DNS to the rescue: discerning content and services in a tangled web

DNS to the rescue: discerning content and services in a tangled web
复制标题

DOI:
10.1145/2398776.2398819
复制
发表时间:
2012-11
期刊:
Proceedings of the 2012 Internet Measurement Conference
影响因子:
--
通讯作者:
Ignacio Bermudez;M. Mellia;M. Munafò;Ram Keralapura;A. Nucci
Ignacio Bermudez;M. Mellia;M. Munafò;Ram Keralapura;A. Nucci
中科院分区:
其他
文献类型:
--
作者:
Ignacio Bermudez;M. Mellia;M. Munafò;Ram Keralapura;A. Nucci

文献摘要

被引文献

相似文献

仔细研究互联网的发展,可以发现两个主要趋势--基于云的服务和视频流应用的爆炸式增长。在上述两种情况下,所有者(例如,CNN、YouTube或Zynga)以及为其提供服务的组织(例如,Akamai、Limelight或Amazon EC2)是解耦的,因此更难理解内容、所有者和内容所在的主机之间的关联。这就造成了一个错综复杂的万维网,很难解开,削弱了互联网服务提供商和网络管理员控制网络流量的能力。在本文中,我们提出了DN-Hunter,一个利用DNS流量提供的信息来识别缠结的系统。通过解析DNS查询,DN-Hunter使用关联的域名标记流量。该关联具有若干应用并且揭示了大量有用的信息:(i)即使当流量被加密时(即,TLS/SSL流),从而实现更有效的策略控制,(ii)甚至在流开始之前就能识别流,从而为管理员提供上级网络管理功能,$(iii)$了解并跟踪(iv)辨别在特定地理位置和时间间隔中由给定CDN或云提供商托管的所有服务/内容,以及(v)提供对在任何给定的第4层端口号上运行的所有应用/服务的洞察。我们进行了广泛的实验分析,并显示结果从真实的流量跟踪(包括FTTH和4G ISP),支持我们的假设。简而言之,DNS流量提供的信息是理解错综复杂的网络所需的关键组件之一,并将有效管理网络流量的能力带回给运营商。
A careful perusal of the Internet evolution reveals two major trends - explosion of cloud-based services and video streaming applications. In both of the above cases, the owner (e.g., CNN, YouTube, or Zynga) of the content and the organization serving it (e.g., Akamai, Limelight, or Amazon EC2) are decoupled, thus making it harder to understand the association between the content, owner, and the host where the content resides. This has created a tangled world wide web that is very hard to unwind, impairing ISPs' and network administrators' capabilities to control the traffic flowing in their networks. In this paper, we present DN-Hunter, a system that leverages the information provided by DNS traffic to discern the tangle. Parsing through DNS queries, DN-Hunter tags traffic flows with the associated domain name. This association has several applications and reveals a large amount of useful information: (i) Provides a fine-grained traffic visibility even when the traffic is encrypted (i.e., TLS/SSL flows), thus enabling more effective policy controls,(ii) Identifies flows even before the flows begin, thus providing superior network management capabilities to administrators, $(iii)$ Understand and track (over time) different CDNs and cloud providers that host content for a particular resource, (iv) Discern all the services/content hosted by a given CDN or cloud provider in a particular geography and time interval, and (v) Provides insights into all applications/services running on any given layer-4 port number. We conduct extensive experimental analysis and show results from real traffic traces (including FTTH and 4G ISPs) that support our hypothesis. Simply put, the information provided by DNS traffic is one of the key components required for understanding the tangled web, and bringing the ability to effectively manage network traffic back to the operators.