analysis of DNS packet sizes

analysis of TCP flags

What do DNS flows look like? (e.g., length in bytes, packets, secs, for both TCP, UDP DNS).

Of interest as we track changes in DNS flow profiles as Gilmore/Vixie's new security modifications deploy, which support transmission of authenticated PGP keys (which can get lengthy) via DNS.

(Note there are approximately 100,000 name server resource record target names, and approximately a million owner names in delegations in the COM zone.) We use oc32dns.pl to graph DNS packet length distributions (probability and cumulative).

sample results:


FIX-West