Measuring the Centrality of DNS Infrastructure in the Wild
The centralization of the global DNS ecosystem may accelerate the creation of an oligopoly market, thereby, increasing the risk of a single point of failure and network traffic manipulation. Earlier studies have revealed the level of centralization in terms of the market share of public DNS services...
Main Authors: | , , , , , , |
---|---|
Format: | Article |
Language: | English |
Published: |
MDPI AG
2023-05-01
|
Series: | Applied Sciences |
Subjects: | |
Online Access: | https://www.mdpi.com/2076-3417/13/9/5739 |
_version_ | 1797602909977837568 |
---|---|
author | Chengxi Xu Yunyi Zhang Fan Shi Hong Shan Bingyang Guo Yuwei Li Pengfei Xue |
author_facet | Chengxi Xu Yunyi Zhang Fan Shi Hong Shan Bingyang Guo Yuwei Li Pengfei Xue |
author_sort | Chengxi Xu |
collection | DOAJ |
description | The centralization of the global DNS ecosystem may accelerate the creation of an oligopoly market, thereby, increasing the risk of a single point of failure and network traffic manipulation. Earlier studies have revealed the level of centralization in terms of the market share of public DNS services and DNS traffic seen by major CDN providers. However, the level of centralization in the infrastructure of the DNS Ecosystem is not well understood. In this paper, we present a novel and lightweight measurement approach that effectively discovers resolver pools from a single probing point. We conduct an Internet-wide active measurement on the client-side as well as the server-side DNS infrastructure to assess the level of DNS centralization in terms of the supporting infrastructure. Our measurement results show that the DNS infrastructure is much more centralized than previously believed. Over 90% of forwarding resolvers are backed by less than 5% (4071) of indirect resolvers. Merely 0.45% (12,679) of all name servers across 1138 gTLDs, operated by just 10 DNS providers, provide authoritative domain resolution service for 48.5% (more than 100 million) of domain names. We also investigated several leading DNS providers in IP infrastructure, load distribution, and service geo-distribution. The findings of our measurements provide novel insights into the centrality of the DNS infrastructure, which will help the Internet community promote the understanding of the DNS ecosystem. |
first_indexed | 2024-03-11T04:23:11Z |
format | Article |
id | doaj.art-5a0cf31eba5b43499a1828666f6c14a4 |
institution | Directory Open Access Journal |
issn | 2076-3417 |
language | English |
last_indexed | 2024-03-11T04:23:11Z |
publishDate | 2023-05-01 |
publisher | MDPI AG |
record_format | Article |
series | Applied Sciences |
spelling | doaj.art-5a0cf31eba5b43499a1828666f6c14a42023-11-17T22:38:10ZengMDPI AGApplied Sciences2076-34172023-05-01139573910.3390/app13095739Measuring the Centrality of DNS Infrastructure in the WildChengxi Xu0Yunyi Zhang1Fan Shi2Hong Shan3Bingyang Guo4Yuwei Li5Pengfei Xue6College of Electronic Engineering, National University of Defense Technology, Hefei 230037, ChinaCollege of Electronic Engineering, National University of Defense Technology, Hefei 230037, ChinaCollege of Electronic Engineering, National University of Defense Technology, Hefei 230037, ChinaCollege of Electronic Engineering, National University of Defense Technology, Hefei 230037, ChinaCollege of Electronic Engineering, National University of Defense Technology, Hefei 230037, ChinaCollege of Electronic Engineering, National University of Defense Technology, Hefei 230037, ChinaCollege of Electronic Engineering, National University of Defense Technology, Hefei 230037, ChinaThe centralization of the global DNS ecosystem may accelerate the creation of an oligopoly market, thereby, increasing the risk of a single point of failure and network traffic manipulation. Earlier studies have revealed the level of centralization in terms of the market share of public DNS services and DNS traffic seen by major CDN providers. However, the level of centralization in the infrastructure of the DNS Ecosystem is not well understood. In this paper, we present a novel and lightweight measurement approach that effectively discovers resolver pools from a single probing point. We conduct an Internet-wide active measurement on the client-side as well as the server-side DNS infrastructure to assess the level of DNS centralization in terms of the supporting infrastructure. Our measurement results show that the DNS infrastructure is much more centralized than previously believed. Over 90% of forwarding resolvers are backed by less than 5% (4071) of indirect resolvers. Merely 0.45% (12,679) of all name servers across 1138 gTLDs, operated by just 10 DNS providers, provide authoritative domain resolution service for 48.5% (more than 100 million) of domain names. We also investigated several leading DNS providers in IP infrastructure, load distribution, and service geo-distribution. The findings of our measurements provide novel insights into the centrality of the DNS infrastructure, which will help the Internet community promote the understanding of the DNS ecosystem.https://www.mdpi.com/2076-3417/13/9/5739internet centralityDNS infrastructureactive measurementinfrastructure structure |
spellingShingle | Chengxi Xu Yunyi Zhang Fan Shi Hong Shan Bingyang Guo Yuwei Li Pengfei Xue Measuring the Centrality of DNS Infrastructure in the Wild Applied Sciences internet centrality DNS infrastructure active measurement infrastructure structure |
title | Measuring the Centrality of DNS Infrastructure in the Wild |
title_full | Measuring the Centrality of DNS Infrastructure in the Wild |
title_fullStr | Measuring the Centrality of DNS Infrastructure in the Wild |
title_full_unstemmed | Measuring the Centrality of DNS Infrastructure in the Wild |
title_short | Measuring the Centrality of DNS Infrastructure in the Wild |
title_sort | measuring the centrality of dns infrastructure in the wild |
topic | internet centrality DNS infrastructure active measurement infrastructure structure |
url | https://www.mdpi.com/2076-3417/13/9/5739 |
work_keys_str_mv | AT chengxixu measuringthecentralityofdnsinfrastructureinthewild AT yunyizhang measuringthecentralityofdnsinfrastructureinthewild AT fanshi measuringthecentralityofdnsinfrastructureinthewild AT hongshan measuringthecentralityofdnsinfrastructureinthewild AT bingyangguo measuringthecentralityofdnsinfrastructureinthewild AT yuweili measuringthecentralityofdnsinfrastructureinthewild AT pengfeixue measuringthecentralityofdnsinfrastructureinthewild |