Enumerating anycast instances of public DNS resolver based on forwarding relationship inference

In order to solve the problems of high measurement resources needed, high cost, and low recall rate for anycast enumeration, an anycast enumeration method based on forwarding relationship inference was proposed for anycast-based public DNS resolvers. Based on the observation of the endogenous forwar...

Full description

Saved in:
Bibliographic Details
Main Authors: XU Chengxi, SHI Fan, ZHANG Yunyi, LIU Baojun, ZHANG Xianguo, LI Zhenhan, WANG Yuxuan
Format: Article
Language:zho
Published: Editorial Department of Journal on Communications 2024-11-01
Series:Tongxin xuebao
Subjects:
Online Access:http://www.joconline.com.cn/zh/article/doi/10.11959/j.issn.1000-436x.2024247/
Tags: Add Tag
No Tags, Be the first to tag this record!
Description
Summary:In order to solve the problems of high measurement resources needed, high cost, and low recall rate for anycast enumeration, an anycast enumeration method based on forwarding relationship inference was proposed for anycast-based public DNS resolvers. Based on the observation of the endogenous forwarding relationship between open forwarders and public DNS resolvers, a massive number of open forwarders were transformed into vantage points in measuring public DNS resolvers’anycast instances; Then, through multiple iterations of forwarding relationship measurement, indirect resolver aggregation, and forwarder correlation, the forwarding relationship between forwarders and the DNS resolvers’service addresses was inferred, achieving a spiral enumeration of public parser anycast nodes. Using the publicly available data of Google Public DNS as the benchmark dataset, the experimental results show that the proposed method only requires one measurement machine to recall 62.5% of the airport codes of Google Public DNS’s anycast instances. Compared with existing methods, the recall rate of anycast instance airport codes has increased by 22.92% under the condition of reducing the demand for measurement nodes by 3-4 orders of magnitude.
ISSN:1000-436X