arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2608.29371cs.NI

谁解析你的DNS?测量解析器的不透明性并缩小可见性差距

Who Resolves Your DNS? Measuring Resolver Opacity and Closing the Visibility Gap

Kedar Thiagarajan, Fabian E. Bustamante

首次发表
浏览论文内容

中文总结 AI 辅助

该研究针对DNS解析无验证路径的架构性问题,通过RIPE Atlas测量发现解析器常跨组织国家,提出Resolver-Path方法,以低开销实现解析器路径的可验证披露与认证,填补DNS在司法问责上的可见性差距。

中文摘要 AI 辅助

DNS解析没有可验证的解析器路径概念。当ISP将解析外包给第三方提供商时,用户的查询可能在其不知情的情况下跨越组织和国家边界,且发起查询的客户端没有协议机制来了解哪些解析器处理了该查询、它们位于何处或由谁运营。我们认为这种不透明性是架构性差距而非部署意外,且报告的可验证解析器路径应是解析协议的首要目标。我们通过测量论证这一点,随后表明缩小该差距的成本很低。使用覆盖190个国家的RIPE Atlas,我们发现解析通常会离开客户端的组织和国家:在对不可归因观测采用保守的AS内处理方式下,39.8%的观测到的解析器链(16636条中的6622条)使用与客户端不同AS的前端;四分之一可地理定位的任播前端对在客户端所在国家之外进行解析;单个运营商Google Public DNS占这些境外案例的约三分之二。随后我们提出Resolver-Path,一种参与式解析器在转发查询时报告自身身份的方法。其基础层是协作带内披露,它承载解析器路径元数据,吞吐量、延迟和CPU成本接近中性。由于非参与式解析器可忽略或移除该选项,仅披露即可建立所报告跳数的可验证存在,而非隐藏跳数的不存在。认证验证所选响应所携带的协作断言的完整性、顺序和新鲜度。披露与认证共同提供关于所选响应所报告解析器链的有限证据——这是当前DNS缺乏的用于司法问责的基础。

英文摘要

DNS resolution has no notion of a verifiable resolver path. When an ISP outsources resolution to a third-party provider, a user's queries can cross organizational and national boundaries without their awareness---and the client that issued them has no protocol mechanism to learn which resolvers handled the query, where they sat, or who operated them. We argue that this opacity is an architectural gap rather than a deployment accident, and that a reported, verifiable resolver path should be a first-class goal of the resolution protocol. We motivate this with measurement and then show the gap is cheap to close. Using RIPE Atlas across 190 countries, we find that resolution routinely leaves the client's organization and country: under a conservative in-AS treatment of unattributable observations, 39.8% of observed resolver chains (6,622 of 16,636) use a frontend in a different AS than the client, one in four geolocatable anycast frontend pairs resolves outside the client's country, and a single operator---Google Public DNS---accounts for roughly two-thirds of those out-of-country cases. We then present Resolver-Path, an approach in which participating resolvers report their identity as they forward the query. Its base layer is cooperative in-band disclosure, it carries resolver-path metadata at near-neutral throughput, latency, and CPU cost. Because a non-participating resolver can ignore or strip the option, disclosure alone establishes the verifiable presence of reported hops, not the absence of hidden ones. Attestation authenticates the integrity, ordering, and freshness of the cooperative assertions carried by the selected response. Together, disclosure and attestation provide bounded evidence about the selected response's reported resolver chain---the substrate DNS currently lacks for jurisdictional accountability.

发表机构

  • Northwestern University(西北大学)

机构由 AI 辅助整理,请以论文原文为准。

↑