The ties that un-bind: decoupling IP from web services and sockets for robust addressing agility at CDN-scale
Marwan Fayed, Lorenz Bauer, Vasileios Giotsas, Sami Kerola, Marek Majkowski, Pavel Odintsov, Jakub Sitnicki, Taejoong Chung, Dave Levin, Alan Mislove, Christopher A. Wood, Nick Sullivan
Abstract
The couplings between IP addresses, names of content or services, and socket interfaces, are too tight. This impedes system manageability, growth, and overall provisioning. In turn, large-scale content providers are forced to use staggering numbers of addresses, ultimately leading to address exhaustion (IPv4) and inefficiency (IPv6).
In this paper, we revisit IP bindings, entirely. We attempt to evolve addressing conventions by decoupling IP in DNS and from network sockets. Alongside technologies such as SNI and ECMP, a new architecture emerges that "unbinds" IP from services and servers, thereby returning IP's role to merely that of reachability. The architecture is under evaluation at a major CDN in multiple datacenters. We show that addresses can be generated randomly per-query, for 20M+ domains and services, from as few as ∼4K addresses, 256 addresses, and even one IP address. We explain why this approach is transparent to routing, L4/L7 load-balancers, distributed caching, and all surrounding systems -and is highly desirable. Our experience suggests that many network-oriented systems and services (e.g., route leak mitigation, denial of service, measurement) could be improved, and new ones designed, if built with addressing agility.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers5
- Seven years in the life of Hypergiants' off-netsPetros Gigis, Matt Calder, Lefteris Manassakis, George Nomikos et al.SIGCOMM 2021 · 68 citations
- Anycast In context: a tale of two systemsThomas Koch, Ethan Katz-Bassett, John S. Heidemann, Matt Calder et al.SIGCOMM 2021 · 39 citations
- NetShuffle: Circumventing Censorship with Shuffle Proxies at the EdgePatrick Tser Jern Kon, Aniket Gattani, Dhiraj Saharia, Tianyu Cao et al.S&P 2024 · 6 citations
- Hermes: Enhancing Layer-7 Cloud Load Balancers with Userspace-Directed I/O Event NotificationTian Pan, Enge Song, Yueshang Zuo, Shaokai Zhang et al.SIGCOMM 2025 · 5 citations
- Topaz: Declarative and Verifiable Authoritative DNS at CDN-ScaleJames Larisch, Timothy Alberdingk Thijm, Suleman Ahmad, Peter Wu et al.SIGCOMM 2024 · 1 citation
Builds on3
- CRLite: A Scalable System for Pushing All TLS Revocations to All BrowsersJames Larisch, David R. Choffnes, Dave Levin, Bruce M. Maggs et al.S&P 2017 · 105 citations
- Akamai DNS: Providing Authoritative Answers to the World's QueriesKyle Schomp, Onkar Bhardwaj, Eymen Kurdoglu, Mashooq Muhaimen et al.SIGCOMM 2020 · 38 citations
- Zero Downtime Release: Disruption-free Load Balancing of a Multi-Billion User WebsiteUsama Naseer, Luca Niccolini, Udip Pant, Alan Frindell et al.SIGCOMM 2020 · 19 citations
Related papers
- Reliable and Decentralized Certificate Revocation via DNS: The Case for RevDNSTaejoong Chung, Dave Levin, Protick BhowmickSIGCOMM 2025 · 2 citations
- Patching up Network Data Leaks with SweeperMarina Vemmou, Albert Cho, Alexandros DaglisMICRO 2022 · 6 citations
- DNS Cache Poisoning Attack Reloaded: Revolutions with Side ChannelsKeyu Man, Zhiyun Qian, Zhongjie Wang, Xiaofeng Zheng et al.CCS 2020 · 62 citations
- An Elemental Decomposition of DNS Name-to-IP GraphsAlex Anderson, Aadi Swadipto Mondal, Paul Barford, Mark Crovella et al.INFOCOM 2024 · 2 citations
- Beyond the Horizon: Uncovering Hosts and Services Behind Misconfigured FirewallsQing Deng, Juefei Pu, Zhaowei Tan, Zhiyun Qian et al.S&P 2025
