论文标题
一个统治他们的人吗?首次查看Quic的DNS
One to Rule them All? A First Look at DNS over QUIC
论文作者
论文摘要
DNS是互联网最关键的部分之一。由于原始DNS规格将UDP和TCP定义为基础传输协议,因此DNS查询本质上没有加密,使其容易受到窃听和路径操作的影响。因此,近年来,人们对DNS隐私的关注引起了人们的关注,这导致引入了https(doh)上的TLS(DOT)和DNS上的加密协议DNS。尽管这些协议解决了向DNS添加隐私的关键问题,但它们固有地受其基本运输协议的限制,这些协议与IP碎片或多RTT握手的纠纷 - 与Quic所满足的挑战。因此,最近在QUIC(DOQ)上添加DNS有望改善已建立的DNS协议。但是,没有研究重点是DOQ,其采用或其响应时间到这个日期 - 我们与研究的差距。我们的主动测量结果表明,DOQ的采用缓慢但稳定地增加了,并揭示了一周间的高度波动,这反映了正在进行的发展过程:因为DOQ仍处于标准化,实施和服务的快速变化中。分析DOQ的响应时间,我们发现大约40%的测量结果显示出比预期的要高得多的握手时间,尽管成功验证了客户的地址,但仍可以追溯到交通扩增限制的执行。但是,DOQ已经优于DOT和DOH,这使其成为迄今为止加密DNS的最佳选择。
The DNS is one of the most crucial parts of the Internet. Since the original DNS specifications defined UDP and TCP as the underlying transport protocols, DNS queries are inherently unencrypted, making them vulnerable to eavesdropping and on-path manipulations. Consequently, concerns about DNS privacy have gained attention in recent years, which resulted in the introduction of the encrypted protocols DNS over TLS (DoT) and DNS over HTTPS (DoH). Although these protocols address the key issues of adding privacy to the DNS, they are inherently restrained by their underlying transport protocols, which are at strife with, e.g., IP fragmentation or multi-RTT handshakes - challenges which are addressed by QUIC. As such, the recent addition of DNS over QUIC (DoQ) promises to improve upon the established DNS protocols. However, no studies focusing on DoQ, its adoption, or its response times exist to this date - a gap we close with our study. Our active measurements show a slowly but steadily increasing adoption of DoQ and reveal a high week-over-week fluctuation, which reflects the ongoing development process: As DoQ is still in standardization, implementations and services undergo rapid changes. Analyzing the response times of DoQ, we find that roughly 40% of measurements show considerably higher handshake times than expected, which traces back to the enforcement of the traffic amplification limit despite successful validation of the client's address. However, DoQ already outperforms DoT as well as DoH, which makes it the best choice for encrypted DNS to date.