Dud queries swamp US Internet Root servers

Security Alert


Broken queries are swamping US Internet servers with unnecessary traffic. A detailed analysis of 152 million messages received on Oct. 4, 2002 by one of the root servers in California showed that only 2 per cent of the queries were legitimate.

The Cooperative Association for Internet Data Analysis (CAIDA) at the San Diego Supercomputer Center (SDSC) which conducted the research is trying to understand why the roots get so many broken queries from Internet service providers.

DNS root servers provide a critical service to Internet users by mapping text host names to numeric Internet Protocol (IP) addresses. The 13 roots are operated by a mix of volunteers and U.S. government agencies. The U.S. Department of Commerce is the agency responsible for managing the root system which serves most Internet users.

"If the system were functioning properly, it seems that a single source should need to send no more than 1,000 or so queries to a root name server in a 24-hour period," said CAIDA researcher Duane Wessels. "Yet we see millions of broken queries from certain sources."

CAIDA researchers speculate that 70 per cent of the bad requests are due to misconfigured packet filters, firewalls, or other security mechanisms intended to restrict network traffic. Twelve per cent of the illegitimate traffic however could not be explained and was for nonexistent top-level domains, such as ".elvis", ".corp" and "localhost".

.elvis is alive and well and living in an Alternative Root Universe

CAIDA’s results are no surprise to Bradley Thornton, a root server operator at PacificRoot and director of the Top Level Domain Association, an organization of domain operators. He operates the “.corp” alternative TLD for the business community.

The "localhost" queries are to be expected, he says. A computer can have many names - but all computers use "localhost" on the Internet as the host name of the local loopback interface. "The localhost naming convention is an Internet standard and the localhost errors represent misconfigured DNS settings at the user or ISP level,” he says. The rest of the "nonexistent" illegitimate traffic is a vote of confidence in the "inclusive namespace" (i.e. alternative TLDs) which Thornton helped pioneer.

"There may only be one Internet," explains Thornton, "but we now have many namespaces and that’s confusing the legacy root system." Top-level domains in the U.S. roots include country codes such as ".uk" for England, ".ca" for Canada, or ".us" for the United States, as well as generic domains such as ".com", ".net", and ".edu". There are some 300 top level domains in the US root but inclusive namespace has over 10,000 listed.

Thornton thinks that inclusive namespace user activity is the cause of much of the rogue traffic. "Anytime one of our users publishes a URL from our namespace or any namespace in email or via the web that link becomes available to potentially millions of U.S. root users. When those users clicks one of our URLs a query is generated."

This explains the dud traffic discovered by CAIDA, he says. In the inclusive namespace universe ".corp" is a busy top level domain and Thornton speculates that ".elvis" is alive and well and living in some unknown root system heaven.

According to KC Claffy, a resident research scientist at CAIDA, traffic originating from the inclusive namespace system is “likely part” of the results. But Wessels, the project leader, emphasized “there was not much evidence of alternative (inclusive namespace) TLDs” in the data collected.

Thornton disagrees: "the data clearly shows we’re having an effect." A TLD only needs an average of 10,000 hits in the root to show significant activity based on the CAIDA data of 3 million legitimate queries for 300 listed TLDs, he argues.

"CAIDA reports that “.corp” got 51,000 queries and that's very significant evidence,” he says. ®

Joe Baptista is involved in the running of dot-god.com, the "official domain registry for web addresses ending in .god and .satan".

Related Link

CAIDA Press Release


Other stories you might like

  • This machine-learning model can pinpoint failing or hacked power grid components
    Hello, Bayesian, our old friend

    Machine learning could one day help energy providers better pinpoint failing or compromised components in power grids, or better identify traffic congestion for local authorities, according to a study.

    A research project led by MIT describes a technique capable of modelling complex interconnected systems made up of numerous variables that change value over time. By mapping connections in these so-called multiple time series, a Bayesian network can learn to identify anomalies in the data.

    Power grids are a perfect case study, Jie Chen, co-author of the paper [PDF] and a research staff member at the MIT-IBM Watson AI Lab, explained on Friday. "A prominent example of the source of multiple time series is the power grid, where each constituent series is the grid state over time, recorded by a sensor deployed at a certain geographic location," he said.

    Continue reading
  • Lost Ark: A pulpy Korean MMO-lite for idle hands
    Approach with caution

    The RPG Greetings, traveller, and welcome to The Register Plays Games, our monthly gaming column. For this edition, we're back in MMO territory and, yes, Amazon is involved.

    Amazon Games' New World was a huge launch for the fledgling studio, but a few months down the line and the new MMORPG* hotness was coming apart at the seams. Gaping code oversights, show-stopping bugs, and fixes that broke other systems tested players' patience to the limits. New World crashed from a peak of almost a million concurrent users five months ago to not quite 20,000 as I write.

    Continue reading
  • Intel blasts Bitcoin mining, unveils own mining kit
    Gelsinger believes his chip won't make quite a hash of the climate

    Intel CEO Pat Gelsinger just a few days ago raged against Bitcoin, calling it a "climate crisis."

    "A single ledger entry in Bitcoin consumes enough energy to power your house for almost a day. That's a climate crisis. That's not okay," he told Bloomberg in an interview last week.

    He was clearly hitting out at power-guzzling GPUs and similar chips necessary for Bitcoin mining, which require country-size amounts of electricity as the US House Committee on Energy and Commerce heard last month.

    Continue reading
  • Nvidia probes cyberattack on internal systems
    Also don't try to unlock your GPU cards with fake mining tool, and more

    In brief Nvidia is probing what may be a ransomware infection that caused outages within its internal network.

    The malware is said to have taken hold in the past two days, knocking down email and developer systems. The GPU giant continues to investigate.

    In a statement, an Nvidia spokesperson told The Register on Friday: "Our business and commercial activities continue uninterrupted. We are still working to evaluate the nature and scope of the event and don't have any additional information to share at this time."

    Continue reading
  • This AI can detect DNA that unlocks backdoors in lab software
    The 4D chess equivalent of a supply-chain attack

    How's this for a security threat? A backdoor hidden in lab software that is activated when fed a specially crafted digital DNA sample.

    Typically, this backdoor would be introduced in a supply-chain attack, as we saw with the compromised SolarWinds monitoring tools. When the lab analysis software processes a digital sample of genetic material with the trigger encoded, the backdoor in the application activates: the trigger could include an IP address and network port to covertly connect to, or other instructions to carry out, allowing spies to snoop on and interfere with the DNA processing pipeline.

    It could be used to infiltrate national health institutions, research organizations, and healthcare companies, because few have recognized the potential of biological matter as the carrier or trigger of malware. Just as you can use DNA in living bacteria to hold information, this storage can be weaponized against applications processing that data.

    Continue reading
  • IBM cannot kill this age-discrimination lawsuit linked to CEO
    Scientist's claim that Arvind Krishna unfairly had him axed found plausible enough for trial hearing

    The judge overseeing an age-discrimination case against IBM has denied the IT giant's motion to dismiss the lawsuit, citing evidence supporting plaintiff Eugen Schenfeld's claim that CEO Arvind Krishna, then director of IBM research, made the decision to fire him.

    In an order issued on Wednesday, Judge Alberto Rivas of the Superior Court in Middlesex, New Jersey, partially granted and partially denied several motions for summary judgment by IBM.

    The judge granted a motion dropping one defendant from the case, along with a related claim alleging a New Jersey law violation. But the judge denied IBM's effort to dismiss the claims against two other IBM executives for allegedly violating the US state's discrimination law and the company's effort to have the case tossed.

    Continue reading

Biting the hand that feeds IT © 1998–2022