Table of Contents
Fetching ...

Forward to Hell? On the Potentials of Misusing Transparent DNS Forwarders in Reflective Amplification Attacks

Maynard Koch, Florian Dolzmann, Thomas C. Schmidt, Matthias Wählisch

TL;DR

Transparent DNS forwarders form a large, under-secured portion of the open DNS infrastructure and enable scalable reflective amplification by bypassing source-address rewrites. The authors combine internet-wide measurements, controlled lab experiments, and fingerprinting to quantify prevalence, rate limits, and amplification potential, demonstrating up to $14\times$ scaling via anycast backends and substantial throughput gains over recursive forwarders. They show how TFs bypass firewalled resolvers and rate limits, and how orchestration across global TFs can induce high-volume, geographically distributed attacks. The work provides concrete mitigation options (ingress filtering, RP filtering, firewall hardening) and highlights the need for ongoing measurement and defender awareness, aided by responsible disclosure that reduced the attack surface by about 30%. Overall, the study reveals a tangible, global threat surface posed by transparent forwarders and offers practical guidance for DNS operators and policymakers to tighten defenses.

Abstract

The DNS infrastructure is infamous for facilitating reflective amplification attacks. Various countermeasures such as server shielding, access control, rate limiting, and protocol restrictions have been implemented. Still, the threat remains throughout the deployment of DNS servers. In this paper, we report on and evaluate the often unnoticed threat that derives from transparent DNS forwarders, a widely deployed, incompletely functional set of DNS components. Transparent DNS forwarders transfer DNS requests without rebuilding packets with correct source addresses. As such, transparent forwarders feed DNS requests into (mainly powerful and anycasted) open recursive resolvers, which thereby can be misused to participate unwillingly in distributed reflective amplification attacks. We show how transparent forwarders raise severe threats to the Internet infrastructure. They easily circumvent rate limiting and achieve an additional, scalable impact via the DNS anycast infrastructure. We empirically verify this scaling behavior up to a factor of 14. Transparent forwarders can also assist in bypassing firewall rules that protect recursive resolvers, making these shielded infrastructure entities part of the global DNS attack surface.

Forward to Hell? On the Potentials of Misusing Transparent DNS Forwarders in Reflective Amplification Attacks

TL;DR

Transparent DNS forwarders form a large, under-secured portion of the open DNS infrastructure and enable scalable reflective amplification by bypassing source-address rewrites. The authors combine internet-wide measurements, controlled lab experiments, and fingerprinting to quantify prevalence, rate limits, and amplification potential, demonstrating up to scaling via anycast backends and substantial throughput gains over recursive forwarders. They show how TFs bypass firewalled resolvers and rate limits, and how orchestration across global TFs can induce high-volume, geographically distributed attacks. The work provides concrete mitigation options (ingress filtering, RP filtering, firewall hardening) and highlights the need for ongoing measurement and defender awareness, aided by responsible disclosure that reduced the attack surface by about 30%. Overall, the study reveals a tangible, global threat surface posed by transparent forwarders and offers practical guidance for DNS operators and policymakers to tighten defenses.

Abstract

The DNS infrastructure is infamous for facilitating reflective amplification attacks. Various countermeasures such as server shielding, access control, rate limiting, and protocol restrictions have been implemented. Still, the threat remains throughout the deployment of DNS servers. In this paper, we report on and evaluate the often unnoticed threat that derives from transparent DNS forwarders, a widely deployed, incompletely functional set of DNS components. Transparent DNS forwarders transfer DNS requests without rebuilding packets with correct source addresses. As such, transparent forwarders feed DNS requests into (mainly powerful and anycasted) open recursive resolvers, which thereby can be misused to participate unwillingly in distributed reflective amplification attacks. We show how transparent forwarders raise severe threats to the Internet infrastructure. They easily circumvent rate limiting and achieve an additional, scalable impact via the DNS anycast infrastructure. We empirically verify this scaling behavior up to a factor of 14. Transparent forwarders can also assist in bypassing firewall rules that protect recursive resolvers, making these shielded infrastructure entities part of the global DNS attack surface.
Paper Structure (58 sections, 1 equation, 14 figures, 8 tables)

This paper contains 58 sections, 1 equation, 14 figures, 8 tables.

Figures (14)

  • Figure 1: Number of transparent DNS forwarders and other open DNS components per week from June 2021 to January 2025. By sharing our results with network operators, we were able to decrease the impact of transparent forwarders by 30%.
  • Figure 2: Data paths in reflective amplification attacks via different open DNS components. Transparent forwarders can scale up attacks as they do not carry amplified traffic and enable distribution without a botnet.
  • Figure 3: Deployment scenarios of transparent forwarders in DNS reflection and amplification attacks.
  • Figure 4: Differences of median response times per scan between transparent and recursive forwarders for countries with a high number of transparent forwarders. Transparent forwarders reply faster.
  • Figure 5: Using transparent forwarders to launch a globally distributed DNS amplification attack via large public DNS providers with anycast deployment such as Google.
  • ...and 9 more figures