From IP to transport and beyond: cross-layer attacks against applications
Tianxiang Dai, Philipp Jeitner, Haya Schulmann, Michael Waidner
Abstract
We perform the first analysis of methodologies for launching DNS cache poisoning: manipulation at the IP layer, hijack of the interdomain routing and probing open ports via side channels. We evaluate these methodologies against DNS resolvers in the Internet and compare them with respect to effectiveness, applicability and stealth. Our study shows that DNS cache poisoning is a practical and pervasive threat.
We then demonstrate cross-layer attacks that leverage DNS cache poisoning for attacking popular systems, ranging from security mechanisms, such as RPKI, to applications, such as VoIP. In addition to more traditional adversarial goals, most notably impersonation and Denial of Service, we show for the first time that DNS cache poisoning can even enable adversaries to bypass cryptographic defences: we demonstrate how DNS cache poisoning can facilitate BGP prefix hijacking of networks protected with RPKI even when all the other networks apply route origin validation to filter invalid BGP announcements. Our study shows that DNS plays a much more central role in the Internet security than previously assumed.
We recommend mitigations for securing the applications and for preventing cache poisoning.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 2ebca2bd-0271-4b35-b725-92916c348fe2Cited by top-tier papers9
- DNS Cache Poisoning Attack: Resurrections with Side ChannelsKeyu Man, Xin'an Zhou, Zhiyun QianCCS 2021 · 33 citations
- The Hijackers Guide To The Galaxy: Off-Path Taking Over Internet ResourcesTianxiang Dai, Philipp Jeitner, Haya Schulmann, Michael WaidnerUSENIX Security 2021 · 22 citations
- RHINE: Robust and High-performance Internet Naming with E2E AuthenticityHuayi Duan, Rubén Fischer, Jie Lou, Si Liu et al.NSDI 2023 · 12 citations
- DNS Cache Poisoning Like it’s 2006Omer Ben-Simhon, Amit KleinUSENIX Security 2026
- Understanding the Implementation and Security Implications of Protective DNS ServicesMingxuan Liu, Yiming Zhang, Xiang Li, Chaoyi Lu et al.NDSS 2024
Builds on13
- Hijacking Bitcoin: Routing Attacks on CryptocurrenciesMaria Apostolaki, Aviv Zohar, Laurent VanbeverS&P 2017 · 473 citations
- A Longitudinal, End-to-End View of the DNSSEC EcosystemTaejoong Chung, Roland van Rijswijk-Deij, Balakrishnan Chandrasekaran, David R. Choffnes et al.USENIX Security 2017 · 125 citations
- Are We There Yet? On RPKI's Deployment and SecurityYossi Gilad, Avichai Cohen, Amir Herzberg, Michael Schapira et al.NDSS 2017 · 108 citations
- Network Hygiene, Incentives, and Regulation: Deployment of Source Address Validation in the InternetMatthew J. Luckie, Robert Beverly, Ryan Koga, Ken Keys et al.CCS 2019 · 89 citations
- Bamboozling Certificate Authorities with BGPHenry Birge-Lee, Yixin Sun, Anne Edmundson, Jennifer Rexford et al.USENIX Security 2018 · 83 citations
Related papers
- DNS Cache Poisoning Attack Reloaded: Revolutions with Side ChannelsKeyu Man, Zhiyun Qian, Zhongjie Wang, Xiaofeng Zheng et al.CCS 2020 · 62 citations
- Good Cache, BAD Cache: Exploiting DNSSEC Validation Failures for DNS Cache Poisoning AttacksShiming Liu, Yunyi Zhang, Chaoyi Lu, Baojun Liu et al.CCS 2026
- Should I Trust You? Rethinking the Principle of Zone-Based Isolation DNS Bailiwick CheckingYuxiao Wu, Yunyi Zhang, Chaoyi Lu, Baojun LiuNDSS 2026 · 2 citations
- XDRI Attacks - and - How to Enhance Resilience of Residential RoutersPhilipp Jeitner, Haya Schulmann, Lucas Teichmann, Michael WaidnerUSENIX Security 2022
- Injection Attacks Reloaded: Tunnelling Malicious Payloads over DNSPhilipp Jeitner, Haya SchulmannUSENIX Security 2021 · 32 citations
