{"title":"理解顶级域和DNSSEC的演进和采用","authors":"Yo-Der Song, Aniket Mahanti, Soorya Charan Ravichandran","doi":"10.1109/IWMN.2019.8805011","DOIUrl":null,"url":null,"abstract":"The Domain Name System (DNS) is a hierarchical distributed database that serves as the directory of the Internet by mapping fully qualified domain names to IP addresses. The top level domain (TLD) is the highest level in the DNS hierarchy and until 2012, there had only been 22 of these domains for generic uses (gTLD). ICANN's New gTLD Program has since opened up the domain names to public registration, leading to the creation of thousands of new gTLDs over the last six years. The rapid increase in the number of gTLDs give registrants a wider choice of domain names but it also offers malicious actors more opportunities of attacks. By mirroring the DNS hierarchy, DNSSEC authenticates DNS responses and prevents modified or forged DNS records. We present a longitudinal analysis on the adoption of the new gTLDs and deployment of DNSSEC using data from a large campus network and a national-level authoritative name server. Although the popularity of new gTLDs is rapidly growing across a large number of domains, we find the proportion of queries to new gTLDs overall to remain very low. None of the top-10 queried TLDs were new gTLDs. We find DNSSEC deployment at the national level to be improving but still weaker than global averages. Efforts need to be made to ensure correct DS records are uploaded to the registry to complete the DNSSEC chain of trust.","PeriodicalId":272577,"journal":{"name":"2019 IEEE International Symposium on Measurements & Networking (M&N)","volume":"93 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2019-07-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"8","resultStr":"{\"title\":\"Understanding Evolution and Adoption of Top Level Domains and DNSSEC\",\"authors\":\"Yo-Der Song, Aniket Mahanti, Soorya Charan Ravichandran\",\"doi\":\"10.1109/IWMN.2019.8805011\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"The Domain Name System (DNS) is a hierarchical distributed database that serves as the directory of the Internet by mapping fully qualified domain names to IP addresses. The top level domain (TLD) is the highest level in the DNS hierarchy and until 2012, there had only been 22 of these domains for generic uses (gTLD). ICANN's New gTLD Program has since opened up the domain names to public registration, leading to the creation of thousands of new gTLDs over the last six years. The rapid increase in the number of gTLDs give registrants a wider choice of domain names but it also offers malicious actors more opportunities of attacks. By mirroring the DNS hierarchy, DNSSEC authenticates DNS responses and prevents modified or forged DNS records. We present a longitudinal analysis on the adoption of the new gTLDs and deployment of DNSSEC using data from a large campus network and a national-level authoritative name server. Although the popularity of new gTLDs is rapidly growing across a large number of domains, we find the proportion of queries to new gTLDs overall to remain very low. None of the top-10 queried TLDs were new gTLDs. We find DNSSEC deployment at the national level to be improving but still weaker than global averages. Efforts need to be made to ensure correct DS records are uploaded to the registry to complete the DNSSEC chain of trust.\",\"PeriodicalId\":272577,\"journal\":{\"name\":\"2019 IEEE International Symposium on Measurements & Networking (M&N)\",\"volume\":\"93 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2019-07-01\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"8\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2019 IEEE International Symposium on Measurements & Networking (M&N)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/IWMN.2019.8805011\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2019 IEEE International Symposium on Measurements & Networking (M&N)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/IWMN.2019.8805011","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 8
摘要
域名系统DNS (Domain Name System)是一种层次化的分布式数据库,通过将完全限定的域名映射到IP地址,充当互联网的目录。顶级域名(TLD)是DNS层次结构中的最高级别,直到2012年,只有22个通用域名(gTLD)。此后,ICANN的新通用顶级域名项目向公众开放了域名注册,导致在过去六年中创建了数千个新通用顶级域名。通用顶级域名数量的快速增长为注册人提供了更广泛的域名选择,但也为恶意行为者提供了更多的攻击机会。DNSSEC通过镜像DNS结构,对DNS响应进行认证,防止DNS记录被篡改或伪造。本文利用来自大型校园网和国家级权威域名服务器的数据,对新通用顶级域名的采用和DNSSEC的部署进行了纵向分析。尽管新通用顶级域的受欢迎程度在大量域名中迅速增长,但我们发现对新通用顶级域的总体查询比例仍然很低。被查询的前10个顶级域名中没有一个是新顶级域名。我们发现,国家层面的DNSSEC部署正在改善,但仍低于全球平均水平。需要努力确保将正确的DS记录上传到注册表,以完成DNSSEC信任链。
Understanding Evolution and Adoption of Top Level Domains and DNSSEC
The Domain Name System (DNS) is a hierarchical distributed database that serves as the directory of the Internet by mapping fully qualified domain names to IP addresses. The top level domain (TLD) is the highest level in the DNS hierarchy and until 2012, there had only been 22 of these domains for generic uses (gTLD). ICANN's New gTLD Program has since opened up the domain names to public registration, leading to the creation of thousands of new gTLDs over the last six years. The rapid increase in the number of gTLDs give registrants a wider choice of domain names but it also offers malicious actors more opportunities of attacks. By mirroring the DNS hierarchy, DNSSEC authenticates DNS responses and prevents modified or forged DNS records. We present a longitudinal analysis on the adoption of the new gTLDs and deployment of DNSSEC using data from a large campus network and a national-level authoritative name server. Although the popularity of new gTLDs is rapidly growing across a large number of domains, we find the proportion of queries to new gTLDs overall to remain very low. None of the top-10 queried TLDs were new gTLDs. We find DNSSEC deployment at the national level to be improving but still weaker than global averages. Efforts need to be made to ensure correct DS records are uploaded to the registry to complete the DNSSEC chain of trust.