Distributed Denial Of Service (DDoS) attacks take many different forms and use a variety of techniques, but the goal is consistent: To overwhelm a service to the extent that it can't provide access to anyone.

Abusing a type of DNS query known as an NXDOMAIN (short for nonexistent domain) has become a popular DDoS technique in recent years. In an effort to help combat the DNS-based DDoS attacks, Akamai is launching a new service called Akamai Shield NS53 that extends the company's Edge DNS technologies in the cloud to on-premises deployments.

“There has been a trend of increasing NXDOMAIN attacks observed by Akamai’s platform over the past three years,” Sean Lyons, senior vice president and general manager, Infrastructure Security Solutions and Services, at Akamai told SDxCentral. “In Q4 of 2023, about 64% of the total DDoS attacks mitigated by Akamai had a DNS component, of which more than 50% were NXDOMAIN attacks.”

How NXDOMAIN attacks work NXDOMAIN is the response a DNS server gives when asked to return the IP address of a nonexistent domain or subdomain name.

Lyons said that an NXDOMAIN is a normal legitimate response when, say, somebody makes an accidental typo in the URL they enter into their browser. The DNS server spends time and resources looking up the IP address of that domain and also asks other servers. This type of DNS query uses a comparably large amount of processing time on multiple machines.

“Now, if you purposely and systematically flood the DNS system with millions of such nonexistent DNS queries, it will exhaust the capacity of the DNS infrastructure to respond; thus resulting in degradation of service and ultimately in denial of service,” he said.

Lyons added that what makes NXDOMAIN attacks particularly challenging for network security teams to mitigate is that attackers design the illegitimate DNS queries to appear like legitimate queries.

NXDOMAIN attacks occur in the cloud and against on-premises resources DNS servers are found on-premises and in the cloud with attackers taking aim at both types of deployments with increasing regularity.

Lyons said that attackers are smart about the location of DNS servers and work through configurations to find specific systems such as on-premises global server load balancers (GSLBs).

“This is particularly challenging for customers who prefer to maintain some or all of their DNS infrastructure on-prem,” he said.

There are many reasons why organizations have DNS on-premises including compliance concerns, or the fact that they might have already made significant capital investments in building on-premises DNS infrastructure.

Bringing a new shield to defend against NXDOMAIN attacks To date, Akamai has provided its customers with NXDOMAIN attack protection with Edge.

Edge DNS, Akamai Prolexic and Akamai Global Traffic Management services. Lyons said that the new Akamai Shield NS53 is a complementary alternative that can be configured to protect the on-premises and hybrid DNS assets of an organization

Lyons said that with Akamai Edge DNS all of an organization's DNS queries are responded to by Akamai. Akamai Shield NS53, on the other hand, is an additional protection layer that an organization puts in front of existing non-Akamai and on-premises DNS deployments.

“Shield NS53 has a dynamic policy engine that builds and regularly updates effective security policies that adds protection against NXDOMAIN attacks, which many DNS solutions are not well equipped to withstand,” he said.