论文标题

加密的DN会很快吗?

Can Encrypted DNS Be Fast?

论文作者

Hounsel, Austin, Schmitt, Paul, Borgolte, Kevin, Feamster, Nick

论文摘要

在本文中,我们研究了2020年以上一个月的美国成千上万个家庭网络的加密DNS协议和常规DNS的性能。我们从联邦通信委员会(FCC)的2,693名参与小组成员的家庭中进行了这些衡量标准。我们发现,客户不必将DNS绩效换成隐私。对于某些解析器,即使延迟增加,DOT在中位响应时间中的性能比DNS更快。我们还发现递归解析器的DOH性能显着差异。基于这些结果,我们建议DNS客户端(例如Web浏览器)应定期进行简单的延迟和响应时间测量,以确定客户端应使用的协议和解析器。没有一个DNS协议和解析器对所有客户都表现出色。

In this paper, we study the performance of encrypted DNS protocols and conventional DNS from thousands of home networks in the United States, over one month in 2020. We perform these measurements from the homes of 2,693 participating panelists in the Federal Communications Commission's (FCC) Measuring Broadband America program. We found that clients do not have to trade DNS performance for privacy. For certain resolvers, DoT was able to perform faster than DNS in median response times, even as latency increased. We also found significant variation in DoH performance across recursive resolvers. Based on these results, we recommend that DNS clients (e.g., web browsers) should periodically conduct simple latency and response time measurements to determine which protocol and resolver a client should use. No single DNS protocol nor resolver performed the best for all clients.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源