Dunqiu Fan

dblp:237/8014 · DBLP profile ↗
← Back
4ranked-venue papers
0as first author
4since 2021 · last 2025
0000-0002-2199-6834ORCID · reported

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 2 · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Systems, architecture and hardware · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
YearPublicationVenuePosition
2025 RebirthDay Attack: Reviving DNS Cache Poisoning with the Birthday Paradox
abstract
DNS cache poisoning is a persistent game of attack and defense, posing an enduring challenge for the DNS community. Significant efforts have been made to uncover, detect, and mitigate vulnerabilities that increase the risk of cache poisoning. However, no work has systematically revisited whether the original cache poisoning attack based on the Birthday Paradox remains effective. In this work, we introduce RebirthDay, a novel DNS cache poisoning attack targeting recursive resolvers and forwarders, reviving the classic DNS Birthday attack that no longer works since 2002. RebirthDay exploits newly uncovered, protocol-compliant vulnerabilities in DNS extension implementations to bypass the query aggregation mechanism intended to prevent DNS Birthday attacks that has not been well understood. We uncovered that 18 out of 22 mainstream DNS software are vulnerable due to weaknesses in the processing of a DNS extension (i.e., ECS option), specifically lacking or incorrectly implemented ECS coherence checks when handling DNS queries and responses, demonstrating the widespread susceptibility to RebirthDay. These flaws could be exploited to circumvent the query aggregation mechanism and launch RebirthDay attacks. Through comprehensive evaluation, we showed that RebirthDay attacks are highly practical and can have significant real-world impact, affecting 16 router vendors, 14 public DNS services, and 365K (15%) open DNS resolvers. We have reported the identified vulnerabilities to affected vendors and discussed mitigation solutions with them. To date, we have received acknowledgments from 8 vendors, including BIND, Unbound, PowerDNS, and Quad9, and have been assigned 50 CVE-ids. Our study emphasizes the need for greater attention to the importance of ECS verification and DNS extension implementations, revealing new security risks introduced by them.
Xiang Li 0108, Mingming Zhang 0010, Zuyao Xu, Fasheng Miao, Yuqi Qiu, Baojun Liu 0002, Jia Zhang 0004, Hai-Xin Duan, Zheli Liu, Yunhai Zhang, Dunqiu Fan
CCS12
2025 A Trustworthy Attribute-Based Searchable Data Sharing Scheme for Cloud-Edge-End Environments
Kaifa Zheng, Junxu Zhou, Zhenpeng Luo, Dunqiu Fan, Wenjin Li, Peihua Xie, Shuai Ou
ICA3PP (6)5
2025 Gradient-Reweighted Adversarial Camouflage for Physical Object Detection Evasion
Siyuan Liang 0004, Tianrui Lou, Wenjin Li, Dunqiu Fan, Xiaochun Cao
ICCV6
2025 Secure and Dynamic Node Selection in Federated Learning: A Reputation-Based Approach with Blockchain
Kaifa Zheng, Yiming Hei, Chenling Bai, Dunqiu Fan, Tiejun Wu
ISPEC4