FINDING · EVALUATION
Among Iris's DNS manipulation detection metrics, AS-level consistency was most effective, classifying 90% of DNS responses as unmanipulated. IP-address identity matching flagged approximately 80% of correct responses, while HTTPS certificate validation improved from 38% to 55% accuracy when SNI was included in follow-up TLS probes.
From 2017-pearce-global — Global Measurement of DNS Manipulation · §5.1, Figure 3 · 2017 · USENIX Security Symposium
Implications
- Circumvention tools validating DNS-resolved proxy IPs should prioritize AS-consistency checks first, then SNI-enabled TLS certificate verification—these two metrics together catch the vast majority of DNS manipulation with low false-positive rates.
- Non-SNI certificate matching misses roughly one-third of cases that SNI-aware probing catches; circumvention bootstrapping must use SNI when validating proxy endpoints to avoid accepting manipulated DNS answers.
Tags
Extracted by claude-sonnet-4-6 — review before relying.