Resolve the Unresolved: Systematic Work Profiling for DNS Resolvers
Liwen Xu, Huayi Duan, Zechao Cai, Adrian Perrig
摘要
The DNS standards mandate that recursive resolvers should bound the amount of work they perform per query. Yet, for nearly four decades, the specifications have offered little concrete guidance on how to enforce such limits, largely because of the system's daunting and growing complexity. This ambiguity has led to divergent implementations, recurring performance bugs, and above all, constant discoveries of denial-of-service (DoS) vectors. Prior research has inspected only fragments of a resolver's behavior, mostly using informal methods, while existing mitigations hinge on heuristic thresholds that lack broadly accepted guidance. As a result, both the issues uncovered and the fixes deployed remain narrow in scope. We address this gap by modeling recursive resolution as an Extended Transition System (ETS) with cost annotations and formulating the computation of maximum per-query work as a constrained longest path search problem with provable guarantees. Building on this formalism, we introduce rProfiler, a systematic profiling framework for measuring and modeling the work performed by DNS resolvers. Applying rProfiler against widely used resolvers exposes severe DoS vectors: issuing only 30 work-intensive queries per second cuts these resolvers' performance by at least 67%-and in some cases, renders them completely unresponsive. Diagnosing resolvers with rProfiler also yields actionable insights to improve their robustness against DoS attacks and subtle performance bugs.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper13
- Global Measurement of DNS ManipulationPaul Pearce, Ben Jones, Frank Li, Roya Ensafi 等USENIX Security 2017 · 被引用 163 次
- GRooT: Proactive Verification of DNS ConfigurationsSiva Kesava Reddy Kakarla, Ryan Beckett, Behnaz Arzani, Todd D. Millstein 等SIGCOMM 2020 · 被引用 24 次
- TuDoor Attack: Systematically Exploring and Exploiting Logic Vulnerabilities in DNS Response Pre-processing with Malformed PacketsXiang Li, Wei Xu, Baojun Liu, Mingming Zhang 等S&P 2024 · 被引用 20 次
- ResolverFuzz: Automated Discovery of DNS Resolver Vulnerabilities with Query-Response FuzzingQifan Zhang, Xuesong Bai, Xiang Li, Haixin Duan 等USENIX Security 2024 · 被引用 13 次
- A Formal Framework for End-to-End DNS ResolutionSi Liu, Huayi Duan, Lukas Heimes, Marco Bearzi 等SIGCOMM 2023 · 被引用 11 次
相关 Paper
- Your Shield is My Sword: A Persistent Denial-of-Service Attack via the Reuse of Unvalidated Caches in DNSSEC ValidationShuhan Zhang, Shuai Wang, Li Chen, Dan Li 等USENIX Security 2025
- NRDelegationAttack: Complexity DDoS attack on DNS Recursive ResolversYehuda Afek, Anat Bremler-Barr, Shani StajnrodUSENIX Security 2023
- DNSBomb: A New Practical-and-Powerful Pulsing DoS Attack Exploiting DNS Queries-and-ResponsesXiang Li, Dashuai Wu, Haixin Duan, Qi LiS&P 2024 · 被引用 14 次
- DNS Congestion Control in Adversarial SettingsHuayi Duan, Jihye Kim, Marc Wyss, Adrian PerrigSOSP 2024 · 被引用 2 次
- DaLens: Charting DNS Self-Amplification Threats at LargeLiwen Xu, Zechao Cai, Huayi Duan, Adrian PerrigUSENIX Security 2026
