TY - GEN
T1 - Resiliency Trade-Offs of DNSSEC Configurations to DDoS Attacks
AU - Dubnikov, Daniel
AU - Afek, Yehuda
AU - Bremler-Barr, Anat
N1 - Publisher Copyright: © The Author(s), under exclusive license to Springer Nature Switzerland AG 2026.
PY - 2026
Y1 - 2026
N2 - First this paper measures and analyzes various trade-offs between different DNSSEC configurations, such as, NSEC, NSEC3, aggressive caching, and online vs. offline signing. These measurements expose a trade-off between (1) aggressive caching DNSSEC configuration that provides excellent performance (higher robustness to DDoS attacks) but is vulnerable to zone enumeration attacks in addition to offline signing disadvantages, and (2) online signing DNSSEC configuration, that prevent zone enumeration but is more susceptible to DDoS attacks due to lower maximum throughput. Second, following these, we suggest and evaluate an alternative, Adaptive DNS over QUIC, (AdaDoQ), an adaptive, efficient and secure communication layer between a DNS resolver and the authoritative servers, that offers a better trade-off between DDoS resiliency and security. Under normal load conditions the resolver communicates with each authoritative server with standard DNSSEC however, when the traffic load increases, AdaDoQ switches to a QUIC connection with heavily communicating authoritative server(s), for as long as the traffic load is high. The public key of the authoritative ZSK (which is verifiable through the DNSSEC chain of trust) is integrated into the symmetric key creation in QUIC to provide a DNSSEC level of authenticity and security. AdaDoQ ensures DNS authenticity, good throughput, and disables zone walking attacks, DNS hijacking, and cache poisoning.
AB - First this paper measures and analyzes various trade-offs between different DNSSEC configurations, such as, NSEC, NSEC3, aggressive caching, and online vs. offline signing. These measurements expose a trade-off between (1) aggressive caching DNSSEC configuration that provides excellent performance (higher robustness to DDoS attacks) but is vulnerable to zone enumeration attacks in addition to offline signing disadvantages, and (2) online signing DNSSEC configuration, that prevent zone enumeration but is more susceptible to DDoS attacks due to lower maximum throughput. Second, following these, we suggest and evaluate an alternative, Adaptive DNS over QUIC, (AdaDoQ), an adaptive, efficient and secure communication layer between a DNS resolver and the authoritative servers, that offers a better trade-off between DDoS resiliency and security. Under normal load conditions the resolver communicates with each authoritative server with standard DNSSEC however, when the traffic load increases, AdaDoQ switches to a QUIC connection with heavily communicating authoritative server(s), for as long as the traffic load is high. The public key of the authoritative ZSK (which is verifiable through the DNSSEC chain of trust) is integrated into the symmetric key creation in QUIC to provide a DNSSEC level of authenticity and security. AdaDoQ ensures DNS authenticity, good throughput, and disables zone walking attacks, DNS hijacking, and cache poisoning.
KW - DDoS Attacks
KW - DNS
KW - DNSSEC
KW - QUIC
KW - Security
UR - https://www.scopus.com/pages/publications/105023412561
U2 - 10.1007/978-3-032-10759-6_17
DO - 10.1007/978-3-032-10759-6_17
M3 - منشور من مؤتمر
SN - 9783032107589
T3 - Lecture Notes in Computer Science
SP - 263
EP - 283
BT - Cyber Security, Cryptology, and Machine Learning - 9th International Symposium, CSCML 2025, Proceedings
A2 - Akavia, Adi
A2 - Dolev, Shlomi
A2 - Lysyanskaya, Anna
A2 - Puzis, Rami
PB - Springer Science and Business Media Deutschland GmbH
T2 - 9th International Symposium on Cyber Security, Cryptology, and Machine Learning, CSCML 2025
Y2 - 4 December 2025 through 5 December 2025
ER -