Research on Defense Strategy of Kaminsky DNS Cache Poisoning

XU Cheng-xi,HU Rong-gui,SHI Fan,ZHANG Yan-qing
DOI: https://doi.org/10.3969/j.issn.1000-3428.2013.01.003
2013-01-01
Abstract:Current cache Domain Name System(DNS) servers can not resist continuing Kaminsky DNS cache poisoning,so this paper proposes a defense strategy based on response packets checking.Probability theory is used to analyze the internal relation between success probability and continuing time of poisoning,which attests the harmfulness of continuing Kaminsky poisoning.Packet checking suppresses success probability's accumulative effect on time on the existing basis so that it can be used to defense continuing Kaminsky poisoning.Simulation experiment is conducted based on probabilistic model checking tool PRISM,whose results prove that the strategy can make poison attack more difficult by over 3 600 times than it is now.
What problem does this paper attempt to address?