DNS Infrastructure & Naming Conventions
A Deep Dive Into DNS Packet Sizes: Why Smaller Packet Sizes Keep The Internet Safe

A Deep Dive Into DNS Packet Sizes: Why Smaller Packet Sizes Keep The Internet Safe

3/4/2016 · Dani Grant

What this post added

This post details Cloudflare's technical approach to mitigating DNS amplification attacks by optimizing DNS packet sizes. It introduces the adoption of ECDSA for smaller DNSKEY sets, comparing its size and security benefits to RSA. It also explains the deprecation of the ANY query type and its role in reducing large DNS responses, thereby preventing abuse for DDoS attacks. The post highlights the use of assembler optimizations for ECDSA signing speed and the creation of an Internet Draft to standardize the deprecation of ANY queries.

Read the original post ↗