Last week, a collaborative effort was presented by a fellow academic at the Conference on Network and Service Management 2024. The work pairs continuous #DNS scans of open resolvers with #DDoS attack telemetry. The paper sheds light on the misuse of reflecting DNS infrastructure. Key takeaways are:
- Not all UDP/53 services are open recursive resolvers while still posing a threat
- Resolvers in countries with low IP churn results in more abuse for R/A
- Exploration of untapped potential.
Glossy Mirrors: On the Role of Open Resolvers in Reflection and Amplification DDoS Attacks