[dns-operations] about DNS attack

Ralf Weber Ralf.Weber at nominum.com
Fri May 30 23:58:36 UTC 2014


Moin!

On 30 May 2014, at 01:36, Roland Dobbins <rdobbins at arbor.net> wrote:
> On May 30, 2014, at 3:30 PM, hua peng <huapeng at arcor.de> wrote:
> 
>> I am just curious that for a common DNS cluster how can it defend that large a flood? 
> 
> Most attacks of that size are DNS reflection/amplification attacks, not query-floods:
> 
> <https://app.box.com/s/r7an1moswtc7ce58f8gg>
And most are caused by open DNS proxies/resolvers. See:

	https://conference.apnic.net/data/37/119-rw-dns-amplification-apricot-rw03_1393420184.pdf

not sure if there is propaganda in there, but my company paid me to research that.

So long
-Ralf
---
Ralf Weber
Senior Infrastructure Architect
Nominum Inc.
2000 Seaport Blvd. Suite 400 
Redwood City, California 94063
ralf.weber at nominum.com






More information about the dns-operations mailing list