The Experts below are selected from a list of 45 Experts worldwide ranked by ideXlab platform
Haya Shulman - One of the best experts on this subject based on the ideXlab platform.
-
CNS - Fragmentation Considered Poisonous, or: One-domain-to-rule-them-all.org
2013 IEEE Conference on Communications and Network Security (CNS), 2013Co-Authors: Amir Herzberg, Haya ShulmanAbstract:We present effective off-path DNS cache poisoning attacks, circumventing widely-deployed challenge-response defenses, e.g., Transaction Identifier randomisation, port and query randomisation. Our attacks depend on the use of UDP to retrieve long DNS responses, resulting in IP fragmentation. We show how attackers are often able to generate such fragmented responses, and then abuse them to inject spoofed, 'poisonous' records, into legitimate DNS responses. We also studied how resolvers, name servers, domains and registrars, can defend against our attacks. The best defense is deployment and enforcement of DNSSEC validation. However, DNSSEC must be deployed correctly by both domain and resolver, which is challenging; we hope our results will catalyse this process, but it will surely take long time. In fact, recent study found less than 1 % of resolvers reject responses upon DNSSEC validation failures. Note also that, ironically, adoption of DNSSEC by a domain, is the main reason for fragmented DNS responses (abused in our attacks). We therefore present several short-term countermeasures, which can complement DNSSEC, especially until DNSSEC deployment is complete. We validated our attacks against popular resolvers (Bind and Unbound), and real domains in the Internet.
-
Fragmentation Considered Poisonous, or: One-domain-to-rule-them-all.org
2013 IEEE Conference on Communications and Network Security (CNS), 2013Co-Authors: Amir Herzberg, Haya ShulmanAbstract:We present effective off-path DNS cache poisoning attacks, circumventing widely-deployed challenge-response defenses, e.g., Transaction Identifier randomisation, port and query randomisation. Our attacks depend on the use of UDP to retrieve long DNS responses, resulting in IP fragmentation. We show how attackers are often able to generate such fragmented responses, and then abuse them to inject spoofed, 'poisonous' records, into legitimate DNS responses. We also studied how resolvers, name servers, domains and registrars, can defend against our attacks. The best defense is deployment and enforcement of DNSSEC validation. However, DNSSEC must be deployed correctly by both domain and resolver, which is challenging; we hope our results will catalyse this process, but it will surely take long time. In fact, recent study found less than 1 % of resolvers reject responses upon DNSSEC validation failures. Note also that, ironically, adoption of DNSSEC by a domain, is the main reason for fragmented DNS responses (abused in our attacks). We therefore present several short-term countermeasures, which can complement DNSSEC, especially until DNSSEC deployment is complete. We validated our attacks against popular resolvers (Bind and Unbound), and real domains in the Internet.
Amir Herzberg - One of the best experts on this subject based on the ideXlab platform.
-
CNS - Fragmentation Considered Poisonous, or: One-domain-to-rule-them-all.org
2013 IEEE Conference on Communications and Network Security (CNS), 2013Co-Authors: Amir Herzberg, Haya ShulmanAbstract:We present effective off-path DNS cache poisoning attacks, circumventing widely-deployed challenge-response defenses, e.g., Transaction Identifier randomisation, port and query randomisation. Our attacks depend on the use of UDP to retrieve long DNS responses, resulting in IP fragmentation. We show how attackers are often able to generate such fragmented responses, and then abuse them to inject spoofed, 'poisonous' records, into legitimate DNS responses. We also studied how resolvers, name servers, domains and registrars, can defend against our attacks. The best defense is deployment and enforcement of DNSSEC validation. However, DNSSEC must be deployed correctly by both domain and resolver, which is challenging; we hope our results will catalyse this process, but it will surely take long time. In fact, recent study found less than 1 % of resolvers reject responses upon DNSSEC validation failures. Note also that, ironically, adoption of DNSSEC by a domain, is the main reason for fragmented DNS responses (abused in our attacks). We therefore present several short-term countermeasures, which can complement DNSSEC, especially until DNSSEC deployment is complete. We validated our attacks against popular resolvers (Bind and Unbound), and real domains in the Internet.
-
Fragmentation Considered Poisonous, or: One-domain-to-rule-them-all.org
2013 IEEE Conference on Communications and Network Security (CNS), 2013Co-Authors: Amir Herzberg, Haya ShulmanAbstract:We present effective off-path DNS cache poisoning attacks, circumventing widely-deployed challenge-response defenses, e.g., Transaction Identifier randomisation, port and query randomisation. Our attacks depend on the use of UDP to retrieve long DNS responses, resulting in IP fragmentation. We show how attackers are often able to generate such fragmented responses, and then abuse them to inject spoofed, 'poisonous' records, into legitimate DNS responses. We also studied how resolvers, name servers, domains and registrars, can defend against our attacks. The best defense is deployment and enforcement of DNSSEC validation. However, DNSSEC must be deployed correctly by both domain and resolver, which is challenging; we hope our results will catalyse this process, but it will surely take long time. In fact, recent study found less than 1 % of resolvers reject responses upon DNSSEC validation failures. Note also that, ironically, adoption of DNSSEC by a domain, is the main reason for fragmented DNS responses (abused in our attacks). We therefore present several short-term countermeasures, which can complement DNSSEC, especially until DNSSEC deployment is complete. We validated our attacks against popular resolvers (Bind and Unbound), and real domains in the Internet.
Wang Yi - One of the best experts on this subject based on the ideXlab platform.
-
research and implementation of Transaction Identifier
Journal of Software, 1999Co-Authors: Wang YiAbstract:The assignment of Transaction Identifiers is one of the important factors influencing the per formance of nested Transactions. In this paper, the requirements which the Transaction process poses on the Transaction Identifiers under the nested Transaction model are analysed. Based on this, a series of efficient and practical assignment strategies are proposed, and the bit based Transaction Identifier strategy is implemented in the object oriented database system——KDOODB (KeDa object oriented database). At last, the performance evaluation results are given.
Yang Qingxiang - One of the best experts on this subject based on the ideXlab platform.
-
method for finding frequent set based on Transaction Identifier sequence
Journal of Anyang Institute of Technology, 2008Co-Authors: Yang QingxiangAbstract:Character string comparing is an important method in computer information managing. To solve the localization question of current algorithms for mining association rule not to save and use historical mining harvest,a method is present that Transaction database is translated item database,and supporting Transaction Identifier sequence is constructed. An algorithm for comparing double sequence strings and a method of finding bigger frequent item set based on string comparing are given in order to improve mining efficiency and decrease negative influence that string comparing' efficiency is lower.
ジン ヨンシュン - One of the best experts on this subject based on the ideXlab platform.
-
system and method for supporting a common Transaction Identifier xid optimization and Transaction affinity based on the resource manager rm instance detection in a Transaction environment
2015Co-Authors: シェン シュガン, ヂャン チンシェン, リトル トッド ジェイ, ジン ヨンシュンAbstract:To provide a system and method capable of supporting Transaction processing in a Transaction environment. Coordinator for global Transactions, a common Transaction Identifier and information about the resource manager instance, operates to propagate the one or more participants of the global Transaction in the Transaction environment. Coordinator, the 1, wherein the one or more participants that the resource manager instance sharing a coordinator, it possible to use a common Transaction Identifier, using a single Transaction branch, share resource manager instance One or more of participation can process global Transactions for punt.