An End-to-End, Large-Scale Measurement of DNS-over-Encryption: How Far Have We Come?

被引:50
|
作者
Lu, Chaoyi [1 ,2 ,7 ]
Liu, Baojun [3 ]
Li, Zhou [4 ]
Hao, Shuang [5 ]
Duan, Haixin [1 ,2 ,6 ]
Zhang, Mingming [1 ]
Leng, Chunying [1 ]
Liu, Ying [1 ]
Zhang, Zaifeng [7 ]
Wu, Jianping [1 ]
机构
[1] Tsinghua Univ, Inst Network Sci & Cyberspace, Beijing, Peoples R China
[2] Tsinghua Univ, Beijing Natl Res Ctr Informat Sci & Technol BNRis, Beijing, Peoples R China
[3] Tsinghua Univ, Dept Comp Sci & Technol, Beijing, Peoples R China
[4] Univ Calif Irvine, Irvine, CA 92717 USA
[5] Univ Texas Dallas, Richardson, TX 75083 USA
[6] Qi An Xin Technol Res Inst, Beijing, Peoples R China
[7] 360 Netlab, Beijing, Peoples R China
基金
国家重点研发计划;
关键词
Domane Name System; DNS Privacy; DNS-over-TLS; DNS-over-HTTPS; DNS Measurement;
D O I
10.1145/3355369.3355580
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
DNS packets are designed to travel in unencrypted form through the Internet based on its initial standard. Recent discoveries show that real-world adversaries are actively exploiting this design vulnerability to compromise Internet users' security and privacy. To mitigate such threats, several protocols have been proposed to encrypt DNS queries between DNS clients and servers, which we jointly term as DNS-over-Encryption. While some proposals have been standardized and are gaining strong support from the industry, little has been done to understand their status from the view of global users. This paper performs by far the first end-to-end and large-scale analysis on DNS-over-Encryption. By collecting data from Internet scanning, user-end measurement and passive monitoring logs, we have gained several unique insights. In general, the service quality of DNS-over-Encryption is satisfying, in terms of accessibility and latency. For DNS clients, DNS-over-Encryption queries are less likely to be disrupted by in-path interception compared to traditional DNS, and the extra overhead is tolerable. However, we also discover several issues regarding how the services are operated. As an example, we find 25% DNS-over-TLS service providers use invalid SSL certificates. Compared to traditional DNS, DNS-over-Encryption is used by far fewer users but we have witnessed a growing trend. As such, we believe the community should push broader adoption of DNS-over-Encryption and we also suggest the service providers carefully review their implementations.
引用
收藏
页码:22 / 35
页数:14
相关论文
共 50 条
  • [1] A large-scale, passive analysis of end-to-end TCP performance over GPRS
    Benko, P
    Malicsko, G
    Veres, A
    [J]. IEEE INFOCOM 2004: THE CONFERENCE ON COMPUTER COMMUNICATIONS, VOLS 1-4, PROCEEDINGS, 2004, : 1882 - 1892
  • [2] END-TO-END APPROACH TO LARGE-SCALE MULTIMEDIA DISSEMINATION
    YAVATKAR, R
    MANOJ, L
    [J]. COMPUTER COMMUNICATIONS, 1994, 17 (03) : 205 - 217
  • [3] Conversational recommendation based on end-to-end learning: How far are we?
    Manzoor, Ahtsham
    Jannach, Dietmar
    [J]. COMPUTERS IN HUMAN BEHAVIOR REPORTS, 2021, 4
  • [4] A large-scale dataset for end-to-end table recognition in the wild
    Fan Yang
    Lei Hu
    Xinwu Liu
    Shuangping Huang
    Zhenghui Gu
    [J]. Scientific Data, 10
  • [5] An end-to-end workflow pipeline for large-scale Grid computing
    McGough A.S.
    Cohen J.
    Darlington J.
    Katsiri E.
    Lee W.
    Panagiotidi S.
    Patel Y.
    [J]. Journal of Grid Computing, 2005, 3 (3-4) : 259 - 281
  • [6] SCALING END-TO-END MODELS FOR LARGE-SCALE MULTILINGUAL ASR
    Li, Bo
    Pang, Ruoming
    Sainath, Tara N.
    Gulati, Anmol
    Zhang, Yu
    Qin, James
    Haghani, Parisa
    Huang, W. Ronny
    Ma, Min
    Bai, Junwen
    [J]. 2021 IEEE AUTOMATIC SPEECH RECOGNITION AND UNDERSTANDING WORKSHOP (ASRU), 2021, : 1011 - 1018
  • [7] A large-scale dataset for end-to-end table recognition in the wild
    Yang, Fan
    Hu, Lei
    Liu, Xinwu
    Huang, Shuangping
    Gu, Zhenghui
    [J]. SCIENTIFIC DATA, 2023, 10 (01)
  • [8] Learning an End-to-End Structure for Retrieval in Large-Scale Recommendations
    Gao, Weihao
    Fan, Xiangjun
    Wang, Chong
    Sun, Jiankai
    Jia, Kai
    Xiao, Wenzhi
    Ding, Ruofan
    Bin, Xingyan
    Yang, Hui
    Liu, Xiaobing
    [J]. PROCEEDINGS OF THE 30TH ACM INTERNATIONAL CONFERENCE ON INFORMATION & KNOWLEDGE MANAGEMENT, CIKM 2021, 2021, : 524 - 533
  • [9] Large-Scale Streaming End-to-End Speech Translation with Neural Transducers
    Xue, Jian
    Wang, Peidong
    Li, Jinyu
    Post, Matt
    Gaur, Yashesh
    [J]. INTERSPEECH 2022, 2022, : 3263 - 3267
  • [10] End-to-End Feasible Optimization Proxies for Large-Scale Economic Dispatch
    Chen, Wenbo
    Tanneau, Mathieu
    Van Hentenryck, Pascal
    [J]. IEEE TRANSACTIONS ON POWER SYSTEMS, 2024, 39 (02) : 4723 - 4734