DNS Resolvers Considered Harmful
DNS Resolvers Considered Harmful
复制标题
DOI:
10.1145/2670518.2673881
复制
发表时间:
2014-10
期刊:
影响因子:
--
通讯作者:
Kyle Schomp;M. Allman;M. Rabinovich
中科院分区:
文献类型:
--
作者:
Kyle Schomp;M. Allman;M. Rabinovich
The Domain Name System (DNS) is a critical component of the Internet infrastructure that has many security vulnerabilities. In particular, shared DNS resolvers are a notorious security weak spot in the system. We propose an unorthodox approach for tackling vulnerabilities in shared DNS resolvers: removing shared DNS resolvers entirely and leaving recursive resolution to the clients. We show that the two primary costs of this approach---loss of performance and an increase in system load---are modest and therefore conclude that this approach is beneficial for strengthening the DNS by reducing the attack surface.