<?xml version="1.0" encoding="UTF-8"?>
<reference anchor="I-D.ietf-dnsop-cookies" target="https://datatracker.ietf.org/doc/html/draft-ietf-dnsop-cookies-08">
   <front>
      <title>Domain Name System (DNS) Cookies</title>
      <author initials="D. E." surname="Eastlake" fullname="Donald E. Eastlake 3rd">
         </author>
      <author initials="M. P." surname="Andrews" fullname="Mark P. Andrews">
         </author>
      <date month="December" day="24" year="2015" />
      <abstract>
	 <t>   DNS cookies are a lightweight DNS transaction security mechanism that
   provides limited protection to DNS servers and clients against a
   variety of increasingly common denial-of-service and amplification /
   forgery or cache poisoning attacks by off-path attackers. DNS Cookies
   are tolerant of NAT, NAT-PT, and anycast and can be incrementally
   deployed. (Since DNS Cookies are only returned to the IP address from
   which they were originally received, they cannot be used to generally
   track Internet users.)


	 </t>
      </abstract>
   </front>
   <seriesInfo name="Internet-Draft" value="draft-ietf-dnsop-cookies-08" />
   
</reference>
