Silence is Not Golden: Disrupting the Load Balancing of Authoritative DNS Servers

Fenglu Zhang,Baojun Liu,Eihal Alowaisheq,Jianjun Chen,Chaoyi Lu,L. M. Song,Yue Ma,Ying Liu,Haixin Duan,Min Yang
DOI: https://doi.org/10.1145/3603165.3607438
2023-01-01
Abstract:We present a new attack, the Disablance, that disrupts the load balancing for authoritative DNS servers. We discovered a prevalent misconfiguration for nameservers and an implementation decision in mainstream DNS software that an adversary can leverage to divert legitimate DNS traffic to a targeted nameserver. Through a systematic evaluation, we confirmed that Disablance is realistic, efficient, and prevalent. In total, 22.24% of the top 1M FQDNs and 3.94% of the top 1M SLDs can be victims of Disablance. Besides, a number of stable open resolvers and several well-known public DNS service providers are also exploitable. Moving forward, we provided suggestions to mitigate the threat of Disablance and responsibly disclosed this issue to service providers. As of the time of writing this paper, several renowned vendors have taken action to fix it.
What problem does this paper attempt to address?