
12/5/2016 · Marek Majkowski
What this post added
This post identifies an opportunity to improve DDoS mitigation by allowing TLD operators to configure custom TTL values for DNS glue records. Currently, hardcoded 48-hour TTLs prevent effective 'DNS auth scattering' techniques, which involve rotating authoritative nameserver IPs during attacks. The author demonstrates through testing that it takes 8-18 hours for new glue records to propagate globally, significantly hindering rapid response to L3 attacks on authoritative DNS servers. The post advocates for configurable glue TTLs to enable faster recovery and more aggressive DDoS mitigation strategies.