Measurement for encrypted open resolvers: Applications and security

分解器 加密 计算机科学 计算机安全 电信 炸薯条
作者
Meng Luo,Yepeng Yao,Liling Xin,Zhengwei Jiang,Qiuyun Wang,Wenchang Shi
出处
期刊:Computer Networks [Elsevier BV]
卷期号:213: 109081-109081 被引量:1
标识
DOI:10.1016/j.comnet.2022.109081
摘要

Encrypted DNS has been proposed to mitigate the vulnerability of traditional DNS to surveillance and tampering. Some encrypted DNS protocols, like DNS over HTTPS (DoH) and DNS over TLS (DoT), have been promoted by the community and supported by the industry. However, although encrypted DNS are proposed to protect users’ privacy and security, the security of their application in practice is still unknown. In this study, we focus on DoH and DoT to study the application and security of encrypted DNS from the perspective of open resolvers. We first propose a novel encrypted open resolvers discovery method. It enables us to implement a comprehensive discovery of encrypted open resolvers across the IPv4 network. Furthermore, we conduct security measurements on encrypted open resolvers for the recursive and iterative resolution they perform. In our measurements, we conduct the most comprehensive discovery to date and detect 5.7k open DoH resolvers and 9.6k open DoT resolvers in the IPv4 network. Moreover, we have observed several security issues of the encrypted open resolvers. For example, we find 10.2% of the open DoH resolvers and 60.7% of the open DoT resolvers use invalid certificates; 19.2% of the DNSSEC-supporting open DoH resolvers do not actually implement DNSSEC validation in resolution, including those from famous providers Facebook and Alidns. Our research reveals pervasive misconfigurations of the encrypted open resolvers in the wild. We recommend that resolver administrators need carefully check and maintain the DNS security configurations on their encrypted resolvers.
最长约 10秒,即可获得该文献文件

科研通智能强力驱动
Strongly Powered by AbleSci AI
科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
1秒前
keyan完成签到 ,获得积分10
3秒前
3秒前
123发布了新的文献求助10
3秒前
杨凡华完成签到,获得积分10
4秒前
5秒前
科研通AI5应助xiaoruan采纳,获得10
6秒前
7秒前
7秒前
思源应助yy123采纳,获得10
7秒前
大头完成签到,获得积分10
7秒前
evvj发布了新的文献求助10
8秒前
8秒前
8秒前
9秒前
科研通AI2S应助开鑫采纳,获得10
9秒前
mm完成签到,获得积分10
9秒前
无助的人完成签到,获得积分10
9秒前
CGTappear发布了新的文献求助10
12秒前
明明发布了新的文献求助10
13秒前
精明人达发布了新的文献求助10
13秒前
77最可爱发布了新的文献求助10
13秒前
未央歌完成签到 ,获得积分10
16秒前
CodeCraft应助一一一采纳,获得10
17秒前
17秒前
精明人达完成签到,获得积分10
18秒前
18秒前
天天快乐应助明明采纳,获得10
19秒前
3189完成签到 ,获得积分10
20秒前
22秒前
TZMY完成签到,获得积分10
22秒前
啦啦发布了新的文献求助10
22秒前
夏天发布了新的文献求助10
23秒前
开鑫发布了新的文献求助10
23秒前
阮楷瑞发布了新的文献求助10
25秒前
shen完成签到 ,获得积分10
25秒前
繁荣的戾完成签到,获得积分10
27秒前
27秒前
MOBIUS完成签到 ,获得积分10
27秒前
27秒前
高分求助中
All the Birds of the World 4000
Production Logging: Theoretical and Interpretive Elements 3000
Les Mantodea de Guyane Insecta, Polyneoptera 2000
Am Rande der Geschichte : mein Leben in China / Ruth Weiss 1500
CENTRAL BOOKS: A BRIEF HISTORY 1939 TO 1999 by Dave Cope 1000
Machine Learning Methods in Geoscience 1000
Resilience of a Nation: A History of the Military in Rwanda 888
热门求助领域 (近24小时)
化学 材料科学 医学 生物 工程类 有机化学 物理 生物化学 纳米技术 计算机科学 化学工程 内科学 复合材料 物理化学 电极 遗传学 量子力学 基因 冶金 催化作用
热门帖子
关注 科研通微信公众号,转发送积分 3738248
求助须知:如何正确求助?哪些是违规求助? 3281724
关于积分的说明 10026477
捐赠科研通 2998622
什么是DOI,文献DOI怎么找? 1645291
邀请新用户注册赠送积分活动 782740
科研通“疑难数据库(出版商)”最低求助积分说明 749891