Impact of configuration errors on DNS robustness

Impact of configuration errors on DNS robustness
复制标题

DOI:
10.1145/1015467.1015503
复制
发表时间:
2004-08
影响因子:
16.4
通讯作者:
V. Pappas;D. Wessels;D. Massey;Songwu Lu;A. Terzis;Lixia Zhang
V. Pappas;D. Wessels;D. Massey;Songwu Lu;A. Terzis;Lixia Zhang
中科院分区:
计算机科学1区
文献类型:
--
作者:
V. Pappas;D. Wessels;D. Massey;Songwu Lu;A. Terzis;Lixia Zhang

文献摘要

被引文献

相似文献

在过去的二十年中,域名系统(DNS)具有惊人的增长,同时保持了令人满意的用户级别的性能。但是,最初的设计主要集中在对物理失败的系统鲁棒性上,并忽略了操作错误(例如错觉)的影响。我们的测量工作表明,今天的DNS中有许多错误的配置:授权不一致,la脚授权,服务器冗余减少和环状区依赖性。具有配置错误的区域的可用性降低,查询延迟延迟至数量级。原始DNS设计假设冗余DNS服务器独立失败,但是我们的测量结果表明,操作选择在服务器之间创造依赖性。我们发现,DNS配置错误是普遍存在的。具体而言,la脚委托会影响测得的DNS区域的15%,授权不一致出现在21%的区域中,服务器冗余减少甚至更为普遍,并且环节依赖性出现在2%的区域中。我们还指出,误配置的程度因区域而异,最受欢迎的区域的错误百分比最低。我们的结果表明,DNS以及任何其他真正可靠的大规模系统都必须包括系统的检查机制,以应对操作错误。
During the past twenty years the Domain Name System (DNS) has sustained phenomenal growth while maintaining satisfactory user-level performance. However, the original design focused mainly on system robustness against physical failures, and neglected the impact of operational errors such as mis-configurations. Our measurement efforts have revealed a number of mis-configurations in DNS today: delegation inconsistency, lame delegation, diminished server redundancy, and cyclic zone dependency. Zones with configuration errors suffer from reduced availability and increased query delays up to an order of magnitude. The original DNS design assumed that redundant DNS servers fail independently, but our measurements show that operational choices create dependencies between servers. We found that, left unchecked, DNS configuration errors are widespread. Specifically, lame delegation affects 15% of the measured DNS zones, delegation inconsistency appears in 21% of the zones, diminished server redundancy is even more prevalent, and cyclic dependency appears in 2% of the zones. We also noted that the degrees of mis-configuration vary from zone to zone, with the most popular zones having the lowest percentage of errors. Our results indicate that DNS, as well as any other truly robust large-scale system, must include systematic checking mechanisms to cope with operational errors.