CSpace  > 中国科学院计算技术研究所期刊论文  > 英文
Securing the internet's backbone: A blockchain-based and incentive-driven architecture for DNS cache poisoning defense
Fu, Yufan1,2; Lee, Xiaodong1,3; Wei, Jiuqi1,2; Li, Ying1,2; Peng, Botao1
2024-12-01
发表期刊COMPUTER NETWORKS
ISSN1389-1286
卷号254页码:18
摘要Domain Name System (DNS) is the backbone of the Internet infrastructure, converting human-friendly domain names into machine-processable IP addresses. However, DNS remains vulnerable to various security threats, such as cache poisoning attacks, where malicious attackers inject false information into DNS resolvers' caches. Although efforts have been made to enhance DNS against such vulnerabilities, existing countermeasures often fall short in one or more areas: they may offer limited resistance to the collusion attack, introduce significant overhead, or require complex implementation that hinders widespread adoption. To address these challenges, this paper introduces TI-DNS+, a trusted and incentivized blockchain-based DNS resolution architecture for cache poisoning defense. TI-DNS+ introduces a Verification Cache exploiting blockchain ledger's immutable nature to detect and correct forged DNS responses. The architecture also incorporates a multi-resolver Query Vote mechanism, enhancing the ledger's credibility by validating each record modification through a stake-weighted algorithm. This algorithm selects resolvers as validators based on their stake proportion. To promote well-behaved participation, TI-DNS+ also implements a novel stake-based incentive mechanism that optimizes the generation and distribution of stake rewards. This ensures that incentives align with participants' contributions, achieving incentive compatibility, fairness, and efficiency. Moreover, TI-DNS+ possesses high practicability as it requires only resolver-side modifications to current DNS. Finally, through comprehensive prototyping and experimental evaluations, the results demonstrate that our solution effectively mitigates DNS cache poisoning. Compared to competitors, our solution improves attack resistance by 1-3 orders of magnitude, while also reducing resolution latency by 5% to 68%.
关键词DNS Cache poisoning attack Blockchain Smart contract Incentive mechanism
DOI10.1016/j.comnet.2024.110777
收录类别SCI
语种英语
资助项目National Natural Science Foundation of China[62202450] ; National Natural Science Foundation of China[E051570]
WOS研究方向Computer Science ; Engineering ; Telecommunications
WOS类目Computer Science, Hardware & Architecture ; Computer Science, Information Systems ; Engineering, Electrical & Electronic ; Telecommunications
WOS记录号WOS:001319410300001
出版者ELSEVIER
引用统计
文献类型期刊论文
条目标识符http://119.78.100.204/handle/2XEOYT63/39586
专题中国科学院计算技术研究所期刊论文_英文
通讯作者Lee, Xiaodong
作者单位1.Chinese Acad Sci, Inst Comp Technol, Lab Internet Infrastruct, Beijing, Peoples R China
2.Univ Chinese Acad Sci, Beijing, Peoples R China
3.Fuxi Inst, Heze 274000, Peoples R China
推荐引用方式
GB/T 7714
Fu, Yufan,Lee, Xiaodong,Wei, Jiuqi,et al. Securing the internet's backbone: A blockchain-based and incentive-driven architecture for DNS cache poisoning defense[J]. COMPUTER NETWORKS,2024,254:18.
APA Fu, Yufan,Lee, Xiaodong,Wei, Jiuqi,Li, Ying,&Peng, Botao.(2024).Securing the internet's backbone: A blockchain-based and incentive-driven architecture for DNS cache poisoning defense.COMPUTER NETWORKS,254,18.
MLA Fu, Yufan,et al."Securing the internet's backbone: A blockchain-based and incentive-driven architecture for DNS cache poisoning defense".COMPUTER NETWORKS 254(2024):18.
条目包含的文件
条目无相关文件。
个性服务
推荐该条目
保存到收藏夹
查看访问统计
导出为Endnote文件
谷歌学术
谷歌学术中相似的文章
[Fu, Yufan]的文章
[Lee, Xiaodong]的文章
[Wei, Jiuqi]的文章
百度学术
百度学术中相似的文章
[Fu, Yufan]的文章
[Lee, Xiaodong]的文章
[Wei, Jiuqi]的文章
必应学术
必应学术中相似的文章
[Fu, Yufan]的文章
[Lee, Xiaodong]的文章
[Wei, Jiuqi]的文章
相关权益政策
暂无数据
收藏/分享
所有评论 (0)
暂无评论
 

除非特别说明,本系统中所有内容都受版权保护,并保留所有权利。