CONTENT-AWARE DNS. IMPROVING CONTENT-AWARE DNS RESOLUTION WITH AKAMAI DNSi CACHESERVE EQUIVALENCE CLASS. AKAMAI DNSi CACHESERVE

Similar documents
AKAMAI WHITE PAPER. Security and Mutual SSL Identity Authentication for IoT. Author: Sonia Burney Solutions Architect, Akamai Technologies

AKAMAI CLOUD SECURITY SOLUTIONS

AKAMAI THREAT ADVISORY. Satori Mirai Variant Alert

SOTI SUMMER [state of the internet] / security ATTACK SPOTLIGHT

THE STATE OF MEDIA SECURITY HOW MEDIA COMPANIES ARE SECURING THEIR ONLINE PROPERTIES

and indeed live most of our lives online. Whether we are enterprise users or endpoint consumers, our digital experiences are increasingly delivered

CIO INSIGHTS Boosting Agility and Performance on the Evolving Internet

THE UTILITY OF DNS TRAFFIC MANAGEMENT

End-user mapping: Next-Generation Request Routing for Content Delivery

OPTIMIZE. MONETIZE. SECURE. Agile, scalable network solutions for service providers.

Survey: Global Efficiency Held Back by Infrastructure Spend in Pharmaceutical Industry

Q&A TAKING ENTERPRISE SECURITY TO THE NEXT LEVEL. An interview with John Summers, Enterprise VP and GM, Akamai

VIDEO ON DEMAND SOLUTION BRIEF

CDN TUNING FOR OTT - WHY DOESN T IT ALREADY DO THAT? CDN Tuning for OTT - Why Doesn t It Already Do That?

John S. Otto Mario A. Sánchez John P. Rula Fabián E. Bustamante

Network Working Group

Distributed Systems. 21. Content Delivery Networks (CDN) Paul Krzyzanowski. Rutgers University. Fall 2018

MULTIPLAYER GAMING SOLUTION BRIEF

Video-Aware Networking: Automating Networks and Applications to Simplify the Future of Video

Top-Down Network Design

AKAMAI SOLUTION BROCHURE CLOUD SECURITY SOLUTIONS FAST RELIABLE SECURE.

is dominated by these trends that characterize the state of all things Business depends on flawless digital experiences. This is true for the

Evidence-based protection of web resources a must under the GDPR. How the Akamai Intelligent Platform helps customers to mitigate risks

Protect vital DNS assets and identify malware

Changing the Voice of

TechValidate Survey Report: SaaS Application Trends and Challenges

NINE MYTHS ABOUT. DDo S PROTECTION

CS November 2018

How to Choose a CDN. Improve Website Performance and User Experience. Imperva, Inc All Rights Reserved

INTRODUCTION OUR SERVICES

Akamai White Paper. FedRAMP SM Helps Government Agencies Jumpstart their Journey to the Cloud. FedRAMP. Federal Risk Authorization Management Program

Considerations and Actions of Content Providers in Adopting IPv6

AKAMAI WHITE PAPER. Enterprise Application Access Architecture Overview

Automating VPN Management

Application-Layer Protocols Peer-to-Peer Systems, Media Streaming & Content Delivery Networks

Cloud DNS. High Performance under any traffic conditions from anywhere in the world. Reliable. Performance

Mitigating DDoS Attacks in Zero Seconds with Proactive Mitigation Controls

DIGITAL TRANSFORMATION IN FINANCIAL SERVICES

From Internet Data Centers to Data Centers in the Cloud

Turbo King: Framework for Large- Scale Internet Delay Measurements

FIGURE 3. Two-Level Internet Address Structure. FIGURE 4. Principle Classful IP Address Formats

DDoS MITIGATION BEST PRACTICES

RADWIN IP Backhaul Solutions. Application Brochure. Meeting the escalating demand for IP backhaul

akamai s [state of the internet] / security

CCNA Exploration Network Fundamentals. Chapter 06 Addressing the Network IPv4

Network Layer (Routing)

Exam - Final. CSCI 1680 Computer Networks Fonseca. Closed Book. Maximum points: 100 NAME: 1. TCP Congestion Control [15 pts]

IP addressing. Overview. IP addressing Issues and solution Variable Length Subnet Mask (VLSM)

AAA Authentication: New Use Cases

Massive Scalability With InterSystems IRIS Data Platform

Web caches (proxy server) Applications (part 3) Applications (part 3) Caching example (1) More about Web caching

Overview of Akamai s Personal Data Processing Activities and Role

Cloudflare CDN. A global content delivery network with unique performance optimization capabilities

MOVE TO A FLEXIBLE IT MODEL ENTERPRISE DATA CENTER SOLUTIONS.

APPLICATION OF POLICY BASED INDEXES AND UNIFIED CACHING FOR CONTENT DELIVERY Andrey Kisel Alcatel-Lucent

31270 Networking Essentials Focus, Pre-Quiz, and Sample Exam Answers

Rock-solid Internet infrastructure. (Yeah, we keep our stuff in bunkers.)

Domain Name System.

Internet Load Balancing Guide. Peplink Balance Series. Peplink Balance. Internet Load Balancing Solution Guide

THE WORLD S BEST- CONNECTED DATA CENTERS EQUINIX MIDDLE EAST & NORTH AFRICA (MENA) Equinix.com

What is the relationship between a domain name (e.g., youtube.com) and an IP address?

CS519: Computer Networks. Lecture 2, part 2: Feb 4, 2004 IP (Internet Protocol)

Chapter 9. Internet. Copyright 2011 John Wiley & Sons, Inc 10-1

Chapter 2 Application Layer

Networked systems and their users

DNS SECURITY BENEFITS OF OUTSOURCING YOUR DNS TO AN IP ANYCAST+ PROVIDER

SmartDNS. Speed: Through load balancing, FatPipe's SmartDNS speeds up the delivery of inbound traffic.

ITTC Science of Communication Networks The University of Kansas EECS 784 Identifiers, Names, and Addressing

Metro Ethernet for Government Enhanced Connectivity Drives the Business Transformation of Government

IT220 Network Standards & Protocols. Unit 9: Chapter 9 The Internet

IPv6 in Asia from Akamai Perspective

Network layer: Overview. Network layer functions IP Routing and forwarding NAT ARP IPv6 Routing

Network Working Group Request for Comments: Category: Best Current Practice October 2008

Video AI Alerts An Artificial Intelligence-Based Approach to Anomaly Detection and Root Cause Analysis for OTT Video Publishers

Content Delivery Networks

Internet Engineering Task Force (IETF) Request for Comments: 7706 Category: Informational ISSN: November 2015

Web Content Cartography. Georgios Smaragdakis Joint work with Bernhard Ager, Wolfgang Mühlbauer, and Steve Uhlig

Network layer: Overview. Network Layer Functions

THE AUTHORITATIVE GUIDE TO DNS TERMINOLOGY

NT1210 Introduction to Networking. Unit 9:

Security Whitepaper. DNS Resource Exhaustion

Real-Time Communications Witout Boundaries. Ribbon Policy Solutions

Application Layer Traffic Optimization (ALTO)

Enterprise Overview. Benefits and features of Cloudflare s Enterprise plan FLARE

Chapter 5 RIP version 1

Building the Routing Table. Introducing the Routing Table Directly Connected Networks Static Routing Dynamic Routing Routing Table Principles

INCREASE APPLICATION SECURITY FOR PCI DSS VERSION 3.1 SUCCESS AKAMAI SOLUTIONS BRIEF INCREASE APPLICATION SECURITY FOR PCI DSS VERSION 3.

CSC 574 Computer and Network Security. DNS Security

DELL EMC DATA DOMAIN BOOST AND DYNAMIC INTERFACE GROUPS

Content Distribution. Today. l Challenges of content delivery l Content distribution networks l CDN through an example

Background Brief. The need to foster the IXPs ecosystem in the Arab region

OSSIR. 8 Novembre 2005

Mapping of Address and Port using Translation (MAP-T) E. Jordan Gottlieb Network Engineering and Architecture

India Operator BNG and IP Router

CS November 2017

CS519: Computer Networks. Lecture 2: Feb 2, 2004 IP (Internet Protocol)

Introduction to Network Address Translation

The Interactive Guide to Protecting Your Election Website

The Emerging Role of a CDN in Facilitating Secure Cloud Deployments

Citrix NetScaler LLB Deployment Guide

Transcription:

AKAMAI DNSi CACHESERVE CONTENT-AWARE DNS IMPROVING CONTENT-AWARE DNS RESOLUTION WITH AKAMAI DNSi CACHESERVE EQUIVALENCE CLASS.

CacheServe is the telecommunication industry s gold standard for caching DNS. Its speed, scalability and security are unsurpassed. Introduction Internet Service Providers (ISPs) are investigating extension mechanisms for DNS (EDNS0) client subnet (referred to as ECS in this paper) to see if it can optimize Quality of Experience (QoE) for their subscribers. In particular, when providers have content delivery network (CDN) caches distributed across their networks, with resolution greater than their resolvers, ECS is being considered as a way to enable selection of content caches closer to subscribers requesting content. CDN authoritative servers consider geolocation of IPs making content requests (DNS queries) to decide which content cache is best. Without ECS, a CDN authoritative server only has the resolver s IP address to decide which content cache is nearest. In this case, the authority doesn t know that there is a content source closer to subscribers. Authoritative Server Which content cache? Provider resolver Resolver IP address Content cache Where is: www.content.com? t.com Content cache

This paper will briefly cover the origins of ECS, describe how it works and discuss limitations of the current Internet Engineering Task Force (IETF) draft Request for Comments (RFC). It will then describe an important new capability for ECS called equivalence class, implemented in CacheServe resolvers, which provides more utility in ISP environments, cost savings for the provider and a better subscriber experience. EDNS0 Client Subnet A draft RFC for ECS was published in 2011 when public DNS resolution services like GoogleDNS and OpenDNS discovered their users were increasingly remote from their resolvers, sometimes many thousands of miles away. In order to offer the best source for content, CDN providers need to know where the actual requestors of content are located, versus where their DNS resolvers are located. Without ECS, CDN authoritative servers rely on a resolvers IP address to suggest the requestor s location. This assumption is reasonable when resolvers are in close proximity to clients, but when resolvers are substantially remote from clients they serve, authoritative servers need a better way to gauge the location of clients. ECS incorporates the subnet of a client in recursive requests to authoritative servers. Given a client subnet, an authoritative server has better information about where a client is located and can make a more informed decision about the optimal location of a content cache. For providers of public DNS services, where clients may be a continent away from their resolvers, ECS offers better resolution of content sources. ECS and ISP Networks For ISPs that have distributed content caches across their networks, with resolution greater than their resolvers, ECS is being evaluated as a way to enable better selection of content sources. However, providers have been challenged to aggregate their IPv4 address space due to increasingly smaller ad- For ISPs that have distributed content caches across their networks, with resolution greater than their resolvers, ECS is being evaluated as a way to enable better selection of content sources.

MUST-HAVE CAPABILITIES TO DELIVER TOP-TIER CARRIER QUALITY dress allocations or other constraints within their networks. This means resolvers serving hundreds of discontiguous subscriber subnets are often encountered. When ECS is configured for a domain, each client subnet may generate a separate recursive query and cache entry. Cache size and load on the resolver can grow exponentially, which impacts both cost (more memory, more processing power needed) and resolver performance. Time to Live (TTLs) commonly used by CDNs magnify this problem. Worse still, the additional effort to optimize answers may be unnecessary, since authoritative servers may reply with the same answer for different client subnets. Providers with highly fragmented address space often have Authoritative Server Provider resolver Separate request for each client subnet Where is: www.content.com? t.com? Highly fragmented address space Content cache AKAMAI, THE TRUSTED LEADER IN DNS RESOLUTION We are continuously innovating to help you increase operational efficiency and manage costs, while optimizing for quality, reliability, and scale. resolvers serving hundreds of client subnets. When ECS is configured for a domain, the recursive load and cache size increases substantially because each subnet generates a separate recursive query and cache entry. To better manage the address fragmentation problem, CacheServe resolvers have a patent-pending capability known as equivalence class. Equivalence class makes ECS scale by allowing any arbitrary group of subnets such as all subscriber subnets behind an edge router (BNG, CMTS, etc.), or all subnets in a city or region, to be configured to use a single representative subnet in ECS requests. CacheServe maintains tables that

map between each group of configured address blocks and their corresponding representative addresses. For domains configured to use equivalence class, when the IP address of an incoming query matches against a table, the corresponding representative address is used for cache lookups, recursive queries and caching results. With equivalence class, CacheServe uses a single representative subnet instead of numerous client subnets. This substantially reduces load on resolvers and authorities. With equivalence class, any representative subnet can be chosen, but as the name suggests its purpose is to represent the location of an arbitrary group of subscribers to CDN authoritative servers. The subnet representing blocks of subscribers can be configured based on the location of content sources, provider network topology and costs. In cases where subscribers use private IP addresses, a public IP address must be used. By using a representative subnet, equivalence class dramatically reduces recursion traffic and the excessive caching that would otherwise be incurred when using ECS. Examples As stated at the beginning of this paper, DNS authorities today depend on resolver addresses to infer a content requestor s location. Conveying a representative location that better reflects where content requestors are actually located helps authorities make better decisions. There are a few ways this capability might be used: Authoritative Server Vantio CacheServe Using equivalence class Single request for all client subnets Where is: www.content.com? t.com? Representative subnet Content cache

Some Internet access providers have the same problem as public DNS providers: subscribers that are substantially distant from the resolvers they use. ECS and equivalence class offer authorities better guidance. Provider resolvers are provisioned in data centers and their connectivity may be different than connectivity of the subscribers they serve. Routes to/from a data center for recursion may be less desirable than using routes to/from subscribers to serve content. An equivalence class representative subnet can be any subnet; it merely offers a hint to an authority about location. Rather than represent the location of subscribers, it could represent a network location a provider prefers from a topological perspective, because it provides lower cost or higher bandwidth. The access provider can guide the CDN provider to offer sources of content at a location that benefits the ISP. Summary Providers with distributed CDN caches across their networks, investigating ECS to better align content sources with their subscribers, can take advantage of equivalence class, a new feature in CacheServe resolvers. Equivalence class can dramatically reduce recursion traffic and unnecessary caching by allowing discontiguous address blocks to use a single representative subnet in ECS requests. CacheServe maintains tables that map between each group of configured address blocks, and their corresponding representative addresses. For domains configured to use equivalence class, when the IP address of an incoming query matches against a table, the corresponding representative address is used for cache lookups, recursive queries, and caching results. ISPs using equivalence class can optimize content sources for their subscribers while managing the load on their resolvers. As the world s largest and most trusted cloud delivery platform, Akamai makes it easier for its customers to provide the best and most secure digital experiences on any device, anytime, anywhere. Akamai s massively distributed platform is unparalleled in scale with more than 200,000 servers across 130 countries, giving customers superior performance and threat protection. Akamai s portfolio of web and mobile performance, cloud security, enterprise access, and video delivery solutions are supported by exceptional customer service and 24/7 monitoring. To learn why the top financial institutions, online retail leaders, media and entertainment providers, and government organizations trust Akamai please visit www.akamai.com, blogs.akamai.com, or @Akamai on Twitter. You can find our global contact information at www.akamai.com/locations. Published 05/18.