what is all that crap
play

What is all that crap? Analysis of DNS root server bogus queries - PowerPoint PPT Presentation

RIPE Network Coordination Centre What is all that crap? Analysis of DNS root server bogus queries Authors: Danil Snchez & Joost Pijnaker Education: System & Network Engineering Supervisors: Cees de Laat (UvA) Daniel


  1. RIPE Network Coordination Centre “What is all that crap?” Analysis of DNS root server bogus queries Authors: Daniël Sánchez & Joost Pijnaker Education: System & Network Engineering Supervisors: Cees de Laat (UvA) Daniel Karrenberg (RIPE NCC) Date: 07-02-2007 14:00 http://www.ripe.net

  2. RIPE Network Coordination Centre Agenda ● Organisation ● Project introduction ● Research ● Conclusion ● Questions http://www.ripe.net

  3. RIPE Network Coordination Centre Agenda ● Organisation ● Project introduction ● Research ● Conclusion ● Questions http://www.ripe.net

  4. RIPE Network Coordination Centre Organisation: RIPE NCC http://www.ripe.net http://www.ripe.net

  5. RIPE Network Coordination Centre Organisation: K-Root server http://k.root-servers.org http://www.ripe.net

  6. RIPE Network Coordination Centre Organisation: DNS Root server http://faq.oneandone.co.uk http://www.ripe.net

  7. RIPE Network Coordination Centre Agenda ● Organisation ● Project introduction ● Research ● Conclusion ● Questions http://www.ripe.net

  8. RIPE Network Coordination Centre Agenda ● Organisation ● Project introduction ● Research ● Conclusion ● Questions http://www.ripe.net

  9. RIPE Network Coordination Centre Project introduction ● Problem definition ● Research question ● Research scope ● Capture data ● Tools http://www.ripe.net

  10. RIPE Network Coordination Centre Project introduction: Capture data http://www.ripe.net

  11. RIPE Network Coordination Centre Project introduction: Tools ● Tcpdump ● Ethereal ● dnstop ● Scripts (awk, Ruby) http://www.ripe.net

  12. RIPE Network Coordination Centre Agenda ● Organisation ● Project introduction ● Research ● Conclusion ● Questions http://www.ripe.net

  13. RIPE Network Coordination Centre Agenda ● Organisation ● Project introduction ● Research ● Conclusion ● Questions http://www.ripe.net

  14. RIPE Network Coordination Centre Research ● Determine bogus categories ● Filter capture data ● Statistics ● Determine possible causes ● Determine possible solutions http://www.ripe.net

  15. RIPE Network Coordination Centre Research ● Determine bogus categories ● Filter capture data ● Statistics ● Determine possible causes ● Determine possible solutions http://www.ripe.net

  16. RIPE Network Coordination Centre Research: Bogus categories ● A for A queries ● Private IP reverse queries ● Reserved IP reverse queries ● Local domain queries ● Invalid TLD queries ● Identical query IDs queries ● Repeated queries ● TLD not cached queries http://www.ripe.net

  17. RIPE Network Coordination Centre A for A queries A? x.y.80.66. http://www.ripe.net

  18. RIPE Network Coordination Centre Private IP reverse queries PTR? 1.0.0.127.in-addr.arpa. http://www.ripe.net

  19. RIPE Network Coordination Centre Reserved IP reverse queries PTR? 192.168.253.241.in-addr.arpa. http://www.ripe.net

  20. RIPE Network Coordination Centre Local domain queries A? svr004.network.local. http://www.ripe.net

  21. RIPE Network Coordination Centre Invalid TLD queries A? Maschult1.Speedport_W_700V. http://www.ripe.net

  22. RIPE Network Coordination Centre Same query IDs queries id 5134, A? www.google.com. id 5134, A? www.os3.nl. http://www.ripe.net

  23. RIPE Network Coordination Centre Repeated queries IP x.y.96.200 A? www.os3.nl. IP x.y.96.200 A? www.os3.nl. IP x.y.96.200 A? www.os3.nl. IP x.y.96.200 A? www.os3.nl. http://www.ripe.net

  24. RIPE Network Coordination Centre TLD not cached queries IP x.y.96.200 A? www.os3.nl. IP x.y.96.200 A? www.google.nl. http://www.ripe.net

  25. RIPE Network Coordination Centre Research ● Determine bogus categories ● Filter capture data ● Statistics ● Determine possible causes ● Determine possible solutions http://www.ripe.net

  26. RIPE Network Coordination Centre Research ● Determine bogus categories ● Filter capture data ● Statistics ● Determine possible causes ● Determine possible solutions http://www.ripe.net

  27. RIPE Network Coordination Centre Research: Filter capture data http://www.ripe.net

  28. RIPE Network Coordination Centre Research: Filter capture data 17:10:34.283465 A? A-1FREEMAN.COM.INBOUND10.MXLOGIC.NET. 17:10:34.933914 A? A-1FREEMAN.COM.INBOUND10.MXLOGIC.NET. 17:10:35.203961 A? A-1FREEMAN.COM.INBOUND10.MXLOGIC.NET. 17:10:35.498391 A? A-1FREEMAN.COM.INBOUND10.MXLOGIC.NET. 17:10:34.283465 A? A-1FREEMAN.COM.INBOUND10.MXLOGIC.NET. http://www.ripe.net

  29. RIPE Network Coordination Centre Research ● Determine bogus categories ● Filter capture data ● Statistics ● Determine possible causes ● Determine possible solutions http://www.ripe.net

  30. RIPE Network Coordination Centre Research ● Determine bogus categories ● Filter capture data ● Statistics ● Determine possible causes ● Determine possible solutions http://www.ripe.net

  31. RIPE Network Coordination Centre Research: Statistics http://www.ripe.net

  32. RIPE Network Coordination Centre Research: Statistics http://www.ripe.net

  33. RIPE Network Coordination Centre Research: Statistics http://www.ripe.net

  34. RIPE Network Coordination Centre Research ● Determine bogus categories ● Filter capture data ● Statistics ● Determine possible causes ● Determine possible solutions http://www.ripe.net

  35. RIPE Network Coordination Centre Research ● Determine bogus categories ● Filter capture data ● Statistics ● Determine possible causes ● Determine possible solutions http://www.ripe.net

  36. RIPE Network Coordination Centre Research: Causes ● Software bugs • A for A, Private IP reverse ● Not updated software • A for A ● Misconfigured software • Private IP reverse, TLD not cached ● Firewalls • Repeated http://www.ripe.net

  37. RIPE Network Coordination Centre Research ● Determine bogus categories ● Filter capture data ● Statistics ● Determine possible causes ● Determine possible solutions http://www.ripe.net

  38. RIPE Network Coordination Centre Research ● Determine bogus categories ● Filter capture data ● Statistics ● Determine possible causes ● Determine possible solutions http://www.ripe.net

  39. RIPE Network Coordination Centre Research: Solutions “Client” side: ● Install and use stable software ● Update software ● Configure software appropriatly http://www.ripe.net

  40. RIPE Network Coordination Centre Research: Solutions “Server” side: ● Access lists ● u(RPF) ● Contact software vendors ● Contact the owners of “big” sources ● Add additional servers http://www.ripe.net

  41. RIPE Network Coordination Centre Agenda ● Organisation ● Project introduction ● Research ● Conclusion ● Questions http://www.ripe.net

  42. RIPE Network Coordination Centre Agenda ● Organisation ● Project introduction ● Research ● Conclusion ● Questions http://www.ripe.net

  43. RIPE Network Coordination Centre Conclusion Statistics: ● Total % of bogus: AMS-IX: 80.70% NAP: 14.65% ● Top 10 IP addresses responsible: AMS-IX: 10.75% NAP: 42.40% ● Sources: 3 or 4 octets? http://www.ripe.net

  44. RIPE Network Coordination Centre Conclusion Solutions: ● Contact software vendors ● Contact owners big sources ● Add additional servers http://www.ripe.net

  45. RIPE Network Coordination Centre Agenda ● Organisation ● Project introduction ● Research ● Conclusion ● Questions http://www.ripe.net

  46. RIPE Network Coordination Centre Agenda ● Organisation ● Project introduction ● Research ● Conclusion ● Questions http://www.ripe.net

  47. RIPE Network Coordination Centre Questions? http://www.ripe.net

Recommend


More recommend