Evidence of Decreasing Internet Entropy: The Lack of Redundancy in Dns Resolution by Major Websites and Services

Evidence of Decreasing Internet Entropy: The Lack of Redundancy in Dns Resolution by Major Websites and Services
复制标题

互联网熵减少的证据:主要网站和服务的 DNS 解析缺乏冗余

DOI:
10.3386/w24317
复制
发表时间:
2018
期刊:
Kauffman: Large Research Projects (Topic)
影响因子:
--
通讯作者:
Jonathan Zittrain
Jonathan Zittrain
中科院分区:
--
文献类型:
--
作者:
Samantha Bates;S. Greenstein;Jordi Weinstock;Jonathan Zittrain

文献摘要

被引文献

相似文献

互联网和在其顶部建立的网络旨在支持“熵”的物理和逻辑网络图(Zittrain,2013年)。临时和不断发展的方式,而不是集中的距离。可以通过使用各种URL,每个指向用户的位置,从任何上游来源组装一个网页。互联网服务变得更加集中,我们探索并记录了该集中化的一个可能性。鉴于基于云的托管和基础架构的兴起,我们提供了DNS托管市场在少数云服务提供商手中的巨大浓度。域名“多样化”其名称服务器库的趋势的变化 - 域名的员工DNS管理服务的频率是多个提供商,而不仅仅是一个提供商。我们使用灾难性的2016年10月对主要DNS主持提供商Dyn的攻击来说明我们的分析的网络安全后果。
The Internet, and the Web built on top of it, were intended to support an “entropic” physical and logical network map (Zittrain, 2013). That is, they have been designed to allow servers to be spread anywhere in the world in an ad hoc and evolving fashion, rather than a centralized one. Arbitrary distance among, and number of, servers causes no particular architectural problems, and indeed ensures that problems experienced by one data source remain unlinked to others. A Web page can be assembled from any number of upstream sources, through the use of various URLs, each pointing to a different location. To a user, the page looks unified. Over time, however, there are signs that the hosting and finding of Internet services has become more centralized. We explore and document one possible dimension of this centralization. We analyze the extent to which the Internet’s global domain name resolution (DNS) system has preserved its distributed resilience given the rise of cloud-based hosting and infrastructure. We offer evidence of the dramatic concentration of the DNS hosting market in the hands of a small number of cloud service providers over a period spanning from 2011-2018. In addition, we examine changes in domains’ tendency to “diversify” their pool of nameservers – how frequently domains employ DNS management services from multiple providers rather than just one provider. Throughout the paper, we use the catastrophic October 2016 attack on Dyn, a major DNS hosting provider, to illustrate the cybersecurity consequences of our analysis.