Jacob Davis

dblp:204/0452 · DBLP profile ↗
← Back
5ranked-venue papers
3as first author
3since 2021 · last 2023
0000-0002-2372-9203ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 2 · 1 first-author · 1 since 2021Security and privacy · 2 · 1 first-author · 2 since 2021Theory of computation · 1 · 1 first-author
YearPublicationVenuePosition
2023 Fourteen Years in the Life: A Root Server's Perspective on DNS Resolver Security
Alden Hilton, Casey T. Deccio, Jacob Davis
USENIX Security Symposium3
2021 Advertising DNS Protocol Use to Mitigate DDoS Attacks
abstract
The Domain Name System (DNS) has been frequently abused for distributed denial-of-service (DDoS) attacks and cache poisoning because it relies on the User Datagram Protocol (UDP). Since UDP is connection-less, it is trivial for an attacker to spoof the source of a DNS query or response. While other secure transport mechanisms provide identity management, such as the Transmission Control Protocol (TCP) and DNS Cookies, there is currently no method for a client to state that they only use a given protocol. This paper presents a new method to allow protocol enforcement: DNS Protocol Advertisement Records (DPAR). Advertisement records allow Internet Protocol (IP) address subnets to post a public record in the reverse DNS zone stating which DNS mechanisms are used by their clients. DNS servers may then look up this record and require a client to use the stated mechanism, in turn preventing an attacker from sending spoofed messages over UDP. In this paper, we define the specification for DNS Protocol Advertisement Records, considerations that were made, and comparisons to alternative approaches. We additionally estimate the effectiveness of advertisements in preventing DDoS attacks and the expected burden to DNS servers.
Jacob Davis, Casey T. Deccio
ICNP1
2021 A Peek into the DNS Cookie Jar - An Analysis of DNS Cookie Use
Jacob Davis, Casey T. Deccio
PAM1
2019 DNS privacy in practice and preparation
abstract
An increased demand for privacy in Internet communications has resulted in privacy-centric enhancements to the Domain Name System (DNS), including the use of Transport Layer Security (TLS) and Hypertext Transfer Protocol Secure (HTTPS) for DNS queries. In this paper, we seek to answer questions about their deployment, including their prevalence and their characteristics. Our work includes an analysis of DNS-over-TLS (DoT) and DNS-over-HTTPS (DoH) availability at open resolvers and authoritative DNS servers. We find that DoT and DoH services exist on just a fraction of open resolvers, but among them are the major vendors of public DNS services. We also analyze the state of TCP Fast Open (TFO), which is considered key to reducing the latency associated with TCP-based DNS queries, required by DoT and DoH. The uptake of TFO is extremely low, both on the server side and the client side, and it must be improved to avoid performance degradation with continued adoption of DNS Privacy enhancements.
Casey T. Deccio, Jacob Davis
CoNEXT2
2017 Universal graphs at N_ω+1
Jacob Davis
Ann. Pure Appl. Log.1