USENIX Security2018Top-tier venue
End-Users Get Maneuvered: Empirical Analysis of Redirection Hijacking in Content Delivery Networks
Shuai Hao, Yubao Zhang, Haining Wang, Angelos Stavrou
Abstract
The success of Content Delivery Networks (CDNs) relies on the mapping system that leverages dynamically generated DNS records to distribute client requests to a proximal server for achieving optimal content delivery. However, the mapping system is vulnerable to malicious hijacks, as (1) it is difficult to provide precomputed DNSSEC signatures for dynamically generated records, and (2) even considering when DNSSEC is enabled, DNSSEC itself is vulnerable to replay attacks. By leveraging crafted but legitimate mapping between the end-user and edge server, adversaries can hijack CDN's request redirection and nullify the benefits offered by CDNs, such as proximal access, load balancing, and Denial-of-Service (DoS) protection, while remaining undetectable by existing security practices including DNSSEC. In this paper, we investigate the security implications of dynamic mapping that remain understudied in security and CDN communities. We perform a characterization of CDN's service delivery and assess this fundamental vulnerability in DNS-based CDNs in the wild. We demonstrate that DNSSEC is ineffective to address this problem, even with the newly adopted ECDSA that is capable of achieving live signing. We then discuss practical countermeasures against such manipulation.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 2cc27ff1-6fdf-4941-a1c4-d16e78e857e6Cited by top-tier papers11
- How Great is the Great Firewall? Measuring China's DNS CensorshipNguyen Phong Hoang, Arian Akhavan Niaki, Jakub Dalek, Jeffrey Knockel et al.USENIX Security 2021 · 80 citations
- Understanding the Impact of Encrypted DNS on Internet CensorshipLin Jin, Shuai Hao, Haining Wang, Chase CottonWWW 2021 · 29 citations
- Regional IP Anycast: Deployments, Performance, and PotentialsMinyuan Zhou, Xiao Zhang, Shuai Hao, Xiaowei Yang et al.SIGCOMM 2023 · 17 citations
- CDN Cannon: Exploiting CDN Back-to-Origin Strategies for Amplification AttacksZiyu Lin, Zhiwei Lin, Ximeng Liu, Jianjun Chen et al.USENIX Security 2024 · 5 citations
- Silence is not Golden: Disrupting the Load Balancing of Authoritative DNS ServersFenglu Zhang, Baojun Liu, Eihal Alowaisheq, Jianjun Chen et al.CCS 2023 · 3 citations
Builds on3
- Global Measurement of DNS ManipulationPaul Pearce, Ben Jones, Frank Li, Roya Ensafi et al.USENIX Security 2017 · 163 citations
- Forwarding-Loop Attacks in Content Delivery NetworksJianjun Chen, Xiaofeng Zheng, Hai-Xin Duan, Jinjin Liang et al.NDSS 2016 · 44 citations
- Practical Censorship Evasion Leveraging Content Delivery NetworksHadi Zolfaghari, Amir HoumansadrCCS 2016 · 44 citations
Related papers
- CDN Judo: Breaking the CDN DoS Protection with ItselfRun Guo, Weizhong Li, Baojun Liu, Shuang Hao et al.NDSS 2020
- Zombie Awakening: Stealthy Hijacking of Active Domains through DNS Hosting ReferralEihal Alowaisheq, Siyuan Tang, Zhihao Wang, Fatemah Alharbi et al.CCS 2020 · 19 citations
- All Your DNS Records Point to Us: Understanding the Security Threats of Dangling DNS RecordsDaiping Liu, Shuai Hao, Haining WangCCS 2016 · 91 citations
- Tracking the Stray Sheep: Understanding DNS Response Manipulation in the WildWenhao Wu, Zhaohua Wang, Zihan Li, Qinxin Li et al.WWW 2026
- Crack in the Armor: Underlying Infrastructure Threats to RPKI Publication Point ReachabilityYunhao Liu, Jessie Hui Wang, Yuedong Xu, Zongpeng Li et al.NDSS 2026
