SCALE: Automatically Finding RFC Compliance Bugs in DNS Nameservers
Siva Kesava Reddy Kakarla, Ryan Beckett, Todd D. Millstein, George Varghese
Abstract
The Domain Name System (DNS) has intricate features that interact in subtle ways. Bugs in DNS implementations can lead to incorrect or implementation-dependent behavior, security vulnerabilities, and more. We introduce the first approach for finding RFC compliance errors in DNS nameserver implementations, via automatic test generation. Our SCALE (Small-scope Constraint-driven Automated Logical Execution) approach jointly generates zone files and corresponding queries to cover RFC behaviors specified by an executable model of DNS resolution. We have built a tool called FERRET based on this approach and applied it to test 8 open-source DNS implementations, including popular implementations such as BIND, POWERDNS, KNOT, and NSD. FERRET generated over 13.5K test cases, of which 62% resulted in some difference among implementations. We identified and reported 30 new unique bugs from these failed test cases, including at least one bug in every implementation, of which 20 have already been fixed. Many of these bugs existed in even the most popular DNS implementations, including a critical vulnerability in BIND that attackers could easily exploit to crash DNS resolvers and nameservers remotely.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers13
- ResolverFuzz: Automated Discovery of DNS Resolver Vulnerabilities with Query-Response FuzzingQifan Zhang, Xuesong Bai, Xiang Li, Haixin Duan et al.USENIX Security 2024 · 13 citations
- A Formal Framework for End-to-End DNS ResolutionSi Liu, Huayi Duan, Lukas Heimes, Marco Bearzi et al.SIGCOMM 2023 · 11 citations
- MESSI: Behavioral Testing of BGP ImplementationsRathin Singha, Rajdeep Mondal, Ryan Beckett, Siva Kesava Reddy Kakarla et al.NSDI 2024 · 8 citations
- Automated Verification of an In-Production DNS Authoritative EngineNaiqian Zheng, Mengqi Liu, Yuxing Xiang, Linjian Song et al.SOSP 2023 · 3 citations
- Once4All: Skeleton-Guided SMT Solver Fuzzing with LLM-Synthesized GeneratorsMaolin Sun, Yibiao Yang, Yuming ZhouASPLOS 2026 · 1 citation
Builds on6
- Coverage-based Greybox Fuzzing as Markov ChainMarcel Böhme, Van-Thuan Pham, Abhik RoychoudhuryCCS 2016 · 1,026 citations
- Angora: Efficient Fuzzing by Principled SearchPeng Chen, Hao ChenS&P 2018 · 616 citations
- Akamai DNS: Providing Authoritative Answers to the World's QueriesKyle Schomp, Onkar Bhardwaj, Eymen Kurdoglu, Mashooq Muhaimen et al.SIGCOMM 2020 · 38 citations
- Prognosis: closed-box analysis of network protocol implementationsTiago Ferreira, Harrison Brewton, Loris D'Antoni, Alexandra SilvaSIGCOMM 2021 · 34 citations
- Semi-automated protocol disambiguation and code generationJane Yen, Tamás Lévai, Qinyuan Ye, Xiang Ren et al.SIGCOMM 2021 · 33 citations
Related papers
- GRooT: Proactive Verification of DNS ConfigurationsSiva Kesava Reddy Kakarla, Ryan Beckett, Behnaz Arzani, Todd D. Millstein et al.SIGCOMM 2020 · 24 citations
- The Maginot Line: Attacking the Boundary of DNS Caching ProtectionXiang Li, Chaoyi Lu, Baojun Liu, Qifan Zhang et al.USENIX Security 2023
- Knocking on the Front Door: An LLM-Guided Systematic Analysis of DNS Query Processing VulnerabilitiesYuqi Qiu, Xiang Li, Zheli LiuS&P 2026
- TuDoor Attack: Systematically Exploring and Exploiting Logic Vulnerabilities in DNS Response Pre-processing with Malformed PacketsXiang Li, Wei Xu, Baojun Liu, Mingming Zhang et al.S&P 2024 · 20 citations
- DNS Cache Poisoning Like it’s 2006Omer Ben-Simhon, Amit KleinUSENIX Security 2026
