{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,12,16]],"date-time":"2025-12-16T12:27:25Z","timestamp":1765888045235,"version":"3.41.0"},"reference-count":30,"publisher":"Association for Computing Machinery (ACM)","issue":"3","license":[{"start":{"date-parts":[[2018,9,7]],"date-time":"2018-09-07T00:00:00Z","timestamp":1536278400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["SIGCOMM Comput. Commun. Rev."],"published-print":{"date-parts":[[2018,9,7]]},"abstract":"<jats:p>\n            Authoritative DNS servers are susceptible to being leveraged in denial of service attacks in which the attacker sends DNS queries while masquerading as a victim---and hence causing the DNS server to send the responses to the victim. This reflection off innocent DNS servers hides the attackers identity and often allows the attackers to amplify their traffic by employing small requests to elicit large responses. Several challenge-response techniques have been proposed to establish a requester's identity before sending a full answer. However, none of these are practical in that they do not work in the face of \"resolver pools\"---or groups of DNS resolvers that work in concert to lookup records in the DNS. In these cases a challenge transmitted to some resolver\n            <jats:italic>R<\/jats:italic>\n            <jats:sub>1<\/jats:sub>\n            may be handled by a resolver\n            <jats:italic>R<\/jats:italic>\n            <jats:sub>2<\/jats:sub>\n            , hence leaving an authoritative DNS server wondering whether\n            <jats:italic>R<\/jats:italic>\n            <jats:sub>2<\/jats:sub>\n            is in fact another resolver in the pool or a victim. We offer a practical challenge-response mechanism that uses challenge chains to establish identity in the face of resolver pools. We illustrate that the practical cost of our scheme in terms of added delay is small.\n          <\/jats:p>","DOI":"10.1145\/3276799.3276802","type":"journal-article","created":{"date-parts":[[2018,9,10]],"date-time":"2018-09-10T12:11:14Z","timestamp":1536581474000},"page":"20-28","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":4,"title":["Practical challenge-response for DNS"],"prefix":"10.1145","volume":"48","author":[{"given":"Rami","family":"Al-Dalky","sequence":"first","affiliation":[{"name":"Case Western Reserve University"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Michael","family":"Rabinovich","sequence":"additional","affiliation":[{"name":"Case Western Reserve University"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Mark","family":"Allman","sequence":"additional","affiliation":[{"name":"International Computer Science Institute"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2018,9,7]]},"reference":[{"key":"e_1_2_1_1_1","unstructured":"Case Connection Zone. http:\/\/www.caseconnectionzone.org\/.  Case Connection Zone. http:\/\/www.caseconnectionzone.org\/."},{"key":"e_1_2_1_2_1","unstructured":"Google Public DNS. https:\/\/developers.google.com\/speed\/public-dns\/docs\/performance.  Google Public DNS. https:\/\/developers.google.com\/speed\/public-dns\/docs\/performance."},{"key":"e_1_2_1_3_1","unstructured":"MaraDNS. http:\/\/maradns.samiam.org\/.  MaraDNS. http:\/\/maradns.samiam.org\/."},{"key":"e_1_2_1_4_1","unstructured":"The Bro Network Security Monitor. https:\/\/www.bro.org\/.  The Bro Network Security Monitor. https:\/\/www.bro.org\/."},{"key":"e_1_2_1_5_1","volume-title":"to DNS-OARC by Verisign","author":"Data Root DITL","year":"2018","unstructured":"A- Root DITL Data , submitted to DNS-OARC by Verisign , Apr. 2018 . https:\/\/www.dns-oarc.net\/oarc\/data\/ditl\/2018. A-Root DITL Data, submitted to DNS-OARC by Verisign, Apr. 2018. https:\/\/www.dns-oarc.net\/oarc\/data\/ditl\/2018."},{"key":"e_1_2_1_6_1","first-page":"Q1","author":"Akamai. {State of the Internet} \/","year":"2017","unstructured":"Akamai. {State of the Internet} \/ Security. Q1 2017 . Akamai. {State of the Internet} \/ Security. Q1 2017.","journal-title":"Security."},{"key":"e_1_2_1_8_1","volume-title":"Characterization of Collaborative Resolution in Recursive DNS Resolvers. In Passive and Active Measurement Conference","author":"Al-Dalky R.","year":"2018","unstructured":"R. Al-Dalky and K. Schomp . Characterization of Collaborative Resolution in Recursive DNS Resolvers. In Passive and Active Measurement Conference , 2018 . To appear. R. Al-Dalky and K. Schomp. Characterization of Collaborative Resolution in Recursive DNS Resolvers. In Passive and Active Measurement Conference, 2018. To appear."},{"key":"e_1_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1145\/1298306.1298316"},{"key":"e_1_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1145\/2488388.2488397"},{"key":"e_1_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1145\/2500098.2500100"},{"volume-title":"Apr.","year":"2014","key":"e_1_2_1_12_1","unstructured":"Cloudflare. Introducing CNAME Flattening: RFC-Compliant CNAMEs at a Domain's Root , Apr. 2014 . https:\/\/blog.cloudflare.com\/introducing-cname-flattening-rfc-compliant-cnames-at-a-domains-root\/. Cloudflare. Introducing CNAME Flattening: RFC-Compliant CNAMEs at a Domain's Root, Apr. 2014. https:\/\/blog.cloudflare.com\/introducing-cname-flattening-rfc-compliant-cnames-at-a-domains-root\/."},{"key":"e_1_2_1_13_1","doi-asserted-by":"crossref","DOI":"10.17487\/RFC7766","volume-title":"DNS Transport Over TCP - Implementation Requirements. RFC","author":"Dickinson J.","year":"2016","unstructured":"J. Dickinson , S. Dickinson , R. Bellis , A. Mankin , and D. Wessels . DNS Transport Over TCP - Implementation Requirements. RFC 7766, Mar. 2016 . J. Dickinson, S. Dickinson, R. Bellis, A. Mankin, and D. Wessels. DNS Transport Over TCP - Implementation Requirements. RFC 7766, Mar. 2016."},{"key":"e_1_2_1_14_1","volume-title":"Domain Name System (DNS) Cookies. RFC","author":"Andrews D. Eastlake","year":"2016","unstructured":"D. Eastlake 3rd and M. Andrews . Domain Name System (DNS) Cookies. RFC 7873, May 2016 . D. Eastlake 3rd and M. Andrews. Domain Name System (DNS) Cookies. RFC 7873, May 2016."},{"key":"e_1_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.17487\/RFC2181"},{"key":"e_1_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICDCS.2006.78"},{"key":"e_1_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1145\/2664243.2664281"},{"key":"e_1_2_1_18_1","unstructured":"G. Huston. A question of DNS protocols. http:\/\/www.potaroo.net\/ispcol\/2013-09\/dnstcp.html 2013.  G. Huston. A question of DNS protocols. http:\/\/www.potaroo.net\/ispcol\/2013-09\/dnstcp.html 2013."},{"key":"e_1_2_1_19_1","unstructured":"Internet Systems Consortium. BIND. https:\/\/www.isc.org\/downloads\/bind\/.  Internet Systems Consortium. BIND. https:\/\/www.isc.org\/downloads\/bind\/."},{"key":"e_1_2_1_20_1","volume-title":"AA-01000","author":"ISC.","year":"2013","unstructured":"ISC. A Quick Introduction to Response Rate Limiting. ISC Knowledge Base , AA-01000 , June 2013 . ISC. A Quick Introduction to Response Rate Limiting. ISC Knowledge Base, AA-01000, June 2013."},{"key":"e_1_2_1_21_1","volume-title":"Reducing the Impact of Amplification DDoS Attacks. In USENIX Security Symposium","author":"K\u00c3ijhrer M.","year":"2014","unstructured":"M. K\u00c3ijhrer , T. Hupperich , C. Rossow , and T. Holz . Exit from Hell ? Reducing the Impact of Amplification DDoS Attacks. In USENIX Security Symposium , 2014 . M. K\u00c3ijhrer, T. Hupperich, C. Rossow, and T. Holz. Exit from Hell? Reducing the Impact of Amplification DDoS Attacks. In USENIX Security Symposium, 2014."},{"key":"e_1_2_1_22_1","volume-title":"Measuring the Practical Impact of DNSSEC Deployment. In USENIX Security Symposium","author":"Lian W.","year":"2013","unstructured":"W. Lian , E. Rescorla , H. Shacham , and S. Savage . Measuring the Practical Impact of DNSSEC Deployment. In USENIX Security Symposium , 2013 . W. Lian, E. Rescorla, H. Shacham, and S. Savage. Measuring the Practical Impact of DNSSEC Deployment. In USENIX Security Symposium, 2013."},{"key":"e_1_2_1_23_1","volume-title":"Characterizing Optimal DNS Amplification Attacks and Effective Mitigation. In Passive and Active Measurement Conference","author":"MacFarland D. C.","year":"2015","unstructured":"D. C. MacFarland , C. A. Shue , and A. J. Kalafut . Characterizing Optimal DNS Amplification Attacks and Effective Mitigation. In Passive and Active Measurement Conference , 2015 . D. C. MacFarland, C. A. Shue, and A. J. Kalafut. Characterizing Optimal DNS Amplification Attacks and Effective Mitigation. In Passive and Active Measurement Conference, 2015."},{"key":"e_1_2_1_24_1","volume-title":"The EDNS(0) Padding Option. RFC","author":"Mayrhofer A.","year":"2016","unstructured":"A. Mayrhofer . The EDNS(0) Padding Option. RFC 7830, May 2016 . A. Mayrhofer. The EDNS(0) Padding Option. RFC 7830, May 2016."},{"key":"e_1_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-28537-0_21"},{"key":"e_1_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1145\/505659.505664"},{"key":"e_1_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1145\/2670518.2673881"},{"key":"e_1_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1145\/2504730.2504734"},{"key":"e_1_2_1_29_1","first-page":"7","author":"Tzakikario R.","year":"2009","unstructured":"R. Tzakikario , D. Touitou , and G. Pazi . DNS Anti-Spoofing Using UDP , November 2009 . US Patent 7 ,620,733. R. Tzakikario, D. Touitou, and G. Pazi. DNS Anti-Spoofing Using UDP, November 2009. US Patent 7,620,733.","journal-title":"DNS Anti-Spoofing Using UDP"},{"key":"e_1_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1145\/2663716.2663731"},{"key":"e_1_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2015.18"}],"container-title":["ACM SIGCOMM Computer Communication Review"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3276799.3276802","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3276799.3276802","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T00:57:41Z","timestamp":1750208261000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3276799.3276802"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2018,9,7]]},"references-count":30,"journal-issue":{"issue":"3","published-print":{"date-parts":[[2018,9,7]]}},"alternative-id":["10.1145\/3276799.3276802"],"URL":"https:\/\/doi.org\/10.1145\/3276799.3276802","relation":{},"ISSN":["0146-4833"],"issn-type":[{"type":"print","value":"0146-4833"}],"subject":[],"published":{"date-parts":[[2018,9,7]]},"assertion":[{"value":"2018-09-07","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}