Speaker
Puneet Sood
(Google)
Description
We discuss standard and non-standard mechanisms for protecting DNS queries against cache poisoning attacks between resolvers and name servers. The techniques covered include DNS cookies, 0x20 bit munging, nonce prefixes and DNS over TLS/QUIC. We present data from implementing these techniques in Google Public DNS and some interesting behaviors observed during the implementation.
The talk builds on the material covered at
https://developers.google.com/speed/public-dns/docs/security.
Presentation delivery | In-person at the workshop venue |
---|
Primary authors
Puneet Sood
(Google)
Mr
Tianhao Chi
(Google)