CISPA
Browse
cispa_all_4033.pdf (856.13 kB)

ResolFuzz: Differential Fuzzing of DNS Resolvers

Download (856.13 kB)
conference contribution
posted on 2024-03-05, 12:15 authored by Bushart, Jonas, Christian RossowChristian Rossow
This paper identifies and analyzes vulnerabilities in the DNS infrastructure, with particular focus on recursive DNS resolvers. We aim to identify semantic bugs that could lead to incorrect resolver responses, introducing risks to the internet’s critical infrastructure. To achieve this, we introduce ResolFuzz, a mutation-based fuzzer to search for semantic differences across DNS resolver implementations. ResolFuzz combines differential analysis with a rule-based mechanism to distinguish between benign differences and potential threats. We evaluate our prototype on seven resolvers and uncover multiple security vulnerabilities, including inaccuracies in resolver responses and possible amplification issues in PowerDNS Recursor’s handling of DNAMEResource Records (RRs). Moreover, we demonstrate the potential for self-sustaining DoS attacks in resolved and trust-dns, further underlining the necessity of comprehensive DNS security. Through these contributions, our research underscores the potential of differential fuzzing in uncovering DNS vulnerabilities.

History

Preferred Citation

Jonas Bushart, Christian Rossow. ResolFuzz: Differential Fuzzing of DNS Resolvers. In: ESORICS 2023. 2023.

Primary Research Area

  • Secure Connected and Mobile Systems

Name of Conference

European Symposium on Research in Computer Security (ESORICS)

Legacy Posted Date

2023-09-07

Open Access Type

  • Unknown

BibTeX

@inproceedings{cispa_all_4033, author = {Jonas Bushart AND Christian Rossow}, title = {ResolFuzz: Differential Fuzzing of DNS Resolvers}, booktitle = {ESORICS 2023}, year = {2023} }

Usage metrics

    Categories

    No categories selected

    Licence

    Exports

    RefWorks
    BibTeX
    Ref. manager
    Endnote
    DataCite
    NLM
    DC