The Internet Engineering Task Force is standardizing new DNS resource records, namely SVCB and HTTPS. Both records inform clients about endpoint and service properties such as supported application layer protocols, IP address hints or Encrypted Client Hello (ECH) information. Therefore, they allow clients to reduce required DNS queries and potential retries during connection establishment and thus help to improve the quality of experience and privacy of the client. The latter is achieved by reducing visible meta-data, which is further improved with encrypted DNS and ECH. The standardization is in its final stages and companies announced support, e.g., Cloudflare and Apple. Therefore, we provide the first large-scale overview of actual record deployment by analyzing more than 400 M domains. We find 3.96 k SVCB and 10.5 M HTTPS records. As of March 2023, Cloudflare hosts and serves most domains, and most records only contain Application-Layer Protocol Negotiation (ALPN) and IP address hints. Besides Cloudflare, we see adoption by a variety of authoritative name servers and hosting providers indicating increased adoption in the near future. Lastly, we can verify the correctness of records for more than 93 % of domains based on three application layer scans.
翻译:互联网工程任务组正在标准化新的DNS资源记录,即SVCB和HTTPS。这两类记录可向客户端通报端点和服务的属性,例如所支持的应用程序层协议、IP地址提示或加密客户端问候信息。因此,它们允许客户端在连接建立期间减少所需的DNS查询和潜在重试,从而有助于提升客户端的体验质量和隐私保护。后者通过减少可见元数据实现,而加密DNS和ECH可进一步增强这一效果。标准化工作已进入最终阶段,Cloudflare和Apple等公司已宣布提供支持。为此,我们通过分析超过4亿个域名,首次大规模呈现了实际记录部署情况。研究发现3.96K个SVCB记录和1050万个HTTPS记录。截至2023年3月,Cloudflare托管并服务于大多数域名,且多数记录仅包含应用层协议协商和IP地址提示。除Cloudflare外,我们观察到各类权威域名服务器和托管服务提供商亦在采用该技术,表明短期内采用率有望提升。最后,基于三次应用层扫描,可验证超过93%域名的记录正确性。