Published December 20, 2021 | Version v1

Fragmentation, truncation, and timeouts: are large DNS messages falling to bits?

  • 1. SIDN Labs
  • 2. SIDN Labs & University of Twente

Description

The DNS provides one of the core services of the Internet, mapping applications and services to hosts. DNS employs both UDP and TCP as a transport protocol, and currently most DNS queries are sent over UDP. The problem with UDP is that large responses run the risk of not arriving a their destinations – which can ultimately lead to un- reachability. However, it remains unclear how much of a problem these large DNS responses over UDP are in the wild. This is the focus on this paper: we analyze 114 billion queries/response pairs from more than 43k autonomous systems, covering two months and a week period (2019 and 2020), collected at the authoritative servers of the .nl, the country-code top-level domain of the Netherlands. We show that fragmentation, and the problems that can follow fragmentation, rarely occur at such author- itative servers. Further, we demonstrate that DNS built-in defenses – use of truncation, EDNS0 buffer sizes, reduced responses and TCP fall back – are effective to reduce fragmentation. Last, we measure the uptake of the DNS flag day in 2020.

Files

Fragmentation__truncation__and_timeouts_are_large_DNS_messages_falling_to_bits.pdf

Files (1.4 MB)

Additional details

Funding

European Commission
CONCORDIA - Cyber security cOmpeteNCe fOr Research anD InnovAtion 830927