We perform a passive measurement study investigating how a Protective DNS service might perform in a Research & Education Network serving hundreds of member institutions. Utilizing freely-available DNS blocklists consisting of domain names deemed to be threats, we test hundreds of millions of users' real DNS queries, observed over a week's time, to find which answers would be blocked because they involve domain names that are potential threats. We find the blocklists disorderly regarding their names, goals, transparency, and provenance making them quite difficult to compare. Consequently, these Protective DNS underpinnings lack organized oversight, presenting challenges and risks in operation at scale.
翻译:我们开展了一项被动测量研究,旨在探究保护性DNS服务在服务于数百个成员机构的研究与教育网络中的表现。通过利用由被认定为威胁的域名组成的免费DNS屏蔽列表,我们测试了数亿用户在为期一周内产生的真实DNS查询,以确定哪些查询因涉及潜在威胁域名而被屏蔽。研究发现,这些屏蔽列表在命名、目标、透明度及来源方面均缺乏规范性,导致其难以进行有效比较。因此,保护性DNS的底层机制缺乏有序监管,在大规模运营中面临挑战与风险。