D-DNS: Towards Re-Decentralizing the DNS

02/20/2020
by   Austin Hounsel, et al.
0

Nearly all Internet services rely on the Domain Name System (DNS) to resolve human-readable names to IP addresses. However, the content of DNS queries and responses can reveal private information, from the websites that a user visits to the types of devices on a network. Industry and researchers have responded in recent years to the inherent privacy risks of DNS information, focusing on tunneling DNS traffic over encrypted transport and application protocols. One such mechanism, DNS-over-HTTPS (DoH) places DNS functionality directly in the web browser itself to direct DNS queries to a trusted recursive resolver (resolver) over encrypted HTTPS connections. The DoH architecture solves privacy risks (e.g., eavesdropping) but introduces new concerns, including those associated with the centralization of DNS queries to the operator of a single recursive resolver that is selected by the browser vendor. It also introduces potential performance problems: if a client's resolver is not proximal to the content delivery network that ultimately serves the content, the CDN may fail to optimally localize the client. In this paper, we revisit the trend towards centralized DNS and explore re-decentralizing the critical Internet protocol, such that clients might leverage multiple DNS resolvers when resolving domain names and retrieving content. We propose and evaluate several candidate decentralized architectures, laying the groundwork for future research to explore decentralized, encrypted DNS architectures that strike a balance between privacy and performance.

READ FULL TEXT
research
06/01/2018

Oblivious DNS: Practical Privacy for DNS Queries

Every Internet communication typically involves a Domain Name System (DN...
research
11/19/2020

Oblivious DNS over HTTPS (ODoH): A Practical Privacy Enhancement to DNS

The Domain Name System (DNS) is the foundation of a human-usable Interne...
research
07/18/2019

Analyzing the Costs (and Benefits) of DNS, DoT, and DoH for the Modern Web

Essentially all Internet communication relies on the Domain Name System ...
research
02/26/2023

Reclaiming Privacy and Performance over Centralized DNS

The Domain Name System (DNS) is both a key determinant of users' quality...
research
02/07/2022

One to Rule them All? A First Look at DNS over QUIC

The DNS is one of the most crucial parts of the Internet. Since the orig...
research
08/09/2022

Measuring the Availability and Response Times of Public Encrypted DNS Resolvers

Unencrypted DNS traffic between users and DNS resolvers can lead to priv...
research
08/09/2022

Understanding User Awareness and Behaviors Concerning Encrypted DNS Settings

Recent developments to encrypt the Domain Name System (DNS) have resulte...

Please sign up or login with your details

Forgot password? Click here to reset