{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T04:21:25Z","timestamp":1750306885815,"version":"3.41.0"},"reference-count":33,"publisher":"Association for Computing Machinery (ACM)","issue":"3","license":[{"start":{"date-parts":[[2013,5,1]],"date-time":"2013-05-01T00:00:00Z","timestamp":1367366400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/100002418","name":"Intel Corporation","doi-asserted-by":"publisher","id":[{"id":"10.13039\/100002418","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000001","name":"National Science Foundation","doi-asserted-by":"publisher","award":["NBD-0520320"],"award-info":[{"award-number":["NBD-0520320"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Internet Technol."],"published-print":{"date-parts":[[2013,5]]},"abstract":"<jats:p>\n            The Domain Name System (DNS) provides a critical service for the Internet -- mapping of user-friendly domain names to their respective IP addresses. Yet, there is no standard set of metrics quantifying the\n            <jats:italic>Quality of Domain Name Service<\/jats:italic>\n            (QoDNS), let alone a thorough evaluation of it. This article attempts to fill this gap from the perspective of a DNS proxy\/cache, which is the bridge between clients and authoritative servers. We present an analytical model of DNS proxy operations that offers insights into the design trade-offs of DNS infrastructure and the selection of critical DNS parameters.\n          <\/jats:p>\n          <jats:p>Due to the critical role DNS proxies play in QoDNS, they are the focus of attacks including cache poisoning attack. We extend the analytical model to study DNS cache poisoning attacks and their impact on QoDNS metrics. This analytical study prompts us to present Domain Name Cross-Referencing (DoX), a peer-to-peer systems for DNS proxies to cooperatively defend cache poisoning attacks. Based on QoDNS, we compare DoX with the cryptography-based DNS Security Extension (DNSSEC) to understand their relative merits.<\/jats:p>","DOI":"10.1145\/2461321.2461324","type":"journal-article","created":{"date-parts":[[2013,5,28]],"date-time":"2013-05-28T16:35:32Z","timestamp":1369758932000},"page":"1-26","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":11,"title":["A Proxy View of Quality of Domain Name Service, Poisoning Attacks and Survival Strategies"],"prefix":"10.1145","volume":"12","author":[{"given":"Lihua","family":"Yuan","sequence":"first","affiliation":[{"name":"University of California, Davis"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Chao-Chih","family":"Chen","sequence":"additional","affiliation":[{"name":"University of California, Davis"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Prasant","family":"Mohapatra","sequence":"additional","affiliation":[{"name":"University of California, Davis"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Chen-Nee","family":"Chuah","sequence":"additional","affiliation":[{"name":"University of California, Davis"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Krishna","family":"Kant","sequence":"additional","affiliation":[{"name":"Intel"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2013,5]]},"reference":[{"key":"e_1_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1109\/HASE.2010.25"},{"key":"e_1_2_1_2_1","doi-asserted-by":"crossref","unstructured":"Arends R. Austein R. Larson M. Massey D. and Rose S. 2005. DNS security introduction and requirements -- RFC 4033.  Arends R. Austein R. Larson M. Massey D. and Rose S. 2005. DNS security introduction and requirements -- RFC 4033.","DOI":"10.17487\/rfc4033"},{"key":"e_1_2_1_3_1","volume-title":"Proceedings of the USENIX Security Symposium.","author":"Bellovin S. M.","year":"1995","unstructured":"Bellovin , S. M. 1995 . Using the domain name system for system break-ins . In Proceedings of the USENIX Security Symposium. Bellovin, S. M. 1995. Using the domain name system for system break-ins. In Proceedings of the USENIX Security Symposium."},{"key":"e_1_2_1_4_1","unstructured":"Bertsekas D. P. and Gallager R. 1992. Data Networks 2nd Ed. Prentice-Hall.   Bertsekas D. P. and Gallager R. 1992. Data Networks 2nd Ed. Prentice-Hall."},{"key":"e_1_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1109\/12.675713"},{"key":"e_1_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1109\/JSAC.2002.801752"},{"volume-title":"Proceedings of the Symposium on Applications and the Internet. 85--94","author":"Cohen E.","key":"e_1_2_1_7_1","unstructured":"Cohen , E. and Kaplan , H . 2001. Proactive caching of dns records: Addressing a performance bottleneck . In Proceedings of the Symposium on Applications and the Internet. 85--94 . Cohen, E. and Kaplan, H. 2001. Proactive caching of dns records: Addressing a performance bottleneck. In Proceedings of the Symposium on Applications and the Internet. 85--94."},{"volume-title":"Proceedings of the 1st International Workshop on Peer-to-Peer Systems (IPTPS\u201901)","author":"Cox R.","key":"e_1_2_1_8_1","unstructured":"Cox , R. , Muthitacharoen , A. , and Morris , R . 2002. Serving DNS using a peer-to-peer lookup service . In Proceedings of the 1st International Workshop on Peer-to-Peer Systems (IPTPS\u201901) (Revised Papers). Springer-Verlag, 155--165. Cox, R., Muthitacharoen, A., and Morris, R. 2002. Serving DNS using a peer-to-peer lookup service. In Proceedings of the 1st International Workshop on Peer-to-Peer Systems (IPTPS\u201901) (Revised Papers). Springer-Verlag, 155--165."},{"key":"e_1_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1007\/11599371_24"},{"key":"e_1_2_1_10_1","volume-title":"Proceedings of the 17th USENIX Syposium.","author":"Dagon D.","year":"2008","unstructured":"Dagon , D. 2008 . DNS poisoning: Developments, attacks and research directions . In Proceedings of the 17th USENIX Syposium. Dagon, D. 2008. DNS poisoning: Developments, attacks and research directions. In Proceedings of the 17th USENIX Syposium."},{"key":"e_1_2_1_11_1","unstructured":"DMOZ. DMOZ -- Open directory project. www.dmoz.org.  DMOZ. DMOZ -- Open directory project. www.dmoz.org."},{"key":"e_1_2_1_12_1","doi-asserted-by":"crossref","unstructured":"Eastlake III D. E. 2001. RSA\/SHA-1 SIGs and RSA KEYs in the Domain Name System (DNS) -- RFC 3110.   Eastlake III D. E. 2001. RSA\/SHA-1 SIGs and RSA KEYs in the Domain Name System (DNS) -- RFC 3110.","DOI":"10.17487\/rfc3110"},{"key":"e_1_2_1_13_1","unstructured":"Evers J. 2005. DNS servers: An Internet\u2019s Achille\u2019s heel. http:\/\/news.cnet.com\/DNS-servers--an-Internet-Achilles-heel\/2100-7349_3-5816061.html.  Evers J. 2005. DNS servers: An Internet\u2019s Achille\u2019s heel. http:\/\/news.cnet.com\/DNS-servers--an-Internet-Achilles-heel\/2100-7349_3-5816061.html."},{"key":"e_1_2_1_14_1","unstructured":"Green I. 2005. DNS spoofing by the man in the middle. http:\/\/www.sans.org\/rr\/whitepapers\/dns\/1567.php.  Green I. 2005. DNS spoofing by the man in the middle. http:\/\/www.sans.org\/rr\/whitepapers\/dns\/1567.php."},{"key":"e_1_2_1_15_1","doi-asserted-by":"crossref","unstructured":"Gudmundsson O. 2001. DNSSEC and IPv6 aware server\/resolver message size requirements -- RFC 3226.   Gudmundsson O. 2001. DNSSEC and IPv6 aware server\/resolver message size requirements -- RFC 3226.","DOI":"10.17487\/rfc3226"},{"key":"e_1_2_1_16_1","unstructured":"Haugsness K. 2005. DNS poisoning scam raises wariness of \u2018pharming\u2019. http:\/\/isc.sans.org\/presentations\/dnspoisoning.php.  Haugsness K. 2005. DNS poisoning scam raises wariness of \u2018pharming\u2019. http:\/\/isc.sans.org\/presentations\/dnspoisoning.php."},{"key":"e_1_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1109\/JSAC.2003.818804"},{"volume-title":"Proceedings of Network Storage Syposium.","author":"Hughes A. S.","key":"e_1_2_1_18_1","unstructured":"Hughes , A. S. and Touch , J . 1999. Cross-domain cache cooperation for small clients . In Proceedings of Network Storage Syposium. Hughes, A. S. and Touch, J. 1999. Cross-domain cache cooperation for small clients. In Proceedings of Network Storage Syposium."},{"key":"e_1_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1109\/TNET.2002.803905"},{"volume-title":"Proceedings of the IEEE INFOCOM.","author":"Jung J.","key":"e_1_2_1_20_1","unstructured":"Jung , J. , Berger , A. W. , and Balakrishnan , H . 2003. Modeling TTL-based Internet caches . In Proceedings of the IEEE INFOCOM. Jung, J., Berger, A. W., and Balakrishnan, H. 2003. Modeling TTL-based Internet caches. In Proceedings of the IEEE INFOCOM."},{"key":"e_1_2_1_21_1","unstructured":"Kolkman O. 2005. Measuring the resource requirements of DNSSEC. Tech. rep. RIPE-352 RIPE NCC\/NLnet Labs. Sept.  Kolkman O. 2005. Measuring the resource requirements of DNSSEC. Tech. rep. RIPE-352 RIPE NCC\/NLnet Labs. Sept."},{"key":"e_1_2_1_22_1","unstructured":"Liu C. 2007. Handicapping new DNS extensions and applications. http:\/\/www.onlamp.com\/pub\/a\/onlamp\/2007\/01\/11\/dns-extensions.html.  Liu C. 2007. Handicapping new DNS extensions and applications. http:\/\/www.onlamp.com\/pub\/a\/onlamp\/2007\/01\/11\/dns-extensions.html."},{"key":"e_1_2_1_23_1","unstructured":"Microsoft. 2005. Description of the DNS server secure cache against pollution setting. http:\/\/support.microsoft.com\/kb\/316786\/EN-US\/.  Microsoft. 2005. Description of the DNS server secure cache against pollution setting. http:\/\/support.microsoft.com\/kb\/316786\/EN-US\/."},{"key":"e_1_2_1_24_1","unstructured":"Naraine R. 2002. Massive DDOs attack hit DNS root servers. http:\/\/www.internetnews.com\/devnews\/article.php\/1486981.  Naraine R. 2002. Massive DDOs attack hit DNS root servers. http:\/\/www.internetnews.com\/devnews\/article.php\/1486981."},{"key":"e_1_2_1_25_1","unstructured":"Netcraft Ltd. N. 2005. DNS poisoning scam raises wariness of \u2018pharming\u2019. http:\/\/news.netcraft.com\/archives\/2005\/03\/07\/dns_poisoning_scam_raises_&percnt;wariness_of_pharming.html.  Netcraft Ltd. N. 2005. DNS poisoning scam raises wariness of \u2018pharming\u2019. http:\/\/news.netcraft.com\/archives\/2005\/03\/07\/dns_poisoning_scam_raises_&percnt;wariness_of_pharming.html."},{"volume-title":"Proceedings of the 6th Conference on Operating Systems Design & Implementation (OSDI&rsquo;\u201904)","author":"Park K.","key":"e_1_2_1_26_1","unstructured":"Park , K. , Pai , V. S. , Peterson , L. , and Wang , Z . 2004. CoDNS: improving DNS performance and reliability via cooperative lookups . In Proceedings of the 6th Conference on Operating Systems Design & Implementation (OSDI&rsquo;\u201904) . USENIX Association, Berkeley, CA, 14--14. Park, K., Pai, V. S., Peterson, L., and Wang, Z. 2004. CoDNS: improving DNS performance and reliability via cooperative lookups. In Proceedings of the 6th Conference on Operating Systems Design & Implementation (OSDI&rsquo;\u201904). USENIX Association, Berkeley, CA, 14--14."},{"key":"e_1_2_1_27_1","volume-title":"Proceedings of WORLDS.","volume":"6","author":"Poole L.","unstructured":"Poole , L. and Pai , V. S . 2006. Confidns: Leveraging scale and history to improve dns security . In Proceedings of WORLDS. Vol. 6 . Poole, L. and Pai, V. S. 2006. Confidns: Leveraging scale and history to improve dns security. In Proceedings of WORLDS. Vol. 6."},{"key":"e_1_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1145\/1015467.1015504"},{"key":"e_1_2_1_30_1","unstructured":"Stewart J. 2003. DNS cache poisoning -- the next generation. http:\/\/www.securityfocus.com\/guest\/17905.  Stewart J. 2003. DNS cache poisoning -- the next generation. http:\/\/www.securityfocus.com\/guest\/17905."},{"key":"e_1_2_1_31_1","unstructured":"Symantec Corporation 2004. Symantec gateway security products DNS cache poisoning vulnerability. http:\/\/securityresponse.symantec.com\/avcenter\/security\/Content\/2004.06.&percnt;21.html.  Symantec Corporation 2004. Symantec gateway security products DNS cache poisoning vulnerability. http:\/\/securityresponse.symantec.com\/avcenter\/security\/Content\/2004.06.&percnt;21.html."},{"volume-title":"Proceedings of the 22nd International Conference on Distributed Computing Systems. 52--61","author":"Theimer M.","key":"e_1_2_1_32_1","unstructured":"Theimer , M. and Jones , M. B . 2002. Overlook: Scalable name service on an overlay network . In Proceedings of the 22nd International Conference on Distributed Computing Systems. 52--61 . Theimer, M. and Jones, M. B. 2002. Overlook: Scalable name service on an overlay network. In Proceedings of the 22nd International Conference on Distributed Computing Systems. 52--61."},{"key":"e_1_2_1_33_1","doi-asserted-by":"crossref","unstructured":"Vixie P. Thomson S. Rekhter Y. and Bound J. 1997. Dynamic updates in the Domain Name System (DNS UPDATE) -- RFC 2136.   Vixie P. Thomson S. Rekhter Y. and Bound J. 1997. Dynamic updates in the Domain Name System (DNS UPDATE) -- RFC 2136.","DOI":"10.17487\/rfc2136"},{"key":"e_1_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1145\/1921233.1921248"}],"container-title":["ACM Transactions on Internet Technology"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2461321.2461324","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/2461321.2461324","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T08:18:43Z","timestamp":1750234723000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2461321.2461324"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2013,5]]},"references-count":33,"journal-issue":{"issue":"3","published-print":{"date-parts":[[2013,5]]}},"alternative-id":["10.1145\/2461321.2461324"],"URL":"https:\/\/doi.org\/10.1145\/2461321.2461324","relation":{},"ISSN":["1533-5399","1557-6051"],"issn-type":[{"type":"print","value":"1533-5399"},{"type":"electronic","value":"1557-6051"}],"subject":[],"published":{"date-parts":[[2013,5]]},"assertion":[{"value":"2010-03-01","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2013-01-01","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2013-05-01","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}