1、DNS加密協議發展及部署現狀 劉保君 清華大學網絡科學與網絡空間研究院 2020年08月12日 An EndAn End- -toto- -End, LargeEnd, Large- -Scale Scale Measurement of DNSMeasurement of DNS- -overover- -Encryption: Encryption: How Far Have We Come? Chaoyi Lu, BaojunBaojun LiuLiu, Zhou Li, Shuang Hao, Haixin Duan, Mingming Zhang, Chunying Leng, Yi
2、ng Liu, Zaifeng Zhang, Jianping Wu The start of Internet activities. .which says a lot about you. Domain Name System 3 DNS ClientResolver Authoritative server ? 42.81.56.61 ? ? ? Where are the risks? DNS Privacy 4 DNS ClientResolver Authoritative server Eavesdropper MITM interception Rogue server Pe
3、ople could be watching our queries. DNS Privacy 5 RFC 7626 on DNS privacy The MORECOWBELL surveillance program of NSA People could be watching our queries. And do stuff like: DNS Privacy 6 Device Fingerprinting Chang 15 User behavior Analysis Kim 15 User Tracking Kirchler 16 DNS Privacy: What Has Been Done? Three IETF WGs.Three IETF WGs. Three standardized protocols.Three standardized protocols. M