Understanding the Implementation and Security Implications of Protective DNS Services
Mingxuan Liu, Yiming Zhang, Xiang Li, Chaoyi Lu, Baojun Liu, Haixin Duan, Xiaofeng Zheng
摘要
—Domain names are often registered and abused for harmful and illegal Internet activities. To mitigate such threats, as an emerging security service, Protective DNS ( PDNS ) blocks access to harmful content by proactively offering rewritten DNS responses, which resolve malicious domains to controlled hosts. While it has become an effective tool against cybercrime, given their implementation divergence, little has been done from the security community in understanding the deployment, operational status and security policies of PDNS services. In this paper, we present a large-scale measurement study of the deployment and security implications of open PDNS services. We first perform empirical analysis over 28 popular PDNS providers and summarize major formats of DNS rewriting policies. Then, powered by the derived rules, we design a methodology that identifies intentional DNS rewriting enforced by open PDNS servers in the wild. Our findings are multi-faceted. On the plus side, the deployment of PDNS is now starting to scale: we identify 17,601 DNS servers (9.1% of all probed) offering such service. For DNS clients, switching from regular DNS to PDNS induces negligible query latency, despite additional steps (e.g., checking against threat intelligence and rewriting DNS response) being required from the server side. However, we also find flaws and vulnerabilities within PDNS implementation, including evasion of blocking policies and denial of service. Through responsible vulnerability disclosure, we have received 12 audit assessment results of high-risk vulnerabilities. Our study calls for proper guidance and best practices for
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper2
- HADES Attack: Understanding and Evaluating Manipulation Risks of Email BlocklistsRuixuan Li, Chaoyi Lu, Baojun Liu, Yunyi Zhang 等NDSS 2025
- BlockMeNot: Automatic Selection of Domain and URL Blocking Granularity to Minimize Collateral Damage and EvasionDaud Ahmed, Srdjan Matic, Platon Kotzias, Emiliano Carlesi 等USENIX Security 2026
它引用的顶会 Paper24
- Tranco: A Research-Oriented Top Sites Ranking Hardened Against ManipulationVictor Le Pochat, Tom van Goethem, Samaneh Tajalizadehkhoob, Maciej Korczynski 等NDSS 2019 · 被引用 826 次
- Global Measurement of DNS ManipulationPaul Pearce, Ben Jones, Frank Li, Roya Ensafi 等USENIX Security 2017 · 被引用 163 次
- Reading the Tea leaves: A Comparative Analysis of Threat IntelligenceVector Guo Li, Matthew Dunn, Paul Pearce, Damon McCoy 等USENIX Security 2019 · 被引用 123 次
- The Circle Of Life: A Large-Scale Study of The IoT Malware LifecycleOmar Alrawi, Charles Lever, Kevin Valakuzhy, Ryan Court 等USENIX Security 2021 · 被引用 109 次
- Cognitive Triaging of Phishing AttacksAmber van der Heijden, Luca AllodiUSENIX Security 2019 · 被引用 100 次
相关 Paper
- Two Sides of the Shield: Understanding Protective DNS adoption factorsElsa Turcios Rodriguez, Radu Anghel, Simon Parkin, Michel van Eeten 等USENIX Security 2023
- Who Is Answering My Queries: Understanding and Characterizing Interception of the DNS Resolution PathBaojun Liu, Chaoyi Lu, Hai-Xin Duan, Ying Liu 等USENIX Security 2018 · 被引用 67 次
- Tracking the Stray Sheep: Understanding DNS Response Manipulation in the WildWenhao Wu, Zhaohua Wang, Zihan Li, Qinxin Li 等WWW 2026
- Rethinking the Security Threats of Stale DNS Glue RecordsYunyi Zhang, Baojun Liu, Haixin Duan, Min Zhang 等USENIX Security 2024 · 被引用 9 次
- Zombie Awakening: Stealthy Hijacking of Active Domains through DNS Hosting ReferralEihal Alowaisheq, Siyuan Tang, Zhihao Wang, Fatemah Alharbi 等CCS 2020 · 被引用 19 次
