{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,9]],"date-time":"2026-07-09T06:13:09Z","timestamp":1783577589537,"version":"3.55.0"},"reference-count":79,"publisher":"IEEE","license":[{"start":{"date-parts":[[2026,6,22]],"date-time":"2026-06-22T00:00:00Z","timestamp":1782086400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,6,22]],"date-time":"2026-06-22T00:00:00Z","timestamp":1782086400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2026,6,22]]},"DOI":"10.1109\/dsn69566.2026.00020","type":"proceedings-article","created":{"date-parts":[[2026,7,8]],"date-time":"2026-07-08T19:41:43Z","timestamp":1783539703000},"page":"38-51","source":"Crossref","is-referenced-by-count":0,"title":["Understanding and Exploiting DNS Relaying: Harnessing Legitimate Services for DNS Attacks"],"prefix":"10.1109","author":[{"given":"Ruian","family":"Duan","sequence":"first","affiliation":[{"name":"Palo Alto Networks,Santa Clara,USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Shu","family":"Wang","sequence":"additional","affiliation":[{"name":"Palo Alto Networks,Santa Clara,USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Daiping","family":"Liu","sequence":"additional","affiliation":[{"name":"Palo Alto Networks,Santa Clara,USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Hongya","family":"Xing","sequence":"additional","affiliation":[{"name":"Palo Alto Networks,Santa Clara,USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Lexuan","family":"Sun","sequence":"additional","affiliation":[{"name":"Palo Alto Networks,Santa Clara,USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yuwen","family":"Dai","sequence":"additional","affiliation":[{"name":"Palo Alto Networks,Santa Clara,USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Zhemin","family":"Su","sequence":"additional","affiliation":[{"name":"Palo Alto Networks,Santa Clara,USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Mengying","family":"Jiang","sequence":"additional","affiliation":[{"name":"Palo Alto Networks,Santa Clara,USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Fan","family":"Fei","sequence":"additional","affiliation":[{"name":"Palo Alto Networks,Santa Clara,USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Qi","family":"Zhang","sequence":"additional","affiliation":[{"name":"Palo Alto Networks,Santa Clara,USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref1","first-page":"631","article-title":"{NXNSAttack}: Recursive {DNS} inefficiencies and vulnerabilities","volume-title":"29th USENIX Security Symposium (USENIX Security 20)","author":"Afek"},{"key":"ref2","first-page":"3081","article-title":"SPF beyond the standard: Management and operational challenges in practice and practical recommendations","volume-title":"33rd USENIX Security Symposium (USENIX Security 24)","author":"Ashiq"},{"key":"ref3","article-title":"Dns amplification attacks","year":"2024"},{"key":"ref4","article-title":"Umbrella popularity list","year":"2024"},{"key":"ref5","article-title":"Configure the default origin host - alibaba cloud documentation"},{"key":"ref6","article-title":"Server load balancer - alibaba cloud","year":"2025"},{"key":"ref7","article-title":"Application load balancer overview","year":"2025"},{"key":"ref8","article-title":"Combining sni proxy with dns resolution","year":"2025"},{"key":"ref9","article-title":"Sni support for binding multiple certificates to a clb instance","year":"2025"},{"key":"ref10","article-title":"Data-bouncing - the art of indirect exfiltration","volume-title":"using & abusing trusted domains as a 2nd order transport","year":"2023"},{"key":"ref11","article-title":"Domain borrowing: Catch my c2 traffic if you can","author":"Ding","year":"2021"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813703"},{"key":"ref13","first-page":"605","article-title":"{ZMap}: Fast internet-wide scanning and its security applications","volume-title":"22nd USENIX Security Symposium (USENIX Security 13)","author":"Durumeric"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1515\/popets-2015-0009"},{"key":"ref15","article-title":"Highly evasive attacker leverages solarwinds supply chain to compromise multiple global victims with sunburst backdoor","volume-title":"FireEye","year":"2020"},{"key":"ref16","article-title":"Multiple threats target adobe coldfusion vulnerabilities","year":"2025"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1145\/3658644.3670389"},{"key":"ref18","article-title":"Introducing improvements in dns tunneling & dns exfiltration detection","author":"Holub","year":"2023"},{"key":"ref19","article-title":"Domain fronting is dead, long live domain fronting","author":"Hunstad","year":"2020"},{"key":"ref20","article-title":"Automatic domain validation for imperva-generated certificates","year":"2025"},{"key":"ref21","article-title":"Decoy dog is no ordinary pupy: Separating a sly dns malware from the pack","year":"2023"},{"key":"ref22","article-title":"Exim libspf2 integer underflow remote code execution vulnerability","year":"2023"},{"key":"ref23","article-title":"Mutually agreed norms for routing security (manrs)","year":"2024"},{"key":"ref24","first-page":"3111","article-title":"{LZR}: Identifying unexpected internet services","volume-title":"30th USENIX Security Symposium (USENIX Security 21)","author":"Izhikevich"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1145\/3412841.3442036"},{"key":"ref26","article-title":"Injection attacks reloaded: Tunnelling malicious payloads over DNS","volume-title":"30th USENIX Security Symposium (USENIX Security 21)","author":"Jeitner"},{"key":"ref27","first-page":"4473","article-title":"{XDRI} attacks-and-how to enhance resilience of residential routers","volume-title":"31st USENIX Security Symposium (USENIX Security 22)","author":"Jeitner"},{"key":"ref28","article-title":"Hundreds of crew members fired for using free internet access app onboard","year":"2018"},{"key":"ref29","first-page":"307","article-title":"{SCALE}: Automatically finding {RFC} compliance bugs in {DNS} nameservers","volume-title":"19th USENIX Symposium on Networked Systems Design and Implementation (NSDI 22)","author":"Kakarla"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1145\/2815675.2815683"},{"key":"ref31","first-page":"3153","article-title":"The maginot line: Attacking the boundary of {DNS} caching protection","volume-title":"32nd USENIX Security Symposium (USENIX Security 23)","author":"Li"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1109\/SP54263.2024.00264"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1109\/SP54263.2024.00172"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1109\/SP61157.2025.00004"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2024.24782"},{"key":"ref36","volume-title":"Burp collaborator","year":"2025"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1145\/3372297.3417280"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3486219"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1145\/3607505.3607526"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.17487\/rfc1035"},{"key":"ref41","article-title":"Report: Air-gapped networks vulnerable to dns attacks","author":"Montalbano","year":"2022"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1145\/3487552.3487824"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2018.09.006"},{"key":"ref44","article-title":"The http x-forwarded-for (xff) request header is a de-facto standard header for identifying the originating ip address of a client connecting to a web server through a proxy server","year":"2025"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1109\/TNET.2023.3257413"},{"key":"ref46","article-title":"A10:2021 \u2013 server-side request forgery (ssrf)","year":"2025"},{"key":"ref47","article-title":"Akamai develops real-time detections for dns exfiltration","author":"Ozery"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2024.24388"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1109\/TNET.2021.3105599"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-45719-2_18"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2019.23386"},{"key":"ref52","first-page":"4365","article-title":"Why {tls} is better without {starttls}: A security analysis of {starttls} in the email context","volume-title":"30th USENIX Security Symposium (USENIX Security 21)","author":"Poddebniak"},{"key":"ref53","article-title":"Oast: Out-of-band application security testing","year":"2017"},{"key":"ref54","article-title":"Finding and exploiting blind xxe vulnerabilities","year":"2025"},{"key":"ref55","article-title":"Spamhaus: Strengthening trust and safety across the internet","year":"2025"},{"key":"ref56","article-title":"An oob interaction gathering server and client library","year":"2025"},{"key":"ref57","article-title":"(pwn2own) tp-link archer a7 dns response stack-based buffer overflow remote code execution vulnerability","author":"Ribeiro","year":"2020"},{"key":"ref58","article-title":"Watching the watchers: Nonce-based inverse surveillance to remotely detect monitoring","volume-title":"Network Traffic Measurement and Analysis Conference","author":"Roberts"},{"key":"ref59","first-page":"3135","article-title":"Two sides of the shield: Understanding protective {DNS} adoption factors","volume-title":"32nd USENIX Security Symposium (USENIX Security 23)","author":"Rodr\u00edguez"},{"key":"ref60","doi-asserted-by":"publisher","DOI":"10.1109\/DSN58367.2023.00034"},{"key":"ref61","article-title":"Network Ingress Filtering: Defeating Denial of Service Attacks which employ IP Source Address Spoofing","volume-title":"RFC 2827","author":"Senie","year":"2000"},{"key":"ref62","article-title":"Listeners for your application load balancers","year":"2025"},{"key":"ref63","article-title":"What is the maximum length of a domain name?","year":"2024"},{"key":"ref64","article-title":"Http\/3 support in curl is considered experimental until further notice when built to use quiche or msh3","volume-title":"only the ngtcp2 backend is not experimental","author":"Stenberg","year":"2024"},{"key":"ref65","article-title":"An origin server is a physical location that houses your deliverable content like a site or app","year":"2025"},{"key":"ref66","article-title":"Ssrf vulnerabilities caused by sni proxy misconfigurations","author":"Tiurin","year":"2022"},{"key":"ref67","article-title":"Sigred \u2013 resolving your way into domain admin: Exploiting a 17 year-old bug in windows dns servers","author":"Tzadik","year":"2020"},{"key":"ref68","doi-asserted-by":"publisher","DOI":"10.1145\/2663716.2663731"},{"key":"ref69","article-title":"Exim dmarc dmarc.c dmarc_dns_lookup use after free","year":"2022"},{"key":"ref70","article-title":"Leveraging dns tunneling for tracking and scanning","author":"Wang","year":"2024"},{"key":"ref71","first-page":"3327","article-title":"Domain shadowing: Leveraging content delivery networks for robust Blocking-Resistant communications","volume-title":"30th USENIX Security Symposium (USENIX Security 21)","author":"Wei"},{"key":"ref72","first-page":"6777","article-title":"SSRF vs. developers: A study of SSRF-Defenses in PHP applications","volume-title":"33rd USENIX Security Symposium (USENIX Security 24)","author":"Wessels"},{"key":"ref73","article-title":"Oilrig uses updated bondupdater to target middle eastern government","author":"Wilhoit","year":"2018"},{"key":"ref74","doi-asserted-by":"publisher","DOI":"10.1145\/3646547.3689023"},{"key":"ref75","doi-asserted-by":"publisher","DOI":"10.1145\/3576915.3616668"},{"key":"ref76","article-title":"Targeted by 20.5 million ddos attacks, up 358% year-over-year: Cloudflare\u2019s 2025 q1 ddos threat report","author":"Yoachimik","year":"2025"},{"key":"ref77","first-page":"4729","article-title":"{ResolverFuzz}: Automated discovery of {DNS} resolver vulnerabilities with {Query-Response} fuzzing","volume-title":"33rd USENIX Security Symposium (USENIX Security 24)","author":"Zhang"},{"key":"ref78","first-page":"577","article-title":"Poison over troubled forwarders: A cache poisoning attack targeting {DNS} forwarding devices","volume-title":"29th USENIX Security Symposium (USENIX Security 20)","author":"Zheng"},{"key":"ref79","article-title":"Dns early detection - cobalt strike dns c2","author":"Zuckerman","year":"2024"}],"event":{"name":"2026 56th Annual IEEE International Conference on Dependable Systems and Networks (DSN)","location":"Charlotte, NC, USA","start":{"date-parts":[[2026,6,22]]},"end":{"date-parts":[[2026,6,25]]}},"container-title":["2026 56th Annual IEEE International Conference on Dependable Systems and Networks (DSN)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/11593123\/11593173\/11593465.pdf?arnumber=11593465","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,7,9]],"date-time":"2026-07-09T05:12:53Z","timestamp":1783573973000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11593465\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,6,22]]},"references-count":79,"URL":"https:\/\/doi.org\/10.1109\/dsn69566.2026.00020","relation":{},"subject":[],"published":{"date-parts":[[2026,6,22]]}}}