Quantifying DNS namespace influence
نویسندگان
چکیده
Name resolution using the Domain Name System (DNS) is integral to today’s Internet. The resolution of a domain name is often dependent on namespace outside the control of the domain’s owner. In this article we review the DNS protocol and several DNS server implementations. Based on our examination, we propose a formal model for analyzing the name dependencies inherent in DNS, and experimentally validate the model with actual domain names. Using our name dependency model we derive metrics to quantify the extent to which domain names affect other domain names. It is found that under certain conditions, more than half of the queries for a domain name are influenced by namespaces not expressly configured by administrators. This result serves to quantify the degree of vulnerability of DNS due to dependencies that administrators are unaware of. When we apply metrics from our model to production DNS data, we show that the set of domains whose resolution affects a given ✩This research was supported in part by the National Science Foundation under the grant CNS-0716741. ✩✩This is a revised personal version of the journal article published by Elsevier in Computer Networks, Volume 56, Issue 2, on 2 February 2012, pages 780 – 794, available at http://dx.doi.org/10.1016/j.comnet.2011.11.005 ∗Corresponding author Email addresses: [email protected] (Casey Deccio), [email protected] (Jeff Sedayao), [email protected] (Krishna Kant), [email protected] (Prasant Mohapatra) Sandia National Laboratories is a multi-program laboratory managed and operated by Sandia Corporation, a wholly owned subsidiary of Lockheed Martin Corporation, for the U.S. Department of Energy’s National Nuclear Security Administration under contract DE-AC0494AL85000. Preprint submitted to Computer Networks February 27, 2012 domain name is much smaller than previously thought. However, behaviors such as using cached addresses for querying authoritative servers and chaining domain name aliases increase the number and diversity of influential domains, thereby making the DNS infrastructure more vulnerable.
منابع مشابه
The Third Rail
4 Naming in an internet context has been plagued for years on a conflict between the name of an object and the 5 location of the object. [1] The Domain Name System has been very successful in avoiding many of the problems 6 of naming by the creation of both scalable, ephemeral namespace and a flexible, extensible query/response 7 protocol for publication of the namespace. A primary problem rema...
متن کاملDoes Query Blocking Improve DNS Privacy? - Quantifying Privacy Under Partial Blocking Deployment
DNS leakage happens when queries for names within a private namespace spread out to the public DNS infrastructure (Internet), which has various privacy implications. An example of this leakage includes the documented [1] leakage of .onion names associated with Tor hidden services to the public DNS infrastructure. To mitigate this leakage, and improve Tor’s privacy, Appelbaum and Muffet [2] prop...
متن کاملMeasuring the Leakage of Onion at the Root
The Tor project provides individuals with a mechanism of communicating anonymously on the Internet. Furthermore, Tor is capable of providing anonymity to servers, which are configured to receive inbound connections only through Tor—more commonly called hidden services. In order to route requests to these hidden services, a namespace is used to identify the resolution requests to such services. ...
متن کاملReview of Mitigating DNS DoS Attacks
The Domain Name system (DNS) has become a ubiquitous part of modern internet infrastructure that maps numeric IP address to human-readable names. In the recent years, denial of service (DoS) attacks on DNS has a trend to be more serious problems. These attack is mainly related the hierarchical namespace architecture, which is hard to avoid as this architecture are widely deployment in multi-lev...
متن کاملNetwork Working Group the E.164 to Uniform Resource Identifiers (uri) Dynamic Delegation Discovery System (ddds) Application for Infrastructure Enum
This document defines the use case for Infrastructure ENUM and proposes its implementation as a parallel namespace to "e164.arpa", as defined in RFC 3761, as the long-term solution to the problem of allowing carriers to provision DNS records for telephone numbers independently of those provisioned by end users (number assignees). Table of
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید
ثبت ناماگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید
ورودعنوان ژورنال:
- Computer Networks
دوره 56 شماره
صفحات -
تاریخ انتشار 2012