Home > CAPEC List > CAPEC-598: DNS Spoofing (Version 3.2)  

CAPEC-598: DNS Spoofing

Attack Pattern ID: 598
Abstraction: Detailed
Status: Draft
Presentation Filter:
+ Description
An adversary sends a malicious ("NXDOMAIN" ("No such domain") code, or DNS A record) response to a targets route request before a legitimate resolver can. This technique requires an On-path or In-path device that can monitor and respond to the targets DNS requests. This attack differs from BGP Tampering in that it directly responds to requests made by the target instead of polluting the routing the targets infrastructure uses.
+ Relationships

The table below shows the other attack patterns and high level categories that are related to this attack pattern. These relationships are defined as ChildOf and ParentOf, and give insight to similar items that may exist at higher and lower levels of abstraction. In addition, relationships such as CanFollow, PeerOf, and CanAlsoBe are defined to show similar attack patterns that the user may want to explore.

NatureTypeIDName
ChildOfStandard Attack PatternStandard Attack Pattern - A standard level attack pattern in CAPEC is focused on a specific methodology or technique used in an attack. It is often seen as a singular piece of a fully executed attack. A standard attack pattern is meant to provide sufficient details to understand the specific technique and how it attempts to accomplish a desired goal. A standard level attack pattern is a specific type of a more abstract meta level attack pattern.194Fake the Source of Data

The table below shows the views that this attack pattern belongs to and top level categories within that view.

+ Prerequisites
On/In Path Device
+ Skills Required
[Level: Low]
To distribute email
+ Mitigations
Design: Avoid dependence on DNS
Design: Include "hosts file"/IP address in the application
Implementation: Utilize a .onion domain with Tor support
Implementation: DNSSEC
Implementation: DNS-hold-open
+ Example Instances
Below-Recursive DNS Poisoning: When an On/In-path device between a recursive DNS server and a user sends a malicious ("NXDOMAIN" ("No such domain") code, or DNS A record ) response before a legitimate resolver can.
Above-Recursive DNS Poisoning: When an On/In-path device between an authority server (e.g., government-managed) and a recursive DNS server sends a malicious ("NXDOMAIN" ("No such domain")code, or a DNS record) response before a legitimate resolver can.
+ References
[REF-477] John-Paul Verkamp and Minaxi Gupta. "Inferring Mechanics of Web Censorship Around the World". USENIX. 2012.
[REF-479] Anonymous. "Towards a Comprehensive Picture of the Great Firewall's DNS Censorship". USENIX. 2014.
+ Content History
Submissions
Submission DateSubmitterOrganization
2017-01-04Seamus Tuohy
Modifications
Modification DateModifierOrganization
2019-04-04CAPEC Content TeamThe MITRE Corporation
Updated Related_Attack_Patterns
More information is available — Please select a different filter.
Page Last Updated or Reviewed: September 30, 2019