Resolvers Revealed: Characterizing DNS Resolvers and their Clients
Resolvers Revealed: Characterizing DNS Resolvers and their Clients
复制标题
解析器揭秘:DNS 解析器及其客户端的特征
DOI:
--
复制
发表时间:
2013
期刊:
影响因子:
--
通讯作者:
Andrew J. Kalafut
中科院分区:
文献类型:
--
作者:
Craig A. Shue;Andrew J. Kalafut
The Domain Name System (DNS) allows clients to use resolvers, sometimes called caches, to query a set of authoritative servers to translate host names into IP addresses. Prior work has proposed using the interaction between these DNS resolvers and the authoritative servers as an access control mechanism. However, while prior work has examined the DNS from many angles, the resolver component has received little scrutiny. Essential factors for using a resolver in an access control system, such as whether a resolver is part of an ISP’s infrastructure or running on an end-user’s system, have not been examined. In this study, we examine DNS resolver behavior and usage, from query patterns and reactions to nonstandard responses to passive association techniques to pair resolvers with their client hosts. In doing so, we discover evidence of security protocol support, misconfigured resolvers, techniques to fingerprint resolvers, and features for detecting automated clients. These measurements can influence the implementation and design of these resolvers and DNS-based access control systems.