ConfiDNS: leveraging scale and history to improve DNS security

  • Authors:
  • Lindsey Poole;Vivek S. Pai

  • Affiliations:
  • Princeton University;Princeton University

  • Venue:
  • WORLDS'06 Proceedings of the 3rd conference on USENIX Workshop on Real, Large Distributed Systems - Volume 3
  • Year:
  • 2006

Quantified Score

Hi-index 0.02

Visualization

Abstract

While cooperative DNS resolver systems, such as Co-DNS, have demonstrated improved reliability and performance over standard approaches, their security has been weaker, since any corruption or misbehavior of a single resolver can easily propagate throughout the system. We address this weakness in a new system called ConfiDNS, which augments the cooperative lookup process with configurable policies that utilize multi-site agreement and per-site lookup histories. Not only does ConfiDNS provide better security than cooperative approaches, but for up to 99.8% of unique lookups, ConfiDNS exceeds the security of standard DNS resolvers. ConfiDNS provides these benefits while retaining the other benefits of Co-DNS, such as incremental deployability, improved performance, and higher reliability.