Enregistré dans:
Détails bibliographiques
Auteurs principaux: Dong, Hongying, Zhang, Yizhe, Lee, Hyeonmin, Huque, Shumon, Sun, Yixin
Format: Preprint
Publié: 2024
Sujets:
Accès en ligne:https://arxiv.org/abs/2403.15672
Tags: Ajouter un tag
Pas de tags, Soyez le premier à ajouter un tag!
_version_ 1866908049114923008
author Dong, Hongying
Zhang, Yizhe
Lee, Hyeonmin
Huque, Shumon
Sun, Yixin
author_facet Dong, Hongying
Zhang, Yizhe
Lee, Hyeonmin
Huque, Shumon
Sun, Yixin
contents The DNS HTTPS resource record is a new DNS record type designed for the delivery of configuration information and parameters required to initiate connections to HTTPS network services. In addition, it is a key enabler for TLS Encrypted ClientHello (ECH) by providing the cryptographic keying material needed to encrypt the initial exchange. To understand the adoption of this new DNS HTTPS record, we perform a longitudinal study on the server-side deployment of DNS HTTPS for Tranco top million domains, as well as an analysis of the client-side support for DNS HTTPS through snapshots from major browsers. To the best of our knowledge, our work is the first longitudinal study on DNS HTTPS server deployment, and the first known study on client-side support for DNS HTTPS. Despite the rapidly growing trend of DNS HTTPS adoption, our study highlights challenges and concerns in the deployment by both servers and clients, such as the complexity in properly maintaining HTTPS records and connection failure in browsers when the HTTPS record is not properly configured.
format Preprint
id arxiv_https___arxiv_org_abs_2403_15672
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Exploring the Ecosystem of DNS HTTPS Resource Records: An End-to-End Perspective
Dong, Hongying
Zhang, Yizhe
Lee, Hyeonmin
Huque, Shumon
Sun, Yixin
Networking and Internet Architecture
The DNS HTTPS resource record is a new DNS record type designed for the delivery of configuration information and parameters required to initiate connections to HTTPS network services. In addition, it is a key enabler for TLS Encrypted ClientHello (ECH) by providing the cryptographic keying material needed to encrypt the initial exchange. To understand the adoption of this new DNS HTTPS record, we perform a longitudinal study on the server-side deployment of DNS HTTPS for Tranco top million domains, as well as an analysis of the client-side support for DNS HTTPS through snapshots from major browsers. To the best of our knowledge, our work is the first longitudinal study on DNS HTTPS server deployment, and the first known study on client-side support for DNS HTTPS. Despite the rapidly growing trend of DNS HTTPS adoption, our study highlights challenges and concerns in the deployment by both servers and clients, such as the complexity in properly maintaining HTTPS records and connection failure in browsers when the HTTPS record is not properly configured.
title Exploring the Ecosystem of DNS HTTPS Resource Records: An End-to-End Perspective
topic Networking and Internet Architecture
url https://arxiv.org/abs/2403.15672