What part of ‘No!’ is so hard for the DNS understand?
APNIC Labs has been experimenting with how DNS handles requests for nonexistent names, aiming to improve resilience against random name attacks by better understanding and strengthening this behavior.
MAIN POINTS
- APNIC Labs is studying DNS responses to nonexistent name queries.
- The goal is to improve DNS resilience against random name attacks.
- Their experiments focus on understanding current DNS handling behavior.
- This work supports making the DNS more robust overall.
TAKEAWAYS
- DNS resilience depends partly on how it manages invalid or nonexistent lookups.
- Random name attacks are a security concern motivating this research.
- Experimental analysis can reveal weaknesses in DNS behavior.
- Improving negative-query handling may strengthen the broader DNS ecosystem.