PREFETCHing to overcome DNSSEC deployment over large resolving platforms - Archive ouverte HAL Accéder directement au contenu
Communication Dans Un Congrès Année : 2013

PREFETCHing to overcome DNSSEC deployment over large resolving platforms

Résumé

Todays' DNS resolving platforms have been designed for DNS with fast and light resolutions over the Internet. With signature checks and larger payload, experimental measurements [10] showed that DNSSEC resolutions require up to 4 times more CPU. While DNSSEC requires more CPU than DNS, this paper proposes PREFETCHX, an architecture that optimizes the use of CPU and thus avoids that resolving platforms increase their size for DNSSEC migration. Current resolving platforms IPXOR split the traffic between the nodes according to the IP addresses. Alternatively, PREFETCHX takes advantage of the FQDN's popularity distribution (Zipf), a layered cache and cache sharing mechanisms between the nodes and requires at least 4 times less nodes. Furthermore PREFETCHX does not impact the network infrastructure which eases its deployment. Then, defining X the number of prefetched FQDNs makes PREFETCHX highly scalable and flexible to different type of traffic
Fichier principal
Vignette du fichier
2013-trustcom-free-pastry-experiment.pdf (1003.29 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)
Loading...

Dates et versions

hal-01262120 , version 1 (26-01-2016)

Identifiants

Citer

Daniel Migault, Stéphane Sénécal, Stanislas Francfort, Emmanuel Herbert, Maryline Laurent. PREFETCHing to overcome DNSSEC deployment over large resolving platforms. TRUSTCOM 2013 : 12th IEEE International Conference on Trust, Security and Privacy in Computing and Communications, Jul 2013, Melbourne, Australia. pp.694 - 703, ⟨10.1109/TrustCom.2013.84⟩. ⟨hal-01262120⟩
95 Consultations
75 Téléchargements

Altmetric

Partager

Gmail Facebook X LinkedIn More