Академический Документы
Профессиональный Документы
Культура Документы
ERIK WU
ACALVIO, INC.
Intro
Subdomain
Mechanism
Impact
Outro
Good
Bad
Ugly
DNS
104.20.66.243
Intro
Subdomain
Mechanism
Impact
Outro
Good
Bad
Ugly
DNS
blackhat.com.
DNS
104.20.66.243
104.20.66.243
Intro
Subdomain
Mechanism
Impact
Outro
Good
Bad
Ugly
1200
1000
800
600
400
200
1993
1994
1995
1996
1997
1998
1999
2000
2001
2002
2003
2004
2005
2006
2007
2008
2009
2010
2011
2012
2013
2014
2015
2016
Source S tatista
Intro
Subdomain
Mechanism
Impact
Outro
Good
Bad
Ugly
FLASHING IN
MARCH 2013
300gbps DNS
amplification
attacks
27.2M open
DNS resolvers
(in 2013)
17.6M of today
(>3yrs later)
Source openresolverproject.org
Responses
Unique
Correct Responses
Wrong Port
RA
Intro
Subdomain
Mechanism
Impact
Outro
Good
Bad
Ugly
Enablers
Open DNS resolvers
DNS amplifiers
DNS Amplifier
Legit
Purpose-built
Open
Resolver
Open
Resolver
attacker
victim
Intro
Subdomain
Mechanism
Impact
Outro
Good
Bad
Ugly
Legit | Purpose-built
Intro
Subdomain
Mechanism
Impact
Outro
Good
Bad
Ugly
Legit | Purpose-built
Intro
Subdomain
Mechanism
Impact
Outro
Good
Bad
Ugly
Legit | Purpose-built
Intro
Subdomain
Mechanism
Impact
Outro
Good
Bad
Ugly
Legit | Purpose-built
Intro
Subdomain
Mechanism
Impact
Outro
Good
Bad
Ugly
Mitigation options
Filter spoofed sending addresses
Disarm amplifiers
Close open resolvers
Intro
Subdomain
Mechanism
Impact
Outro
Good
Bad
Ugly
6000
5000
4000
3000
2000
1000
0
Source: Nominum
Intro
Subdomain
Mechanism
Impact
Outro
Good
Bad
Ugly
104.20.66.243
NXDOMAIN
Intro
Subdomain
Mechanism
Impact
Outro
Initial Trial
Serious
weapon
Subdomain attack as a
competitive edge
100000000.sf520.com.
100000001.sf520.com.
100000010.sf520.com.
100000011.sf520.com.
100000100.sf520.com.
100000101.sf520.com.
100000110.sf520.com.
100000111.sf520.com.
100001000.sf520.com.
Intro
Subdomain
Mechanism
Impact
Outro
Initial Trial
Serious
weapon
Intro
Subdomain
Mechanism
Impact
Outro
Initial Trial
Serious
weapon
Intro
Subdomain
Mechanism
Impact
Outro
Strings
Position
Composition
Subdomain strings
SUBDOMAIN STRINGS:
Fixed or varying length:
z5kr836ws qjkn
zdecc7nnx
styzcphur
Time stamps:
1465560729 1465561210
Random strings
WO423WWWOX5C
FN88RBHXWX9J
Random numbers
2967230841
4343234574
Sequence numbers
1165885261118
1165885261119
Dictionary words
glassmaking
dishwater
Intro
Subdomain
Mechanism
Impact
Outro
Strings
Position
Composition
Subdomain position
SUBDOMAIN POSITION:
Left most
2nd left most
3rd left most
Any position on the left side of target domain
zdecc7nnx.www.blackhat.com.
m.zdecc7nnx.www.blackhat.com.
n.m.zdecc7nnx.www.blackhat.com.
Intro
Subdomain
Mechanism
Impact
Outro
Strings
Position
Composition
Subdomain composition
SUBDOMAIN COMPOSITION:
Single subdomain string
Multiple subdomain strings
FN88RBHXWX9J.blackhat.com.
WO423WW1WX5.FN88RBHXWX9J.blackhat.com.
a.FN88RBHXWX9J.blackhat.com.
b.WO423WW1WX5.blackhat.com.
Intro
Subdomain
Mechanism
Impact
Outro
Operation
Mitigation
Impact
Resolver
Resolver
what is IP address
of victim.com?
victim.com.
Intro
Subdomain
Mechanism
Impact
Outro
Operation
Mitigation
Operation Disruption
2gbps vs 300gbps
Intro
Subdomain
Mechanism
Impact
Outro
Operation
Mitigation
Mitigation Option
Intro
Subdomain
Mechanism
Impact
Outro
Innovation
Defense
Intro
Subdomain
Mechanism
Impact
Outro
Innovation
Defense
Rethinking of our
defense strategy
Deception to help rebalance the
asymmetric warfare situation between
the dark-side and us