Iris: Detecting DNS Manipulation
💡 The Core Idea
Iris is a system that uses thousands of Open DNS Resolvers worldwide to measure DNS manipulation without requiring user participation.
🧠Methodology
- Scan: Find open resolvers in Internet infrastructure (avoiding home routers).
- Query: Ask these resolvers for sensitive domains.
- Verify: Check if the response is valid using:
- Consistency Metrics: Does the IP match what other resolvers see?
- Independent Verifiability: Does the returned IP present a valid HTTPS certificate for that domain?