Collected research
Increased DNS Forgery Resistance Through 0x20-Bit Encoding
Randomise the case of each letter in a DNS query name: authority servers copy the question section back bit-for-bit, so the case pattern becomes a free extra token an off-path poisoner must guess alongside the ID and source port. Stateless, AES-derived, recursive-side only. A 5.6M-packet trace gives ~12 extra bits on average, and scanning .com/.net authorities found over 99.7% preserve case.
Record
- Researcher
- David Dagon, Manos Antonakakis, Paul Vixie, Tatuya Jinmei and Wenke Lee
- Published by
- Astrolavos Lab
- Topic
- Other
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of David Dagon, Manos Antonakakis, Paul Vixie, Tatuya Jinmei and Wenke Lee, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .