DNS信道传输加密技术:现状、趋势和挑战  被引量:5

Encryption Technologies for DNS Channel Transmission:Status,Trends and Challenges

在线阅读下载全文

作  者:张曼 姚健康[1] 李洪涛[1] 董科军 延志伟[1] ZHANG Man;YAO Jian-Kang;LI Hong-Tao;DONG Ke-Jun;YAN Zhi-Wei(China Internet Network Information Center,Beijing 100190,China)

机构地区:[1]中国互联网络信息中心,北京100190

出  处:《软件学报》2024年第1期309-332,共24页Journal of Software

基  金:北京市科技新星计划(Z191100001119113)。

摘  要:DNS作为重要的互联网基础设施,其明文传输的特点带来很多隐私安全风险.DoH、DoT、DoQ等DNS信道传输加密技术致力于防止DNS数据被泄露或篡改,并保证DNS消息来源的可靠性.首先从DNS消息格式、数据存储和管理、系统架构和部署等6个方面分析明文DNS存在的隐私安全问题,并对已有的相关技术和协议进行总结.其次分析DNS信道传输加密技术的实现原理及应用现状,进而基于多角度评测指标对各加密协议在不同网络条件下的性能表现进行讨论.同时通过填充机制的局限性、加密流量识别和基于指纹的加密活动分析等方向探讨DNS信道传输加密技术的隐私保护效果.此外从部署规范、恶意流量对加密技术的利用和攻击、隐私和网络安全管理之间的矛盾,以及加密后影响隐私安全的其他因素等方面总结DNS信道传输加密技术存在的问题、挑战和相关解决方案.最后总结加密DNS服务的发现、递归解析器到权威服务器之间的加密、服务器端的隐私保护、基于HTTP/3的DNS等后续需要着重关注的研究方向.As critical Internet infrastructure,DNS brings many privacy and security risks due to its plaintext transmission.Many encryption technologies for DNS channel transmission,such as DoH,DoT,and DoQ,are committed to preventing DNS data from leaking or tampering and ensuring the reliability of DNS message sources.Firstly,this study analyzes the privacy and security problems of plaintext DNS from six aspects,including the DNS message format,data storage and management,and system architecture and deployment,and then summarizes the existing related technologies and protocols.Secondly,the implementation principles and the application statuses of the encryption protocols for DNS channel transmission are analyzed,and the performance of each encryption protocol under different network conditions is discussed with multi-angle evaluation indicators.Meanwhile,it discusses the privacy protection effects of the encryption technologies for DNS channel transmission through the limitations of the padding mechanism,the encrypted traffic identification,and the fingerprint-based encryption activity analysis.In addition,the problems and challenges faced by encryption technologies for DNS channel transmission are summarized from the aspects of the deployment specifications,the illegal use of encryption technologies by malicious traffic and its attack on them,the contradiction between privacy and network security management,and other factors affecting privacy and security after encryption.Relevant solutions are also presented.Finally,it summarizes the highlights of future research,such as the discovery of the encrypted DNS service,server-side privacy protection,the encryption between recursive resolvers and authoritative servers,and DNS over HTTP/3.

关 键 词:隐私 安全 QUIC TLS 1.3 DoH DOT DoQ 

分 类 号:TP393[自动化与计算机技术—计算机应用技术]

 

参考文献:

正在载入数据...

 

二级参考文献:

正在载入数据...

 

耦合文献:

正在载入数据...

 

引证文献:

正在载入数据...

 

二级引证文献:

正在载入数据...

 

同被引文献:

正在载入数据...

 

相关期刊文献:

正在载入数据...

相关的主题
相关的作者对象
相关的机构对象