A Formal Framework for End-to-End DNS Resolution
Si Liu, Huayi Duan, Lukas Heimes, Marco Bearzi, Jodok Vieli, David A. Basin, Adrian Perrig
Abstract
Despite the central importance of DNS, numerous attacks and vulnerabilities are regularly discovered. The root of the problem is the ambiguity and tremendous complexity of DNS protocol specifications, amid a rapidly evolving Internet infrastructure. To counteract the vicious break-and-fix cycle for improving DNS infrastructure, we instigate a foundational approach: we construct the first formal semantics of end-to-end name resolution, a collection of components for the formal analyses of both qualitative and quantitative properties, and an automated tool for discovering DoS attacks. Our formal framework represents an important step towards a substantially more secure and reliable DNS infrastructure.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 5f045df3-d0b5-4115-b448-4fee94c72680Cited by top-tier papers8
- Reachability Analysis of the Domain Name SystemDhruv Nevatia, Si Liu, David A. BasinPOPL 2025 · 2 citations
- A Flushing Attack on the DNS CacheYehuda Afek, Anat Bremler-Barr, Shoham Danino, Yuval ShavittUSENIX Security 2024 · 2 citations
- DNS Congestion Control in Adversarial SettingsHuayi Duan, Jihye Kim, Marc Wyss, Adrian PerrigSOSP 2024 · 2 citations
- Topaz: Declarative and Verifiable Authoritative DNS at CDN-ScaleJames Larisch, Timothy Alberdingk Thijm, Suleman Ahmad, Peter Wu et al.SIGCOMM 2024 · 1 citation
- Resolve the Unresolved: Systematic Work Profiling for DNS ResolversLiwen Xu, Huayi Duan, Zechao Cai, Adrian PerrigS&P 2026
Builds on5
- GRooT: Proactive Verification of DNS ConfigurationsSiva Kesava Reddy Kakarla, Ryan Beckett, Behnaz Arzani, Todd D. Millstein et al.SIGCOMM 2020 · 24 citations
- Bridging the semantic gap between qualitative and quantitative models of distributed systemsSi Liu, José Meseguer, Peter Csaba Ölveczky, Min Zhang et al.OOPSLA 2022 · 16 citations
- RHINE: Robust and High-performance Internet Naming with E2E AuthenticityHuayi Duan, Rubén Fischer, Jie Lou, Si Liu et al.NSDI 2023 · 12 citations
- NXNSAttack: Recursive DNS Inefficiencies and VulnerabilitiesYehuda Afek, Anat Bremler-Barr, Lior ShafirUSENIX Security 2020
- SCALE: Automatically Finding RFC Compliance Bugs in DNS NameserversSiva Kesava Reddy Kakarla, Ryan Beckett, Todd D. Millstein, George VargheseNSDI 2022
Related papers
- CAMP: Compositional Amplification Attacks against DNSHuayi Duan, Marco Bearzi, Jodok Vieli, David A. Basin et al.USENIX Security 2024 · 9 citations
- Knocking on the Front Door: An LLM-Guided Systematic Analysis of DNS Query Processing VulnerabilitiesYuqi Qiu, Xiang Li, Zheli LiuS&P 2026
- DaLens: Charting DNS Self-Amplification Threats at LargeLiwen Xu, Zechao Cai, Huayi Duan, Adrian PerrigUSENIX Security 2026
- One Char to Rule Them All: Systematically Exploring and Exploiting DNS Silent Vulnerabilities in Domain Name ResolutionFasheng Miao, Xiang Li, Changqing An, Wenbin Xu et al.S&P 2026
- ResolverFuzz: Automated Discovery of DNS Resolver Vulnerabilities with Query-Response FuzzingQifan Zhang, Xuesong Bai, Xiang Li, Haixin Duan et al.USENIX Security 2024 · 13 citations
