FINDING · EVALUATION

Among Iris's DNS manipulation detection metrics, AS-level consistency was most effective, classifying 90% of DNS responses as unmanipulated. IP-address identity matching flagged approximately 80% of correct responses, while HTTPS certificate validation improved from 38% to 55% accuracy when SNI was included in follow-up TLS probes.

From 2017-pearce-globalGlobal Measurement of DNS Manipulation · §5.1, Figure 3 · 2017 · USENIX Security Symposium

Implications

Tags

techniques
dns-poisoningmeasurement-platform

Extracted by claude-sonnet-4-6 — review before relying.