Tấn Công Khuếch Đại DNS
Embed This Widget
Add the script tag and a data attribute to embed this widget.
Embed via iframe for maximum compatibility.
<iframe src="https://tldfyi.com/iframe/glossary/dns-amplification/" width="420" height="400" frameborder="0" style="border:0;border-radius:10px;max-width:100%" loading="lazy"></iframe>
Paste this URL in WordPress, Medium, or any oEmbed-compatible platform.
https://tldfyi.com/glossary/dns-amplification/
Add a dynamic SVG badge to your README or docs.
[](https://tldfyi.com/glossary/dns-amplification/)
Use the native HTML custom element.
Tấn công khuếch đại DNS là loại tấn công DDoS khai thác các [[recursive-dns|DNS resolver]] mở để làm tràn lưu lượng đến nạn nhân. Kẻ tấn công giả mạo [[ip-address|địa chỉ IP]] của nạn nhân trong các truy vấn [[dns|DNS]] dựa trên UDP và gửi tới các resolver mở, sau đó các resolver gửi phản hồi lớn (thường là bản ghi kích hoạt [[edns|EDNS]] hoặc ký [[dnssec|DNSSEC]], lớn hơn truy vấn hàng trăm lần) trực tiếp đến nạn nhân. Hệ số khuếch đại 50–70x rất phổ biến. Biện pháp giảm thiểu gồm RRL trên authoritative server, lọc BCP38 để chống giả mạo IP, và hạn chế recursive resolution mở chỉ cho client được phép.
Ví dụ
An attacker sending 1 Gbps of spoofed DNS queries to open resolvers can generate 50–70 Gbps of response traffic directed at a victim, overwhelming their network with a fraction of the upstream bandwidth required.