<?xml version="1.0" standalone="no"?>
                    <!DOCTYPE div SYSTEM "/www/backend/www-xml-443/dtd/caidaML.dtd">
                    <!-- do NOT ERASE the DOCTYPE declaration! --><div>


<tr bgcolor="#f4f4f4">
  <td>
<font face="helvetica,arial" size="2">
<b>URL:</b>
</font>
</td>
  <td>
<font face="helvetica,arial" size="2">
<a href="http://www.caida.org/publications/papers/2003/dnsspectroscopy/">http://www.caida.org/publications/papers/2003/dnsspectroscopy/</a>
</font>
  </td>
</tr>


<tr bgcolor="#e9e9e9">
  <td>
<font face="helvetica,arial" size="2">
<b>Entry Date:</b>
</font>
</td>
  <td>
<font face="helvetica,arial" size="2">
2003-01-30


</font>
  </td>
</tr>


<tr bgcolor="#f4f4f4">
  <td>
<font face="helvetica,arial" size="2">
<b>Abstract:</b>
</font>
</td>
  <td>
<font face="helvetica,arial" size="2">
<p>
We study attempts to dynamically update DNS records for
private (RFC1918) addresses, by analyzing the frequency
spectrum of updates observed at an authoritative name-
server for these addresses. Using a discrete autocorrelation
algorithm we found that updates series have periods of 60
or 75 minutes, which we identied as default settings of out-
of-the-box Microsoft Windows 2000 and XP DNS software.
</p>


</font>
  </td>
</tr>


<tr bgcolor="#e9e9e9">
  <td>
<font face="helvetica,arial" size="2">
<b>Datasets:</b>
</font>
</td>
  <td>
<font face="helvetica,arial" size="2">
<p>
We use the BIND logs of attempted DNS updates to RFC1918 zones.
The logs were collected at the blackhole server
(prisoner.iana.org) located in topological proximity of
the Palo Alto instance of F-root DNS server.
</p>


</font>
  </td>
</tr>


<tr bgcolor="#f4f4f4">
  <td>
<font face="helvetica,arial" size="2">
<b>Experiments:</b>
</font>
</td>
  <td>
<font face="helvetica,arial" size="2">
<p>
We installed several versions of Widows 2000 and Windows XP
(desctop and server editions) including original release,
Service Pack (SP) 1 and SP 2 and confirmed in laboratory setting
that the default behavior of Windows is to send dynamic DNS
updates with the periods that we identified by spectral analysis
of BIND logs.
</p>


</font>
  </td>
</tr>


<tr bgcolor="#e9e9e9">
  <td>
<font face="helvetica,arial" size="2">
<b>Results:</b>
</font>
</td>
  <td>
<font face="helvetica,arial" size="2">
<p>
Using a combination of spectroscopy and laboratory experiment 
we prove that the majority of DNS updates to RFC1918 zones
(i.e. attempts to associate names with private addresses
like 192.168.1.1) at public blackhole DNS servers are originated
by the Windows 200 and XP DNS software.
</p>


</font>
  </td>
</tr>


<tr bgcolor="#f4f4f4">
  <td>
<font face="helvetica,arial" size="2">
<b>References:</b>
</font>
</td>
  <td>
<font face="helvetica,arial" size="2">
<p>
The paper expands the results of Evi Nemeth published in
N.Brownlee, kc claffy, and E.Nemeth. DNS Measurements at a Root Server.
Globecom, 2001.
</p>

<p>
In terms of methods, it develops the network spectroscopy approach
advocated in: A.Broido, R.King, E.Nemeth, kc claffy
"Radon spectroscopy of inter-packet delay", IEEE High Speed
Networking (HSN) Workshop, Sna Francisco, March 2003.
</p>

<p>
The RFC1918 private addresses are defined in:
Y.Rekhter, B.Moskovitz, D.Carrenberg, G.J.de Groot, K.Lear.
RFC 1918 - Address Allocation for Private Internets.
</p>

<p>
Full version of this paper:
A.Broido, E.Nemeth, and kc claffy, 
"Spectroscopy of Private DNS Update Sources",
Proceedings of the Workshop on Internet
Applications (WIAPP), San Jose, June 2003.
</p>



</font>
  </td>
</tr>
</div>
