uni
To statically add DNS entries on Unix edit /etc/hosts.
2.3 The Domain Name System (DNS) (2.4)
Problem: internet hosts and routers have both an IP address (IP), used for addressing datagrams, and a “name”, used by humans (like www.google.com).
How do we map between IP address and name, and vice versa?The Domain Name System (DNS) is a distributed database implemented in a hierarchy of many DNS servers.
It is also an application-layer protocol that allows hosts to query the distributed database.Registering a subdomain means linking it univocally to an IP address, registering it in the DNS database.
2.3.1 DNS services (2.4.1)
- hostname to IP address translation
- host aliasing: provides alias names for the canonical hostname
- mail server aliasing
- load distribution: replicated web servers: many IP addresses correspond to one name. When a client asks for the resolution for a hostname, the DNS server answers with the whole list of associated IP addresses, but each time in a different order, since the client normally goes for the first in the list.
2.3.2 ICANN
The distributed DNS server is managed by Internet Corporation for Assigned Names and Numbers (ICANN), which defines what the top layer domains* are and accredits the various registrars (read more on registrars below).
2.3.3 DNS structure
The DNS is a distributed, hierarchical database, which can be approximated to these 3 classes of DNS servers:
- ROOT: the client queries the root DNS server to find the IP address of the Top level domain’s DNS server.
- TOP LEVEL DOMAIN: the client queries the top level domain DNS server to find the address of the authoritative DNS server.
- AUTHORITATIVE: the client queries the authoritative DNS server to find the IP address for the desired host.
A distributed structure was chosen because a centralized DNS:
- doesn’t scale
- has a single point of failure (SPF)
- cannot be near every host
- cannot handle that much traffic volume (Comcast DNS servers serve 600B DNS queries per day)
- cannot be easily maintained
ROOT name servers
These servers are the official contact-of-last-resort for name servers that cannot resolve the queried name.
The are 13 logical root name servers worldwide, each server is replicated many times (there are more than 200 root name server in the US alone).Local DNS name servers
Also called default name servers, these do not strictly belong to the hierarchy of servers and are installed into each ISP and they act as a sort of proxy DNS server, they have a local cache of recent name-to-address translations pairs, BUT it may be out of date!
When a host connects to an ISP, the latter provides the host with the IP addresses of one or more of its local DNS servers, typically through DHCP.
When a host makes a DNS query it is sent to its local DNS server which then queries the main hierarchy.DNS caching
DNS caching is essential for reducing the load on the DNS servers and the internet as a whole, given the frequency of such requests.
In a query chain when a DNS server receives a DNS reply, it stores the translation in its local memory, then, when it receives a DNS query for that same host, it replies with its stored translation – if it is recent enough – even if it isn’t an authoritative server for that hostname.Cached translations last for their initial TTL (time-to-live) – which usually is two days – before getting thrashed.
2.3.4 DNS records (2.4.3)
The DNS is a distributed database storing resource records (RR). Each DNS reply contains one or more of these records.
A Resource Record is a 4-tuple that contains these fields:name, value, type, ttl, whose meaning depends on the type of record:
- type=A (address)
- name is a hostname
- value is the associated IP address
- type=NS (name server)
- name is the domain (what you enter in the search bar)
- value is the hostname of the authoritative name server for said domain
- type=CNAME (“canonical name”)
- name is an alias name for some “canonical” name (the real name)
- value is the canonical name for the alias
- type=MX
- value is the name of the mailserver associated with
name- there are even more types
If a server is authoritative for some hostname, it will contain a type A record for it.
If a server is not authoritative for some hostname, it will contain a type NS record for the domain that includes the hostname and it will also contain a type A record that provides the IP address of the DNS server referenced in the NS record.2.3.5 DNS protocol messages (2.4.3)
The first 12 bytes of a DNS message are the header section, of which the first 2 bytes are the DNS query ID, this identifier is copied into the reply message to the query, allowing the client to match received replies with sent queries.
← 2 bytes → ← 2 bytes → query ID flags number of questions number of answer RRs number of authority RRs number of additional RRs question RRs (4 bytes) name and type fields of a query answer RRs (4 bytes) reply RRs authority RRs (4 bytes) RRs for authoritative servers additional info (4 bytes) RRs flags:
- query (0) or reply (1).
- recursion desired; can be set by both hosts and DNS servers.
- recursion available; set by DNS servers who offer recursion.
- reply is authoritative; set by DNS servers when their reply is authoritative.
nslookup: command-line tool to query the DNS server.2.3.6 Name resolution Approaches
Iterated Query
The host first asks the local DNS server, which in turn contacts every required DNS server until resolution, the contacted servers reply with the name of the server to contact and the local DNS server executes.
When the local DNS server has resolved the name, it replies to the host with the answer.This approach is better.
Recursive Query
The host first asks the local DNS server, which in turn contacts the next server (the root), which then asks the next (TLD) eccetera, until resolution.
Every contacted server asks the next, in a chain of queries and answers, until the authoritative server has the answer, at this point every server replies with the answer down the chain, until it arrives to the host.This leads to more load on the servers, apart from the local DNS servers.
2.3.7 Inserting Names into the DNS
To insert a domain in the DNS, the domain name must be registered at a DNS registrar*.Registrars are commercial entities that verify the uniqueness of the domain name and enter it into the DNS database; Network Solutions had the monopoly of most domains until 1999.
To register a name you must create the primary and secondary authoritative DNS servers locally, provide names and IP addresses of your primary and secondary authoritative name server to the Registrar, who then will inserts NS and A records (RRs) into the TLD (top level domain) servers.
Until recently, DNS records had to be manually configured, now a
UPDATEoption has been aded to the DNS protocol, to allow data to be dynamically added or deleted from the database via DNS messages.2.3.8 example of a (iterative) DNS resolution
Requesting host (alice.iet.unipi.it) asks the local DNS server what the IP for www.networkutopia.com is.
Local DNS server contacts the root DNS server, which replies with the IP of the .com DNS server.
Local DNS server now contacts the .com DNS servers, which replies with the IP of the authoritative server for networkutopia.com.
Now the local DNS server contacts the authoritative server, which replies with the information needed, which is now rooted back towards the initial client with finally a reply to the requesting host.2.3.9 DNS security
DNS servers are susceptible to:
- DDoS bandwidth-flooding attacks, who have not been successful to date
- Redirect attacks:
- man-in-the-middle: intercepting DNS queries and return bogus replies to the hosts
- DNS poisoning: sending false replies to the DNS servers, which then get cached
- exploit of DNS for DDoS: spoofing the source IP address of DNS requests so they appear to come from the victim’s IP. When the DNS servers respond, they send the (much larger amplification) replies to the victim, overwhelming it with traffic.
DNSSEC
Redirect Attacks and Exploit DNS for DDoS are accounted for by DNSSEC (domain name system security extensions), which is a set of extensions that add security to the DNS protocol. This works by signing with crypted signatures the DNS records. This guarantees the authenticity and integrity of the replies.
Link to original