首页> 外文会议>International conference on passive and active measurement >A First Look at QNAME Minimization in the Domain Name System
【24h】

A First Look at QNAME Minimization in the Domain Name System

机译:域名系统中的QNAME最小化初探

获取原文

摘要

The Domain Name System (DNS) is a critical part of network and Internet infrastructure; DNS lookups precede almost any user request. DNS lookups may contain private information about the sites and services a user contacts, which has spawned efforts to protect privacy of users, such as transport encryption through DNS-over-TLS or DNS-over-HTTPS. In this work, we provide a first look on the resolver-side technique of query name minimization (qmin), which was standardized in March 2016 as RFC 7816. qmin aims to only send minimal information to authoritative name servers, reducing the number of servers that full DNS query names are exposed to. Using passive and active measurements, we show a slow but steady adoption of qmin on the Internet, with a surprising variety in implementations of the standard. Using controlled experiments in a test-bed, we validate lookup behavior of various resolvers, and quantify that qmin both increases the number of DNS lookups by up to 26%, and also leads to up to 5% more failed lookups. We conclude our work with a discussion of qmin's risks and benefits, and give advice for future use.
机译:域名系统(DNS)是网络和Internet基础结构的重要组成部分。 DNS查找几乎在所有用户请求之前。 DNS查找可能包含有关用户联系的站点和服务的私人信息,这催生了保护用户隐私的工作,例如通过TLS上的DNS或HTTPS上的DNS进行传输加密。在这项工作中,我们对查询名称最小化(qmin)的解析器端技术进行了初步研究,该技术于2016年3月作为RFC 7816进行了标准化。qmin旨在仅向权威名称服务器发送最少的信息,从而减少服务器的数量。完整的DNS查询名称。通过使用被动和主动测量,我们显示了Internet上qmin的缓慢但稳定的采用,并且该标准的实现方式令人惊讶。在测试台中使用受控实验,我们验证了各种解析程序的查找行为,并量化了qmin不仅使DNS查找次数最多增加了26%,而且还使失败查找次数增加了多达5%。我们在讨论qmin的风险和收益时结束了我们的工作,并为以后的使用提供了建议。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号