{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,14]],"date-time":"2026-07-14T10:12:48Z","timestamp":1784023968659,"version":"3.55.0"},"publisher-location":"New York, NY, USA","reference-count":69,"publisher":"ACM","license":[{"start":{"date-parts":[[2024,11,4]],"date-time":"2024-11-04T00:00:00Z","timestamp":1730678400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"name":"SNSF","award":["200021_215318"],"award-info":[{"award-number":["200021_215318"]}]},{"DOI":"10.13039\/501100003475","name":"Hasler Stiftung","doi-asserted-by":"publisher","award":["2024-07-02-105"],"award-info":[{"award-number":["2024-07-02-105"]}],"id":[{"id":"10.13039\/501100003475","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2024,11,4]]},"DOI":"10.1145\/3694715.3695982","type":"proceedings-article","created":{"date-parts":[[2024,11,15]],"date-time":"2024-11-15T19:28:18Z","timestamp":1731698898000},"page":"726-747","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":4,"title":["DNS Congestion Control in Adversarial Settings"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-1162-2337","authenticated-orcid":false,"given":"Huayi","family":"Duan","sequence":"first","affiliation":[{"name":"ETH Z\u00fcrich, Zurich, Switzerland"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0000-3062-0225","authenticated-orcid":false,"given":"Jihye","family":"Kim","sequence":"additional","affiliation":[{"name":"ETH Z\u00fcrich, Zurich, Switzerland"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9267-6646","authenticated-orcid":false,"given":"Marc","family":"Wyss","sequence":"additional","affiliation":[{"name":"ETH Z\u00fcrich, Zurich, Switzerland"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5280-5412","authenticated-orcid":false,"given":"Adrian","family":"Perrig","sequence":"additional","affiliation":[{"name":"ETH Z\u00fcrich, Zurich, Switzerland"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2024,11,15]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"DCC Artefact. https:\/\/gitlab.ethz.ch\/netsec\/dcc-artefact."},{"key":"e_1_3_2_1_2_1","unstructured":"DNS Nameserver Counts for Top Million Websites (2020-08). https:\/\/dnsinstitute.com\/research\/2020\/top-million-202008.html."},{"key":"e_1_3_2_1_3_1","volume-title":"https:\/\/developers.google.com\/speed\/public-dns\/docs\/isp","author":"Ps Google Public DNS","year":"2024","unstructured":"Google Public DNS for ISPs. https:\/\/developers.google.com\/speed\/public-dns\/docs\/isp, 2024."},{"key":"e_1_3_2_1_4_1","volume-title":"Janurary","year":"2024","unstructured":"resolv.conf(5) --- linux manual page. https:\/\/man7.org\/linux\/man-pages\/man5\/resolv.conf.5.html, Janurary 2024."},{"key":"e_1_3_2_1_5_1","volume-title":"Janurary","author":"Zone File Statistics TLD","year":"2024","unstructured":"TLD Zone File Statistics. https:\/\/www.statdns.com, Janurary 2024."},{"key":"e_1_3_2_1_6_1","volume-title":"IETF","author":"Andrews D. Eastlake","year":"2016","unstructured":"D. Eastlake 3rd and M. Andrews. Domain Name System (DNS) Cookies. RFC 7873, IETF, May 2016."},{"key":"e_1_3_2_1_7_1","volume-title":"Proceedings of the USENIX Security Symposium","author":"Afek Yehuda","year":"2020","unstructured":"Yehuda Afek, Anat Bremler-Barr, and Lior Shafir. Nxnsarttack: Recursive DNS inefficiencies and vulnerabilities. In Proceedings of the USENIX Security Symposium, 2020."},{"key":"e_1_3_2_1_8_1","volume-title":"Amplification, & DNS Water-torture. Technical report","year":"2019","unstructured":"Akamai. Whitepaper: DNS Reflection, Amplification, & DNS Water-torture. Technical report, 2019."},{"key":"e_1_3_2_1_9_1","volume-title":"Al-Dalky and Kyle Schomp. Characterization of Collaborative Resolution in Recursive DNS Resolvers. In Proceedings of the International Conference on Passive and Active Measurement (PAM)","author":"Rami","year":"2018","unstructured":"Rami Al-Dalky and Kyle Schomp. Characterization of Collaborative Resolution in Recursive DNS Resolvers. In Proceedings of the International Conference on Passive and Active Measurement (PAM), 2018."},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1145\/3544216.3544263"},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1145\/964723.383074"},{"key":"e_1_3_2_1_12_1","volume-title":"IETF","author":"Bortzmeyer S.","year":"2021","unstructured":"S. Bortzmeyer, R. Dolmans, and P. Hoffman. DNS Query Name Minimisation to Improve Privacy. RFC 9156, IETF, November 2021."},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1145\/63039.63045"},{"key":"e_1_3_2_1_14_1","volume-title":"Proceedings of the International Symposium on Research in Attacks, Intrusions, and Defenses (RAID)","author":"Bushart Jonas","year":"2018","unstructured":"Jonas Bushart and Christian Rossow. DNS unchained: Amplified application-layer dos attacks against DNS authoritatives. In Proceedings of the International Symposium on Research in Attacks, Intrusions, and Defenses (RAID), 2018."},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP57164.2023.00040"},{"key":"e_1_3_2_1_16_1","volume-title":"Proceedings of the 17th Conference on Security Symposium, SS'08, USA","author":"Chou Jerry","year":"2008","unstructured":"Jerry Chou, Bill Lin, Subhabrata Sen, and Oliver Spatscheck. Proactive surge protection: a defense mechanism for bandwidth-based attacks. In Proceedings of the 17th Conference on Security Symposium, SS'08, USA, 2008. USENIX Association."},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.17487\/RFC7871"},{"key":"e_1_3_2_1_18_1","volume-title":"Extension Mechanisms for DNS (EDNS(0)). RFC","author":"da Silva Damas Joao","year":"2013","unstructured":"Joao da Silva Damas, Michael Graff, and Paul A. Vixie. Extension Mechanisms for DNS (EDNS(0)). RFC 6891, April 2013."},{"key":"e_1_3_2_1_19_1","volume-title":"Jonathan Demke. A Quantitative Study of the Deployment of DNS Rate Limiting. In 2019 International Conference on Computing, Networking and Communications (ICNC)","author":"Deccio Casey","year":"2019","unstructured":"Casey Deccio, Derek Argueta, and Jonathan Demke. A Quantitative Study of the Deployment of DNS Rate Limiting. In 2019 International Conference on Computing, Networking and Communications (ICNC), 2019."},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1145\/75247.75248"},{"key":"e_1_3_2_1_21_1","volume-title":"Proceedings of the USENIX Annual Technical Conference (ATC)","author":"Demoulin Henri Maxime","year":"2019","unstructured":"Henri Maxime Demoulin, Isaac Pedisich, Nikos Vasilakis, Vincent Liu, Boon Thau Loo, and Linh Thi Xuan Phan. Detecting asymmetric application-layer Denial-of-Service attacks In-Flight with FineLame. In Proceedings of the USENIX Annual Technical Conference (ATC), 2019."},{"key":"e_1_3_2_1_22_1","volume-title":"Proceedings of the USENIX Security Symposium","author":"Duan Huayi","year":"2024","unstructured":"Huayi Duan, Marco Bearzi, Jodok Vieli, David Basin, Adrian Perrig, Si Liu, and Bernhard Tellenbach. CAMP: Compositional Amplification Attacks against DNS. In Proceedings of the USENIX Security Symposium, 2024."},{"key":"e_1_3_2_1_23_1","volume-title":"IETF","author":"Ferguson P.","year":"2000","unstructured":"P. Ferguson and D. Senie. Network Ingress Filtering: Defeating Denial of Service Attacks which employ IP Source Address Spoofing. RFC 2827, IETF, May 2000."},{"key":"e_1_3_2_1_24_1","volume-title":"IETF","author":"Fujiwara K.","year":"2017","unstructured":"K. Fujiwara, A. Kato, and W. Kumari. Aggressive Use of DNSSEC-Validated Cache. RFC 8198, IETF, July 2017."},{"key":"e_1_3_2_1_25_1","volume-title":"Ion Stoica. Multi-Resource Fair Queueing for Packet Processing. In Proceedings of the ACM SIGCOMM Conference","author":"Ghodsi Ali","year":"2012","unstructured":"Ali Ghodsi, Vyas Sekar, Matei Zaharia, and Ion Stoica. Multi-Resource Fair Queueing for Packet Processing. In Proceedings of the ACM SIGCOMM Conference, 2012."},{"key":"e_1_3_2_1_26_1","volume-title":"Mike Marty. Multi-Queue Fair Queuing. In Proceedings of the USENIX Annual Technical Conference (ATC)","author":"Hedayati Mohammad","year":"2019","unstructured":"Mohammad Hedayati, Kai Shen, Michael L Scott, and Mike Marty. Multi-Queue Fair Queuing. In Proceedings of the USENIX Annual Technical Conference (ATC), 2019."},{"key":"e_1_3_2_1_27_1","volume-title":"IETF","author":"Hoffman P.","year":"2018","unstructured":"P. Hoffman and P. McManus. DNS Queries over HTTPS (DoH). RFC 8484, IETF, October 2018."},{"key":"e_1_3_2_1_28_1","volume-title":"IETF","author":"Huitema C.","year":"2022","unstructured":"C. Huitema, S. Dickinson, and A. Mankin. DNS over Dedicated QUIC Connections. RFC 9250, IETF, May 2022."},{"key":"e_1_3_2_1_29_1","volume-title":"IEEE Symposium on Security and Privacy","author":"Kang Min Suk","year":"2013","unstructured":"Min Suk Kang, Soo Bum Lee, and Virgil D. Gligor. The crossfire attack. In IEEE Symposium on Security and Privacy, 2013."},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1145\/3419394.3423664"},{"key":"e_1_3_2_1_31_1","volume-title":"IETF","author":"Kent S.","year":"2005","unstructured":"S. Kent. IP Authentication Header. RFC 4302, IETF, December 2005."},{"key":"e_1_3_2_1_32_1","volume-title":"IETF","author":"Kinnear E.","year":"2022","unstructured":"E. Kinnear, P. McManus, T. Pauly, T. Verma, and C.A. Wood. Oblivious DNS over HTTPS. RFC 9230, IETF, June 2022."},{"key":"e_1_3_2_1_33_1","volume-title":"IETF","author":"Kumari W.","year":"2020","unstructured":"W. Kumari, E. Hunt, R. Arends, W. Hardaker, and D. Lawrence. Extended DNS Errors. RFC 8914, IETF, October 2020."},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICNP.2015.11"},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1145\/2535372.2535398"},{"key":"e_1_3_2_1_36_1","volume-title":"IETF","author":"Lewis E.","year":"2006","unstructured":"E. Lewis. The Role of Wildcards in the Domain Name System. RFC 4592, IETF, July 2006."},{"key":"e_1_3_2_1_37_1","volume-title":"Qi Li. DNSBomb: A New Practical-and-Powerful Pulsing DoS Attack Exploiting DNS Queries-and-Responses. In Proceedings of the IEEE Symposium on Security and Privacy (S&P)","author":"Li Xiang","year":"2024","unstructured":"Xiang Li, Dashuai Wu, Haixin Duan, and Qi Li. DNSBomb: A New Practical-and-Powerful Pulsing DoS Attack Exploiting DNS Queries-and-Responses. In Proceedings of the IEEE Symposium on Security and Privacy (S&P), 2024."},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3484737"},{"key":"e_1_3_2_1_39_1","volume-title":"Adrian Perrig. A Formal Framework for End-to-End DNS Resolution. In Proceedings of the ACM SIGCOMM Conference.","author":"Liu Si","unstructured":"Si Liu, Huayi Duan, Lukas Heimes, Marco Bearzi, Jodok Vieli, David Basin, and Adrian Perrig. A Formal Framework for End-to-End DNS Resolution. In Proceedings of the ACM SIGCOMM Conference."},{"key":"e_1_3_2_1_40_1","volume-title":"Vyas Sekar. Jaqen: A High-Performance Switch-Native Approach for Detecting and Mitigating Volumetric DDoS Attacks with Programmable Switches. In Proceedings of the USENIX Security Symposium","author":"Liu Zaoxing","year":"2021","unstructured":"Zaoxing Liu, Hun Namkung, Georgios Nikolaidis, Jeongkeun Lee, Changhoon Kim, Xin Jin, Vladimir Braverman, Minlan Yu, and Vyas Sekar. Jaqen: A High-Performance Switch-Native Approach for Detecting and Mitigating Volumetric DDoS Attacks with Programmable Switches. In Proceedings of the USENIX Security Symposium, 2021."},{"key":"e_1_3_2_1_41_1","volume-title":"The \"indefinitely\" delegating name servers (idns) attack. https:\/\/indico.dns-oarc.net\/event\/21\/contributions\/301\/attachments\/272\/492\/slides.pdf","author":"Maury Florian","year":"2015","unstructured":"Florian Maury. The \"indefinitely\" delegating name servers (idns) attack. https:\/\/indico.dns-oarc.net\/event\/21\/contributions\/301\/attachments\/272\/492\/slides.pdf, 2015. Accessed 2022-04-30."},{"key":"e_1_3_2_1_42_1","volume-title":"Proceedings of the International Conference on Passive and Active Measurement (PAM)","author":"McGregor Andrew","year":"2021","unstructured":"Andrew McGregor, Phillipa Gill, and Nicholas Weaver. Cache Me Outside: A New Look at DNS Cache Probing. In Proceedings of the International Conference on Passive and Active Measurement (PAM), 2021."},{"key":"e_1_3_2_1_43_1","volume-title":"IETF","author":"Moura G.","year":"2022","unstructured":"G. Moura, W. Hardaker, J. Heidemann, and M. Davids. Considerations for Large Authoritative DNS Server Operators. RFC 9199, IETF, March 2022."},{"key":"e_1_3_2_1_44_1","doi-asserted-by":"publisher","DOI":"10.1145\/3487552.3487824"},{"key":"e_1_3_2_1_45_1","volume-title":"IETF","author":"Nagle J.","year":"1985","unstructured":"J. Nagle. On Packet Switches With Infinite Storage. RFC 970, IETF, December 1985."},{"key":"e_1_3_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.1145\/3485983.3494872"},{"key":"e_1_3_2_1_47_1","volume-title":"IETF","author":"Proust S.","year":"2016","unstructured":"S. Proust. Additional WebRTC Audio Codecs for Interoperability. RFC 7875, IETF, May 2016."},{"key":"e_1_3_2_1_48_1","doi-asserted-by":"publisher","DOI":"10.1109\/TNET.2007.896231"},{"key":"e_1_3_2_1_49_1","volume-title":"IETF","author":"Ramakrishnan K.","year":"2001","unstructured":"K. Ramakrishnan, S. Floyd, and D. Black. The Addition of Explicit Congestion Notification (ECN) to IP. RFC 3168, IETF, September 2001."},{"key":"e_1_3_2_1_50_1","doi-asserted-by":"publisher","DOI":"10.1145\/3274694.3274717"},{"key":"e_1_3_2_1_51_1","doi-asserted-by":"publisher","DOI":"10.1145\/3419394.3423640"},{"key":"e_1_3_2_1_52_1","doi-asserted-by":"publisher","DOI":"10.1145\/3320269.3384743"},{"key":"e_1_3_2_1_53_1","volume-title":"Proceedings on Privacy Enhancing Technologies","author":"Schmitt Paul","year":"2019","unstructured":"Paul Schmitt, Anne Edmundson, Allison Mankin, and Nick Feamster. Oblivious DNS: practical privacy for DNS queries. In Proceedings on Privacy Enhancing Technologies, 2019."},{"key":"e_1_3_2_1_54_1","volume-title":"Proceedings of the ACM SIGCOMM Conference","author":"Schomp Kyle","year":"2020","unstructured":"Kyle Schomp, Onkar Bhardwaj, Eymen Kurdoglu, Mashooq Muhaimen, and Ramesh K Sitaraman. Akamai DNS: Providing Authoritative Answers to the World's Queries. In Proceedings of the ACM SIGCOMM Conference, 2020."},{"key":"e_1_3_2_1_55_1","volume-title":"Mark Allman. On Measuring The Client-Side DNS Infrastructure. In Proceedings of the ACM Internet Measurement Conference (IMC)","author":"Schomp Kyle","year":"2013","unstructured":"Kyle Schomp, Tom Callahan, Michael Rabinovich, and Mark Allman. On Measuring The Client-Side DNS Infrastructure. In Proceedings of the ACM Internet Measurement Conference (IMC), 2013."},{"key":"e_1_3_2_1_56_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2018.00032"},{"key":"e_1_3_2_1_57_1","volume-title":"Michael Swift. Titan: Fair Packet Scheduling for Commodity Multiqueue NICs. In Proceedings of the USENIX Annual Technical Conference (ATC)","author":"Stephens Brent","year":"2017","unstructured":"Brent Stephens, Arjun Singhvi, Aditya Akella, and Michael Swift. Titan: Fair Packet Scheduling for Commodity Multiqueue NICs. In Proceedings of the USENIX Annual Technical Conference (ATC), 2017."},{"key":"e_1_3_2_1_58_1","doi-asserted-by":"publisher","DOI":"10.1145\/285237.285273"},{"key":"e_1_3_2_1_59_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-04444-1_3"},{"key":"e_1_3_2_1_60_1","volume-title":"Proceedings of the USENIX Symposium on Networked Systems Design and Implementation (NSDI)","author":"Tahir Ammar","year":"2023","unstructured":"Ammar Tahir and Radhika Mittal. Enabling users to control their internet. In Proceedings of the USENIX Symposium on Networked Systems Design and Implementation (NSDI), 2023."},{"key":"e_1_3_2_1_61_1","volume-title":"Leader: Defense against exploit-based denial-of-service attacks on web applications","author":"Tandon Rajat","year":"2023","unstructured":"Rajat Tandon, Haoda Wang, Nicolaas Weideman, Shushan Arakelyan, Genevieve Bartlertt, Christophe Hauser, and Jelena Mirkovic. Leader: Defense against exploit-based denial-of-service attacks on web applications. 2023."},{"key":"e_1_3_2_1_62_1","article-title":"A sketch-based defense system against application layer ddos attacks","author":"Wang Chenxu","year":"2018","unstructured":"Chenxu Wang, Tony T. N. Miu, Xiapu Luo, and Jinhe Wang. Skyshield: A sketch-based defense system against application layer ddos attacks. IEEE Transactions on Information Forensics and Security, 2018.","journal-title":"IEEE Transactions on Information Forensics and Security"},{"key":"e_1_3_2_1_63_1","volume-title":"Decentralized Link-Flooding Defense Against Adaptive Adversaries. In Proceedings of the USENIX Security Symposium","author":"Xing Jiarong","year":"2021","unstructured":"Jiarong Xing, Wenqing Wu, and Ang Chen. Ripple: A Programmable, Decentralized Link-Flooding Defense Against Adaptive Adversaries. In Proceedings of the USENIX Security Symposium, 2021."},{"key":"e_1_3_2_1_64_1","doi-asserted-by":"publisher","DOI":"10.1145\/3576915.3616668"},{"key":"e_1_3_2_1_65_1","doi-asserted-by":"publisher","DOI":"10.1145\/3555050.3569121"},{"key":"e_1_3_2_1_66_1","doi-asserted-by":"publisher","DOI":"10.1145\/2535372.2535387"},{"key":"e_1_3_2_1_67_1","volume-title":"Proceedings of the ACM SIGCOMM Conference","author":"Yu Liangcheng","year":"2022","unstructured":"Liangcheng Yu, John Sonchack, and Vincent Liu. Cebinae: Scalable in-network fairness augmentation. In Proceedings of the ACM SIGCOMM Conference, 2022."},{"key":"e_1_3_2_1_68_1","volume-title":"USENIX Symposium on Networked Systems Design and Implementation (NSDI)","author":"Yu Z.","year":"2021","unstructured":"Z. Yu, J. Wu, V. Braverman, I. Stoica, and X. Jin. Twenty years after: Hierarchical core-stateless fair queueing. In USENIX Symposium on Networked Systems Design and Implementation (NSDI), 2021."},{"key":"e_1_3_2_1_69_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2020.24007"}],"event":{"name":"SOSP '24: ACM SIGOPS 30th Symposium on Operating Systems Principles","location":"Austin TX USA","acronym":"SOSP '24","sponsor":["SIGOPS ACM Special Interest Group on Operating Systems","USENIX"]},"container-title":["Proceedings of the ACM SIGOPS 30th Symposium on Operating Systems Principles"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3694715.3695982","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3694715.3695982","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T00:05:48Z","timestamp":1750291548000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3694715.3695982"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,11,4]]},"references-count":69,"alternative-id":["10.1145\/3694715.3695982","10.1145\/3694715"],"URL":"https:\/\/doi.org\/10.1145\/3694715.3695982","relation":{},"subject":[],"published":{"date-parts":[[2024,11,4]]},"assertion":[{"value":"2024-11-15","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}