Resolve the Unresolved: Systematic Work Profiling for DNS Resolvers
Liwen Xu, Huayi Duan, Zechao Cai, Adrian Perrig
Abstract
The DNS standards mandate that recursive resolvers should bound the amount of work they perform per query. Yet, for nearly four decades, the specifications have offered little concrete guidance on how to enforce such limits, largely because of the system's daunting and growing complexity. This ambiguity has led to divergent implementations, recurring performance bugs, and above all, constant discoveries of denial-of-service (DoS) vectors. Prior research has inspected only fragments of a resolver's behavior, mostly using informal methods, while existing mitigations hinge on heuristic thresholds that lack broadly accepted guidance. As a result, both the issues uncovered and the fixes deployed remain narrow in scope. We address this gap by modeling recursive resolution as an Extended Transition System (ETS) with cost annotations and formulating the computation of maximum per-query work as a constrained longest path search problem with provable guarantees. Building on this formalism, we introduce rProfiler, a systematic profiling framework for measuring and modeling the work performed by DNS resolvers. Applying rProfiler against widely used resolvers exposes severe DoS vectors: issuing only 30 work-intensive queries per second cuts these resolvers' performance by at least 67%-and in some cases, renders them completely unresponsive. Diagnosing resolvers with rProfiler also yields actionable insights to improve their robustness against DoS attacks and subtle performance bugs.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Builds on13
- Global Measurement of DNS ManipulationPaul Pearce, Ben Jones, Frank Li, Roya Ensafi et al.USENIX Security 2017 · 163 citations
- GRooT: Proactive Verification of DNS ConfigurationsSiva Kesava Reddy Kakarla, Ryan Beckett, Behnaz Arzani, Todd D. Millstein et al.SIGCOMM 2020 · 24 citations
- TuDoor Attack: Systematically Exploring and Exploiting Logic Vulnerabilities in DNS Response Pre-processing with Malformed PacketsXiang Li, Wei Xu, Baojun Liu, Mingming Zhang et al.S&P 2024 · 20 citations
- ResolverFuzz: Automated Discovery of DNS Resolver Vulnerabilities with Query-Response FuzzingQifan Zhang, Xuesong Bai, Xiang Li, Haixin Duan et al.USENIX Security 2024 · 13 citations
- A Formal Framework for End-to-End DNS ResolutionSi Liu, Huayi Duan, Lukas Heimes, Marco Bearzi et al.SIGCOMM 2023 · 11 citations
Related papers
- Your Shield is My Sword: A Persistent Denial-of-Service Attack via the Reuse of Unvalidated Caches in DNSSEC ValidationShuhan Zhang, Shuai Wang, Li Chen, Dan Li et al.USENIX Security 2025
- NRDelegationAttack: Complexity DDoS attack on DNS Recursive ResolversYehuda Afek, Anat Bremler-Barr, Shani StajnrodUSENIX Security 2023
- DNSBomb: A New Practical-and-Powerful Pulsing DoS Attack Exploiting DNS Queries-and-ResponsesXiang Li, Dashuai Wu, Haixin Duan, Qi LiS&P 2024 · 14 citations
- DNS Congestion Control in Adversarial SettingsHuayi Duan, Jihye Kim, Marc Wyss, Adrian PerrigSOSP 2024 · 2 citations
- DaLens: Charting DNS Self-Amplification Threats at LargeLiwen Xu, Zechao Cai, Huayi Duan, Adrian PerrigUSENIX Security 2026
