In this paper, we study the performance of encrypted DNS protocols and conventional DNS from thousands of home networks in the United States, over one month in 2020. We perform these measurements from the homes of 2,693 participating panelists in the Federal Communications Commission's (FCC) Measuring Broadband America program. We found that clients do not have to trade DNS performance for privacy. For certain resolvers, DoT was able to perform faster than DNS in median response times, even as latency increased. We also found significant variation in DoH performance across recursive resolvers. Based on these results, we recommend that DNS clients (e.g., web browsers) should periodically conduct simple latency and response time measurements to determine which protocol and resolver a client should use. No single DNS protocol nor resolver performed the best for all clients.
翻译:在本文中,我们研究了美国数千家家庭网络加密DNS协议和常规DNS的性能,2020年超过一个月。我们从联邦通信委员会(FCC)测量宽带美国方案的2 693名参与小组成员的家中进行这些测量。我们发现客户不必将DNS的性能用于隐私交易。对于某些解决者来说,即使延缓性能增加,但DT在中位反应时间比DNS的性能更快。我们还发现,在DH的性能方面,重复性决定者之间的性能差异很大。基于这些结果,我们建议DNS客户(例如网络浏览器)应定期进行简单的延时和反应时间测量,以确定客户应使用什么协议和确定者。没有单一的DNS协议,也没有解决者为所有客户提供最好的服务。