Je mehr man sich anstrengt, desto mehr scheitert man: Die Denial-of-Service-Angriffe auf DNSSEC durch die algorithmische Komplexität von KeyTrap

Teilen:
Elias Heftrig, Haya Schulmann, Niklas Vogel, Michael Waidner

Availability is a major concern in the design of DNSSEC. To ensure availability, DNSSEC follows Postel’s Law [RFC1123]: “Be liberal in what you accept, and conservative in what you send.” Hence, nameservers should send not just one matching key for a record set, but all the relevant cryptographic material, e.g., all the keys for all the ciphers that they support and all the corresponding signatures. This ensures that validation succeeds, and hence availability, even if some of the DNSSEC keys are misconfigured, incorrect or correspond to unsupported ciphers.
We show that this design of DNSSEC is flawed. Exploiting vulnerable recommendations in the DNSSEC standards, we develop a new class of DNSSEC-based algorithmic complexity attacks on DNS, we dub KeyTrap attacks. All popular DNS implementations and services are vulnerable. With just a single DNS packet, the KeyTrap attacks lead to a 2.000.000x spike in CPU instruction count in vulnerable DNS resolvers, stalling some for as long as 16 hours. This devastating effect prompted major DNS vendors to refer to KeyTrap as the worst attack on DNS ever discovered. Exploiting KeyTrap, an attacker could effectively disable Internet access in any system utilizing a DNSSEC-validating resolver.
We disclosed KeyTrap to vendors and operators on November 2, 2023, confidentially reporting the vulnerabilities to a closed group of DNS experts, operators and developers from the industry. Since then we have been working with all major vendors to mitigate KeyTrap, repeatedly discovering and assisting in closing weaknesses in proposed patches. Following our disclosure, the industry-wide umbrella CVE-2023-50387 has been assigned, covering the DNSSEC protocol vulnerabilities we present in this work.

Quelle

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
7:19 pm, Mai 17, 2025
Wetter-Symbol 18°C
L: 18° | H: 20°
klarer Himmel
Luftfeuchtigkeit: 52 %
Druck: 1021 mb
Wind: 2 mph NNW
Windböe: 4 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 0%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 5:05 am
Sonnenuntergang: 8:48 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
18° | 20°°C 0 mm 0% 7 mph 57 % 1021 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
9° | 16°°C 0 mm 0% 9 mph 83 % 1022 mb 0 mm/h
Mo. Mai 19 10:00 pm
Wetter-Symbol
11° | 19°°C 0.2 mm 20% 13 mph 78 % 1022 mb 0 mm/h
Di. Mai 20 10:00 pm
Wetter-Symbol
9° | 21°°C 0.35 mm 35% 9 mph 81 % 1022 mb 0 mm/h
Mi. Mai 21 10:00 pm
Wetter-Symbol
11° | 20°°C 0.09 mm 9% 11 mph 79 % 1020 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
15° | 17°°C 0 mm 0% 7 mph 57 % 1021 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
12° | 14°°C 0 mm 0% 5 mph 68 % 1022 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
11° | 11°°C 0 mm 0% 6 mph 83 % 1021 mb 0 mm/h
Tomorrow 7:00 am
Wetter-Symbol
9° | 9°°C 0 mm 0% 8 mph 82 % 1021 mb 0 mm/h
Tomorrow 10:00 am
Wetter-Symbol
11° | 11°°C 0 mm 0% 6 mph 69 % 1022 mb 0 mm/h
Tomorrow 1:00 pm
Wetter-Symbol
15° | 15°°C 0 mm 0% 7 mph 52 % 1021 mb 0 mm/h
Tomorrow 4:00 pm
Wetter-Symbol
16° | 16°°C 0 mm 0% 9 mph 49 % 1020 mb 0 mm/h
Tomorrow 7:00 pm
Wetter-Symbol
14° | 14°°C 0 mm 0% 8 mph 56 % 1019 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€92,469.39
-0.76%
Ethereum(ETH)
€2,216.49
-4.21%
Fesseln(USDT)
€0.90
0.00%
XRP(XRP)
€2.09
-3.16%
Solana(SOL)
€148.92
-2.69%
USDC(USDC)
€0.90
0.00%
Dogecoin(DOGE)
€0.192512
-5.18%
Shiba Inu(SHIB)
€0.000013
-5.14%
Pepe(PEPE)
€0.000011
-8.19%
Peanut das Eichhörnchen(PNUT)
€0.269711
-10.27%
Nach oben scrollen