John Heidemann / Papers / When the Dike Breaks: Dissecting DNS Defenses During DDoS (extended)

When the Dike Breaks: Dissecting DNS Defenses During DDoS (extended)
Giovane C
USC/Information Sciences Institute


Giovane C. M. Moura, John Heidemann, Moritz Müller, Ricardo de O. Schmidt and Marco Davids. When the Dike Breaks: Dissecting DNS Defenses During DDoS (extended). Technical Report ISI-TR-725. USC/Information Sciences Institute. [PDF] [alt PDF]


The Internet’s Domain Name System (DNS) is a frequent target of Distributed Denial-of-Service (DDoS) attacks, but such attacks have had very different outcomes—some attacks have disabled major public websites, while the external effects of other attacks have been minimal. While on one hand the DNS protocol is a relatively simple, the \emphsystem has many moving parts, with multiple levels of caching and retries and replicated servers. This paper uses controlled experiments to examine how these mechanisms affect DNS resilience and latency, exploring both the client side’s DNS \emphuser experience, and server-side traffic. We find that, for about about 30% of clients, caching is not effective. However, when caches are full they allow about half of clients to ride out server outages, and caching and retries allow up to half of the clients to tolerate DDoS attacks that result in 90% query loss, and almost all clients to tolerate attacks resulting in 50% packet loss. The cost of such attacks to clients are greater median latency. For servers, retries during DDoS attacks increase normal traffic up to 8\times. Our findings about caching and retries can explain why some real-world DDoS cause service outages for users while other large attacks have minimal visible effects.

Bibtex Citation

  author = {Moura, Giovane C. M. and Heidemann, John and M{\"u}ller, Moritz and de O. Schmidt, Ricardo and Davids, Marco},
  title = {When the Dike Breaks: Dissecting {DNS}
                    Defenses During {DDoS} (extended)},
  institution = {USC/Information Sciences Institute},
  year = {2018},
  sortdate = {2018-05-30},
  number = {ISI-TR-725},
  project = {ant, lacanic, pinest, nipet},
  jsubject = {network_security},
  month = may,
  location = {johnh: pafile},
  keywords = {anycast, dns, ddos, root ddos},
  url = {},
  pdfurl = {},
  otherurl = {},
  myorganization = {USC/Information Sciences Institute},
  copyrightholder = {authors}
Copyright © by John Heidemann