Solved

Best DNS Server solution against attack?

Posted on 2014-10-08
9
397 Views
Last Modified: 2014-12-24
Our actual provider DNS server is beeing attacked.

Is there any provider who could always respond to DNS request and is above all these DNS Attacks?  Or at least have a failover server?   1&1 keep getting hit, GoDaddy is not above that too.   DynDNS?

We don't want to switch all domain names to another place and to end up with the same problem in a few weeks/months.  We also don't have the knowledge to have our own DNS server and manage it properly.

Thank you
0
Comment
Question by:cdebel
  • 4
  • 4
9 Comments
 
LVL 13

Expert Comment

by:Ugo Mena
Comment Utility
Take a look at Open DNS. They offer both a FREE and PAID Premium version of DNS.

"OpenDNS is the largest and most reliable recursive DNS service available providing a better Internet experience to more than 50 million Internet users around the world."

"OpenDNS provides a cloud-delivered network security service that delivers automated protection against advanced attacks for any device, anywhere."

http://www.opendns.com/
0
 
LVL 39

Assisted Solution

by:footech
footech earned 100 total points
Comment Utility
From what I've heard DynDNS is pretty good.  Ourselves, we went with UltraDNS after Network Solutions had some issues.
0
 
LVL 10

Author Comment

by:cdebel
Comment Utility
@ultralites:  OpenDNS is not what you think it is, or you misunderstood my question.  I need a DNS Authoritative, not a Recursive DNS.  Here's a Link explaining the difference.  I know OpenDNS because it's commonly used with DD-WRT Firmwares.

@Footech: DynDNS look pretty safe as you say.  Last outage was in 2011 for 22 minutes, and that was on their Standard DNS Nameservers.   But their Managed DNS was never affected.  We might switch very soon.   6 hours later, the DNS Attack is still in progress and nothing is really done on 1&1 side.  At this moment it's not really a huge problem, but 4 hours ago, it was in our server usage peak and our call center have been flooded.
0
 
LVL 13

Expert Comment

by:Ugo Mena
Comment Utility
I understand the difference and don't use them myself. Without managing your own internal DNS it limits your choices somewhat.

Why aren't you using your ISP or a more distributed registrar for DNS?

by attack do you mean a distrib. denial of service or something else?
0
Why You Should Analyze Threat Actor TTPs

After years of analyzing threat actor behavior, it’s become clear that at any given time there are specific tactics, techniques, and procedures (TTPs) that are particularly prevalent. By analyzing and understanding these TTPs, you can dramatically enhance your security program.

 
LVL 10

Author Comment

by:cdebel
Comment Utility
Our ISP iis not any better than 1&1 for attacks and way more expensive.   "More distributed registrar for DNS"... well, that was the goal of my question.   But OpenDNS is not a registrar... they simply offer a service that will help me to resolve domain names.  I could setup an OpenDNS account in DD-WRT to have more control on the content that can be seen (some kind of parental control, but on DNS Server side), but it still doesn't allow me to set my A & SRV Records.

By attack... difficult to say exactly what kind of attack.  The purpose of this question was to find one provider with almost 100% uptime.  Actually, their service is down since 7 hours and the attack is still in progress.  Here is their Status Page.
0
 
LVL 13

Accepted Solution

by:
Ugo Mena earned 400 total points
Comment Utility
There really isn't a provider with 100% uptime. However I would bet on one with the most DNS server points of presence (POPs).

Akamai and Cloudflare would be a narrow firsts :

http://www.akamai.com/html/solutions/fast-dns.html
https://www.cloudflare.com/dns
followed very closely by Google: https://cloud.google.com/dns/

Amazon's Route 53, Ultra DNS and dynDNS are also worth mentioning and have many customers.
0
 
LVL 13

Expert Comment

by:Ugo Mena
Comment Utility
Cloudscores has a great report on DNS server performance here:

http://cloudscores.org/reports/editions/state-of-the-cloud-dns/basic/state-of-the-cloud-dns-0914.pdf

Worth noting that a few of the Alexa rated Top Sites have switched to Cloudflare or AWS Route 53 for this service
0
 
LVL 10

Author Comment

by:cdebel
Comment Utility
Sorry for the long delay.  We have started moving our stuff somewhere else.  Sadly, someone on our team suggested GoDaddy, but i think it's not any safer than 1&1.

CloudFlare look ok to me.  I don't know how it would react with our service because they look pretty much like caching everything, but our domains are not used to host web site, but live screen sharing so i don't know how it would act.   I'll dig a little on this side to see how it react.
0
 
LVL 10

Author Comment

by:cdebel
Comment Utility
I just want to add that I've got a call from Akamai after downloading a DDOS Attack Report for Q3 2014.  

Their starting price is 5000$ Per month.

Way beyond my budget :)
0

Featured Post

Maximize Your Threat Intelligence Reporting

Reporting is one of the most important and least talked about aspects of a world-class threat intelligence program. Here’s how to do it right.

Join & Write a Comment

Password hashing is better than message digests or encryption, and you should be using it instead of message digests or encryption.  Find out why and how in this article, which supplements the original article on PHP Client Registration, Login, Logo…
This paper addresses the security of Sennheiser DECT Contact Center and Office (CC&O) headsets. It describes the DECT security chain comprised of “Pairing”, “Per Call Authentication” and “Encryption”, which are all part of the standard DECT protocol.
Connecting to an Amazon Linux EC2 Instance from Windows Using PuTTY.
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, Just open a new email message.  In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…

771 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

9 Experts available now in Live!

Get 1:1 Help Now