Sep 6 – 7, 2023 Workshop
Meliá Danang Beach Resort
Asia/Ho_Chi_Minh timezone

TsuKing: Coordinating DNS Resolvers and Queries into Potent DoS Amplifiers

Sep 7, 2023, 2:25 PM
19 Trường Sa, Hoà Hải, Ngũ Hành Sơn, Đà Nẵng 550000, Vietnam
In-Person Standard Presentation OARC 41 Day 2


Fenglu Zhang (Tsinghua University)


In this talk, we present a new DNS amplification attack named TsuKing. Instead of exploiting individual DNS resolvers independently to achieve an amplification effect, TsuKing deftly coordinates numerous vulnerable DNS resolvers and crafted queries together to form potent DoS amplifiers. We demonstrate that with TsuKing, an initial small amplification factor can increase exponentially through the internal layers of coordinated amplifiers, resulting in an extremely powerful amplification attack. TsuKing has three variants, including DNSRetry, DNSChain, and DNSLoop, all of which exploit a suite of inconsistent DNS implementations to achieve an enormous amplification effect. We conducted comprehensive measurements and evaluations to demonstrate the feasibility of TsuKing. In particular, we found that about 11.7% of 1.3M open DNS resolvers are potentially vulnerable to being exploited by TsuKing. And real-world controlled evaluations indicated that adversaries can achieve an amplification factor of at least 3,700×. We have reported the above vulnerabilities to all relevant vendors and also provided them with our recommendations for mitigation. We have received positive responses from 5 vendors, such as Unbound, confirming the issues, and got 3 CVE numbers. Some of the vendors are actively implementing our recommendations.

Primary authors

Mr Wei Xu (Tsinghua University) Xiang Li (Tsinghua University) Dr Chaoyi Lu (Tsinghua University) Prof. Baojun Liu (Tsinghua University) Dr Jia Zhang (Tsinghua University) Prof. Jianjun Chen (Tsinghua University) Prof. Tao Wan (University of Texas at Dallas) Prof. Haixin Duan (Tsinghua University)

Presentation materials