인터넷 서비스의 보안과 성능 향상을 위한 온디바이스 재귀 DNS 구현에 관한 연구 : PC형 재귀 DNS 구현 연구
A Study on On-Device Recursive DNS Implementation for Enhanced Security and Performance: A Study on PC-Based Recursive DNS Implementation
- 주제(키워드) 도움말 온디바이스(On-device) , 재귀(Recursive) DNS , DNS보안 , DDoS공격 , DNS 캐시 포이즈닝 , DNSSEC
- 발행기관 강원대학교 일반대학원
- 지도교수 도움말 이준동
- 발행년도 2026
- 학위수여년월 2026. 6
- 학위명 석사
- 학과 및 전공 도움말 일반대학원 AI콘텐츠공학과
- 세부분야 해당없음
- 실제URI http://www.dcollection.net/handler/kangnung/000000012422
- UCI I804:42001-000000012422
- 본문언어 한국어
초록/요약 도움말
본 논문은 현대 인터넷 인프라의 핵심 시스템인 DNS(Domain Name System)가 직면한 중앙 집중형 구조의 한계와 보안 취약점을 해결하기 위한 방안으로 '온디바이스(On-device) 재귀 DNS(Recursive DNS)' 기법을 제안하고 그 유효성을 검증하였다. 기존의 DNS 서비스는 대형 ISP(인터넷 서비스 제공자)가 운영하는 중앙 집중식 재귀 DNS 서버에 의존함에 따라, 질의량 급증 시 성능 저하가 발생하고 DDoS 공격이나 DNS 캐시 포이즈닝(Cache Poisoning)과 같은 외부 공격에 매우 취약한 구조적 문제를 안고 있다. 특히 장애 발생 시 사회적 혼란을 초래할 수 있는 대규모 재난으로 이어질 가능성이 크다. 본 연구에서는 하드웨어 기술의 발전에 따라 개인용 디바이스(PC 등)에서도 충분히 재귀 DNS 기능을 수용할 수 있다는 점에 주목하였다. 제안된 온디바이스 재귀 DNS는 외부 서버의 도움 없이 사용자 단말 내부에서 직접 DNS 질의를 처리하는 방식으로, 다음과 같은 연구 성과를 도출하였다. ▶ 성능 개선: 사용자 단말에서 직접 질의를 처리함으로써 PC와 외부 재귀 DNS 서버 간의 네트워크 지연 시간(TRDR)을 제거하여 응답 속도를 평균 0.17ms에서 0.04ms로 약 4배 이상 향상시켰다. ▶ 보안 강화: DNSSEC(DNS Security Extensions)를 적용하여 응답의 무결성을 검증하고, 로컬 분산 처리를 통해 중앙 집중형 서버를 대상으로 하는 대규모 DDoS 공격 및 캐시 포이즈닝 위협을 최소화하였다. ▶ 자원 효율성: 실험 결과, 온디바이스 DNS 운용 시 CPU 점유율은 약 0.02%, 메모리는 약 2.62% 수준으로 측정되어 현재 유통되는 일반적인 PC 사양으로도 충분히 구현 가능함을 입증하였다. 결론적으로 본 논문은 온디바이스 재귀 DNS가 기존의 중앙 집중형 모델을 보완하여 인터넷 서비스의 신뢰성과 안정성을 높이는 효과적인 대안이 될 수 있음을 확인하였다. 향후에는 모바일 및 IoT 환경 등 다양한 디바이스로의 확장 적용에 관한 연구가 지속되어야 할 것이다.
more초록/요약 도움말
This thesis proposes and verifies the effectiveness of 'On-device Recursive DNS' as a solution to overcome the limitations and security vulnerabilities of the current centralized Recursive DNS structure. Traditional DNS services rely on large-scale centralized Recursive DNS servers operated by ISPs, which face performance degradation during query surges and are structurally vulnerable to external threats such as DDoS attacks and DNS cache poisoning. Such centralized systems risk large-scale disasters and social disruption in the event of a failure. This study focuses on the fact that modern hardware technology has advanced sufficiently for personal devices (PCs, etc.) to handle Recursive DNS functions. The proposed On-device Recursive DNS processes DNS queries directly within the user terminal without external server assistance, achieving the following results ⁝ ▶ Performance Improvement: By processing queries locally, the network delay between the PC and external servers (TRDR) is eliminated, improving response speed from an average of 0.17ms to 0.04ms ▶ Enhanced Security: By implementing DNSSEC, the integrity of responses is verified, and the risk of centralized DDoS and cache poisoning attacks is minimized through localized distributed processing. ▶ Resource Efficiency: Experimental results show that the system utilizes approximately 0.02% of CPU and 2.62% of memory, proving it can be implemented within the specifications of standard PCs currently in use. In conclusion, this thesis demonstrates that On-device Recursive DNS is an effective alternative that complements the existing centralized model and enhances the reliability and stability of internet services. Future research should continue to explore its expandability to various environments, including mobile and IoT devices.
more목차 도움말
Ⅰ. 서론 1
1. 연구의 배경 및 필요성 1
2. 연구 목적 3
3. 연구 범위 및 방법 3
Ⅱ. 본론 5
1. 이론적 배경 및 기존 연구 분석 5
1) DNS의 개념 및 역할 5
2) DNS 정의 및 동작 방식 5
3) 권위있는 DNS 8
4) 재귀 DNS 9
5) 재귀 DNS에 대한 위협 11
6) 국내외 DNS 운영 현황 분석 12
7) DNS 보안 위협 분석 및 기존 연구 13
8) 기존 DNS DDoS 공격 방어 방법 분석 16
2. 온디바이스 재귀 DNS 기법 18
1) 온디바이스 재귀 DNS 개요 18
2) 온디바이스 재귀 DNS 설계 18
3) 온디바이스 재귀 DNS 구현 방안 19
4) 기존 DNS 모델과 온디바이스 재귀 DNS 모델 비교 21
5) DNS 서비스 질의·응답 속도 개선 22
3. 기대효과 23
4. 실험 및 평가 24
Ⅲ. 결론 및 향후 연구 방향 29
1. 결론 29
2. 향후 연구 방향 29
□ 참고문헌 31
□ Abstract 33

