An organization's security team observes a surge in outgoing DNS queries to external servers from a single internal host, with each query returning unusually large responses (e.g., 4000 bytes). The host is not configured as a DNS resolver. Which attack is MOST likely occurring?
Trap 1: DNS cache poisoning
DNS cache poisoning involves injecting forged or malicious data into a DNS resolver's cache, causing it to return incorrect IP addresses for legitimate domains. While this redirects user traffic to attacker-controlled servers, it does not inherently generate a large volume of outgoing DNS responses from the poisoned server itself. The attack manipulates resolution, rather than creating a surge in response traffic.
Trap 2: DNS zone transfer
A DNS zone transfer is a legitimate process where a secondary DNS server requests and receives a full copy of a zone file from a primary DNS server. This mechanism ensures data consistency and redundancy across authoritative DNS servers. Although it involves data transfer, it is a controlled, authorized replication process, not an unsolicited attack that would cause an unexpected, massive surge in outgoing responses from a server.
Trap 3: DNS amplification DDoS attack
A DNS amplification DDoS attack leverages open recursive DNS resolvers to flood a target with an overwhelming volume of DNS response traffic. Attackers send small DNS queries with a spoofed source IP address (the target's IP) to numerous vulnerable resolvers, which then send much larger responses to the unsuspecting victim. This technique effectively uses the compromised or misconfigured DNS servers as amplifiers, generating a significant surge in outgoing data towards the target.
- A
DNS cache poisoning
Why it fails: DNS cache poisoning involves injecting forged or malicious data into a DNS resolver's cache, causing it to return incorrect IP addresses for legitimate domains. While this redirects user traffic to attacker-controlled servers, it does not inherently generate a large volume of outgoing DNS responses from the poisoned server itself. The attack manipulates resolution, rather than creating a surge in response traffic.
- B
DNS zone transfer
Why it fails: A DNS zone transfer is a legitimate process where a secondary DNS server requests and receives a full copy of a zone file from a primary DNS server. This mechanism ensures data consistency and redundancy across authoritative DNS servers. Although it involves data transfer, it is a controlled, authorized replication process, not an unsolicited attack that would cause an unexpected, massive surge in outgoing responses from a server.
- C
DNS amplification DDoS attack
Why it fails: A DNS amplification DDoS attack leverages open recursive DNS resolvers to flood a target with an overwhelming volume of DNS response traffic. Attackers send small DNS queries with a spoofed source IP address (the target's IP) to numerous vulnerable resolvers, which then send much larger responses to the unsuspecting victim. This technique effectively uses the compromised or misconfigured DNS servers as amplifiers, generating a significant surge in outgoing data towards the target.
- D
DNS tunneling
DNS tunneling is a technique used to encapsulate data of other protocols within DNS queries and responses, often for covert communication or data exfiltration. While it involves using DNS traffic to bypass firewalls or security controls, its primary goal is to establish a hidden communication channel, not to generate an enormous volume of large, legitimate-looking DNS responses for denial-of-service. The data volume is typically limited by the tunneling payload, not designed for massive amplification.