EDBT 2026 Demo / reviewers in the wild / expert
Jonas Bushart
dblp:169/8821
· DBLP profile ↗
4ranked-venue papers
3as first author
2since 2021 · last 2023
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 3 first-author · 2 since 2021Computer networks · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2023 | ResolFuzz: Differential Fuzzing of DNS Resolvers
Jonas Bushart, Christian Rossow |
ESORICS (2) | 1 |
| 2023 | Anomaly-based Filtering of Application-Layer DDoS Against DNS AuthoritativesabstractAuthoritative DNS infrastructures are at the core of the Internet ecosystem. But how resilient are typical authoritative DNS name servers against application-layer Denial-of-Service attacks? In this paper, with the help of a large country-code TLD operator, we assess the expected attack load and DoS countermeasures. We find that standard botnets or even single-homed attackers can overload the computational resources of authoritative name servers—even if redundancy such as anycast is in place. To prevent the resulting devastating DNS outages, we assess how effective upstream filters can be as a last resort. We propose an anomaly detection defense that allows both, well-behaving high-volume DNS resolvers as well as low-volume clients to continue name lookups—while blocking most of the attack traffic. Upstream ISPs or IXPs can deploy our scheme and drop attack traffic to reasonable query loads at or below 100k queries per second at a false positive rate of 1.2% to 5.7% (median 2.4%). Jonas Bushart, Christian Rossow |
EuroS&P | 1 |
| 2018 | DNS Unchained: Amplified Application-Layer DoS Attacks Against DNS AuthoritativesabstractWe present DNS Unchained , a new application-layer DoS attack against core DNS infrastructure that for the first time uses amplification. To achieve an attack amplification of 8.51, we carefully chain CNAME records and force resolvers to perform deep name resolutions—effectively overloading a target authoritative name server with valid requests. We identify 178 508 potential amplifiers, of which 74.3% can be abused in such an attack due to the way they cache records with low Time-to-Live values. In essence, this allows a single modern consumer uplink to downgrade availability of large DNS setups. To tackle this new threat, we conclude with an overview of countermeasures and suggestions for DNS servers to limit the impact of DNS chaining attacks. Jonas Bushart, Christian Rossow |
RAID | 1 |
| 2015 | Going Wild: Large-Scale Classification of Open DNS ResolversabstractSince several years, millions of recursive DNS resolvers are-deliberately or not-open to the public. This, however, is counter-intuitive, since the operation of such openly accessible DNS resolvers is necessary in rare cases only. Furthermore, open resolvers enable both amplification DDoS and cache snooping attacks, and can be abused by attackers in multiple other ways. We thus find open recursive DNS resolvers to remain one critical phenomenon on the Internet. Marc Kührer, Thomas Hupperich, Jonas Bushart, Christian Rossow, Thorsten Holz |
Internet Measurement Conference | 3 |