Look-aside At Your Own Risk: Privacy Implications of DNSSEC Look-aside Validation

نویسندگان

  • Aziz Mohaisen
  • Zhongshu Gu
  • Kui Ren
  • Zhenhua Li
  • Charles Kamhoua
  • Laurent Njilla
  • DaeHun Nyang
چکیده

The Domain Name System Security Extension (DNSSEC) leverages public-key cryptography to provide data integrity, source authentication, and denial of existence for DNS responses. To complement DNSSEC operations, DNSSEC Look-aside Validation (DLV) is designed for alternative off-path validation. Although DNS privacy attracts a lot of attention, the privacy implications of DLV are not fully investigated and understood. In this paper, we take a first in-depth look into DLV, highlighting its lax specifications and privacy implications. By performing extensive experiments over datasets of domain names under comprehensive experimental settings, our findings firmly confirm the privacy leakages caused by DLV. We discover that a large number of domains that should not be sent to DLV servers are being leaked. We explore the root causes, including the lax specifications of DLV. We also propose two approaches to fix the privacy leakages. Our approaches require trivial modifications to the existing DNS standards, and we demonstrate their cost in terms of latency and communication.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

P14: How to Find a Talent?

Talents may be artistic or technical, mental or physical, personal or social. You can be a talented introvert or a talented extrovert. Learning to look for your talents in the right places and building those talents into skills and abilities might take some work, but going about it creatively will let you explore your natural abilities and find your innate talents. You’re not going to fin...

متن کامل

The Design of Metrics for Quantifying the DNSSEC Deployment

This paper examines the deployment of the DNS Security Extensions (DNSSEC), which adds cryptographic protection to DNS, one of the core components in the Internet infrastructure. We analyze the data collected from the initial DNSSEC deployment which started in 2005, and identify three critical metrics to gauge the deployment: availability, verifiability, and validity. Our results provide the fi...

متن کامل

IJESRT INTERNATIONAL JOURNA Towards the Understanding of the Look aside Buffer

not only by the emulation of in -identity split. Given the current status of multimodal

متن کامل

When to defer to majority testimony – and when not

How sensitive should you be to the testimony of others? You saw the car that caused an accident going through traffic lights on the red; or so you thought. Should you revise your belief on discovering that the majority of bystanders, equally well-equipped, equally well-positioned and equally impartial, reported that it went through on the green? Or take another case. You believe that intelligen...

متن کامل

A Futuristic Look at the Islamic Republic of Iran’s Developmental Plans in Education

Among educational philosophies and approaches, the social reconstruction philosophy with a futuristic approach can be helpful in overcoming the challenges that Iranian education will be facing in the near future, as it can predict the future based on the rapid developments and changes occurring at present. From this perspective, a positive outlook on the future can help clarifying the goals and...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2018