4 ms·
> I doubt they thought they'd take down the root servers, but it seems totally reasonable that they might have wondered if the root server operators would filte
by zrm 3y ago
> I doubt they thought they'd take down the root servers, but it seems totally reasonable that they might have wondered if the root server operators would filter DDoS traffic based on the domain name appearing in the requests.
Which wouldn't have worked even if it worked.
When a recursive nameserver asks the root servers for the address of "916yy.com", the root servers are just going to direct it to the .com servers. Which the recursive nameserver already knows when it has the address of the .com servers cached, as would be the case >99% of the time, and would ask them directly instead of bothering the root servers to begin with.
Even in the rare case when the recursive nameserver doesn't have the address of the .com servers cached yet, that condition would last for approximately zero seconds before someone tries to resolve some other .com domain name and it gets cached, typically for at least a day.
- paulddraper 3y agoSurely there are a number of resolvers who have a cold cache. But yes, even taking down every root server (temporarily) has a limited effect.
- zrm 3y agoWe're not talking about taking down the root servers, we're talking about the root servers mitigating the attack by dropping requests for that specific .com domain name. That would have no effect on any recursive resolver that had the .com nameservers cached, which is substantially all of them because it happens as soon as they resolve any other .com domain name. That happens immediately and continuously even for small nameservers. You would have a window of under a second once every TTL (currently 48 hours for gtld-servers.net, the nameservers for .com) between when the cached entry expires and when the next request for some other .com domain name comes in and refreshes it with a request to the root servers that they'd actually answer.
- remram 3y ago> dropping requests for that specific .com domain name To do that, you have to accept client traffic, and parse the request. The only thing you "drop" is sending the response. It is not a very efficient mitigation mechanism, the DNS server would still become unavailable under pressure. It also hurts the victim, which is senseless.
- zrm 3y agoDNS has a design flaw where the responses are often much larger than the requests, so dropping the response could reduce bandwidth use by a factor of ten or more.
- plagiat0r 3y agoA lot of recursive servers can be bootstrapped with a entire root zone, which content is public here: https://www.iana.org/domains/root/files https://www.iana.org/domains/root/files Recursive servers do not need public root servers because you could run a root yourself at 127.0.0.99 and point recursive to it, or bootstrap recursive one with this data. Of course, you need full control of the recursive server to set it up this way. Taking down all public root servers (all 1723 of them, according to public data) may have no impact on a properly set up recursive servers, because root zone is public and you can host it yourself.