Updating Resolver Algorithm

Updating Resolver Algorithm
复制标题

更新解析器算法

DOI:
--
复制
发表时间:
2016
期刊:
影响因子:
--
通讯作者:
Kazunori Fujiwara
Kazunori Fujiwara
中科院分区:
--
文献类型:
--
作者:
Kazunori Fujiwara

文献摘要

被引文献

相似文献

父端NS RRSet和胶水记录都是要访问的信息 子区域的服务器。但是,它们可能会被子区域覆盖 数据(区域顶点 NS RRSet 和其他 A/AAAA RRSet)。覆盖使得 名称解析不稳定并引发漏洞。 RFC 2181 部分 5.4.1 规定了 DNS 数据的可信度。并且认为 所有缓存的数据(权威数据、非权威数据、 推荐和粘合记录)合并为一。解决者可能会回答 不应使用的非权威数据、推荐和粘合记录 回来了。本文档提出了更新解析器算法 将缓存分为“权威数据缓存”和“委托数据缓存” 缓存”。前者用于应答存根解析器,后者是 用于迭代区域。
Parent side NS RRSet and glue records are all information to access servers for child zone. However, they may be overwritten by child zone data (zone apex NS RRSet and other A/AAAA RRSets). The overwrite makes name resolution unstable and induces vulnerabilities. RFC 2181 section 5.4.1 specifies trustworthiness of DNS data. And it is deemed that that all cached data (authoritative data, non- authoritative data, referrals and glue records) are merged into one. Resolvers may answer non-authoritative data, referrals and glue records that should not be returned. This document proposes updating resolver algorithm that separates the cache to "authoritative data cache" and "delegation cache". The former is used to answer stub resolvers, and the latter is used to iterate zones.