End-Users Get Maneuvered: Empirical Analysis of Redirection Hijacking in Content Delivery Networks
Shuai Hao, Yubao Zhang, Haining Wang, Angelos Stavrou
摘要
The success of Content Delivery Networks (CDNs) relies on the mapping system that leverages dynamically generated DNS records to distribute client requests to a proximal server for achieving optimal content delivery. However, the mapping system is vulnerable to malicious hijacks, as (1) it is difficult to provide precomputed DNSSEC signatures for dynamically generated records, and (2) even considering when DNSSEC is enabled, DNSSEC itself is vulnerable to replay attacks. By leveraging crafted but legitimate mapping between the end-user and edge server, adversaries can hijack CDN's request redirection and nullify the benefits offered by CDNs, such as proximal access, load balancing, and Denial-of-Service (DoS) protection, while remaining undetectable by existing security practices including DNSSEC. In this paper, we investigate the security implications of dynamic mapping that remain understudied in security and CDN communities. We perform a characterization of CDN's service delivery and assess this fundamental vulnerability in DNS-based CDNs in the wild. We demonstrate that DNSSEC is ineffective to address this problem, even with the newly adopted ECDSA that is capable of achieving live signing. We then discuss practical countermeasures against such manipulation.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper11
- How Great is the Great Firewall? Measuring China's DNS CensorshipNguyen Phong Hoang, Arian Akhavan Niaki, Jakub Dalek, Jeffrey Knockel 等USENIX Security 2021 · 被引用 80 次
- Understanding the Impact of Encrypted DNS on Internet CensorshipLin Jin, Shuai Hao, Haining Wang, Chase CottonWWW 2021 · 被引用 29 次
- Regional IP Anycast: Deployments, Performance, and PotentialsMinyuan Zhou, Xiao Zhang, Shuai Hao, Xiaowei Yang 等SIGCOMM 2023 · 被引用 17 次
- CDN Cannon: Exploiting CDN Back-to-Origin Strategies for Amplification AttacksZiyu Lin, Zhiwei Lin, Ximeng Liu, Jianjun Chen 等USENIX Security 2024 · 被引用 5 次
- Silence is not Golden: Disrupting the Load Balancing of Authoritative DNS ServersFenglu Zhang, Baojun Liu, Eihal Alowaisheq, Jianjun Chen 等CCS 2023 · 被引用 3 次
它引用的顶会 Paper3
- Global Measurement of DNS ManipulationPaul Pearce, Ben Jones, Frank Li, Roya Ensafi 等USENIX Security 2017 · 被引用 163 次
- Forwarding-Loop Attacks in Content Delivery NetworksJianjun Chen, Xiaofeng Zheng, Hai-Xin Duan, Jinjin Liang 等NDSS 2016 · 被引用 44 次
- Practical Censorship Evasion Leveraging Content Delivery NetworksHadi Zolfaghari, Amir HoumansadrCCS 2016 · 被引用 44 次
相关 Paper
- CDN Judo: Breaking the CDN DoS Protection with ItselfRun Guo, Weizhong Li, Baojun Liu, Shuang Hao 等NDSS 2020
- Zombie Awakening: Stealthy Hijacking of Active Domains through DNS Hosting ReferralEihal Alowaisheq, Siyuan Tang, Zhihao Wang, Fatemah Alharbi 等CCS 2020 · 被引用 19 次
- All Your DNS Records Point to Us: Understanding the Security Threats of Dangling DNS RecordsDaiping Liu, Shuai Hao, Haining WangCCS 2016 · 被引用 91 次
- Tracking the Stray Sheep: Understanding DNS Response Manipulation in the WildWenhao Wu, Zhaohua Wang, Zihan Li, Qinxin Li 等WWW 2026
- Crack in the Armor: Underlying Infrastructure Threats to RPKI Publication Point ReachabilityYunhao Liu, Jessie Hui Wang, Yuedong Xu, Zongpeng Li 等NDSS 2026
