课题基金 / 基金详情

SaTC: CORE: Small: Understanding Practical Deployment Considerations for Decentralized, Encrypted DNS

SaTC: CORE: Small: Understanding Practical Deployment Considerations for Decentralized, Encrypted DNS
SaTC:核心:小型:了解去中心化加密 DNS 的实际部署注意事项
批准号:
2155128
负责人:
Nicholas Feamster
金额:
$50.0万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2022
资助国家:
美国
项目状态:
未结题
起止时间:
2022-08-01 至 2025-07-31

项目摘要

项目成果

Nicholas Feamster的其他基金

相似基金

相关文献

中文摘要
翻译
域名系统(DNS)是一种互联网协议和系统,它将人类可读的名称映射到互联网协议地址;它是从网页浏览到视频流的每一项互联网活动的核心。尽管DNS在基本上所有互联网通信中发挥着核心作用,但直到最近它一直未加密,这带来了重大的隐私风险和漏洞。近年来,加密DNS查询和响应的技术包括传输DNS查询和响应。该项目正在研究现有加密DNS协议(如DoH和DoT)的性能和隐私属性,最终目标是部署使用这些新协议的应用程序和系统,以提高用户隐私并为用户提供满意的性能。 互联网正在迅速转向加密DNS协议,加密DNS现在在许多标准互联网浏览器和互联网连接的嵌入式设备中可用或默认启用。 然而,有相对较少的知识或协议的性能和隐私特性,这样的协议。 该项目建立在该领域的早期工作基础上,旨在开发用于评估依赖加密DNS协议的新网络应用程序、系统和架构的性能和隐私的综合技术。 该研究将有助于对DNS性能和隐私的更大的知识体系,并将向社区发布用于评估加密DNS协议的可用性能和评估框架,以允许其他人继续构建这些结果。该项目的第一个主题旨在了解现有加密DNS协议和架构对DNS查找时间的性能影响,以及取决于流行的因特网应用的性能,所述流行的因特网应用的性能取决于DNS,特别是对于诸如网页加载时间的度量。 了解加密DNS为什么(以及何时)优于未加密DNS-以及何时不优于未加密DNS-将最终阐明如何最好地构建DNS解析以确保机密性和良好性能。本项目的第二个主题认识到加密DNS不一定意味着集中化。将客户端的DNS查询分布在多个递归解析器上可以提高可靠性、隐私性甚至性能,尽管这种改进最终需要设计适当的策略来分布这些查询。本主题探讨了重新分散DNS的前景。 第三,该项目正在将各种DNS隐私方法(从DNS加密到以前的不经意DNS(ODNS))合并到一个连贯的架构框架中。本主题探讨如何以及在何处部署DNS隐私扩展(例如,该奖项反映了NSF的法定使命,并通过使用基金会的知识价值和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
The Domain Name System (DNS) is the Internet protocol and system that maps human-readable names to Internet protocol addresses; it is central to every Internet activity, from web browsing to video streaming. Despite the central role of the DNS in essentially all Internet communications, until recently it has been unencrypted, which has introduced significant privacy risks and vulnerabilities. In recent years, technology to encrypt DNS queries and responses includes transmitting DNS queries and responses. This project is studying the performance and privacy properties of existing encrypted DNS protocols such as DoH and DoT, towards the ultimate goal of deploying applications and systems that use these new protocols to improve user privacy and provide users satisfactory performance. The Internet is rapidly moving towards encrypted DNS protocols, with encrypted DNS now either available or enabled by default in many standard Internet browsers and Internet-connected embedded devices. Yet, there is relatively little knowledge or agreement about the performance and privacy characteristics of such protocols. This project builds on the early work in this area to develop comprehensive techniques for evaluating both the performance and privacy of new network applications, systems, and architectures that rely on encrypted DNS protocols. The research will contribute to the larger body of knowledge on both DNS performance and privacy, and the available performance and evaluation frameworks for evaluating encrypted DNS protocols will be released to the community to allow others to continue to build on these results.The first theme of this project seeks to understand the performance implications of existing encrypted DNS protocols and architectures, on DNS lookup time, as well as on the performance of popular Internet applications whose performance depends on the DNS, particularly for metrics such as web page load time. Understanding why (and when) encrypted DNS outperforms unencrypted DNS---as well as when it does not---will ultimately shed light on how to best architect DNS resolution to ensure both confidentiality and good performance. The second theme of this project recognizes that encrypting DNS need not imply centralization. Distributing a client's DNS queries across multiple recursive resolvers may improve reliability, privacy, and even performance, although such improvements will ultimately require the design of appropriate strategies for distributing these queries. This theme explores the prospect of re-decentralizing the DNS. Third, the project is coalescing various approaches to DNS privacy---from DNS encryption to previous work on oblivious DNS (ODNS)---into a coherent architectural framework. This theme explores how and where DNS privacy extensions could be deployed (e.g., in a local DNS resolver, in a web browser) to both preserve user privacy and preserve a seamless user experience.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Collaborative Research: IMR: MM-1A: Measuring Internet Access Networks Across Space and Time
  • 批准号:
    2319603
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $51.4万
  • 财政年份:
    2023
  • 负责人:
    Nicholas Feamster
  • 依托单位:
IMR: MT: A Community Platform for Controlled Experiments on Internet Access Networks
  • 批准号:
    2223610
  • 项目类别:
    Standard Grant
  • 资助金额:
    $60.0万
  • 财政年份:
    2022
  • 负责人:
    Nicholas Feamster
  • 依托单位:
Collaborative Research: CISE-ANR: CNS Core: Small: Modeling Modern Network Traffic: From Data Representation to Automated Machine Learning
  • 批准号:
    2124393
  • 项目类别:
    Standard Grant
  • 资助金额:
    $25.0万
  • 财政年份:
    2021
  • 负责人:
    Nicholas Feamster
  • 依托单位:
EAGER: SaTC-EDU: Training Mid-Career Security Professionals in Machine Learning and Data-Driven Cybersecurity
  • 批准号:
    2041970
  • 项目类别:
    Standard Grant
  • 资助金额:
    $29.99万
  • 财政年份:
    2020
  • 负责人:
    Nicholas Feamster
  • 依托单位:
国内基金
海外基金
胆固醇羟化酶CH25H非酶活依赖性促进乙型肝炎病毒蛋白Core及Pre-core降解的分子机制研究
  • 批准号:
    82371765
  • 项目类别:
    面上项目
  • 资助金额:
    50万元
  • 批准年份:
    2023
  • 负责人:
    谭广云
  • 依托单位:
锕系元素5f-in-core的GTH赝势和基组的开发
  • 批准号:
    22303037
  • 项目类别:
    青年科学基金项目
  • 资助金额:
    30万元
  • 批准年份:
    2023
  • 负责人:
    鲁俊波
  • 依托单位:
基于合成致死策略搭建Core-matched前药共组装体克服肿瘤耐药的机制研究
  • 批准号:
    --
  • 项目类别:
    --
  • 资助金额:
    52万元
  • 批准年份:
    2022
  • 负责人:
    孙丙军
  • 依托单位:
鼠伤寒沙门氏菌LPS core经由CD209/SphK1促进树突状细胞迁移加重炎症性肠病的机制研究
  • 批准号:
    --
  • 项目类别:
    青年科学基金项目
  • 资助金额:
    30万元
  • 批准年份:
    2022
  • 负责人:
    叶成林
  • 依托单位: