highlight: damage in the DNS system if you think that's bad, you should see how bad baseline is analysis of 24 hours of traffic at f-root http://www.nanog.org/mtg-0210/ppt/duane.pdf only about 2% of the observed traffic to a root server appears to be "legitimate" queries! part of larger CAIDA DNS research efforts (another talk) http://www.caida.org/projects/dns-analysis/ continuous monitoring of the DNS root servers performance analysis of bogus queries and broken resolver configurations investigation and modeling of BIND algorithm behavior evaluation and optimization of root servers' placement tools for measuring (you can play too!) dnstop: www.caida.org/tools/measurement/dnstop/ dnstat: www.caida.org/tools/measurement/dnstat/