Ghost Domain Names: Revoked Yet Still Resolvable.

Jian Jiang,Jinjin Liang,Kang Li,Jun Li,Hai-Xin Duan,Jianping Wu
2012-01-01
Abstract:Attackers often use domain names for various malicious purposes such as phishing, botnet command and control, and malware propagation. An obvious strategy for preventing these activities is deleting the malicious domain from the upper level DNS servers. In this paper, we show that this is insufficient. We demonstrate a vulnerability affecting the large majority of popular DNS implementations which allows a malicious domain name to stay resolvable long after it has been removed from the upper level servers. Our experiments with 19,045 open DNS servers show that even one week after a domain name has been revoked and its TTL expired, more than 70% of the servers will still resolve it. Finally, we discuss several strategies to prevent this attack.
What problem does this paper attempt to address?