ddos-simulation.com
All 130 Techniques Explore full Layer 3–7 attack library Network & Transport SYN flood, UDP flood, ICMP, TCP states Application & Protocols HTTP/2 Rapid Reset, Slowloris, QUIC, TLS API Gateway Resilience Kong, APISIX, Spring Cloud, Tyk, KrakenD
Compliance & Audits EU DORA Compliance Regulation 2022/2554 & TLPT stress testing NIS2 Directive Cyber resilience for essential entities PCI DSS v4.0 Testing Req 11.4 & 6.4 payment perimeter defense
Cloud & Programs AWS DDoS Testing Shield Advanced, CloudFront & ALB Azure DDoS Testing Network Protection & Front Door WAF Google Cloud Armor Adaptive Protection & Cloud CDN Cloudflare Testing WAF, rate limits & Magic Transit Periodic Testing Quarterly & continuous resilience drills White-Label Program Deliver testing under your own brand
Controlled Testing Process War room, stepped ramp-up & safety How auto-abort works 50ms health sampling & instant safety Testing Legality & RoE Rules of Engagement & authorizations
Pricing
Sign in Build a test plan
Sign in
Simulations All 130 Techniques Network & Transport (L3/L4) Application & Protocols (L7) API Gateways
Solutions & Compliance EU DORA Compliance NIS2 Directive PCI DSS v4.0 Testing AWS DDoS Testing Guide Azure DDoS Testing Guide Google Cloud Armor Guide Cloudflare Testing Guide Periodic Testing Program White-Label Partner Program
Methodology & Safety Controlled Testing Process Sub-Second Auto-Abort Testing Legality & RoE
Platform Timeline Builder Live Monitoring Pricing
Home › DDoS simulation testing › DNS infrastructure resilience suite

Layer 3/4/7 · Core DNS Infrastructure · BIND 9, PowerDNS

DNS Infrastructure Resilience Suite

Simulates authoritative and recursive DNS server vulnerability checks, DNSSEC cryptographic verification loads, and assertion crash vectors against BIND 9 and PowerDNS instances.

Target BIND 9, PowerDNS Layer L4 & DNS Techniques 6 simulations Access Reviewed engagement

On this page

  1. Suite Overview
  2. BIND 9 RRset DB Exhaustion (CVE-2024-1737)
  3. BIND 9 SIG(0) Crypto CPU (CVE-2024-1975)
  4. PowerDNS Delegation Loop (CVE-2024-25584)
  5. BIND 9 DNSKEY CPU Load (CVE-2025-8677)
  6. BIND 9 BRID/HHIT Parser Crash (CVE-2025-13878)
  7. BIND 9 TSIG Assertion Crash (CVE-2025-40775)
  8. Safe Execution
  9. Related simulations

Suite Overview

DNS is the foundation of domain reachability. This suite evaluates whether authoritative nameservers and recursive resolvers withstand complex cryptographic verification chains, high-cardinality record caching, and malformed signature packets.

BIND 9 RRset Database Exhaustion (CVE-2024-1737)

cve_2024_1737 — Tests ISC BIND 9 lookup table limits under high-cardinality record floods in cache databases.

BIND 9 SIG(0) Crypto CPU Load (CVE-2024-1975)

cve_2024_1975 — Evaluates BIND 9 recursive resolver SIG(0) cryptographic verification CPU consumption.

PowerDNS Delegation Loop Saturation (CVE-2024-25584)

cve_2024_25584 — Probes PowerDNS recursor delegation loop bounds and amplification defense under circular NS referrals.

BIND 9 DNSKEY Verification CPU Load (CVE-2025-8677)

cve_2025_8677 — Sends DNS queries targeting zones with malformed DNSKEY records to test DNSSEC verification CPU bounds.

BIND 9 BRID/HHIT Record Crash (CVE-2025-13878)

cve_2025_13878 — Sends DNS queries for malformed BRID/HHIT resource records to test BIND 9 parser resilience.

BIND 9 Invalid TSIG Assertion Crash (CVE-2025-40775)

cve_2025_40775 — Sends DNS control packets with invalid TSIG signatures to verify BIND 9 assertion failure protection.

Safe Execution

DNS infrastructure tests are strictly reviewed and bounded to confirmed customer-owned authoritative domains or recursor IP addresses.

Related simulations

DNS query flood test Simulate a DNS query flood / NXDOMAIN water-torture against a domain you own: random-subdomain queries over UDP forcing uncached authoritative lookups. UDP flood test Simulate a bounded UDP flood against infrastructure you own to probe UDP ingress filtering, bandwidth headroom and rate limits. QUIC / HTTP3 Initial flood test Simulate a QUIC / HTTP3 Initial-packet flood against a host you own: valid QUIC Initial packets over UDP, each a fresh connection the server must decrypt.

Test your DNS infrastructure resilience safely.

Build a test plan
← All DDoS simulations
ddos-simulation.com

Authorized, bounded resilience testing for infrastructure you own.

Product

Simulations Timeline builder Live monitoring Periodic testing White-label program

Guides

Controlled Testing Process How Auto-Abort Works AWS DDoS Testing Guide Azure DDoS Testing Guide Google Cloud Armor Guide Cloudflare Testing Guide 130 Attack Techniques

Portal

Sign in Create account Build a test plan

Compliance

EU DORA Compliance NIS2 Directive Compliance PCI DSS v4.0 Testing Testing Legality & RoE

Legal

Terms of Service Acceptable Use Privacy Policy Data Processing Addendum Contact
© 2026 ddos-simulation.com · Authorized testing only. DORA · PCI DSS · Terms · Privacy · Acceptable use · DPA