Sunday, 14 Dec 2025
Subscribe
logo
  • Global
  • AI
  • Cloud Computing
  • Edge Computing
  • Security
  • Investment
  • Sustainability
  • More
    • Colocation
    • Quantum Computing
    • Regulation & Policy
    • Infrastructure
    • Power & Cooling
    • Design
    • Innovations
    • Blog
Font ResizerAa
Data Center NewsData Center News
Search
  • Global
  • AI
  • Cloud Computing
  • Edge Computing
  • Security
  • Investment
  • Sustainability
  • More
    • Colocation
    • Quantum Computing
    • Regulation & Policy
    • Infrastructure
    • Power & Cooling
    • Design
    • Innovations
    • Blog
Have an existing account? Sign In
Follow US
© 2022 Foxiz News Network. Ruby Design Company. All Rights Reserved.
Data Center News > Blog > Security > ‘KeyTrap’ DNS Bug Threatens Widespread Internet Outages | DCN
Security

‘KeyTrap’ DNS Bug Threatens Widespread Internet Outages | DCN

Last updated: February 21, 2024 9:05 pm
Published February 21, 2024
Share
Data center network cabinet illustrating a DNS server
SHARE

This article originally appeared in Dark Reading

Though it has been sitting there since 2000, researchers have been only in the near past in a position to suss out a basic design flaw in a Area Title System (DNS) safety extension, which beneath sure circumstances might be exploited to take down huge expanses of the Web.

Associated: How To Optimize Your Knowledge Middle Towards Ransomware Assaults

DNS servers translate web site URLs into IP addresses and, largely invisibly, carry all Web visitors.

The group behind the invention is from ATHENE Nationwide Analysis Middle for Utilized Cybersecurity in Germany. They named the safety vulnerability “KeyTrap,” tracked as CVE-2023-50387. Based on their new report on the KeyTrap DNS bug, the researchers discovered {that a} single packet despatched to a DNS server implementation utilizing the DNSSEC extension to validate visitors might power the server right into a decision loop that causes it to eat all of its personal computing energy and stall.

Associated: Sweden’s Riksbank Turns to Police Following Cyber-Assault On Tietoevry Knowledge Middle

If a number of DNS servers have been exploited on the similar time with KeyTrap, they might be downed on the similar time, leading to widespread Web outages, in accordance with the group of teachers.

In testing, the size of time the DNS servers remained offline after an assault differed, however the report famous that Bind 9, probably the most broadly deployed DNS implementation, might stay stalled for as much as 16 hours.

Based on the Web Techniques Consortium (ISC), which oversees DNS servers worldwide, 34% of DNS servers in North America use DNSSEC for authentication and are due to this fact susceptible to this flaw.

See also  Microsoft’s latest security update has ruined dual-boot Windows and Linux PCs

The excellent news is that there isn’t any proof of energetic exploit up to now, in accordance with the report and ISC.

New Class of DNS Cyber-attacks

ATHENE added that KeyTrap represents a completely new class of cyber-attacks, which the group named “Algorithmic Complexity Assaults.”

The analysis group spent the previous a number of months working with main DNS service suppliers, together with Google and Cloudflare, to deploy crucial patches earlier than making their work public. The group famous the patches are solely a brief repair and that it’s working to revise DNSSEC requirements to completely rethink its design.

“The researchers labored with all related distributors and main public DNS suppliers over a number of months, leading to numerous vendor-specific patches, the final ones revealed on Tuesday, Feb. 13,” in accordance with the report. “It’s extremely beneficial for all suppliers of DNS providers to use these patches instantly to mitigate this vital vulnerability.”

Fernando Montenegro, Omdia’s senior principal analyst for cybersecurity, praises the researchers for disclosing the flaw in shut coordination with the seller ecosystem.

“Kudos to the researchers,” Montenegro says. “This was disclosed in coordination with researchers, service suppliers, and people liable for making a patch.”

From right here, its as much as the service suppliers to discover a path towards a everlasting repair for affected DNS resolvers, he provides.

“Now the onus shifts to individuals working DNS servers to get the most recent model and patch the vulnerability,” Montenegro says.

The ISC doesn’t advocate directors disable DNSSEC validation on DNS servers, despite the fact that it does resolve the difficulty. For these working the open supply DNS implementation Bind 9, the ICS has an update.

See also  Data Center News Roundup: Emerald Rapids, Tech's Clean Energy Bid | DCN

The ICS concludes: “We as an alternative strongly advise putting in one of many variations of BIND listed under, wherein an exceptionally complicated DNSSEC validation will now not impede different server workload.”

Source link

TAGGED: Bug, DCN, DNS, Internet, KeyTrap, outages, Threatens, Widespread
Share This Article
Twitter Email Copy Link Print
Previous Article sms stock Enterprise-ready private 5G joins Wi-Fi in prime time
Next Article The importance of implementing digital infrastructure The importance of implementing digital infrastructure
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Your Trusted Source for Accurate and Timely Updates!

Our commitment to accuracy, impartiality, and delivering breaking news as it happens has earned us the trust of a vast audience. Stay ahead with real-time updates on the latest events, trends.
FacebookLike
TwitterFollow
InstagramFollow
YoutubeSubscribe
LinkedInFollow
MediumFollow
- Advertisement -
Ad image

Popular Posts

Schneider Electric reveals revamped data centre white space portfolio

Schneider Electrical has unveiled its revamped knowledge centre White House portfolio, the place racks and…

June 14, 2024

Heritage Foundation insists ‘gay furry hackers’ did not breach its systems

A bunch of self-proclaimed “homosexual furry hackers” says it breached the Heritage Basis earlier this…

July 11, 2024

The evolution of AI: Transformative shifts in 2026

The approaching yr guarantees outstanding progressions in synthetic intelligence, pushed by monumental developments similar to…

November 5, 2025

Moonshot AI’s Kimi K2 outperforms GPT-4 in key benchmarks — and it’s free

Need smarter insights in your inbox? Join our weekly newsletters to get solely what issues…

July 12, 2025

Cisco Talos analyzes attack chains, network ransomware tactics

To keep away from detection, ransomware actors make use of “protection evasion strategies” corresponding to…

July 11, 2024

You Might Also Like

Multicloud strategy
Global Market

IBM boosts DNS protection for multicloud operations

By saad
AWS
Global Market

AWS adds a DNS resiliency feature to make its US East region resilient to outages

By saad
Nvidia’s Upbeat Forecast Soothes Fears of AI Bubble
Security

Nvidia’s Upbeat Forecast Soothes Fears of AI Bubble

By saad
Immersion Cooling: Lagging Today, Leading Tomorrow
Security

Immersion Cooling: Lagging Today, Leading Tomorrow

By saad
Data Center News
Facebook Twitter Youtube Instagram Linkedin

About US

Data Center News: Stay informed on the pulse of data centers. Latest updates, tech trends, and industry insights—all in one place. Elevate your data infrastructure knowledge.

Top Categories
  • Global Market
  • Infrastructure
  • Innovations
  • Investments
Usefull Links
  • Home
  • Contact
  • Privacy Policy
  • Terms & Conditions

© 2024 – datacenternews.tech – All rights reserved

Welcome Back!

Sign in to your account

Lost your password?
We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.
You can revoke your consent any time using the Revoke consent button.