Resolvers Revealed: Characterizing DNS Resolvers and their Clients

Resolvers Revealed: Characterizing DNS Resolvers and their Clients
复制标题

解析器揭秘:DNS 解析器及其客户端的特征

DOI:
--
复制
发表时间:
2013
期刊:
TOIT
影响因子:
--
通讯作者:
Andrew J. Kalafut
Andrew J. Kalafut
中科院分区:
--
文献类型:
--
作者:
Craig A. Shue;Andrew J. Kalafut

文献摘要

被引文献

相似文献

域名系统(DNS)允许客户端使用解析器(有时称为缓存)来查询一组权威服务器,以将主机名转换为IP地址。先前的工作已经提出使用这些DNS解析器和权威服务器之间的交互作为访问控制机制。然而,虽然先前的工作从许多角度检查了DNS,但解析器组件很少受到审查。在访问控制系统中使用解析器的基本因素,例如解析器是ISP基础设施的一部分还是运行在最终用户的系统上,尚未得到研究。在本研究中,我们研究了DNS解析器的行为和使用情况,从查询模式和对非标准响应的反应到被动关联技术,再到将解析器与其客户端主机配对。在此过程中,我们发现了安全协议支持、错误配置的解析器、指纹解析器的技术以及检测自动客户机的特性的证据。这些测量可以影响这些解析器和基于dns的访问控制系统的实现和设计。
The Domain Name System (DNS) allows clients to use resolvers, sometimes called caches, to query a set of authoritative servers to translate host names into IP addresses. Prior work has proposed using the interaction between these DNS resolvers and the authoritative servers as an access control mechanism. However, while prior work has examined the DNS from many angles, the resolver component has received little scrutiny. Essential factors for using a resolver in an access control system, such as whether a resolver is part of an ISP’s infrastructure or running on an end-user’s system, have not been examined. In this study, we examine DNS resolver behavior and usage, from query patterns and reactions to nonstandard responses to passive association techniques to pair resolvers with their client hosts. In doing so, we discover evidence of security protocol support, misconfigured resolvers, techniques to fingerprint resolvers, and features for detecting automated clients. These measurements can influence the implementation and design of these resolvers and DNS-based access control systems.