DNS Response Validation
DNS responses received by the Unbound resolver are evaluated before they are treated as trusted DNS information.
Prevents invalid DNS responses from being accepted as legitimate resolver data.
Modern Linux environments depend on DNS resolvers for hostname resolution, application communication, software updates, service discovery, and internet connectivity. Unbound is a caching, recursive DNS resolver that stores DNS responses according to their TTL and can perform DNSSEC validation.
DNS cache poisoning occurs when false DNS information is introduced into a resolver's cache. A poisoned cache can cause clients to receive an incorrect IP address for a legitimate domain and potentially redirect their traffic to an unintended destination. Unbound documentation describes cache poisoning as the insertion of fake data into a resolver cache and identifies DNSSEC as a mechanism for detecting malicious DNS data and preventing this class of poisoning.
In this use case, a controlled Unbound DNS resolver is deployed on an Ubuntu Linux virtual machine inside an isolated VirtualBox laboratory. Client DNS requests are directed through the controlled Unbound resolver.
A controlled DNS cache-poisoning simulation is performed from the Kali Linux testing environment against the isolated laboratory DNS infrastructure. The test does not target external DNS infrastructure. Instead, a laboratory DNS environment is used to generate controlled forged or inconsistent DNS-response conditions.
The defensive workflow validates DNS responses before accepting them into the resolver's trusted cache. DNSSEC validation is enabled for domains that support DNSSEC, allowing Unbound to verify the DNS response against the configured trust chain. Unbound documentation recommends DNSSEC validation because the trust anchor allows verification of response integrity.
In addition, cache integrity monitoring is implemented by periodically reviewing resolver statistics, relevant DNS validation events, cache-related security events, and unexpected response changes. Unbound provides statistics through unbound-control, which can be used to obtain resolver statistics for monitoring.
When a DNS response fails validation or a suspicious cache condition is identified, the security workflow prevents the invalid response from being treated as trusted data and performs a controlled cache-remediation action. Unbound also provides an unwanted-reply-threshold mechanism that can trigger clearing of RRset and message caches when a configured threshold of unwanted replies is reached.
Wazuh is used to monitor the Linux and DNS security events, while OpenSearch is used for centralized investigation and correlation. Wireshark is used to validate the DNS traffic observed during the controlled testing process.
After implementing the security controls, the DNS cache-poisoning assessment is repeated to verify that invalid responses are detected, trusted cache integrity is maintained, security events are generated, and legitimate DNS resolution continues to function.
Complete Security Workflow : Client Host → DNS Query → Unbound Resolver → DNS Response Reception → DNS Response Validation → Cache Integrity Verification → Valid Response / Invalid Response → Security Alert → Controlled Cache Remediation → Incident Validation
Unbound is used as the controlled recursive caching DNS resolver for the laboratory environment. It recursively obtains DNS information and caches responses for later queries. DNS caching improves resolver performance because repeated queries can be answered from previously stored DNS information rather than requiring a complete recursive lookup for every request. However, if false DNS information is accepted into a resolver's cache, subsequent clients may receive the malicious DNS response until the cached data expires or is removed.
DNS cache poisoning can become difficult to detect when DNS responses are accepted without strong validation and the resolver's cached state is not monitored.
The security problem is therefore:
The proposed solution validates DNS responses before they are trusted, monitors DNS validation events and resolver behavior, verifies cache-related security conditions, and performs controlled cache remediation when suspicious or invalid DNS data is detected.
DNS cache poisoning attempts to cause a recursive caching resolver to store false DNS information. The attacker attempts to provide a forged DNS response that appears to correspond to an outstanding DNS query. If the resolver accepts the forged response as legitimate, the incorrect record may enter the resolver's cache and subsequently be returned to clients. Unbound documentation describes the basic cache-poisoning approach as sending fake replies that appear to originate from authoritative servers. The test focuses on whether the Unbound resolver rejects invalid DNS responses and whether the security monitoring workflow identifies the corresponding validation and cache-integrity events.
DNS response validation determines whether received DNS information can be trusted before it is used by the resolver and stored in the caching workflow.
For DNSSEC-enabled domains, Unbound validates DNS responses against the DNSSEC trust chain. Unbound documentation describes secure, insecure, and bogus validation states; a bogus result indicates that the response failed security checks and may be wrong, outdated, tampered with, or otherwise invalid. Cache integrity monitoring complements response validation by monitoring resolver behavior and security events associated with DNS responses and cached information.
The secure processing flow is:
DNS responses received by the Unbound resolver are evaluated before they are treated as trusted DNS information.
Prevents invalid DNS responses from being accepted as legitimate resolver data.
DNSSEC validation is enabled for applicable DNS zones so that Unbound can verify the DNS response using the DNSSEC chain of trust.
Detects DNS responses that fail cryptographic integrity and authenticity validation.
DNS validation failures are monitored for responses classified as security failures or otherwise inconsistent with the expected DNS validation state.
Identifies potentially forged, manipulated, or invalid DNS responses.
DNS responses are monitored for unexpected changes in returned addresses and validation status during controlled testing.
Identifies suspicious DNS-response changes that may indicate manipulation or poisoning attempts.
Resolver behavior and cache-related statistics are periodically collected using Unbound monitoring capabilities and unbound-control.
Detects abnormal resolver behavior and supports verification of the trusted DNS cache state.
Unbound can track unwanted replies and, when the configured threshold is reached, perform a defensive action that clears RRset and message caches.
Provides an additional resolver-level mechanism for responding to suspicious unwanted DNS replies.
A security alert is generated when DNS validation failure or configured cache-integrity detection conditions are satisfied.
Provides actionable notification of a potential DNS cache-poisoning event.
When a confirmed laboratory poisoning condition is identified, the affected cache information is cleared using the predefined controlled remediation procedure.
Removes potentially untrusted DNS information from the resolver cache.
DNS queries, validation results, suspicious responses, cache events, alerts, remediation actions, and validation results are recorded.
Provides an auditable record for investigation and post-remediation verification.
Unbound provides the controlled recursive caching DNS resolver used in the laboratory. It performs recursive resolution, caching, and DNSSEC validation.
unbound-control is used to obtain Unbound statistics and perform controlled resolver-management operations. Unbound documentation describes unbound-control stats for obtaining resolver statistics.
dig is used to generate controlled DNS queries and inspect DNS responses during the testing process.
Wireshark is used to capture and inspect DNS traffic generated during the controlled assessment.
Wazuh is used to monitor Ubuntu, Unbound, and DNS-related security activity.
OpenSearch is used for centralized investigation and analysis of DNS security events.
Ubuntu provides the controlled Linux environment hosting the Unbound DNS resolver.
Kali Linux provides the controlled security-testing environment used to generate and validate the DNS cache-poisoning scenario.
DNSSEC provides cryptographic validation of signed DNS data through a chain of trust. Unbound supports DNSSEC validation using configured trust anchors.
VirtualBox provides the isolated environment for the Ubuntu DNS resolver and Kali Linux testing system.