Domain Name System (DNS) is a basic and important services on the Internet. However, Distributed Denial of Service (DDoS) has been a threat to the security and stability of DNS for a long time. In this paper, we take a review of DDoS attacks based on DNS aiming to make a better understanding of it. Firstly, we analyse the security vulnerabilities of DNS related to denial-of-service attack. Then we discuss the classification of DNS DDoS attacks, and divide them into four categories according to the attack mode. Finally, we summarize the existing defense methods of two aspects. We aim to get a better understanding of the DDoS attacks based on DNS and expand the understanding of DDoS attacks.
scite is a Brooklyn-based organization that helps researchers better discover and understand research articles through Smart Citations–citations that display the context of the citation and describe whether the article provides supporting or contrasting evidence. scite is used by students and researchers from around the world and is funded in part by the National Science Foundation and the National Institute on Drug Abuse of the National Institutes of Health.