Rolling the root key
Have DNSSEC-validating recursive resolvers updated their Trust Anchor sets to include KSK-2024, and how can we measure whether this transition has been successfully adopted?
Have DNSSEC-validating recursive resolvers updated their Trust Anchor sets to include KSK-2024, and how can we measure whether this transition has been successfully adopted?
Guest Post: DDoS attacks continue to be a destructive force on the Internet. ReAct was created to provide efficient and effective mitigation against AR-DDoS attacks, when routing is either symmetric or asymmetric.
Geoff Huston discusses the CIDR Report, a 30-year-long series of data about who is sending excess data in BGP. Does the CIDR Report still hold value?
IPv6 has reached a major milestone, with around half of Google’s users now accessing its services over IPv6.
‘Revocation is broken’ is a catchphrase in the world of certificates and Certificate Authorities. Certification infrastructure may not have been designed for the Internet of today.
Guest Post: Analysing public BGP data to characterize the real‑world behaviour of five major scrubbing services.
Guest Post: What can we learn about QUIC deployments just by listening to unsolicited QUIC traffic? As it turns out, quite a lot.
Guest Post: An analysis of more than 80 billion updates reveals how ‘noisy’ BGP updates inflate MRT archives, bias measurements, and highlights the need for more careful interpretation of BGP data.
Marc Blanchet discusses modelling the delay of a deep space IP stack using Linux virtual network methods, and the suitability of QUIC as a transport for applications in space.
Guest Post: IRR-based filtering at IXPs often breaks the link between prefixes and their legitimate AS, allowing invalid announcements to slip through. This study measures the issue across many IXPs and offers actionable fixes.