Uppsats

Beyond the Third Party : Quantifying Systemic Risk in DNS Supply Chains

Yrkesexamen på grundnivå

Blekinge Tekniska Högskola/Institutionen för datavetenskap

Publicerad: 2026

Språk: Engelska

Sammanfattning

Background. Modern organisations delegate critical functions such as email delivery, authentication, and content distribution to external providers, creating recursive chains of third-party DNS trust that extend far beyond what administrators can directly observe. Existing third-party risk management tools assess vendors in isolationusing flat, surface-level indicators, without capturing the depth or criticality of transitive dependencies. To the best of our knowledge, no existing tool applies recursive graph analysis to DNS infrastructure for quantitative supply chain risk scoring. Objectives. This thesis develops a method, supported by a tool and a Risk Scoring Model (RSM), that constructs a systemic DNS supply chain risk model by performing Recursive Graph Analysis (RGA) of SPF and MX trust chains. The method maps multi-tier third-party relationships and produces a quantitative risk score incorporating dependency depth, service criticality and misconfiguration detection, with vulnerability scoring identified as a future extension. Methods. The RGA tool was implemented in Python and executed against 44 manually selected domains spanning six organisational sectors, producing a dependencygraph for each domain. The RSM combines four normalised factors into a per-nodescore aggregated to an organisational score. Scans were conducted non-intrusivelyby the authors in May 2026 under scanning authorisation from Outpost24 AB andin accordance with their internet-scanning guidelines, limited to DNS lookups anddefault HTTP requests against public end points. Results. The tool mapped 6134 dependency nodes across 44 domains, with chains reaching up to 13 levels deep. Two dangling records were detected in 1 domain(0.03% of nodes); no confirmed hijack candidates were found. Organisational risk scores ranged from 0.220 to 0.301 with a mean of 0.276. The Swedish public sector produced the highest mean sector score (0.289), driven by deep DNS delegation chains containing high-criticality infrastructure invisible without recursive traversal.The results demonstrate that node count is not a direct proxy for risk. For instance, google.com and cloudflare.com returned identical risk scores (0.2661) despite amassive disparity in their dependency graphs (7 nodes vs. 149 nodes), confirmingthat the criticality-weighted model prioritises the nature of a dependency over thesize of the graph. Conclusions. Recursive DNS analysis surfaces supply chain structure that is invisible to flat inspection tools and produces risk rankings that differ meaningfully fromfootprint-based vendor ratings. The depth and criticality of transitive DNS dependencies are the primary drivers of organisational risk in well-managed infrastructure, rather than the presence of dangling records or known vulnerabilities. The RGA tool and RSM together provide a practical, reproducible, and auditable complement to existing cyber third-party risk management approaches.

Information

Lärosäte / institution
Blekinge Tekniska Högskola/Institutionen för datavetenskap
Publiceringsdatum
2026
Uppsatstyp
Yrkesexamen på grundnivå
Språk
Engelska