FINDING · DETECTION

Prior DNS-manipulation measurement systems suffered from high false-positive rates because DNS anomalies are also produced by benign infrastructure (CDNs, geo-DNS, captive portals). CERTainty's TLS certificate inspection step disambiguates these cases, establishing that certificate validation is a necessary complement to DNS-response comparison for reliable censor classification.

From 2023-ramesh-certaintyCERTainty: Detecting DNS Manipulation at Scale using TLS Certificates · Abstract / §3 · 2023 · USENIX Security Symposium

Implications

Tags

censors
generic
techniques
dns-poisoningmeasurement-platform

Extracted by claude-sonnet-4-6 — review before relying.