{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,5]],"date-time":"2026-06-05T04:33:13Z","timestamp":1780633993659,"version":"3.54.1"},"publisher-location":"Cham","reference-count":62,"publisher":"Springer International Publishing","isbn-type":[{"value":"9783030017033","type":"print"},{"value":"9783030017040","type":"electronic"}],"license":[{"start":{"date-parts":[[2018,1,1]],"date-time":"2018-01-01T00:00:00Z","timestamp":1514764800000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2018]]},"DOI":"10.1007\/978-3-030-01704-0_10","type":"book-chapter","created":{"date-parts":[[2018,12,28]],"date-time":"2018-12-28T16:02:50Z","timestamp":1546012970000},"page":"171-191","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":5,"title":["Adaptive Deterrence of DNS Cache Poisoning"],"prefix":"10.1007","author":[{"given":"Sze Yiu","family":"Chau","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Omar","family":"Chowdhury","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Victor","family":"Gonsalves","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Huangyi","family":"Ge","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Weining","family":"Yang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Sonia","family":"Fahmy","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ninghui","family":"Li","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2018,12,29]]},"reference":[{"key":"10_CR1","unstructured":"5 Myths about Content Delivery Networks and the truths you should know. https:\/\/www.thatwhitepaperguy.com\/downloads\/5-CDN-Myths.pdf"},{"key":"10_CR2","unstructured":"Vulnerability Note VU 800113: Multiple DNS implementations vulnerable to cache poisoning. Technical report, US CERT Vulnerability Notes Database (2008)"},{"key":"10_CR3","unstructured":"DNS Census 2013 (2013). https:\/\/dnscensus2013.neocities.org"},{"key":"10_CR4","unstructured":"DNS, DNSSEC and Google\u2019s Public DNS Service (2013). http:\/\/www.circleid.com\/posts\/20130717_dns_dnssec_and_googles_public_dns_service\/"},{"key":"10_CR5","unstructured":"Google\u2019s Malaysian domains hit with DNS cache poisoning attack (2013). http:\/\/www.tripwire.com\/state-of-security\/latest-security-news\/googles-malaysian-domains-hit-dns-cache-poisoning-attack\/"},{"key":"10_CR6","unstructured":"DNS poisoning slams web traffic from millions in China into the wrong hole (2014). http:\/\/www.theregister.co.uk\/2014\/01\/21\/china_dns_poisoning_attack\/"},{"key":"10_CR7","unstructured":"Google Public DNS - Security Benefits (2014). https:\/\/developers.google.com\/speed\/public-dns\/docs\/security"},{"key":"10_CR8","unstructured":"CloudFlare Enables Universal DNSSEC for Its Millions of Customers for Free (2015). http:\/\/www.marketwired.com\/press-release\/cloudflare-enables-universal-dnssec-for-its-millions-of-customers-for-free-2072174.htm"},{"key":"10_CR9","unstructured":"DNSSEC name and shame! (2015). https:\/\/dnssec-name-and-shame.com\/"},{"key":"10_CR10","doi-asserted-by":"crossref","unstructured":"Ager, B., Dreger, H., Feldmann, A.: Predicting the DNSSEC overhead using DNS traces. In: 40th IEEE CISS (2006)","DOI":"10.1109\/CISS.2006.286699"},{"key":"10_CR11","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"18","DOI":"10.1007\/978-3-642-15512-3_2","volume-title":"Recent Advances in Intrusion Detection","author":"M Antonakakis","year":"2010","unstructured":"Antonakakis, M., Dagon, D., Luo, X., Perdisci, R., Lee, W., Bellmor, J.: A centralized monitoring infrastructure for improving DNS security. In: Jha, S., Sommer, R., Kreibich, C. (eds.) RAID 2010. LNCS, vol. 6307, pp. 18\u201337. Springer, Heidelberg (2010). https:\/\/doi.org\/10.1007\/978-3-642-15512-3_2"},{"key":"10_CR12","unstructured":"APNIC Labs: Use of DNSSEC validation for world (2015). http:\/\/stats.labs.apnic.net\/dnssec\/XA"},{"key":"10_CR13","unstructured":"Assolini, F.: Attacks against Boletos (2014). https:\/\/securelist.com\/attacks-against-boletos\/66591\/"},{"key":"10_CR14","unstructured":"Bernstein, D.J.: DNSCurve: usable security for DNS (2009). http:\/\/dnscurve.org\/"},{"key":"10_CR15","unstructured":"Bernstein, D.J.: DNS forgery (2002). http:\/\/cr.yp.to\/djbdns\/forgery.html"},{"key":"10_CR16","doi-asserted-by":"crossref","unstructured":"Calder, M., Flavel, A., Katz-Bassett, E., Mahajan, R., Padhye, J.: Analyzing the performance of an anycast CDN. In: Proceedings of ACM IMC, pp. 531\u2013537 (2015)","DOI":"10.1145\/2815675.2815717"},{"key":"10_CR17","unstructured":"CCCen: An overview of secure name resolution [29c3] (2013). https:\/\/www.youtube.com\/watch?v=eOGezLjlzFU"},{"key":"10_CR18","unstructured":"Catalin Cimpanu: Around four in five DNSSEC servers can be hijacked for DDoS attacks (2016). http:\/\/news.softpedia.com\/news\/around-four-in-five-dnssec-servers-can-be-used-in-ddos-attacks-507503.shtml"},{"key":"10_CR19","unstructured":"CommunityDNS: Performance testing of BIND, NSD and CDNS platforms on identical hardware (2010). http:\/\/communitydns.net\/DNSSEC-Performance.pdf"},{"key":"10_CR20","unstructured":"Constantin, L.: DNS cache poisoning used in Brazilian phishing attack (2011). http:\/\/news.softpedia.com\/news\/DNS-Cache-Poisoning-Used-in-Brazilian-Phishing-Attack-212328.shtml"},{"key":"10_CR21","unstructured":"Czarny, M.: How anycast IP routing is used at MaxCDN (2013). https:\/\/www.maxcdn.com\/blog\/anycast-ip-routing-used-maxcdn\/"},{"key":"10_CR22","doi-asserted-by":"crossref","unstructured":"Dagon, D., Antonakakis, M., Vixie, P., Jinmei, T., Lee, W.: Increased DNS forgery resistance through 0x20-bit encoding: security via LeET queries. In: Proceedings of the 15th ACM CCS, pp. 211\u2013222 (2008)","DOI":"10.1145\/1455770.1455798"},{"key":"10_CR23","unstructured":"Duan, H., et al.: Hold-on: protecting against on-path DNS poisoning. In: Securing and Trusting Internet Names (SATIN) (2012)"},{"key":"10_CR24","unstructured":"Flavel, A., et al.: FastRoute: a scalable load-aware anycast routing architecture for modern CDNs. In: 12th USENIX NSDI, pp. 381\u2013394 (2015)"},{"key":"10_CR25","unstructured":"Godard, S.: sysstat - system Performance tools for the Linux operating system (2015). https:\/\/github.com\/sysstat\/sysstat"},{"key":"10_CR26","unstructured":"Gu\u00f0mundsson, \u00d3., Crocker, S.D.: Observing DNSSEC validation in the wild. In: Securing and Trusting Internet Names (SATIN) (2011)"},{"issue":"1","key":"10_CR27","doi-asserted-by":"publisher","first-page":"66","DOI":"10.1109\/MIC.2014.14","volume":"18","author":"A Herzberg","year":"2014","unstructured":"Herzberg, A., Shulman, H.: Retrofitting security into network protocols: the case of DNSSEC. IEEE Internet Comput. 18(1), 66\u201371 (2014)","journal-title":"IEEE Internet Comput."},{"key":"10_CR28","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"271","DOI":"10.1007\/978-3-642-33167-1_16","volume-title":"Computer Security \u2013 ESORICS 2012","author":"A Herzberg","year":"2012","unstructured":"Herzberg, A., Shulman, H.: Security of patched DNS. In: Foresti, S., Yung, M., Martinelli, F. (eds.) ESORICS 2012. LNCS, vol. 7459, pp. 271\u2013288. Springer, Heidelberg (2012). https:\/\/doi.org\/10.1007\/978-3-642-33167-1_16"},{"key":"10_CR29","doi-asserted-by":"crossref","unstructured":"Hubert, A., van Mook, R.: Measures for making DNS more resilient against forged answers, January 2009. https:\/\/www.rfc-editor.org\/rfc\/rfc5452.txt","DOI":"10.17487\/rfc5452"},{"key":"10_CR30","unstructured":"Hussain, I.: Google.com.bd down (2016). http:\/\/www.dhakatribune.com\/feature\/2016\/12\/20\/google-com-bd\/"},{"key":"10_CR31","unstructured":"Huston, G.: Measuring DNSSEC use (2013). https:\/\/labs.apnic.net\/presentations\/store\/2013-08-27-dnssec-apnic.pdf"},{"key":"10_CR32","unstructured":"Huston, G., Michaelson, G.: Measuring DNSSEC performance (2013). http:\/\/impossible.rand.apnic.net\/ispcol\/2013-05\/dnssec-performance.pdf"},{"key":"10_CR33","unstructured":"Infoblox: Infoblox DNS Threat Index (2015). https:\/\/www.infoblox.com\/sites\/infobloxcom\/files\/resources\/infoblox-white-paper-dns-threat-index-q2-2015-report.pdf"},{"key":"10_CR34","unstructured":"JUNIPER TechLibrary: Network address translation feature guide for security devices - disabling port randomization for source NAT (CLI Procedure) (2016). https:\/\/www.juniper.net\/documentation\/en_US\/junos\/topics\/task\/configuration\/nat-security-source-port-randomization-disabiling-cli.html"},{"key":"10_CR35","unstructured":"Kaminsky, D.: Black Ops 2008: It\u2019s The End Of The Cache As We Know It (2008)"},{"key":"10_CR36","unstructured":"Kaminsky, D.: DNSSEC Interlude 2: DJB@CCC | Dan Kaminsky\u2019s Blog (2011). http:\/\/dankaminsky.com\/2011\/01\/05\/djb-ccc\/"},{"key":"10_CR37","unstructured":"Levine, M.: Measuring throughput performance: DNS vs. TCP anycast routing (2014). http:\/\/www.cachefly.com\/2014\/07\/11\/measuring-throughput-performance-dns-vs-tcp-anycast-routing\/"},{"key":"10_CR38","unstructured":"Lian, W., Rescorla, E., Shacham, H., Savage, S.: Measuring the practical impact of DNSSEC deployment. In: USENIX Security, pp. 573\u2013588 (2013)"},{"key":"10_CR39","unstructured":"Lindstrom, A.: DNSSEC implementation in Sweden (2012). https:\/\/www.antonlindstrom.com\/2012\/01\/02\/dnssec-implementation-in-sweden.html"},{"key":"10_CR40","unstructured":"Lowe, G., Winters, P., Marcus, M.L.: The great DNS wall of china, December 2007"},{"key":"10_CR41","unstructured":"Nice, B.V.: High performance DNS needs high performance security (2012). http:\/\/nominum.com\/high-performance-dns-needs-high-performance-security\/"},{"key":"10_CR42","unstructured":"NIST National Vulnerability Database: CVE-2002-2211 (2002). http:\/\/web.nvd.nist.gov\/view\/vuln\/detail?vulnId=CVE-2002-2211"},{"key":"10_CR43","first-page":"14","volume":"4","author":"K Park","year":"2004","unstructured":"Park, K., Pai, V.S., Peterson, L.L., Wang, Z.: CoDNS: improving DNS performance and reliability via cooperative lookups. OSDI 4, 14 (2004)","journal-title":"OSDI"},{"key":"10_CR44","doi-asserted-by":"crossref","unstructured":"Perdisci, R., Antonakakis, M., Luo, X., Lee, W.: WSEC DNS: Protecting recursive DNS resolvers from poisoning attacks. In: IEEE\/IFIP International Conference on Dependable Systems & Networks, DSN 2009, pp. 3\u201312. IEEE (2009)","DOI":"10.1109\/DSN.2009.5270363"},{"key":"10_CR45","unstructured":"Poole, L., Pai, V.S.: ConfiDNS: leveraging scale and history to improve DNS security. In: WORLDS (2006)"},{"key":"10_CR46","unstructured":"Prince, M.: A brief primer on Anycast (2011). https:\/\/blog.cloudflare.com\/a-brief-anycast-primer\/"},{"key":"10_CR47","unstructured":"Rashid, F.Y.: Poorly configured DNSSEC servers at root of DDoS attacks (2016). http:\/\/www.infoworld.com\/article\/3109581\/security\/poorly-configured-dnssec-servers-at-root-of-ddos-attacks.html"},{"key":"10_CR48","unstructured":"Raywood, D.: Irish ISP Eircom hit by multiple attacks that restrict service for users (2009). http:\/\/www.scmagazineuk.com\/irish-isp-eircom-hit-by-multiple-attacks-that-restrict-service-for-users\/article\/140243\/"},{"key":"10_CR49","unstructured":"Schuba, C.: Addressing weaknesses in the domain name system protocol. Ph.D. thesis, Purdue University (1993)"},{"key":"10_CR50","unstructured":"Seltzer, L.: Report claims DNS cache poisoning attack against Brazilian Bank and ISP (2009). http:\/\/www.eweek.com\/c\/a\/Security\/Report-Claims-DNS-Cache-Poisoning-Attack-Against-Brazilian-Bank-and-ISP-761709"},{"key":"10_CR51","unstructured":"Shulman, H., Waidner, M.: One key to sign them all considered vulnerable: evaluation of DNSSEC in the Internet. In: NSDI, pp. 131\u2013144 (2017)"},{"key":"10_CR52","first-page":"466","volume-title":"Lecture Notes of the Institute for Computer Sciences, Social Informatics and Telecommunications Engineering","author":"Sooel Son","year":"2010","unstructured":"Son, S., Shmatikov, V.: The Hitchhiker\u2019s guide to DNS cache poisoning. In: Security and Privacy in Communication Networks, pp. 466\u2013483 (2010)"},{"key":"10_CR53","unstructured":"Spring, J.: Probable cache poisoning of mail handling domains (2014). https:\/\/insights.sei.cmu.edu\/cert\/2014\/09\/-probable-cache-poisoning-of-mail-handling-domains.html"},{"key":"10_CR54","unstructured":"StatDNS: TLD zone file statistics (2016). http:\/\/www.statdns.com\/"},{"key":"10_CR55","unstructured":"KeyCDN Support: Anycast (2016). https:\/\/www.keycdn.com\/support\/anycast\/"},{"key":"10_CR56","unstructured":"Tatuya, J.: queryperf++ (2014). https:\/\/github.com\/jinmei\/queryperfpp"},{"key":"10_CR57","unstructured":"Verisign Labs: DNSSEC Scoreboard. http:\/\/scoreboard.verisignlabs.com\/"},{"key":"10_CR58","unstructured":"Virus Bulletin: DNS cache poisoning used to steal emails (2014). https:\/\/www.virusbtn.com\/blog\/2014\/09_12.xml"},{"key":"10_CR59","unstructured":"Wikipedia: Deterrence theory \u2013 Wikipedia, The Free Encyclopedia. https:\/\/en.wikipedia.org\/w\/index.php?title=Deterrence_theory"},{"key":"10_CR60","series-title":"Communications in Computer and Information Science","doi-asserted-by":"publisher","first-page":"429","DOI":"10.1007\/978-3-642-35795-4_54","volume-title":"Trustworthy Computing and Services","author":"Y Yao","year":"2013","unstructured":"Yao, Y., He, L., Xiong, G.: Security and cost analyses of DNSSEC protocol. In: Yuan, Y., Wu, X., Lu, Y. (eds.) ISCTCS 2012. CCIS, vol. 320, pp. 429\u2013435. Springer, Heidelberg (2013). https:\/\/doi.org\/10.1007\/978-3-642-35795-4_54"},{"key":"10_CR61","doi-asserted-by":"crossref","unstructured":"Yuan, L., Kant, K., Mohapatra, P., Chuah, C.N.: DoX: a peer-to-peer antidote for DNS cache poisoning attacks. In: IEEE ICC 2006, vol. 5 (2006)","DOI":"10.1109\/ICC.2006.255120"},{"key":"10_CR62","doi-asserted-by":"crossref","unstructured":"Zhu, L., Hu, Z., Heidemann, J., Wessels, D., Mankin, A., Somaiya, N.: Connection-oriented DNS to improve privacy and security (extended). Technical Report ISI-TR-2015-695, Febuary 2015. http:\/\/www.isi.edu\/~johnh\/PAPERS\/Zhu15c.html","DOI":"10.1109\/SP.2015.18"}],"container-title":["Lecture Notes of the Institute for Computer Sciences, Social Informatics and Telecommunications Engineering","Security and Privacy in Communication Networks"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-030-01704-0_10","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,11,13]],"date-time":"2019-11-13T06:03:21Z","timestamp":1573625001000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-030-01704-0_10"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2018]]},"ISBN":["9783030017033","9783030017040"],"references-count":62,"URL":"https:\/\/doi.org\/10.1007\/978-3-030-01704-0_10","relation":{},"ISSN":["1867-8211","1867-822X"],"issn-type":[{"value":"1867-8211","type":"print"},{"value":"1867-822X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2018]]},"assertion":[{"value":"SecureComm","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Security and Privacy in Communication Systems","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Singapore","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Singapore","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2018","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"8 August 2018","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"10 August 2018","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"securecomm2018","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"http:\/\/securecomm.org\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}