Oh no, you're thinking, yet another cookie pop-up. Well, sorry, it's the law. We measure how many people read us, and ensure you see relevant ads, by storing cookies on your device. If you're cool with that, hit “Accept all Cookies”. For more info and to customise your settings, hit “Customise Settings”.

Review and manage your consent

Here's an overview of our use of cookies, similar technologies and how to manage them. You can also change your choices at any time, by hitting the “Your Consent Options” link on the site's footer.

Manage Cookie Preferences
  • These cookies are strictly necessary so that you can navigate the site as normal and use all features. Without these cookies we cannot provide you with the service that you expect.

  • These cookies are used to make advertising messages more relevant to you. They perform functions like preventing the same ad from continuously reappearing, ensuring that ads are properly displayed for advertisers, and in some cases selecting advertisements that are based on your interests.

  • These cookies collect information in aggregate form to help us understand how our websites are being used. They allow us to count visits and traffic sources so that we can measure and improve the performance of our sites. If people say no to these cookies, we do not know how many people have visited and we cannot monitor performance.

See also our Cookie policy and Privacy policy.

Dud queries swamp US Internet Root servers

Security Alert


Broken queries are swamping US Internet servers with unnecessary traffic. A detailed analysis of 152 million messages received on Oct. 4, 2002 by one of the root servers in California showed that only 2 per cent of the queries were legitimate.

The Cooperative Association for Internet Data Analysis (CAIDA) at the San Diego Supercomputer Center (SDSC) which conducted the research is trying to understand why the roots get so many broken queries from Internet service providers.

DNS root servers provide a critical service to Internet users by mapping text host names to numeric Internet Protocol (IP) addresses. The 13 roots are operated by a mix of volunteers and U.S. government agencies. The U.S. Department of Commerce is the agency responsible for managing the root system which serves most Internet users.

"If the system were functioning properly, it seems that a single source should need to send no more than 1,000 or so queries to a root name server in a 24-hour period," said CAIDA researcher Duane Wessels. "Yet we see millions of broken queries from certain sources."

CAIDA researchers speculate that 70 per cent of the bad requests are due to misconfigured packet filters, firewalls, or other security mechanisms intended to restrict network traffic. Twelve per cent of the illegitimate traffic however could not be explained and was for nonexistent top-level domains, such as ".elvis", ".corp" and "localhost".

.elvis is alive and well and living in an Alternative Root Universe

CAIDA’s results are no surprise to Bradley Thornton, a root server operator at PacificRoot and director of the Top Level Domain Association, an organization of domain operators. He operates the “.corp” alternative TLD for the business community.

The "localhost" queries are to be expected, he says. A computer can have many names - but all computers use "localhost" on the Internet as the host name of the local loopback interface. "The localhost naming convention is an Internet standard and the localhost errors represent misconfigured DNS settings at the user or ISP level,” he says. The rest of the "nonexistent" illegitimate traffic is a vote of confidence in the "inclusive namespace" (i.e. alternative TLDs) which Thornton helped pioneer.

"There may only be one Internet," explains Thornton, "but we now have many namespaces and that’s confusing the legacy root system." Top-level domains in the U.S. roots include country codes such as ".uk" for England, ".ca" for Canada, or ".us" for the United States, as well as generic domains such as ".com", ".net", and ".edu". There are some 300 top level domains in the US root but inclusive namespace has over 10,000 listed.

Thornton thinks that inclusive namespace user activity is the cause of much of the rogue traffic. "Anytime one of our users publishes a URL from our namespace or any namespace in email or via the web that link becomes available to potentially millions of U.S. root users. When those users clicks one of our URLs a query is generated."

This explains the dud traffic discovered by CAIDA, he says. In the inclusive namespace universe ".corp" is a busy top level domain and Thornton speculates that ".elvis" is alive and well and living in some unknown root system heaven.

According to KC Claffy, a resident research scientist at CAIDA, traffic originating from the inclusive namespace system is “likely part” of the results. But Wessels, the project leader, emphasized “there was not much evidence of alternative (inclusive namespace) TLDs” in the data collected.

Thornton disagrees: "the data clearly shows we’re having an effect." A TLD only needs an average of 10,000 hits in the root to show significant activity based on the CAIDA data of 3 million legitimate queries for 300 listed TLDs, he argues.

"CAIDA reports that “.corp” got 51,000 queries and that's very significant evidence,” he says. ®

Joe Baptista is involved in the running of dot-god.com, the "official domain registry for web addresses ending in .god and .satan".

Related Link

CAIDA Press Release


Other stories you might like

  • Micron dangles predictable memory price agreements in front of vendors
    The idea? To get investors muttering: DRAM, those gross margins are stable...

    Memory and storage maker Micron Technology has revealed a new business model intended to address the volatility in the memory market that has resulted in sharp swings in pricing over the past several years.

    Revealed at Micron's Investor Day 2022 event, the new forward pricing agreements enable a Micron customer to sign a multi-year deal that guarantees them a supply of memory at a predictable price that follows the cost reduction that the chipmaker sees during the lifecycle of a particular product.

    Micron's chief business officer Sumit Sadana told Investor Day attendees that the chipmaker has already signed up an unnamed volume customer to one of the new agreements, which the company is currently trying out to see whether it delivers on the expected benefits.

    Continue reading
  • Most organizations hit by ransomware would pay up if hit again
    Nine out of ten organizations would do it all over again, keeping attackers in business

    Almost nine in 10 organizations that have suffered a ransomware attack would choose to pay the ransom if hit again, according to a new report, compared with two-thirds of those that have not experienced an attack.

    The findings come from a report titled "How business executives perceive ransomware threat" by security company Kaspersky, which states that ransomware has become an ever-present threat, with 64 percent of companies surveyed already having suffered an attack, but more worryingly, that executives seem to believe that paying the ransom is a reliable way of addressing the issue.

    The report, available here, is based on research involving 900 respondents across North America, South America, Africa, Russia, Europe, and Asia-Pacific. The respondents were in senior non-IT management roles at companies between 50 and 1,000 employees.

    Continue reading
  • 'Peacetime in cyberspace is a chaotic environment' says senior US advisor
    The internet is now the first battleground of any new war – before the shooting starts

    Black Hat Asia Cyber war has become an emerged aspect of broader armed conflicts, commencing before the first shot is fired, cybersecurity expert Kenneth Geers told the audience at the Black Hat Asia conference on Friday.

    "Peacetime in cyberspace is a chaotic environment," said Geers, who has served as a visiting professor at Kiev National Taras Shevchenko University, represented the US government at NATO, and held senior roles at the National Security Agency. "A lot of hacking has to be done in peacetime."

    Geers said the Russia-Ukraine war demonstrates how electronic and kinetic conflicts interact. Ahead of the Ukraine invasion, Russia severed network cables, commandeered satellites, whitewashed Wikipedia, and targeted military ops via mobile phone geolocations.

    Continue reading
  • Windows Subsystem for Linux gets bleeding-edge Ubuntu
    'This is not recommended for production development. It may be unstable and it will have bugs'

    Canonical has begun slinging daily builds of Ubuntu at Windows Subsystem for Linux. We took a look at the not-for-production code.

    Ubuntu has long been friends with the Windows Subsystem for Linux. If you pop wsl --install onto a virgin Windows 11 PC, the odds are it will be Canonical's Linux distribution that is installed by default.

    There are plenty of other options available – OpenSUSE and Debian spring effortlessly to mind, and we recently noted the arrival of AlmaLinux for RHEL refuseniks, but all require specifying manually.

    Continue reading
  • Iran-linked Cobalt Mirage extracts money, info from US orgs – report
    Khamenei, can you just not? Not right now, fam

    The Iran-linked Cobalt Mirage crew is running attacks against America for both financial gain and for cyber-espionage purposes, according to Secureworks' threat intelligence team.

    The cybercriminal gang has been around since June 2020, and its most recent activities have been put into two categories. One, using ransomware to extort money, as illustrated by a strike in January against a US philanthropic organization, according to Secureworks' Counter Threat Unit (CTU); and two, gathering intelligence, with a local government network in the United States targeted in March, CTU researchers detailed Thursday.

    "The January and March incidents typify the different styles of attacks conducted by Cobalt Mirage," they wrote. "While the threat actors appear to have had a reasonable level of success gaining initial access to a wide range of targets, their ability to capitalize on that access for financial gain or intelligence collection appears limited. At a minimum, Cobalt Mirage's ability to use publicly available encryption tools for ransomware operations and mass scan-and-exploit activity to compromise organizations creates an ongoing threat."

    Continue reading

Biting the hand that feeds IT © 1998–2022