In a domain fronting attack, a client connects to a CDN using a reputable domain in the TLS handshake (SNI) but asks for a different, attacker-controlled domain in the encrypted HTTP Host header. To a network observer, the traffic looks like it is going to the legitimate site, while the CDN quietly forwards it to the attacker’s server. Malware uses this to hide its command-and-control traffic.
Measuring without the usual cost
Finding which CDNs allow fronting is usually assumed to require paid accounts on each CDN or globally distributed test infrastructure. We designed a measurement system that avoids both:
- Domain discovery. Passive and active DNS analysis identifies domains served by each CDN.
- URL discovery. A Puppeteer-based crawler visits those domains and records the resource URLs they load.
- Fronting tester. Candidate (front, target) domain pairs are generated and tested automatically to see whether the CDN routes by the
Hostheader.
Key contributions
- A low-cost methodology based on passive DNS and targeted crawling, with no paid CDN subscriptions.
- A measurement of which CDNs can be used to conceal a communication’s true destination.
- Selected for oral presentation at The Web Conference 2024 (20% acceptance rate).