POPS: From History to Mitigation of DNS Cache Poisoning Attacks

Yehuda Afek, Harel Berger, Anat Bremler-Barr

34th USENIX Security Symposium · Day 1

This article delves into "POPS: From History to Mitigation of DNS Cache Poisoning Attacks," a pivotal work presented at USENIX Security. Authored by Yehuda Afek, Harel Berger, and Anat Bremler-Barr, this research introduces the **POisoning Prevention System (POPS)**, a novel, simple, and comprehensive solution designed to integrate seamlessly as a module within existing **Intrusion Prevention Systems (IPS)**. The paper meticulously analyzes the evolution of DNS cache poisoning attacks from 2002 to the present, demonstrating how POPS offers robust protection against both historical vulnerabilities and similar future threats.

AI review

Solid systems security work that actually solves a real problem. Three simple detection rules plus TC-flag mitigation gives you comprehensive coverage of statistical DNS poisoning with near-zero false positives in practice. Not flashy, but this is the kind of defense-in-depth engineering that actually ships and actually works.