论文标题

没有停机时间:了解托管DNS提供商客户的攻击后行为

No Time for Downtime: Understanding Post-Attack Behaviors by Customers of Managed DNS Providers

论文作者

Haq, Muhammad Yasir Muzayan, Jonker, Mattijs, van Rijswijk-Deij, Roland, Claffy, KC, Nieuwenhuis, Lambert J. M., Abhishta, Abhishta

论文摘要

我们利用权威名称服务器的大规模DNS测量数据来研究受2016年DDOS攻击Dyn影响的域所有者的反应。我们使用有关域名的行业信息来源来研究诸如行业领域和网站受欢迎程度诸如领域经理愿意投资高可用在线服务的影响的影响。具体而言,我们将域所有者的业务特征与DOS攻击影响其领域的弹性策略相关联。我们的分析揭示了领域的两个属性 - 行业和受欢迎程度 - 攻击后策略之间的相关性。具体来说,更受欢迎的领域的所有者更有可能重新行动增加其权威DNS服务的多样性。同样,某些行业领域的领域更有可能在其DNS服务中寻找这种多样性。例如,被归类为一般新闻的域名重复性的可能性是互联网服务的域的近6倍。我们的结果可以告知托管DNS和其他网络服务提供商停机对客户投资组合的潜在影响。

We leverage large-scale DNS measurement data on authoritative name servers to study the reactions of domain owners affected by the 2016 DDoS attack on Dyn. We use industry sources of information about domain names to study the influence of factors such as industry sector and website popularity on the willingness of domain managers to invest in high availability of online services. Specifically, we correlate business characteristics of domain owners with their resilience strategies in the wake of DoS attacks affecting their domains. Our analysis revealed correlations between two properties of domains -- industry sector and popularity -- and post-attack strategies. Specifically, owners of more popular domains were more likely to re-act to increase the diversity of their authoritative DNS service for their domains. Similarly, domains in certain industry sectors were more likely to seek out such diversity in their DNS service. For example, domains categorized as General News were nearly 6 times more likely to re-act than domains categorized as Internet Services. Our results can inform managed DNS and other network service providers regarding the potential impact of downtime on their customer portfolio.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源