181
Naming Services in the Internet of Things
9.3.3 ONS Security Analysis
DNS is an old and central Internet service with a long history of security and configuration
issues in the protocol itself and in particular implementations. Various vulnerabilities and
attacks can be listed by consulting established security sites as CERT, SecurityFocus, and
the SANS Institute’s top 20 list of internet security vulnerabilities.
A corresponding request-for-comments, RFC 3833 Threat Analysis of the DNS, was
published quite late after two decades of DNS use, though many of its security problems
have been identified before. Some of the main threats discussed are packet interception,
i.e., manipulating IP packets carrying DNS information, query prediction by manipulating
the query and answer schemes of the DNS protocol, cache poisoning by injecting manipulated information into DNS caches, betrayal by trusted servers controlled by an attacker,
and denial of service, a threat to every Internet service—but DNS itself might be used as
an amplifier to attack third parties.
Besides bugs in the code, the fundamental reason for most of these vulnerabilities is the
fact that even though DNS is a central and highly exposed service by definition, it has—in
its original and widely deployed form—no way of authenticating a client, the server, nor
the information that is provided. In addition, DNS uses a clear text protocol, as do most of
the early IPs.
These DNS weaknesses directly transfer to ONS. In the following sections, a discussion
on ONS availability, integrity, and confidentiality risks is given.
9.3.3.1 ONS Availability
ONS will constitute a service highly exposed to attacks from the Internet, if only due to
its necessary widespread accessibility. A particular threat is denial of service (DoS), which
abuses system and network resources to make the service unavailable or unusably slow
for legitimate users. This could include DDoS attacks overwhelming a particular server or
its network connection by issuing countless and intense queries, e.g., by the use of zombie networks, Botnets or the so-called Puppetnets, i.e., hosts controlled by browser-based
malware. DoS attacks can also use more sophisticated methods, e.g., targeted exploits that
shut down the DNS server software or the operating system. Though distributed, DNS
suffers from limited redundancy in practical implementations. Authoritative name servers for any given zone should be redundant according to RFC 1034. Recent studies on real
implementations, however, show that for a non-insignificant part of the global name-space
this requirement does not hold. Name servers storing the same information for a given
zone are often few and not redundantly placed with respect to geographical location and
IP subnets, and often reside inside of the same autonomous system (AS). There are many
servers that have single distinct routing bottlenecks on paths to reach them—from every
place in the world.
The small number of servers for a given zone information, and their limited redundancy creates single points or small areas of failure. Those are also attractive targets for
DDoS attacks—not only at the DNS root, which is currently run by fewer than 150 servers
and has been attacked with some, but so far moderate, success before. Failure of the root,
though, would after some time to account for caching imply failure of the whole system,
not only of some of its subtrees. Root and TLD servers, as well as name servers for domains
that rise in popularity (flash crowds, for example the famous Slashdot effect), suffer from
strong load imbalance induced by the architecture. Omnipresent DNS caching, on the
other hand, reduces flexibility and the speed of update propagation. Studies also show the
Précédent

- 206/358

Suivant