MTDNS: Moving Target Defense for Resilient DNS Infrastructure
Abdullah Aydeger, Pei Zhou, Sanzida Hoque, Marco Carvalho, Engin, Zeydan

TL;DR
This paper introduces MTDNS, a resilient DNS infrastructure using Moving Target Defense with SDN and NFV to dynamically redirect traffic, improving attack resilience and reducing latency during DNS flooding attacks.
Contribution
It presents a novel MTD-based DNS defense mechanism leveraging SDN and NFV, with implementation and testing demonstrating improved resilience and performance.
Findings
Higher success rate in DNS query resolution under attack
Significantly reduced average latency during flooding attacks
Effective traffic redirection using SDN and NFV
Abstract
One of the most critical components of the Internet that an attacker could exploit is the DNS (Domain Name System) protocol and infrastructure. Researchers have been constantly developing methods to detect and defend against the attacks against DNS, specifically DNS flooding attacks. However, most solutions discard packets for defensive approaches, which can cause legitimate packets to be dropped, making them highly dependable on detection strategies. In this paper, we propose MTDNS, a resilient MTD-based approach that employs Moving Target Defense techniques through Software Defined Networking (SDN) switches to redirect traffic to alternate DNS servers that are dynamically created and run under the Network Function Virtualization (NFV) framework. The proposed approach is implemented in a testbed environment by running our DNS servers as separate Virtual Network Functions, NFV Manager,…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsNetwork Security and Intrusion Detection · Software-Defined Networks and 5G · Internet Traffic Analysis and Secure E-voting
