Knocking on the Front Door: An LLM-Guided Systematic Analysis of DNS Query Processing Vulnerabilities
Yuqi Qiu, Xiang Li, Zheli Liu
Abstract
The Domain Name System (DNS) is defined by simple rules, yet its implementations are notoriously complex. While significant research, such as the TuDoor Attack, has systematically explored logic vulnerabilities in DNS response pre-processing (the back door), a fundamental and equally critical question remains unanswered: what occurs when a malformed query is Knocking on the Front Door? This represents a substantial, unassessed attack surface. To address this research gap, we present QuerySynth, an LLM-guided protocol behavior exploration framework. QuerySynth's core innovation is to automatically deconstruct the vast corpus of DNS RFC documents into a machinereadable Structured Protocol Model (SPM), which in turn guides the systematic generation of a malformed query corpus. We then conducted a large-scale differential analysis of 22 mainstream DNS resolver software, including BIND, Unbound, and PowerDNS. Our analysis reveals a class of severe, exploitable flaws stemming from implementation inconsistencies, which we collectively term the JIGGLE Attack. The JIGGLE Attack includes 3 primitives that an attacker can exploit to: (1) instigate a Pulsing DoS attack via anomalous echo response, (2) establish a Covert Channel for data exfiltration using the same anomalous echo logic, and (3) enhance existing off-path cache poisoning attacks by using Upstream Silence to open a multi-second vulnerability window. We further conducted an in-the-wild active measurement of 44 major public DNS services such as Cloudflare and Google DNS, and of million open DNS resolvers. We found that the silence behavior was observed across all tested services and no less than open resolvers, while the anomalous echo primitives affect 18 services and a minimum of open resolvers. Following the best practice of responsible disclosure, we have responsibly disclosed our findings to related vendors. Our research highlights the urgent need for the standardization of DNS query processing logic.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get d36707a5-4fdb-4e95-a8d1-b033f543bfa1Related papers
- TuDoor Attack: Systematically Exploring and Exploiting Logic Vulnerabilities in DNS Response Pre-processing with Malformed PacketsXiang Li, Wei Xu, Baojun Liu, Mingming Zhang et al.S&P 2024 · 20 citations
- DNSBomb: A New Practical-and-Powerful Pulsing DoS Attack Exploiting DNS Queries-and-ResponsesXiang Li, Dashuai Wu, Haixin Duan, Qi LiS&P 2024 · 14 citations
- One Char to Rule Them All: Systematically Exploring and Exploiting DNS Silent Vulnerabilities in Domain Name ResolutionFasheng Miao, Xiang Li, Changqing An, Wenbin Xu et al.S&P 2026
- DNS Cache Poisoning Attack Reloaded: Revolutions with Side ChannelsKeyu Man, Zhiyun Qian, Zhongjie Wang, Xiaofeng Zheng et al.CCS 2020 · 62 citations
- TsuKing: Coordinating DNS Resolvers and Queries into Potent DoS AmplifiersWei Xu, Xiang Li, Chaoyi Lu, Baojun Liu et al.CCS 2023 · 15 citations
