{"id":1759,"date":"2023-09-21T21:33:42","date_gmt":"2023-09-21T21:33:42","guid":{"rendered":"https:\/\/blogs.infoblox.com\/?p=8908"},"modified":"2023-09-21T21:33:42","modified_gmt":"2023-09-21T21:33:42","slug":"protecting-uptime-everytime-the-importance-of-dns-ddos-defense","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2023\/09\/21\/protecting-uptime-everytime-the-importance-of-dns-ddos-defense\/","title":{"rendered":"Protecting Uptime Everytime \u2013 The Importance of DNS DDoS Defense"},"content":{"rendered":"<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/09\/protecting-uptime-everytime-the-importance-of-dns-ddos-defense.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p>One thing that could threaten your online presence are DNS DDoS attacks. DNS is a critical component of the Internet that translates domain names into IP addresses. Without DNS, it would be impossible to access websites using domain names. A DNS DDoS (distributed denial-of-service) attack is a type of cyber attack that works by overwhelming an organization\u2019s authoritative DNS server with a flood of requests, rendering the server unable to respond to legitimate requests. This surge can cause websites to slow down or even become unavailable, resulting in disruption of services to end users, and lost revenue and reputation damage for the business.<\/p>\n<p>We all still remember the <strong><a href=\"https:\/\/www.theguardian.com\/technology\/2016\/oct\/26\/ddos-attack-dyn-mirai-botnet\">Dyn attack of 2016<\/a><\/strong>, where the Internet infrastructure company that hosted authoritative DNS for several Internet domains was impacted by a DDoS attack, affecting availability of many popular websites and online services. Well, DNS DDoS attacks have been on the rise again recently. According to this <strong><a href=\"https:\/\/www.fastcompany.com\/90945374\/why-leaders-should-care-about-the-surge-in-domain-name-system-ddos-attacks\" target=\"_blank\" rel=\"noopener\">Fast Company article<\/a><\/strong>, there has been a 243% increase in sophisticated DNS attacks since 2019.<\/p>\n<h3>Types of DNS DDoS Attacks<\/h3>\n<p>All DNS DDoS attacks are not created equal. Each type of attack has a different technique and can cause varying degrees of impact.<\/p>\n<p><strong>Volumetric Attacks:<\/strong><\/p>\n<ol>\n<li>DNS reflection\/DDoS attacks\u2014These volumetric attacks use third-party DNS servers (open resolvers) to propagate a DoS or DDoS attack.<\/li>\n<li>DNS amplification\u2014This uses a specially crafted query to create an amplified response to flood the victim with traffic.<\/li>\n<li>TCP\/UDP\/ICMP floods\u2014These are denial-of-service attacks on layer 3 to bring a network or service down by flooding it with large amounts of traffic.<\/li>\n<li>NXDOMAIN\u2014These attacks flood the DNS server with requests for non-existent domains, causing cache saturation and slower response times.<\/li>\n<li>Random sub-domain (slow drip attacks)\/domain lock-up attacks\/phantom domain attacks\u2014These low-volume stealth attacks flood the DNS server with requests for phantom or misbehaving domains that are set up as part of the attack, causing resource exhaustion, cache saturation, outbound query limit exhaustion, and degraded performance.<\/li>\n<\/ol>\n<p><strong>Exploits:<\/strong><\/p>\n<ol>\n<li>DNS-based exploits\u2014These are attacks that exploit vulnerabilities in the DNS software.<\/li>\n<li>DNS cache poisoning\u2014These attacks corrupt the DNS cache data with a rogue address.<\/li>\n<li>Protocol anomalies\u2014These attacks cause the server to crash by sending malformed packets and queries.<\/li>\n<li>Reconnaissance\u2014These are attempts by hackers to get information on the network environment before launching a large DDoS or other type of attack.<\/li>\n<li>DNS hijacking\u2014These attacks override domain registration information to point to a rogue DNS server.<\/li>\n<li>Data exfiltration (using known tunnels)\u2014These attacks involve tunneling another protocol through DNS port 53 to exfiltrate data.<\/li>\n<\/ol>\n<h3>Protecting Uptime With Built-In DNS DDoS Defense<\/h3>\n<p>If you are hosting your own authoritative DNS, use DNS infrastructure that has built-in DDoS mitigation to stay resilient even when there is an attack. The solution should block against not only volumetric attacks but also DNS specific exploits and DNS hijacking to cover all aspects of protection.<\/p>\n<p>Infoblox <strong><a href=\"https:\/\/www.infoblox.com\/products\/advanced-dns-protection\/\" target=\"_blank\" rel=\"noopener\">Advanced DNS Protection<\/a><\/strong> is a DNS DDoS mitigation solution available on Infoblox DNS servers, that effectively shields you from the widest range of DNS attacks, such as volumetric attacks, NXDOMAIN, exploits and more. Instead of just relying on infrastructure overprovisioning or simple rate-response limiting, the solution intelligently detects and mitigates DNS attacks using signature based methods and constantly updated threat intelligence, without the need to apply security patches. In addition, it provides easy-to-access reporting on the attacks, so that the admin knows the type and impact of the attacks.<\/p>\n<p><strong>Using Hybrid External DNS<\/strong><\/p>\n<p>If your authoritative DNS is hosted by a third party provider, it\u2019s not a good idea to solely rely on that hosting provider for your external DNS presence. Employ a hybrid external DNS approach, where on-premises DNS appliances are used in combination with the DNS hosting provider to support external authoritative service. This approach helps ensure that if the hosting provider\u2019s DNS service goes down, you still have the on-premises DNS servers as a fallback to minimize any disruptions. A hybrid approach enables organizations to retain control of their DNS and provides redundancy.<\/p>\n<p>Don\u2019t leave your online presence to chance. Bolster your DNS defenses for maximum uptime everytime.<\/p>\n<p> <a href=\"https:\/\/blogs.infoblox.com\/security\/protecting-uptime-everytime-the-importance-of-dns-ddos-defense\/\">Infoblox Original<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>One thing that could threaten your online presence are DNS<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[978,174,977,976,550,42],"tags":[981,178,980,979,558,50],"class_list":["post-1759","post","type-post","status-publish","format-standard","hentry","category-advanced-dns-protection","category-ddos","category-dns-attacks","category-dns-ddos","category-nios","category-security","tag-advanced-dns-protection","tag-ddos","tag-dns-attacks","tag-dns-ddos","tag-nios","tag-security"],"featured_image_urls":{"full":"","thumbnail":"","medium":"","medium_large":"","large":"","1536x1536":"","2048x2048":"","chromenews-featured":"","chromenews-large":"","chromenews-medium":""},"author_info":{"display_name":"Infoblox","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/infoblox\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/advanced-dns-protection\/\" rel=\"category tag\">Advanced DNS Protection<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/ddos\/\" rel=\"category tag\">DDoS<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/dns-attacks\/\" rel=\"category tag\">DNS Attacks<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/dns-ddos\/\" rel=\"category tag\">DNS DDoS<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/nios\/\" rel=\"category tag\">NIOS<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/security\/\" rel=\"category tag\">Security<\/a>","tag_info":"Security","comment_count":"0","jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/1759","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=1759"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/1759\/revisions"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=1759"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=1759"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=1759"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}