FINDING · EVALUATION

CERTainty identifies DNS manipulation by attempting a full TLS handshake with the IP returned by a remote resolver and inspecting whether the resulting certificate belongs to the legitimate origin or to an injected blockpage destination. This certificate-based ground truth substantially reduces false positives compared to prior DNS measurement systems that could not distinguish intentional manipulation from CDN geo-DNS or captive portals.

From 2023-ramesh-certaintyCERTainty: Detecting DNS Manipulation at Scale using TLS Certificates · Abstract / §1 · 2023 · USENIX Security Symposium

Implications

Tags

censors
cnirru
techniques
dns-poisoningmeasurement-platform

Extracted by claude-sonnet-4-6 — review before relying.