Abstract
The present study endeavors to enhance DNS over TLS performance via the development of an Adaptive Transport Layer Security Model (ad-TLSM). DNS over TLS, which employs TLS encryption to safeguard communication between clients and DNS recursive resolvers, suffers from performance issues that pose significant challenges. In response to these issues, the ad-TLSM has been designed to boost DNS performance by integrating a monitoring mechanism for real-time observation of the DNS recursive resolver. During the TLS handshake, crucial data, including throughput, CPU load, and the active cryptographic algorithm, are meticulously monitored and documented. This data forms the foundation for an adaptive strategy, which facilitates intelligent security adaptation during runtime, based on the prevailing conditions between the client and the server at the time of secure connection establishment. The performance evaluation of the ad-TLSM demonstrated that the DNS recursive resolver experiences excessive load while employing AES-GCM 256. However, it was found capable of managing an additional 15%-25% requests per second when ChaCha20 was implemented. These findings led to the formation of an adaptive strategy that effectively alleviates CPU load by adjusting the security level, thereby ameliorating the overall performance. In summary, the ad-TLSM surpasses existing models in latency performance and can be employed to improve performance, while satisfying quality of service constraints. This research represents a significant step towards the development of more efficient and secure DNS services.
Author supplied keywords
Cite
CITATION STYLE
Ohwo, O. B., Ayankoya, F. Y., Ajayi, O. F., & Alao, D. O. (2023). Advancing DNS Performance Through an Adaptive Transport Layer Security Model (ad-TLSM). Ingenierie Des Systemes d’Information, 28(3), 777–790. https://doi.org/10.18280/isi.280329
Register to see more suggestions
Mendeley helps you to discover research relevant for your work.