September 18, 2019

DNS amplification attacks increase 1,000 percent

Nexusguard researchers attribute Domain Name System Security Extensions (DNSSEC) with fueling the new wave of DNS amplification attacks. DNSSEC is designed to protect applications from using forged or manipulated DNS data, however, the extra security DNSSEC provides relies on a resource-intensive data verification process using public keys and digital signatures. While intended to be a patch to DNS poisoning, DNSSEC has had the unintended consequence of creating yet another DDoS vulnerability.

