FINDING · EVALUATION

A prototype Hold-On DNS proxy introduced no perceptible additional latency for either cached or uncached DNS queries in live testing; query-time measurements for both sets of names overlapped entirely with baseline (Hold-On disabled) measurements. The Hold-On timer (set to 5 seconds initial, 10s second try, 15s third try) is only reached under anomalous conditions; under normal operation the resolver returns as soon as the legitimate reply validates.

From 2012-duan-hold-onHold-On: Protecting Against On-Path DNS Poisoning · §V.B · 2012 · Securing and Trusting Internet Names

Implications

Tags

techniques
dns-poisoning

Extracted by claude-sonnet-4-6 — review before relying.