Casey T. Deccio

dblp:69/6101 · DBLP profile ↗
← Back
19ranked-venue papers
9as first author
10since 2021 · last 2025
0000-0003-0938-375XORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 14 · 9 first-author · 6 since 2021Security and privacy · 5 · 4 since 2021
YearPublicationVenuePosition
2025 Modeling DNS Queries and Caching to Evaluate the Merits of QNAME Minimization
abstract
QNAME minimization is an extension to the DNS protocol, designed to allow DNS resolvers to prevent disclosure of DNS activity beyond that which is necessary for resolution. Since it was originally proposed in 2014, QNAME minimization has been incorporated into most of the well-known DNS resolvers. But the question remains: how effective is QNAME minimization at preserving privacy in practice? We answer that question by creating a model that defines DNS privacy roles and quantifies information leakage to third parties. We apply that model to DNS query data from a large university. We observe that QNAME minimization adds modest privacy gains and suggest that its benefits be considered alongside its costs.
Casey T. Deccio, Nathaniel Bennett, Nathan Craddock
ICNP1
2025 Decoding DNSSEC Errors at Scale: An Automated DNSSEC Error Resolution Framework using Insights from DNSViz Logs
abstract
Low adoption and high misconfiguration rates continue to blunt the security benefits of DNSSEC. Drawing on 1.1M historical diagnostic snapshots covering 319K second-level and their subdomains between 2020 and 2024 from the DNSViz service, this paper delivers the first longitudinal, data-driven taxonomy of real-world DNSSEC failures. The study shows that NSEC3 misconfigurations, delegation failures and missing/expired signatures account for more than 70% of all bogus states, and that 18% of such domains remain broken.
Md. Ishtiaq Ashiq, Olivier Hureau, Casey T. Deccio, Taejoong Chung
IMC3
2023 TTL Violation of DNS Resolvers in the Wild
Protick Bhowmick, Md. Ishtiaq Ashiq, Casey T. Deccio, Taejoong Chung
PAM3
2023 Fourteen Years in the Life: A Root Server's Perspective on DNS Resolver Security
Alden Hilton, Casey T. Deccio, Jacob Davis
USENIX Security Symposium2
2022 SPFail: discovering, measuring, and remediating vulnerabilities in email sender validation
abstract
Email is an important medium for Internet communication. Secure email infrastructure is therefore of utmost importance. In this paper we discuss two software vulnerabilities discovered in libSPF2, a library used by mail servers across the Internet for email sender validation with the Sender Policy Framework (SPF). We describe a technique to remotely detect the vulnerabilities in a production mail server, and we use that technique to quantify the vulnerability of Internet mail servers. We also monitor the patch rate of affected servers by performing continuous measurement over a period of roughly four months. We identify thousands of vulnerable mail servers, some associated with high-profile mail providers. Even after private notifications and public disclosure of the vulnerabilities roughly 80% of the vulnerable servers remain vulnerable.
Nathaniel Bennett, Rebekah Sowards, Casey T. Deccio
IMC3
2022 Mirrors in the Sky: On the Potential of Clouds in DNS Reflection-based Denial-of-Service Attacks
abstract
Clouds are likely to be well-provisioned in terms of network capacity by design. The rapid growth of cloud-based services means an increased availability of network infrastructure for all types of customers. However, it could also provide attackers opportunity to misuse cloud infrastructure to bring about attacks, or to target the cloud infrastructure itself.
Ramin Yazdani, Alden Hilton, Jeroen van der Ham, Roland van Rijswijk-Deij, Casey T. Deccio, Anna Sperotto, Mattijs Jonker
RAID5
2022 Beware of IPs in Sheep's Clothing: Measurement and Disclosure of IP Spoofing Vulnerabilities
abstract
Networks not employing destination-side source address validation (DSAV) expose themselves to a class of pernicious attacks which could be prevented by filtering inbound traffic purporting to originate from within the network. In this work, we survey the pervasiveness of networks vulnerable to infiltration using spoofed addresses internal to the network. We issue recursive Domain Name System (DNS) queries to a large set of known DNS servers world-wide using various spoofed-source addresses. In late 2019, we found that 49% of the autonomous systems we tested lacked DSAV. After a large-scale notification campaign run in late 2020, we repeated our measurements in early 2021 and found that 44% of ASes lacked DSAV—though importantly, as this is an observational study, we cannot conclude causality. As case studies illustrating the dangers of a lack of DSAV, we measure susceptibility of DNS resolvers to cache poisoning attacks and the NXNS attack, two attacks whose attack surface is significantly reduced when DSAV in place. We discover 309K resolvers vulnerable to the NXNS attack and 4K resolvers vulnerable to cache poisoning attacks, 70% and 59% of which would have been protected had DSAV been in place.
Alden Hilton, Joel Hirschmann, Casey T. Deccio
IEEE/ACM Trans. Netw.3
2021 Measuring email sender validation in the wild
abstract
Email is a critical Internet application, and its security is important. The Sender Policy Framework (SPF), DomainKeys Identified Mail (DKIM), and Domain-based Message Authentication, Reporting, and Conformance (DMARC) were developed to enable mail servers to detect and reject email coming from fraudulent sources. In this paper we study the state of SPF, DKIM, and DMARC validation across a large number of mail servers, the first such study at scale that we know of. We consider two behaviors of sender-validating mail servers: behavior when an email with a valid sender is received and behavior when an email from a invalid sender is received. Our techniques allow us to elicit SPF, DKIM, and DMARC validation behavior of the servers without spam. We find that as many as 85% of mail servers are deploying SPF validation, and over half are deploying all three mechanisms: SPF, DKIM, and DMARC. We also observe there are some nuanced behaviors with regard to adherence to the SPF specification.
Casey T. Deccio, Tarun Kumar Yadav, Nathaniel Bennett, Alden Hilton, Michael Howe, Tanner Norton, Jacob Rohde, Eunice Tan, Bradley Taylor
CoNEXT1
2021 Advertising DNS Protocol Use to Mitigate DDoS Attacks
abstract
The Domain Name System (DNS) has been frequently abused for distributed denial-of-service (DDoS) attacks and cache poisoning because it relies on the User Datagram Protocol (UDP). Since UDP is connection-less, it is trivial for an attacker to spoof the source of a DNS query or response. While other secure transport mechanisms provide identity management, such as the Transmission Control Protocol (TCP) and DNS Cookies, there is currently no method for a client to state that they only use a given protocol. This paper presents a new method to allow protocol enforcement: DNS Protocol Advertisement Records (DPAR). Advertisement records allow Internet Protocol (IP) address subnets to post a public record in the reverse DNS zone stating which DNS mechanisms are used by their clients. DNS servers may then look up this record and require a client to use the stated mechanism, in turn preventing an attacker from sending spoofed messages over UDP. In this paper, we define the specification for DNS Protocol Advertisement Records, considerations that were made, and comparisons to alternative approaches. We additionally estimate the effectiveness of advertisements in preventing DDoS attacks and the expected burden to DNS servers.
Jacob Davis, Casey T. Deccio
ICNP2
2021 A Peek into the DNS Cookie Jar - An Analysis of DNS Cookie Use
Jacob Davis, Casey T. Deccio
PAM2
2020 Behind Closed Doors: A Network Tale of Spoofing, Intrusion, and False DNS Security
abstract
Networks not employing destination-side source address validation (DSAV) expose themselves to a class of pernicious attacks which could be easily prevented by filtering inbound traffic purporting to originate from within the network. In this work, we survey the pervasiveness of networks vulnerable to infiltration using spoofed addresses internal to the network. We issue recursive Domain Name System (DNS) queries to a large set of known DNS servers worldwide, using various spoofed-source addresses. We classify roughly half of the 62,000 networks (autonomous systems) we tested as vulnerable to infiltration due to lack of DSAV. As an illustration of the dangers these networks expose themselves to, we demonstrate the ability to fingerprint the operating systems of internal DNS servers. Additionally, we identify nearly 4,000 DNS server instances vulnerable to cache poisoning attacks due to insufficient---and often non-existent---source port randomization, a vulnerability widely publicized 12 years ago.
Casey T. Deccio, Alden Hilton, Michael Briggs, Trevin Avery
Internet Measurement Conference1
2019 DNS privacy in practice and preparation
abstract
An increased demand for privacy in Internet communications has resulted in privacy-centric enhancements to the Domain Name System (DNS), including the use of Transport Layer Security (TLS) and Hypertext Transfer Protocol Secure (HTTPS) for DNS queries. In this paper, we seek to answer questions about their deployment, including their prevalence and their characteristics. Our work includes an analysis of DNS-over-TLS (DoT) and DNS-over-HTTPS (DoH) availability at open resolvers and authoritative DNS servers. We find that DoT and DoH services exist on just a fraction of open resolvers, but among them are the major vendors of public DNS services. We also analyze the state of TCP Fast Open (TFO), which is considered key to reducing the latency associated with TCP-based DNS queries, required by DoT and DoH. The uptake of TFO is extremely low, both on the server side and the client side, and it must be improved to avoid performance degradation with continued adoption of DNS Privacy enhancements.
Casey T. Deccio, Jacob Davis
CoNEXT1
2019 On DNSSEC Negative Responses, Lies, and Zone Size Detection
Jonathan Demke, Casey T. Deccio
PAM2
2012 Quantifying DNS namespace influence
Casey T. Deccio, Jeff Sedayao, Krishna Kant 0001, Prasant Mohapatra
Comput. Networks1
2011 Quantifying and Improving DNSSEC Availability
abstract
The Domain Name System (DNS) is a foundational component of today's Internet for mapping Internet names to addresses. With the DNS Security Extensions (DNSSEC) DNS responses can be cryptographically verified to prevent malicious tampering. The protocol complexity and administrative overhead associated with DNSSEC can significantly impact the potential for name resolution failure. We present metrics for assessing the quality of a DNSSEC deployment, based on its potential for resolution failure in the presence of DNSSEC misconfiguration. We introduce a metric to analyze the administrative complexity of a DNS configuration, which contributes to its failure potential. We then discuss a technique which uses soft anchoring to increase robustness in spite of misconfigurations. We analyze a representative set of production signed DNS zones and determine that 28% of the validation failures we encountered would be mitigated by the soft anchoring technique we propose.
Casey T. Deccio, Jeff Sedayao, Krishna Kant 0001, Prasant Mohapatra
ICCCN1
2010 Measuring Availability in the Domain Name System
abstract
The domain name system (DNS) is critical to Internet functionality. The availability of a domain name refers to its ability to be resolved correctly. We develop a model for server dependencies that is used as a basis for measuring availability. We introduce the minimum number of servers queried (MSQ) and redundancy as availability metrics and show how common DNS misconfigurations impact the availability of domain names. We apply the availability model to domain names from production DNS and observe that 6.7% of names exhibit sub-optimal MSQ, and 14% experience false redundancy. The MSQ and redundancy values can be optimized by proper maintenance of delegation records for zones.
Casey T. Deccio, Jeff Sedayao, Krishna Kant 0001, Prasant Mohapatra
INFOCOM1
2009 Quality of Name Resolution in the Domain Name System
abstract
The domain name system (DNS) is integral to today's Internet. Name resolution for a domain is often dependent on servers well outside the control of the domain's owner. In this paper we propose a formal model for analyzing the name dependencies inherent in DNS, based on protocol specification and actual implementations. We derive metrics to quantify the extent to which domain names affect other domain names. It is found that under certain conditions, the name resolution for over one-half of the queries exhibits influence of domains not expressly configured by administrators. This result serves to quantify the degree of vulnerability of DNS due to dependencies that administrators are unaware of. The model presented in the paper also shows that the set of domains whose resolution affects a given domain name is much smaller than previously thought. The model also shows that with caching of NS target addresses, the number of influential domains expands greatly, thereby making the DNS infrastructure more vulnerable.
Casey T. Deccio, Chao-Chih Chen, Jeff Sedayao, Krishna Kant 0001, Prasant Mohapatra
ICNP1
2004 Aggressive telecommunications overbooking ratios
abstract
The Internet is comprised of vast networks of wires and fiber. A common misconception is that there is an unlimited amount of bandwidth; in reality there exists only a finite amount. Each length of wire and fiber is owned by a company, and every company wants to maximize its profit. One means of improving profit is to overbook existing transmission lines in order to increase income without increasing expenses. If too much overbooking is performed, the quality of service (QoS) seen by customers declines. This paper explains a process to achieve an optimal overbooking ratio (OR) for admission control in network routers. By optimizing the overbooking ratio, profits can be increased while minimizing QoS problems for users.
Robert Ball, Mark J. Clement, Quinn Snell, Casey T. Deccio
IPCCC5
2003 A study of the suitability of IrOBEX for high-speed exchange of large data objects
abstract
This paper demonstrates that careful tuning of the OBEX and IrLAP negotiated parameters allows OBEX to scale well for use with large data objects and high transmission rates. Due to the substantial time overhead inherent in link turnarounds, minimizing turnarounds during the transmission of a large object helps to maximize link efficiency. The IrLAP window size and OBEX packet size significantly impact the number of required turnarounds during the transmission of a large object. When these parameters are properly tuned, maximum throughput can be achieved, and OBEX performs efficiently at high data rates.
Casey T. Deccio, Joseph J. Ekstrom, D. Ryan Partridge, Kevin Tew, Charles D. Knutson
GLOBECOM1