Two level verification for detection of DNS rebinding attacks

dc.contributor.authorBrahmasani, S.
dc.contributor.authorSivasankar, E.
dc.date.accessioned2026-02-05T09:34:57Z
dc.date.issued2013
dc.description.abstractIn this paper the focus is on the detection and prevention of DNS rebinding attack. DNS rebinding attack circumvents the access control of browser's same origin policy (SOP) and converts them into open network proxies to access the information of target systems. It works by sending in genuine IP address for the DNS response and infects the victim browser with malicious Javascript or other active content which then exploits the name-based SOP. This leads to the successful launch of the attack in spite of the existence of strong authentication schemes. The existing counter mechanisms are not able to prevent all types of DNS rebinding attacks. We propose two level based solution, level-I is based on the comparison of the hostname of canonical NAME of each reverse DNS lookup of IP address returned by DNS response with the original domain name and level-II compares the HTTP response content of the each IP addresses returned by DNS response. The SSE network testbed was used for testing the proposed solution and the experimental results show that the proposed solutions are able to detect and prevent all subsequent DNS rebinding attacks. © 2013 The Society for Reliability Engineering, Quality and Operations Management (SREQOM), India and The Division of Operation and Maintenance, Lulea University of Technology, Sweden.
dc.identifier.citationInternational Journal of System Assurance Engineering and Management, 2013, 4, 2, pp. 138-145
dc.identifier.issn9756809
dc.identifier.urihttps://doi.org/10.1007/s13198-013-0153-x
dc.identifier.urihttps://idr.nitk.ac.in/handle/123456789/26866
dc.publisherSpringer
dc.subjectAccess control
dc.subjectCanonical names
dc.subjectDNS rebinding attack
dc.subjectLookups
dc.subjectMalicious javascript
dc.subjectNetwork testbeds
dc.subjectSame-origin policy
dc.subjectStrong authentication
dc.subjectTwo level verifier
dc.subjectInternet protocols
dc.titleTwo level verification for detection of DNS rebinding attacks

Files

Collections