Enhanced Performance and Privacy via Resolver-Less DNS

08/13/2019
by   Erik Sy, et al.
0

The domain name resolution into IP addresses can significantly delay connection establishments on the web. Moreover, the common use of recursive DNS resolvers presents a privacy risk as they can closely monitor the user's browsing activities. In this paper, we present a novel HTTP response header allowing web server to provide their clients with relevant DNS records. Our results indicate, that this resolver-less DNS mechanism allows user agents to save the DNS lookup time for subsequent connection establishments. We find, that this proposal saves at least 80ms per DNS lookup for the one percent of users having the longest round-trip times towards their recursive resolver. Furthermore, our proposal decreases the number of DNS lookups and thus improves the privacy posture of the user towards the used recursive resolver. Comparing the security guarantees of the traditional DNS to our proposal, we find that resolver-less DNS achieves at least the same security properties. In detail, it even improves the user's resilience against censorship through tampered DNS resolvers.

READ FULL TEXT
research
07/02/2019

Accelerating QUIC's Connection Establishment on High-Latency Access Networks

A significant amount of connection establishments on the web require a p...
research
05/09/2019

Enhanced Performance and Privacy for TLS over TCP Fast Open

Small TCP flows make up the majority of web flows. For them, the TCP thr...
research
11/04/2022

On the Interplay between TLS Certificates and QUIC Performance

In this paper, we revisit the performance of the QUIC connection setup a...
research
11/05/2021

Security Header Fields in HTTP Clients

HTTP headers are commonly used to establish web communications, and some...
research
03/22/2019

Surfing the Web quicker than QUIC via a shared Address Validation

QUIC is a performance-optimized secure transport protocol and a building...
research
04/12/2019

QUICker connection establishment with out-of-band validation tokens

QUIC is a secure transport protocol and aims to improve the performance ...
research
02/02/2022

Saving Brian's Privacy: the Perils of Privacy Exposure through Reverse DNS

Given the importance of privacy, many Internet protocols are nowadays de...

Please sign up or login with your details

Forgot password? Click here to reset