การโจมตีขยาย DNS

การโจมตีขยาย DNS คือประเภทหนึ่งของการโจมตี DDoS ที่ใช้ประโยชน์จาก [[recursive-dns|DNS resolver]] แบบเปิดเพื่อท่วม victim ด้วย traffic ผู้โจมตี spoof [[ip-address|IP address]] ของ victim ในคำถาม [[dns|DNS]] แบบ UDP และส่งไปยัง resolver แบบเปิด ซึ่งจะส่งการตอบสนองขนาดใหญ่ (มักเป็น record ที่เปิดใช้ [[edns|EDNS]] หรือลงนาม [[dnssec|DNSSEC]] ที่ใหญ่กว่าคำถามหลายร้อยเท่า) ไปยัง victim โดยตรง ปัจจัยขยายที่ 50x-70x เป็นเรื่องปกติ มาตรการบรรเทา ได้แก่ RRL บน authoritative server, BCP38 ingress filtering เพื่อป้องกัน IP spoofing และการจำกัด open recursive resolution เฉพาะ client ที่ได้รับอนุญาต

ตัวอย่าง

An attacker sending 1 Gbps of spoofed DNS queries to open resolvers can generate 50–70 Gbps of response traffic directed at a victim, overwhelming their network with a fraction of the upstream bandwidth required.