predicted to result in a DNS response exceeding a certain threshold.
[0061] 2 is a block diagram of a threat intelligence system 112 for identifying and mitigating DNS amplification attacks, according to one embodiment. The threat intelligence system 112 may include, but is not limited to, a threat analysis unit 200, a threshold manager 202, and a threat mitigation system 204. While the threat analysis unit 200, the threshold manager 202, and the threat mitigation system 204 are depicted in FIG. 2 as separate components, those skilled in the art will recognize that these components 200, 202, and 204 may be combined into a single component, or one or more of these components may be further subdivided into separate subcomponents as would be understood by those skilled in the art.
[0062] In one embodiment, the threat analysis device 200 is configured to collect traffic information (e.g., from the traffic monitoring system 106) and information regarding DNS responses by one or more DNS resolvers 102 and analyze the information to determine a DNS amplification attack. The traffic information may include a flow summary generated by the traffic monitoring. For example, the flow summary may include identification of source IP addresses generating requests targeted to the network environment, the size of the requests, timestamp information, and / or the like. The information provided by one or more of these DNS resolvers 102 may include, but is not limited to, the identification of the DNS resolver, the size of the received query, the timestamp of the received query, and the size of the response generated in response to the query (e.g., payload size).
[0063] In one embodiment, the threat analysis unit 200 analyzes information from the traffic monitoring system 106 and information from the DNS resolver 102 to identify evidence of a DNS amplification attack. For example, the threat analysis unit 200 can detect evidence of a DNS amplification attack if the rate of requests received from a source IP address exceeds a threshold rate. The threshold rate may be set based on an analysis of historical data and may be time-based. For example, a DNS amplification attack threat count for a source IP address may be incremented in response to detecting a rate of requests that exceeds the threshold rate in a first preset time window (e.g., the past X minutes).
[0064] In another example, a DNS amplification attack threat count for a source IP address may be incremented in response to detecting a DNS response that exceeds the current threshold payload size in a second preset time window (e.g., Y minutes in the past). The first and second preset time windows may be the same or different.
[0065] In one embodiment, the threat analysis device 200 detects a DNS amplification attack when the threat count of such an attack exceeds an appropriate threshold, and when the threat count exceeds an appropriate threshold, the threat mitigation system 204 can cause one or more mitigation actions to be taken.
[0066] Threat mitigation actions may include generating a filtering notification and deploying a filter on the router 108. The filter may also be deployed in another scrubbing system, a third-party filtering system, and / or the like. For example, the threat mitigation system 204 may deploy a filtering notification (e.g., filtering notification 110 of FIG. 1 ) containing filtering rules on the router 108. The filtering rules (e.g., FlowSpec rules) may be to discard or ignore any DNS response data packets larger than a preset threshold payload size that target an IP address (e.g., a spoofed IP address). The filtering rules may be implemented for a preset period of time until the conditions that caused the mitigation action to be taken are remedied or until an administrator of the threat mitigation system 204 determines that the threat mitigation action is no longer necessary, among other options. As described, the filtering notification (or another filtering notification) may be sent to the DNS resolver 102 and / or the authoritative DNS server 114 to instruct such systems to discard or refuse to generate responses to DNS queries. The condition is if such a response is determined to exceed, or is likely to exceed, the then-current threshold payload size.
[0067] In one embodiment, the threshold manager 202 includes at least one machine learning model for setting a maximum threshold payload size for DNS responses that one or more IP source addresses may receive before being filtered. The threshold payload size may vary based on one or more factors, such as, for example, the IP source address receiving the DNS response, the DNS resolver 102 generating the DNS response, and / or the like.
[0068] In one example, the machine learning model includes a deep learning neural network model with one or more layers, such as an input layer that receives current network statistics, an output layer that outputs a recommended threshold payload value, and one or more hidden layers. One or more layers of the neural network can represent different collections or sets of artificial neurons, which can represent different functions on the input data. The artificial neurons may apply different weights to the functions applied to the input data to attempt to identify an optimal threshold payload value.
[0069] In one embodiment, the machine learning model is trained and / or adjusted based on a labeled training dataset. The labeled training dataset may include labeled examples of traffic during a DNS amplification attack. The threshold payload value set by the threshold manager 202 during training may be validated and / or adjusted based on the training dataset. In some embodiments, the machine learning model is trained using an unsupervised training technique. Regardless of the particular training technique, the threshold manager 202 periodically adjusts the threshold payload value to optimize filtering of DNS responses generated based on malicious queries while minimizing filtering of DNS responses generated based on legitimate queries. In an embodiment, the latest threshold payload value is communicated by the threshold manager 202 to one or more network elements (e.g., the router 108 and the DNS server 102, 114) using the latest filtering notification.
[0070] 3 is a flow diagram of a process for mitigating DNS amplification attacks, according to one embodiment. It should be understood, and those skilled in the art will recognize, that the steps in this process are not fixed in sequence and can be modified, reordered, performed differently, sequentially, in parallel, or simultaneously, or in any desired sequence.
[0071] The process begins at operation 300, where a DNS query is received, for example, by DNS resolver 102. In a DNS amplification attack, the DNS query is sent by a fake device (e.g., fake device 100 of FIG. 1 ), where the DNS query may include the address of a compromised target system (e.g., target system 104 of FIG. 1 ) as the source IP address.
[0072] In operation 302, the DNS resolver 102 receives a DNS query and generates a DNS response, which may include a payload of a payload size.
[0073] In operation 304, a DNS amplification attack is detected. For example, the threat intelligence system 112 may detect a DNS amplification attack based on traffic flow information from the traffic monitoring system 106, information about DNS queries (e.g., size) from the DNS resolver 102, and / or information about responses (e.g., size) from the DNS resolver 102. For example, the threat intelligence system 112 may analyze the traffic flow information from sampled packets to determine the rate of requests received from a source IP address. A rate (or an increase in rate) exceeding a threshold rate may be evidence of a DNS amplification attack.
[0074] The threat intelligence system 112 may also analyze the payload size of the sampled DNS response packets. For example, a payload size (e.g., an average or median size) exceeding a threshold size (e.g., X bytes) may be evidence of a DNS amplification attack. In another example, a ratio of the DNS response size to the DNS request size (referred to as an amplification factor) exceeding a threshold amplification factor may be evidence of a DNS amplification attack.
[0075] In one embodiment, multiple DNS resolvers 112 provide information about DNS queries and / or responses for evaluation by the threat intelligence system 112. For example, an attacker may distribute DNS requests across multiple DNS resolvers to keep the rate of requests below a threshold rate. To address this situation, the threat intelligence system 112 may be configured to aggregate DNS requests received by multiple DNS resolvers and calculate a total rate of these requests. If the total rate of DNS queries exceeds a threshold rate, this may be evidence of a DNS amplification attack.
[0076] In operation 306, a filtering notification similar to filtering notification 110 of FIG. 1 is deployed in response to detecting the DNS amplification attack. The filtering notification may be a FlowSpec filtering notification deployed to one or more of the routers 108. The filtering notification may specify one or more filtering rules for filtering data packets that satisfy the filtering rule. For example, the filtering rule may include a particular IP address (e.g., a spoofed IP source address of the targeted system 104) and a threshold payload size above which the data packets are filtered. In some embodiments, the filtering rule is deployed to one or more of the DNS resolvers 102.
[0077] In operation 308, the router 108 (or DNS resolver 102) with configured filtering rules monitors DNS responses addressed to the IP source address.
[0078] At operation 310, a determination is made as to whether the payload of a particular DNS response exceeds a threshold payload size specified in a filtering rule. If the payload of the DNS response is below the threshold payload size, then the DNS response is sent to the IP source address that issued the query at operation 312. If the payload of the DNS response is above the threshold payload size, then the DNS response is filtered at operation 314.
[0079] In operation 316, a determination is made as to whether the DNS amplification attack has ended. In one embodiment, the DNS amplification attack may be deemed to have ended based on traffic flow information from the traffic monitoring system 106, information (e.g., size) of DNS queries from the DNS resolver 102, and / or information (e.g., size) of responses from the DNS resolver 102. For example, the threat intelligence system 112 may analyze the traffic flow information to determine the rate of requests received from a source IP address. If the rate falls below a threshold rate for a particular time window (e.g., the past Y minutes), this may be evidence that the DNS amplification attack has ended.
[0080] The threat intelligence system 112 may also analyze the payload size of DNS response packets. For example, if the average or median payload size falls below a threshold size (e.g., over the past Z minutes), this may be evidence that a DNS amplification attack has ended. In another example, if the ratio of the average / median DNS response size to the average / median DNS request size (referred to as the amplification factor) falls below a threshold amplification factor, this may be evidence that a DNS amplification attack has ended.
[0081] Once the attack is deemed to have ended, the filtering rule may be removed from the router 108 (or DNS resolver 102) or disabled. It is also understood that if the threshold manager 202 modifies the threshold payload size of a filter applied to traffic for a particular IP address, a new filtering notification may be issued (operation 306), and the subsequent operations may be repeated for this new filtering notification. In other embodiments, no new filtering notification is deployed, but the latest threshold payload size for filtering may be communicated as a parameter to any devices that already implement a filter for the source IP address in question, so that subsequent filtering will be performed using the latest threshold payload size. As described, the threshold payload size may be updated periodically or continuously.
[0082] Figure 4 is a block diagram of a computing device 400 according to one embodiment. Various components and systems of computing device 400 or computing device 500 may be integrated with or associated with DNS resolver 102, target system 104, traffic monitor 106, router 108, threat intelligence system 112, and authoritative DNS 114 of Figure 1. As shown in Figure 4, physical components (e.g., hardware) of the computing device are illustrated, and these physical components may be used to implement various aspects of the present disclosure.
[0083] The computing device 400 may include at least one processing unit 410 and a system memory 420. The system memory 420 may include, but is not limited to, volatile storage (e.g., random access memory), non-volatile storage (e.g., read-only memory), flash memory, or any combination of such memory. The system memory 420 may also include an operating system 430 that controls the operation of the computing device 400, and one or more program modules 440. The program modules 440 may be responsible for mitigating DNS amplification attacks in accordance with various embodiments of the present disclosure. A number of different program modules and data files may be stored in the system memory 420. The program modules 440, when executed by the processing unit 410, may perform the various operations described above.
[0084] Computing device 400 may also have additional features or functionality. For example, computing device 400 may include additional data storage devices (e.g., removable and / or non-removable storage devices), such as magnetic disks, optical disks, or tape. These additional storage devices are labeled removable storage 460 and non-removable storage 470.
[0085] Embodiments of the present disclosure may be implemented using electrical circuits with discrete electronic elements, packaged or integrated electronic chips containing logic gates, microprocessor-based circuits, or a single chip containing electronic elements or a microprocessor. For example, embodiments of the present disclosure may be implemented by a system-on-chip (SOC) that may integrate each or many of the components illustrated in FIG. 4 into a single integrated circuit. Such an SOC device may include one or more processing units, graphics units, communications units, system virtualization units, and various application functions, all of which are integrated (or "burned") onto the chip substrate as a single integrated circuit.
[0086] When operating via a SOC, the functionality described herein may be performed by application specific logic integrated with other components of computing device 500 on a single integrated circuit (chip). The present disclosure may also be implemented using other technologies capable of performing logical operations such as, for example, AND, OR, and NOT, including, but not limited to, mechanical, optical, fluidic, and quantum technologies.
[0087] The computing device 400 may include one or more communication systems 480 that enable the computing device 400 to interact with other computing devices 495, such as, for example, servers, routers, network devices, client computing devices, etc. Examples of communication systems 480 include, but are not limited to, wireless communication, wired communication, cellular communication, radio frequency (RF) transmitter, receiver, and / or transceiver circuitry, a controller area network (CAN) bus, a universal serial bus (USB), a parallel port, a serial port, etc.
[0088] Computing device 400 may also have one or more input devices and / or one or more output devices, shown as input / output devices 490. These input / output devices 490 may include keyboards, sound or voice input devices, tactile, touch-, pressure-sensitive, and / or swipe-based input devices, displays, speakers, etc. The foregoing devices are examples and others may be used.
[0089] As used herein, the term computer-readable medium may include non-transitory computer storage media, which may include volatile and non-volatile, removable and non-removable media implemented in any method or technology for storage of information, such as computer-readable instructions, data structures, or program modules.
[0090] System memory 420, removable storage 460, and non-removable storage 470 are all examples of computer storage media (e.g., memory storage). Computer storage media may include memory technologies such as RAM, ROM, electrically erasable read-only memory (EEPROM), flash memory, optical storage such as CD-ROMs, digital versatile disks (DVDs), magnetic storage devices such as magnetic cassettes, magnetic tape, magnetic disk storage, or any other article of manufacture usable to store information and accessible by computing device 400. Any such computer storage media may be part of computing device 400. Computer storage media may be tangible and non-transitory, and do not include propagated or modulated data signals, such as carrier waves.
[0091] Communication media may be embodied by computer-readable instructions, data structures, program modules, or other data in a modulated data signal (e.g., carrier wave or other transport mechanism) and includes any information transmission media. The term "modulated data signal" may describe a signal that has one or more characteristics set or changed in such a manner as to encode information in the signal. By way of example, and not limitation, communication media may include wired media such as a wired network or direct-wired connection, and wireless media such as acoustic, radio frequency (RF), infrared and other wireless media.
[0092] The terms used herein are merely for the purpose of describing particular examples and are not intended to limit the concepts of the present invention. Furthermore, unless expressly stated, the embodiments described herein are not mutually exclusive. Aspects of the embodiments described herein may be combined in some implementations.
[0093] As used herein, the singular forms "a" and "an" are intended to include the plural forms unless the context clearly indicates otherwise. It is further understood that the terms "comprises" and / or "comprising," when used herein, specify the presence of stated features, integers, steps, operations, elements, and / or components, but do not exclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof. As used herein, the term "and / or" includes any of the associated listed items, and any and all combinations of one or more of them. Expressions such as "at least one of," when placed before a list of elements, modify the entire list of elements, and not each individual element of the list. Furthermore, the use of "may," when describing examples of the inventive concepts, refers to "one or more embodiments of the present disclosure." Also, the term "exemplary" is intended to refer to an example or illustration. As used herein, the terms "use," "using," and "used" may be considered synonymous with the terms "utilize," "utilizing," and "utilized," respectively.
[0094] As will be apparent to those skilled in the art, embodiments of the present system and method have several technical advantages by preventing or making DNS amplification attacks more difficult, including, among other advantages, savings in computational resources, bandwidth usage, and increased user productivity.
[0095] In one aspect, the technology includes a method comprising: analyzing network traffic information; identifying a Domain Name System (DNS) amplification attack based on the network traffic information; invoking a threat mitigation action in response to identifying the DNS amplification attack; receiving a Domain Name System (DNS) query from a source address; determining, by a DNS server, that a payload size of a response to the DNS query exceeds a threshold payload size; and discarding the response to the DNS query based on the threat mitigation action.
[0096] In one embodiment, and in combination with any of the above aspects and embodiments, detecting a DNS amplification attack includes determining a rate of traffic from a source address over a period of time; and determining that the rate of traffic exceeds a threshold rate.
[0097] In another embodiment, and in combination with any of the above aspects and embodiments, detecting a DNS amplification attack includes examining payloads of multiple first responses generated by the DNS server over a period of time; and determining that one or more payloads of the multiple first responses exceed a threshold payload size.
[0098] In another embodiment, and in combination with any of the above aspects and embodiments, detecting a DNS amplification attack includes determining a past ratio based on one or more past DNS queries and one or more past responses; determining a current ratio based on recent DNS queries and associated DNS responses in a particular time period; and determining that a difference between the current ratio and the past ratio exceeds a threshold.
[0099] In another embodiment, and in combination with any of the above aspects and embodiments, the threat mitigation measures include deploying filtering rules to filter responses to the DNS queries.
[0100] In another embodiment, and in combination with any of the above aspects and embodiments, filtering rules are deployed in routers to filter responses to DNS queries.
[0101] In another embodiment, and in combination with any of the above aspects and embodiments, filtering rules are deployed in a DNS server to filter responses to DNS queries.
[0102] In another embodiment, and in combination with any of the above aspects and embodiments, the filtering rules include a source address and a threshold payload size.
[0103] In another embodiment, and in combination with any of the above aspects and embodiments, the method further includes dynamically determining the threshold payload size based on the machine learning model and previous responses to DNS queries within the specified period.
[0104] In another embodiment, and in combination with any of the above aspects and embodiments, the DNS server calculates an expected payload size of the response before generating the response, wherein discarding the response to the DNS query includes not generating the response.
[0105] In another aspect, the technology includes a system having the following elements: at least one processor; and a memory storing instructions that, when executed by the at least one processor, cause the system to perform a method. In one embodiment, the method includes analyzing network traffic information; identifying a Domain Name System (DNS) amplification attack based on the network traffic information; invoking a threat mitigation action in response to identifying the DNS amplification attack; receiving a Domain Name System (DNS) query from a source address; determining, by a DNS server, that a payload size of the response to the DNS query exceeds a threshold payload size; and discarding the response to the DNS query based on the threat mitigation action.
[0106] In another embodiment, and in combination with any of the above aspects and embodiments, detecting a DNS amplification attack includes determining a rate of traffic from a source address over a period of time; and determining that the rate of traffic exceeds a threshold rate.
[0107] In another embodiment, and in combination with any of the above aspects and embodiments, detecting a DNS amplification attack includes examining payloads of multiple first responses generated by the DNS server over a period of time; and determining that one or more payloads of the multiple first responses exceed a threshold payload size.
[0108] In another embodiment, and in combination with any of the above aspects and embodiments, detecting a DNS amplification attack includes determining a past ratio based on one or more past DNS queries and one or more past responses; determining a current ratio based on recent DNS queries and associated DNS responses in a particular time period; and determining that a difference between the current ratio and the past ratio exceeds a threshold.
[0109] In another embodiment, and in combination with any of the above aspects and embodiments, the threat mitigation measures include deploying filtering rules to filter responses to the DNS queries.
[0110] In another embodiment, and in combination with any of the above aspects and embodiments, filtering rules are deployed in routers to filter responses to DNS queries.
[0111] In another embodiment, and in combination with any of the above aspects and embodiments, filtering rules are deployed in a DNS server to filter responses to DNS queries.
[0112] In another embodiment, and in combination with any of the above aspects and embodiments, the filtering rules include a source address and a threshold payload size.
[0113] In another embodiment, and in combination with any of the above aspects and embodiments, the method further comprises dynamically determining the threshold payload size based on the machine learning model and previous responses to DNS queries within the specified period.
[0114] In another aspect, the present technology includes a system comprising: at least one processor; and a memory storing instructions that, when executed by the at least one processor, cause the system to perform a method. In one embodiment, the method includes the steps of: the method includes steps of: analyzing network traffic information; identifying a Domain Name System (DNS) amplification attack based on the network traffic information; dynamically determining a threshold payload size based on the machine learning model and network traffic information received within a specified first period of time; invoking threat mitigation actions including distributing a filtering notice to at least one network device in response to identifying the DNS amplification attack, wherein the filtering notice includes instructions to cause the at least one network device to receive a current DNS query from a source address; receive a response to the current DNS query; determine that the payload size of the response to the current DNS query exceeds a threshold payload size; and, based on the determination that the payload size of the response to the current DNS query exceeds the threshold payload size, discard the response to the DNS query; dynamically determining an updated threshold payload size based on the machine learning model and network traffic information received within a specified second period of time; and distributing an updated filtering notice including the updated threshold payload size to the at least one network device.
[0115] While exemplary embodiments of systems and methods for mitigating DNS amplification attacks have been specifically described and illustrated herein, many modifications and variations will be apparent to those skilled in the art. Accordingly, it should be understood that systems and methods for mitigating DNS amplification attacks constructed in accordance with the principles of the present disclosure may be embodied other than as specifically described herein. The present disclosure is also defined by the following claims and their equivalents.
Claims
1. analyzing the network traffic information; identifying a Domain Name System (DNS) amplification attack based on the network traffic information; invoking threat mitigation measures in response to identifying the DNS amplification attack; receiving a Domain Name System (DNS) query from a source address; determining by the DNS server that a payload size of a response to the DNS query exceeds a threshold payload size; and discarding the response to the DNS query based on the threat mitigation action. A method for providing the above.
2. The step of identifying the DNS amplification attack includes: determining a rate of traffic from the source address over a period of time; and determining that the rate of the traffic exceeds a threshold rate; The method of claim 1 , comprising:
3. The step of identifying the DNS amplification attack includes: examining payloads of a plurality of first responses generated by the DNS server over a period of time; and determining that one or more payloads of the plurality of first responses exceed the threshold payload size; The method of claim 1 , comprising:
4. The step of identifying the DNS amplification attack includes: determining a historical ratio based on one or more historical DNS queries and one or more historical responses; determining a current ratio based on recent DNS queries and associated DNS responses over a specified time period; and determining that a difference between the current ratio and the past ratio exceeds a threshold; The method of claim 1 , comprising:
5. The method of claim 1 , wherein the threat mitigation action includes deploying a filtering rule to filter the response to the DNS query.
6. The method of claim 5 , wherein the filtering rules are deployed in a router to filter the responses to the DNS queries.
7. The method of claim 5 , wherein the filtering rules are deployed to the DNS server for filtering the responses to the DNS queries.
8. The method of claim 5 , wherein the filtering rules include the source address and the threshold payload size.
9. 10. The method of claim 1, further comprising dynamically determining the threshold payload size based on a machine learning model and previous responses to DNS queries within a specified period of time.
10. 2. The method of claim 1, wherein the DNS server calculates an expected payload size of the response before generating the response, and discarding the response to the DNS query includes not generating the response.
11. 1. A system comprising: at least one processor; and a memory storing instructions that, when executed by the at least one processor, cause the system to perform a method; wherein the method comprises: analyzing the network traffic information; identifying a Domain Name System (DNS) amplification attack based on the network traffic information; invoking threat mitigation measures in response to identifying the DNS amplification attack; receiving a Domain Name System (DNS) query from a source address; determining by the DNS server that a payload size of a response to the DNS query exceeds a threshold payload size; and discarding the response to the DNS query based on the threat mitigation action. A system comprising:
12. The step of identifying the DNS amplification attack includes: determining a rate of traffic from the source address over a period of time; and determining that the rate of the traffic exceeds a threshold rate; The system of claim 11 , comprising:
13. The step of identifying the DNS amplification attack includes: examining payloads of a plurality of first responses generated by the DNS server over a period of time; and determining that one or more payloads of the plurality of first responses exceed the threshold payload size; The system of claim 11 , comprising:
14. The step of identifying the DNS amplification attack includes: determining a historical ratio based on one or more historical DNS queries and one or more historical responses; determining a current ratio based on recent DNS queries and associated DNS responses over a specified time period; and determining that a difference between the current ratio and the past ratio exceeds a threshold; The system of claim 11 , comprising:
15. The system of claim 11 , wherein the threat mitigation action includes deploying a filtering rule to filter the response to the DNS query.
16. 16. The system of claim 15, wherein the filtering rules are deployed in a router to filter the responses to the DNS queries.
17. 16. The system of claim 15, wherein the filtering rules are deployed to the DNS server for filtering the responses to the DNS queries.
18. The system of claim 15 , wherein the filtering rules include the source address and the threshold payload size.
19. 12. The system of claim 11, wherein the method further comprises dynamically determining the threshold payload size based on a machine learning model and previous responses to DNS queries within a specified period of time.
20. 1. A system comprising: at least one processor; and a memory storing instructions that, when executed by the at least one processor, cause the system to perform a method; wherein the method comprises: analyzing the network traffic information; identifying a Domain Name System (DNS) amplification attack based on the network traffic information; dynamically determining a threshold payload size based on a machine learning model and the network traffic information received within a specified first time period; In response to identifying the DNS amplification attack, invoking threat mitigation measures including distributing a filtering notice to at least one network device, wherein the filtering notice includes a notification to the at least one network device. Have the current DNS query received from the source address; receiving a response to the current DNS query; determining that the payload size of the response to the current DNS query exceeds the threshold payload size; and Discarding the response to the DNS query based on a determination that the payload size of the response to the current DNS query exceeds the threshold payload size. Includes instructions; dynamically determining an updated threshold payload size based on the machine learning model and the network traffic information received within a specified second time period; and distributing an updated filtering notification including the updated threshold payload size to the at least one network device; A system comprising: