Who Resolves Your DNS? Measuring Resolver Opacity and Closing the Visibility Gap
Kedar Thiagarajan, Fabian E. Bustamante
Abstract
DNS resolution has no notion of a verifiable resolver path. When an ISP outsources resolution to a third-party provider, a user's queries can cross organizational and national boundaries without their awareness---and the client that issued them has no protocol mechanism to learn which resolvers handled the query, where they sat, or who operated them. We argue that this opacity is an architectural gap rather than a deployment accident, and that a reported, verifiable resolver path should be a first-class goal of the resolution protocol. We motivate this with measurement and then show the gap is cheap to close. Using RIPE Atlas across 190 countries, we find that resolution routinely leaves the client's organization and country: under a conservative in-AS treatment of unattributable observations, 39.8% of observed resolver chains (6,622 of 16,636) use a frontend in a different AS than the client, one in four geolocatable anycast frontend pairs resolves outside the client's country, and a single operator---Google Public DNS---accounts for roughly two-thirds of those out-of-country cases. We then present Resolver-Path, an approach in which participating resolvers report their identity as they forward the query. Its base layer is cooperative in-band disclosure, it carries resolver-path metadata at near-neutral throughput, latency, and CPU cost. Because a non-participating resolver can ignore or strip the option, disclosure alone establishes the verifiable presence of reported hops, not the absence of hidden ones. Attestation authenticates the integrity, ordering, and freshness of the cooperative assertions carried by the selected response. Together, disclosure and attestation provide bounded evidence about the selected response's reported resolver chain---the substrate DNS currently lacks for jurisdictional accountability.
Create a lesson
Related papers
Predictive Traffic Shaping as a UE Network Control Loop in Wireless Systems
Shriram Vasudevan, Subramanian Vasudevan
Matched-View Cross-Domain Evaluation of WireGuard VPN Traffic Classification Using Early-Flow Fingerprints
Yasameen Sajid Razooqi, Adrian Pekar
RadioSight: Predictive mmWave XR Network Optimization from Dynamic Neural Radio Fields
Lihao Zhang, Paul Kudyba, Zhenlin An et al.
RL-based Network Slice Embedding over Space Division Multiplexed Elastic Optical Networks
Divya Khanure, Riti Gour†, Congzhou Li et al.
Sense Once, Serve Many: Common-Trace Factorized Constrained PPO for Online Sensing-Session Consolidation in Multi-Tenant ISAC Networks
Dang-Dung Vu
A-MADiff: Attention-Guided Multi-Agent DRL with Diffusion Policies for Memory-Aware Task Orchestration in Mobile AIGC Networks
Chongzhi Wu, Zhengtao Li, Jiawen Kang et al.