论文标题

测量公共加密DNS解析器的可用性和响应时间

Measuring the Availability and Response Times of Public Encrypted DNS Resolvers

论文作者

Sharma, Ranya, Feamster, Nick, Hounsel, Austin

论文摘要

用户和DNS解析器之间的未加密DNS流量可能会导致隐私和安全问题。为了应对这些隐私风险,许多浏览器供应商已部署了DNS-Over-HTTPS(DOH)来加密用户和DNS解析器之间的查询。如今,尽管在实践中部署了更多加密的DNS解析器,但许多客户端部署DOH,尤其是在浏览器中,仅在几个解析器之间进行选择。不幸的是,如果用户只有几个选择加密解析器的选择,并且只有少数从任何特定的有利位置表现出色,则部署了DOH的隐私问题来帮助解决不同的第三方。因此,重要的是要评估更加密的DNS解析器的性能特征,以确定在实践中倾向于使用加密的DNS解析器使用者有多少选项。在本文中,我们通过测量北美,欧洲和亚洲的全球有利位置的DNS查询响应时间来探讨了支持DOH的大量加密DNS解析器的性能。我们的结果表明,许多非主流解析器的响应时间比主流解析器更高,尤其是对于从更遥远的有利位置查询的非主流解析器而言,这表明大多数加密的DNS解析器都不复制或任何cast。但是,在某些情况下,某些非主流解析器至少和主流解析器一样,表明用户可能能够使用比当前浏览器配置中可用于的更广泛的加密DNS解析器。

Unencrypted DNS traffic between users and DNS resolvers can lead to privacy and security concerns. In response to these privacy risks, many browser vendors have deployed DNS-over-HTTPS (DoH) to encrypt queries between users and DNS resolvers. Today, many client-side deployments of DoH, particularly in browsers, select between only a few resolvers, despite the fact that many more encrypted DNS resolvers are deployed in practice. Unfortunately, if users only have a few choices of encrypted resolver, and only a few perform well from any particular vantage point, then the privacy problems that DoH was deployed to help address merely shift to a different set of third parties. It is thus important to assess the performance characteristics of more encrypted DNS resolvers, to determine how many options for encrypted DNS resolvers users tend to have in practice. In this paper, we explore the performance of a large group of encrypted DNS resolvers supporting DoH by measuring DNS query response times from global vantage points in North America, Europe, and Asia. Our results show that many non-mainstream resolvers have higher response times than mainstream resolvers, particularly for non-mainstream resolvers that are queried from more distant vantage points -- suggesting that most encrypted DNS resolvers are not replicated or anycast. In some cases, however, certain non-mainstream resolvers perform at least as well as mainstream resolvers, suggesting that users may be able to use a broader set of encrypted DNS resolvers than those that are available in current browser configurations.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源