Google Public DNS’s approach to fight against cache poisoning attacks
ID: 40f4210b-5aeb-56b7-98c8-020bae9d6a15
STIX ID: report--40f4210b-5aeb-56b7-98c8-020bae9d6a15
Feed Name: Google Online Security Blog
Google Public DNS details its multi-layer defenses against DNS cache poisoning, including RFC 5452 source port/ID randomization, selective DNS Cookies (RFC 7873), global default 0x20 query name case randomization now covering over 90% of UDP traffic, and deployment of recursive-to-authoritative DNS-over-TLS per RFC 9539 (about 6% of egress), with exceptions and fallbacks for nonconformant servers; the post reports real-world effectiveness and urges DNS operators to adopt these mechanisms to strengthen DNS security.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
