Network Working Group J. Damas
Request for Comments: 5358 ISC
BCP: 140 F. Neves
Category: Best Current Practice Registro.br
October 2008
Preventing Use of Recursive Nameservers in Reflector Attacks
Damas & Neves Best Current Practice [Page 1]
RFC 5358 Preventing Rec. NS in Reflector Attacks October 2008 1. IntroductionRecently, DNS [RFC1034] has been named as a major factor in the generation of massive amounts of network traffic used in Denial of Service (DoS) attacks. These attacks, called reflector attacks, are not due to any particular flaw in the design of the DNS or its implementations, except that DNS relies heavily on UDP, the easy abuse of which is at the source of the problem. The attacks have preferentially used DNS due to common default configurations that allow for easy use of open recursive nameservers that make use of such a default configuration.
2. Document Terminology
The key words "MUST", "MUST NOT", "REQUIRED", "SHALL", "SHALL NOT", "SHOULD", "SHOULD NOT", "RECOMMENDED", "MAY", and "OPTIONAL" in this document are to be interpreted as described in [RFC2119].
3. Problem Description
Because most DNS traffic is stateless by design, an attacker could start a DoS attack in the following way:
Damas & Neves Best Current Practice [Page 2]
RFC 5358 Preventing Rec. NS in Reflector Attacks October 2008
2. Taking advantage of clients on non-BCP38 networks, the attacker then crafts a query using the source address of their target victim and sends it to an open recursive nameserver.
Damas & Neves Best Current Practice [Page 3]
RFC 5358 Preventing Rec. NS in Reflector Attacks October 2008 4. Recommended ConfigurationIn this section we describe the Best Current Practice for operating recursive nameservers. Following these recommendations would reduce the chances of any given recursive nameserver being used for the generation of an amplification attack.
Damas & Neves Best Current Practice [Page 4]
RFC 5358 Preventing Rec. NS in Reflector Attacks October 2008
By default, nameservers SHOULD NOT offer recursive service to external networks.
5. Security Considerations
This document does not create any new security issues for the DNS protocol, it deals with a weakness in implementations.
6. Acknowledgments
The authors would like to acknowledge the helpful input and comments of Joe Abley, Olafur Gudmundsson, Pekka Savola, Andrew Sullivan, and Tim Polk.7. References 7.1. Normative References[RFC1034] Mockapetris, P., "Domain names - concepts and facilities",
Damas & Neves Best Current Practice [Page 5]
RFC 5358 Preventing Rec. NS in Reflector Attacks October 2008
[RFC2931] Eastlake, D., "DNS Request and Transaction Signatures
7.2. Informative References
[BCP38] Ferguson, P. and D. Senie, "Network Ingress Filtering:
Damas & Neves Best Current Practice [Page 6]
RFC 5358 Preventing Rec. NS in Reflector Attacks October 2008
Full Copyright Statement