Proceedings of the Internet Measurement Conference 2019
DOI: 10.1145/3355369.3355580
|View full text |Cite
|
Sign up to set email alerts
|

An End-to-End, Large-Scale Measurement of DNS-over-Encryption

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
1
1
1

Citation Types

0
55
0

Year Published

2020
2020
2021
2021

Publication Types

Select...
5
1

Relationship

0
6

Authors

Journals

citations
Cited by 81 publications
(57 citation statements)
references
References 10 publications
0
55
0
Order By: Relevance
“…They find that despite higher response times, page load times for DoT and DoH can be faster than DNS on lossy networks. Lu et al utilized residential TCP SOCKS networks to measure response times from 166 countries and found that, in the median case with connection re-use, DoT and DoH were slower than conventional DNS over TCP by 9 ms and 6 ms, respectively [14].…”
Section: Related Workmentioning
confidence: 99%
See 1 more Smart Citation
“…They find that despite higher response times, page load times for DoT and DoH can be faster than DNS on lossy networks. Lu et al utilized residential TCP SOCKS networks to measure response times from 166 countries and found that, in the median case with connection re-use, DoT and DoH were slower than conventional DNS over TCP by 9 ms and 6 ms, respectively [14].…”
Section: Related Workmentioning
confidence: 99%
“…Past work has shown that typical DoT and DoH query response times are typically marginally slower than DNS [3,9,14]. However, these measurements were performed from university networks, proxy networks, and cloud data centers, rather than directly from homes.…”
Section: Introductionmentioning
confidence: 99%
“…Moura et al [71] shows that 30% of the DNS queries to their studied '.nz' and '.nl' country code Top Level Domains (ccTLDs) are generated by the recursive resolvers, which resided in 5 top cloud providers. Lu et al [63] also found an increasing pattern in using DoT and DoH with public resolvers. As such, public recursive resolvers, which are neither in the clients' local networks nor their ISPs, form a significant portion of DNS queries over the Internet.…”
Section: Stage-1mentioning
confidence: 90%
“…DoT is a relatively new DNS scheme, which has been deployed by large public DNS resolvers (e.g., Google, 1 Cloudflare, and Comcast [32]). Previous research [63] showed that the number of DoT clients was increasing during their research period. Transferring DNS messages over secure TLS sessions adds new TLS-related vulnerabilities to the DNS ecosystem.…”
Section: Problem Statementmentioning
confidence: 98%
See 1 more Smart Citation