June 9, 2020
Intranet Redirect Detector or Pseudo Random Subdomain Attack?

Jun 9, 2020, 7:10 PM
Duane Wessels (Verisign)


DNS query traffic received by root name servers include a significant amount of queries for random, single-label strings. These first appeared in 2011 and are attributed to a function in the Chrome browser source code, whose purpose is to detect NXDOMAIN "hijacking."

In this presentation we show how the volume of these probe queries from Chrome have grown over time and now comprises nearly 50% of root server query traffic. We further show how the query patterns have changed over time, and that these queries can expose domain search list processing by resolvers.

Duane Wessels (Verisign)


Matthew Thomas (Verisign)

