DNS Resolvers Considered Harmful

DNS Resolvers Considered Harmful
复制标题

DOI:
10.1145/2670518.2673881
复制
发表时间:
2014-10
期刊:
Proceedings of the 13th ACM Workshop on Hot Topics in Networks
影响因子:
--
通讯作者:
Kyle Schomp;M. Allman;M. Rabinovich
Kyle Schomp;M. Allman;M. Rabinovich
中科院分区:
其他
文献类型:
--
作者:
Kyle Schomp;M. Allman;M. Rabinovich

文献摘要

被引文献

相似文献

域名系统(DNS)是Internet基础设施的关键组成部分,存在许多安全漏洞。特别是,共享DNS解析器是系统中臭名昭著的安全弱点。我们提出了一种非传统的方法来解决共享DNS解析器中的漏洞:完全删除共享DNS解析器,并将递归解析留给客户端。我们表明,这种方法的两个主要成本——性能损失和系统负载的增加——是适度的,因此得出结论,这种方法有利于通过减少攻击面来加强DNS。
The Domain Name System (DNS) is a critical component of the Internet infrastructure that has many security vulnerabilities. In particular, shared DNS resolvers are a notorious security weak spot in the system. We propose an unorthodox approach for tackling vulnerabilities in shared DNS resolvers: removing shared DNS resolvers entirely and leaving recursive resolution to the clients. We show that the two primary costs of this approach---loss of performance and an increase in system load---are modest and therefore conclude that this approach is beneficial for strengthening the DNS by reducing the attack surface.