CycleHunter
Requires Python3.7 minimum
Required packages for Debian/Ubuntu
CycleHunter
users newer versions of packages than the ones shipped with Debianpip
python3-tqdm python3-multiprocess python3-dnspython
pip install async_lru
To analyze a full zone, you can use CycleHunter.py
as below
python CycleHunter.py --zonefile <ZONEFILE> --origin <ORIGIN> --save-file <FILE_TO_SAVE_AFFECTED_DOMAINS> --base-dir <BASE_DIR> --workers <WORKERS>
Where
ZONEFILE
is the file with the zone you want to analyzeORIGIN
is the zone represented by the ZONEFILE
, for example, .COM or .NLFILE_TO_SAVE_AFFECTED_DOMAINS
is a JSON file that in the end will have the list of domains affected by full cyclesBASE_DIR
is the base directory used to write the intermediate filesWORKERS
is the number of parallel works that will use to send queries
CycleHunter.py
wraps all the steps below, but if you still want to run them by hand, the process is:
Extract all NS records from the zone file
python largeZoneParser.py $zonefile $TLD $output1
python3 largeZoneParser.py /var/cache/bind/com.zone .com com-nses.csv
Query these NSes, and output those that timeout into $output2
python CyclicDetector.py $output1 $output2
Scrutinize each timed out NS, either parent or child, and see if which ones are really cyclic dependent into output3
python findCyclicDep.py $output2 $output3
Note: $output3 is a json file with 3 categories of dependency. fullDep
is the one very bad, but the other two can quickily become fullDep
Get only the fully cyclic dependent ones from output3
python fullDepParser.py $output3 $output4
output4
has the zones that are cyclic dependent. These are likely parent zones of NSes
Determine how many zones are affected by cyclic dependency
python zoneMatcher.py $output4 $zoneFile $TLD $output5
zoneMatcher-com.py
output5
has all domains affected by cyclic dependency
docker build -t sidn/cyclehunter --no-cache .
docker run -it -v $(pwd):/data --rm sidn/cyclehunter pypy3 CycleHunter.py --zonefile /data/org.txt --origin ".org" --save-file /data/org-final.out --base-dir /data --workers 6
or to run specific step within the container as per the general instructions:
e.g.
docker run -it -v $(pwd):/data --rm sidn/cyclehunter pypy3 findCyclicDep.py /data/$output2 /data/$output3