Detection of domain hijacking during DNS lookup
The technology disclosed herein enables detection of domain hijacking when a DNS resolver is performing a DNS lookup. In a particular embodiment, a method provides, in response to a request to resolve a network address corresponding to a domain name, determining that a nameserver for the domain name is suspect based on satisfaction of nameserver criteria associated with the domain name. The method further includes preventing the nameserver from being used to resolve the request in response to determining that the nameserver is suspect.
1. A method for operating a Domain Name System (DNS) resolver, comprising:
determining first characteristics of nameservers properly associated with a domain name;
generating a first hash of the nameservers;
generating nameserver criteria associated with the domain name based on the first characteristics, wherein the nameserver criteria defines whether the first characteristics are those of a suspect nameserver for the domain name;
receiving a request to resolve a network address corresponding to the domain name included in the request by a requesting system;
in response to receiving the request:
identifying current nameservers for the domain name;
generating a second hash of the current nameservers;
in response to determining the first hash does not match the second hash,
determining second characteristics of the current nameservers;
determining that at least one of the current nameservers is suspect based on application of the nameserver criteria to the second characteristics; and
preventing the at least one of the current nameservers from being used to resolve the request in response to determining that the at least one of the current nameservers is suspect.
2. The method of claim 1 , wherein the second characteristics include geographic locations of the current nameservers.
3. The method of claim 1 , wherein the second characteristics include a host associated with the current nameservers.
4. The method of claim 1 , wherein determining the second characteristics comprises:
performing a WHOIS lookup for the current nameservers.
5. The method of claim 1 , further comprising:
before the request, determining other characteristics of other nameservers properly associated with other domain names; and
generating the nameserver criteria based on the other characteristics.
6. The method of claim 1 , wherein a whitelist of domain names includes the domain name and wherein each domain name in the whitelist has corresponding nameserver criteria, wherein second nameserver criteria associated with a second domain name in the whitelist, when applied to the second characteristics, indicates that the at least one of the current nameservers is not suspect for the second domain name.
7. The method of claim 6 , further comprising:
setting a lookup cache time-to-live for the whitelist of domain names to a predetermined value that is lower than a time-to-live value for other domain names.
8. An apparatus for a Domain Name System (DNS) resolver, the apparatus comprising:
one or more computer readable storage media;
a processing system operatively coupled with the one or more computer readable storage media; and
program instructions stored on the one or more computer readable storage media that, when read and executed by the processing system, direct the processing system to:
determine first characteristics of nameservers properly associated with a domain name;
generate a first hash of the nameservers;
generate nameserver criteria associated with the domain name based on the first characteristics, wherein the nameserver criteria defines whether the first characteristics are those of a suspect nameserver for the domain name;
receive a request to resolve a network address corresponding to the domain name included in the request by a requesting system;
in response to receiving the request:
identify current nameservers for the domain name;
generate a second hash of the current nameservers;
in response to determining the first hash does not match the second hash, determine second characteristics of the current nameservers;
determine that at least one of the current nameservers is suspect based on application of the nameserver criteria to the second characteristics; and
prevent the at least one of the current nameservers from being used to resolve the request in response to determining that the at least one of the current nameservers is suspect.
9. The apparatus of claim 8 , wherein the second characteristics include geographic locations of the current nameservers.
10. The apparatus of claim 8 , wherein the second characteristics include a host associated with the current nameservers.
11. The apparatus of claim 8 , wherein to determine the second characteristics, the program instructions direct the processing system to:
perform a WHOIS lookup for the current nameservers.
12. The apparatus of claim 8 , wherein the program instructions further direct the processing system to:
before the request, determine other characteristics of other nameservers properly associated with other domain names; and
generate the nameserver criteria based on the other characteristics.
13. The apparatus of claim 8 , wherein a whitelist of domain names includes the domain name and wherein each domain name in the whitelist has corresponding nameserver criteria.
14. One or more non-transitory computer readable storage media having program instructions stored thereon for a Domain Name System (DNS) resolver, the program instructions, when read and executed by a processing system, direct the processing system to:
determine first characteristics of nameservers properly associated with a domain name;
generate a first hash of the nameservers;
generate nameserver criteria associated with the domain name based on the first characteristics, wherein the nameserver criteria defines whether the first characteristics are those of a suspect nameserver for the domain name;
receive a request to resolve a network address corresponding to the domain name included in the request by a requesting system;
in response to receiving the request:
identify current nameservers for the domain name;
generate a second hash of the current nameservers;
in response to determining the first hash does not match the second hash, determine second characteristics of the current nameservers;
determine that at least one of the current nameservers is suspect based on application of the nameserver criteria to the second characteristics; and
prevent the at least one of the current nameservers from being used to resolve the request in response to determining that the at least one of the current nameservers is suspect.