Local and Public DNS Resolvers: do you trade off performance against security?

Antonia Affinito, A. Botta, G. Ventre
{"title":"Local and Public DNS Resolvers: do you trade off performance against security?","authors":"Antonia Affinito, A. Botta, G. Ventre","doi":"10.23919/ifipnetworking55013.2022.9829756","DOIUrl":null,"url":null,"abstract":"The Domain Name System (DNS) is a vital component of the Internet, used for all the operations performed over the network and, recently, also for protecting users from malicious activities. In this work, we analyze the behavior of DNS resolvers provided by three main Italian ISPs and contrast them with open, public resolvers provided by Google and Cisco. We consider two aspects. The first one is the time spent to perform a query and obtain a response from the resolvers, which has a considerable impact on the performance of most applications on the Internet. The second one is the capability to recognize domains associated with malicious activities, blocking related requests to protect users. The DNS response time is generally shorter for local resolvers since they are closer to the users. On the other hand, public resolvers are typically considered more efficient in detecting malicious domains. We performed a large number of DNS queries towards the different resolvers, both local and public, using different sets of domain names and different Internet access networks from main Italian providers. Our results confirm that the response time of local resolvers is shorter than the public ones. However, they also show that, unexpectedly, the protection level of local resolvers is largely comparable with the one of public resolvers. Consequently, you do not have to trade off security against performance. In addition, we study the impact of DNS over HTTPs, we unveil the different mechanisms implemented to block users from accessing malicious domains and assess the impact of caching on the obtained results.","PeriodicalId":31737,"journal":{"name":"Edutech","volume":"13 1","pages":"1-9"},"PeriodicalIF":0.0000,"publicationDate":"2022-06-13","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"3","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Edutech","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.23919/ifipnetworking55013.2022.9829756","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 3

Abstract

The Domain Name System (DNS) is a vital component of the Internet, used for all the operations performed over the network and, recently, also for protecting users from malicious activities. In this work, we analyze the behavior of DNS resolvers provided by three main Italian ISPs and contrast them with open, public resolvers provided by Google and Cisco. We consider two aspects. The first one is the time spent to perform a query and obtain a response from the resolvers, which has a considerable impact on the performance of most applications on the Internet. The second one is the capability to recognize domains associated with malicious activities, blocking related requests to protect users. The DNS response time is generally shorter for local resolvers since they are closer to the users. On the other hand, public resolvers are typically considered more efficient in detecting malicious domains. We performed a large number of DNS queries towards the different resolvers, both local and public, using different sets of domain names and different Internet access networks from main Italian providers. Our results confirm that the response time of local resolvers is shorter than the public ones. However, they also show that, unexpectedly, the protection level of local resolvers is largely comparable with the one of public resolvers. Consequently, you do not have to trade off security against performance. In addition, we study the impact of DNS over HTTPs, we unveil the different mechanisms implemented to block users from accessing malicious domains and assess the impact of caching on the obtained results.
本地和公共DNS解析器:您会权衡性能和安全性吗?
域名系统(DNS)是互联网的一个重要组成部分,用于在网络上执行的所有操作,最近也用于保护用户免受恶意活动的侵害。在这项工作中,我们分析了三个主要意大利isp提供的DNS解析器的行为,并将它们与谷歌和Cisco提供的开放、公共解析器进行了对比。我们考虑两个方面。第一个是执行查询和从解析器获得响应所花费的时间,这对Internet上大多数应用程序的性能有相当大的影响。第二个是识别与恶意活动相关的域,阻止相关请求以保护用户的能力。本地解析器的DNS响应时间通常较短,因为它们离用户更近。另一方面,公共解析器通常被认为在检测恶意域方面更有效。我们对不同的解析器执行了大量的DNS查询,包括本地的和公共的,使用不同的域名集和来自意大利主要提供商的不同的互联网接入网络。结果表明,本地解析器的响应时间比公共解析器短。然而,它们也意外地表明,本地解析器的保护级别在很大程度上与公共解析器相当。因此,您不必在安全性和性能之间进行权衡。此外,我们还研究了DNS对HTTPs的影响,揭示了阻止用户访问恶意域名的不同机制,并评估了缓存对获得结果的影响。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
审稿时长
4 weeks
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信