T-DNS

T-DNS
复制标题

域名解析服务

DOI:
10.1145/2740070.2631442
复制
发表时间:
2014
影响因子:
2.8
通讯作者:
Nikita Somaiya
Nikita Somaiya
中科院分区:
计算机科学4区
文献类型:
--
作者:
Liang Zhu;Zi Hu;J. Heidemann;D. Wessels;A. Mankin;Nikita Somaiya

文献摘要

被引文献

相似文献

DNS是无连接UDP的规范协议。然而,今天的DNS面临的挑战包括:危及隐私的窃听、导致对服务器和第三方的拒绝服务(DoS)攻击的源地址欺骗、利用碎片的注入攻击,以及限制策略和操作选择的大小限制。我们提出T-DNS来解决这些问题。它使用TCP平滑地支持大的有效负载,并减少对DoS的欺骗和放大。T-DNS使用传输层安全性(TLS)为用户提供对其DNS解析器的隐私保护,也可选择向授权服务器提供隐私保护。我们的模型显示,当使用UDP作为授权服务器时,从TLS到递归解析器的端到端延迟仅慢9%左右,使用TCP作为授权服务器时慢22%。通过不同的跟踪,我们发现频繁的连接重用是可能的(对于存根和递归解析器来说是60-95%,而对于授权服务器来说是一半)。我们的实验表明,连接建立后,TCP和TLS的延迟与UDP相当。使用保守超时(权威服务器为20秒,其他服务器为60秒)和对连接状态内存需求的保守估计,我们显示服务器内存需求完全符合当前的商品服务器硬件。我们确定了最小化开销所需的关键设计和实现决策:查询流水线、乱序响应、TLS连接恢复和合理的超时。这份海报摘要总结了我们在ISI-TR-2014-693中详细描述的工作。
DNS is the canonical protocol for connectionless UDP. Yet DNS today is challenged by eavesdropping that compromises privacy, source-address spoofing that results in denial-of-service (DoS) attacks on the server and third parties, injection attacks that exploit fragmentation, and size limitations that constrain policy and operational choices. We propose T-DNS to address these problems. It uses TCP to smoothly support large payloads and to mitigate spoofing and amplification for DoS. T-DNS uses transport-layer security (TLS) to provide privacy from users to their DNS resolvers and optionally to authoritative servers. Our model shows end-to-end latency from TLS to the recursive resolver is only about 9% slower when UDP is used to the authoritative server, and 22% slower with TCP to the authoritative. With diverse traces we show that frequent connection reuse is possible (60-95% for stub and recursive resolvers, although half that for authoritative servers). Our experiment shows that after connection establishment, TCP and TLS latency is equivalent to UDP. With conservative timeouts (20 s at authoritative servers and 60 s elsewhere) and conservative estimates of connection state memory requirements, we show that server memory requirements well within current, commodity server hardware. We identify the key design and implementation decisions needed to minimize overhead: query pipelining, out-of-order responses, TLS connection resumption, and plausible timeouts. This poster abstract summarizes work we describe in detail in ISI-TR-2014-693.