首页> 外文会议>International conference on detection of intrusions and malware, and vulnerability assessment >Security in Plain TXT Observing the Use of DNS TXT Records in the Wild
【24h】

Security in Plain TXT Observing the Use of DNS TXT Records in the Wild

机译:纯文本中的安全性,以野外观察DNS TXT记录的使用

获取原文

摘要

The Domain Name System is a critical piece of infrastructure that has expanded into use cases beyond its original intent. DNS TXT records are intentionally very permissive in what information can be stored there, and as a result are often used in broad and undocumented ways to support Internet security and networked applications. In this paper, we identified and categorized the patterns in TXT record use from a representative collection of resource record sets. We obtained the records from a data set containing 1.4 billion TXT records collected over a 2 year period and used pattern matching to identify record use cases present across multiple domains. We found that 92% of these records generally fall into 3 categories; protocol enhancement, domain verification, and resource location. While some of these records are required to remain public, we discovered many examples that unnecessarily reveal domain information or present other security threats (e.g., amplification attacks) in conflict with best practices in security.
机译:域名系统是基础架构的重要组成部分,它已超出其初衷而扩展为用例。 DNS TXT记录故意允许在其中存储哪些信息,因此,通常以广泛且未记录的方式使用它们来支持Internet安全性和网络应用程序。在本文中,我们从资源记录集的代表性集合中识别并分类了TXT记录使用中的模式。我们从一个数据集中获得了记录,该数据集包含在两年内收集的14亿个TXT记录,并使用模式匹配来识别跨多个域的记录用例。我们发现,这些记录中的92%通常分为3类。协议增强,域验证和资源位置。尽管其中一些记录需要保持公开状态,但我们发现了许多示例,这些示例不必要地泄露域信息或存在与安全最佳实践相冲突的其他安全威胁(例如,放大攻击)。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号