This commit is contained in:
John Gatward committed 2026-10-04 15:24:17 +01:00
1 parent d0f27f276b
commit d6f54d4ec2
103 files changed
+3663 -3779

No files matched your search

+37 -37
View File
@@ -1,6 +1,6 @@
# Naming
IPs are not human readable.
IPs are not human-readable.
Not always the appropriate granularity
@@ -10,11 +10,11 @@ Not always the appropriate granularity
A file maps names to addresses
- Unix & Linux
- `/etc/hosts`
- `/etc/hosts`
- Windows
- `C:\Windows\System32\drivers\etc\hosts`
- `C:\Windows\System32\drivers\etc\hosts`
These are simple but neither automatic or scalable which led to **DNS**.
These are simple but neither automatic nor scalable, which led to **DNS**.
- Was initially `RFC882`
- Now is `RFC1035, 1987`
@@ -22,24 +22,24 @@ These are simple but neither automatic or scalable which led to **DNS**.
DNS is a consistent namespace
- No reference to addresses, routes etc
- Is hierarchical, distributed & cache
- All of which to help with scalability
- Is hierarchical, distributed and cached
- All of which help with scalability
- **Federated** - sources control trade-off
- This just means DNS are worldwide
- **Flexible** - many record
- This just means DNS is worldwide
- **Flexible** - many records
- Simple client-server name resolution protocol
#### Components
- *Domain name space* and *resource records*
- Tree structured name space
- Data associated with names
- Tree-structured name space
- Data associated with names
- *Name server*
- Contains records for a sub tree
- May cache information about any part of the tree
- Contains records for a subtree
- May cache information about any part of the tree
- Resolver
- Extract information from tree upon client requests
- `gethostbyname()`
- Extracts information from the tree upon client requests
- `gethostbyname()`
![img](img/aa.png)
@@ -48,26 +48,26 @@ DNS is a consistent namespace
- Ultimate authority with the US Dept. of commerce (NITA)
- Managed by IANA, operated by ICANN, maintained by Verisign
- Started with only thirteen root server clusters
- Now much more
- Top level Domains, TLDs
- Operated by registrars, delegated by ICANN
- Now many more
- Top-level domains, TLDs
- Operated by registrars, delegated by ICANN
- Delegate zones to other registrars
- and so on down the hierarchy
- Eventually customer rents a name - their **zone**
- Registrar installs appropriate *resource records*
- Associated with names within the zone
- and so on down the hierarchy
- Eventually, a customer rents a name - their **zone**
- Registrar installs appropriate *resource records*
- Associated with names within the zone
#### Query
- Query generated by resolver
- e.g. call to `gethostbyname()`, `gethostbyaddr()`
- e.g. call to `gethostbyname()`, `gethostbyaddr()`
- Carried in single UDP/53 packet
- Or more rarely TCP/53 in case of truncation
- UDP is not smart and therefore does not follow traffic routing (it is selfish)
- It is beneficial for the internet as a whole to use UDP sometimes
- Or more rarely TCP/53 in case of truncation
- UDP is not smart and therefore does not follow traffic routing (it is selfish)
- It is beneficial for the internet as a whole to use UDP sometimes
- Header followed by question
- ID, Q/R, opcode, AA/TC/RD/RA, response code, counts
- Query type, query class, query name
- ID, Q/R, opcode, AA/TC/RD/RA, response code, counts
- Query type, query class, query name
Response consists of three RRsets following the header and question
@@ -113,27 +113,27 @@ nott.ac.uk. 3600 IN MX 2 mx192.emailfiltering.com.
nott.ac.uk 3600 IN MX 3 mx193.emailfiltering.com.
```
What happens when the resolver queries a server that doesn't know the answer? two solutions:
What happens when the resolver queries a server that doesn't know the answer? There are two solutions:
1. **Iterative** (required)
- Server responds indicating who to ask next
- This method is slower and more difficult to retrieve an answer
- Server responds indicating who to ask next
- This method is slower and more difficult to retrieve an answer
1. **Recursive** (optional)
- Server generates a new query to the next server
- Server generates a new query to the next server
![img](img/ab.png)
#### Load Balancing
DNS may have multiple servers, when a query comes various algorithms can be used to choose the best one, this can be geographical location.
DNS may have multiple servers. When a query arrives, various algorithms can be used to choose the best one, for example, based on geographical location.
#### Operational & Security Issues
- Usually need primary and secondary servers
- Separate IP netblocks, physical networks - more robust
- DNS is a *very* common single point of failure
- Separate IP netblocks, physical networks - more robust
- DNS is a *very* common single point of failure
- Cache poisoning
- Caching and soft-state means bad data propagates and can persist for some time
- Even if through simple mistakes (or of course malicious attacks)
- Caching and soft-state means bad data propagates and can persist for some time
- Even if through simple mistakes (or of course malicious attacks)
- Man-in-the-middle attacks
- Can happen with both iterative & recursive queries
- Can happen with both iterative & recursive queries