skip to main content
10.1145/3517745.3563016acmconferencesArticle/Chapter ViewAbstractPublication PagesimcConference Proceedingsconference-collections
poster
Public Access

Observable KINDNS: validating DNS hygiene

Published:25 October 2022Publication History

ABSTRACT

The Internet's naming system (DNS) is a hierarchically structured database, with hundreds of millions of domains in a radically distributed management architecture. The distributed nature of the DNS is the primary factor that allowed it to scale to its current size, but it also brings security and stability risks. The Internet standards community (IETF) has published several operational best practices to improve DNS resilience, but operators must make their own decisions that tradeoff security, cost, and complexity. Since these decisions can impact the security of billions of Internet users, recently ICANN has proposed an initiative to codify best practices into a set of global norms to improve security: the Knowledge-Sharing and Instantiating Norms for DNS and Naming Security (KINDNS) [4]. A similar effort for routing security - Mutually Agreed Norms for Routing Security - provided inspiration for this effort. The MANRS program encourages operators to voluntarily commit to a set of practices that will improve collective routing security - a challenge when incentives to conform with these practices does not generate a clear return on investment for operators. One challenge for both initiatives is independent verification of conformance with the practices. The KINDNS conversation has just started, and stakeholders are still debating what should be in the set of practices. At this early stage, we analyze possible best practices in terms of their measurability by third parties, including a review of DNS measurement studies and available data sets (Table 1).

References

  1. G. Akiwate et al. 2020. Unresolved Issues: Prevalence, Persistence, and Perils of Lame Delegations (IMC '20).Google ScholarGoogle ScholarDigital LibraryDigital Library
  2. M. Allman. 2018. Comments on DNS Robustness (IMC '18).Google ScholarGoogle Scholar
  3. W.B. de Vries et al. 2019. A First Look at QNAME Minimization in the Domain Name System (PAM '19).Google ScholarGoogle Scholar
  4. ICANN. 2022. KINDNS. (2022). https://kindns.org/Google ScholarGoogle Scholar
  5. G.C.M. Moura et al. 2016. Anycast vs. DDoS: Evaluating the November 2015 Root DNS Event (IMC '16).Google ScholarGoogle Scholar
  6. G.C.M. Moura et al. 2018. When the Dike Breaks: Dissecting DNS Defenses During DDoS (IMC '18).Google ScholarGoogle ScholarDigital LibraryDigital Library
  7. Giovane C. M. Moura et al. 2019. Cache Me If You Can: Effects of DNS Time-to-Live (IMC '19).Google ScholarGoogle Scholar
  8. M. Muller et al. 2020. The Reality of Algorithm Agility: Studying the DNSSEC Algorithm Life-Cycle (IMC '20).Google ScholarGoogle ScholarDigital LibraryDigital Library
  9. R. Sommese et al. 2020. When parents and children disagree: Diving into DNS delegation inconsistency (IMC '20).Google ScholarGoogle Scholar
  10. R. Sommese et al. 2021. Characterization of Anycast Adoption in the DNS Authoritative Infrastructure (TMA '21).Google ScholarGoogle Scholar
  11. R. Yazdani et al. 2022. A Matter of Degree: Characterizing the Amplification Power of Open DNS Resolvers (PAM '22).Google ScholarGoogle Scholar

Index Terms

  1. Observable KINDNS: validating DNS hygiene

    Recommendations

    Comments

    Login options

    Check if you have access through your login credentials or your institution to get full access on this article.

    Sign in
    • Published in

      cover image ACM Conferences
      IMC '22: Proceedings of the 22nd ACM Internet Measurement Conference
      October 2022
      796 pages
      ISBN:9781450392594
      DOI:10.1145/3517745

      Copyright © 2022 Owner/Author

      Permission to make digital or hard copies of part or all of this work for personal or classroom use is granted without fee provided that copies are not made or distributed for profit or commercial advantage and that copies bear this notice and the full citation on the first page. Copyrights for third-party components of this work must be honored. For all other uses, contact the Owner/Author.

      Publisher

      Association for Computing Machinery

      New York, NY, United States

      Publication History

      • Published: 25 October 2022

      Check for updates

      Qualifiers

      • poster

      Acceptance Rates

      Overall Acceptance Rate277of1,083submissions,26%

      Upcoming Conference

      IMC '24
      ACM Internet Measurement Conference
      November 4 - 6, 2024
      Madrid , AA , Spain

    PDF Format

    View or Download as a PDF file.

    PDF

    eReader

    View online with eReader.

    eReader