<?xml version="1.0" encoding="UTF-8"?>
<reference anchor="I-D.zhang-dnsop-dnssec-unvalidated-data" target="https://datatracker.ietf.org/doc/html/draft-zhang-dnsop-dnssec-unvalidated-data-00">
   <front>
      <title>Handling Unvalidated Data during DNSSEC Troubleshooting</title>
      <author initials="S." surname="Zhang" fullname="Shuhan Zhang">
         <organization>Tsinghua University</organization>
      </author>
      <author initials="S." surname="Wang" fullname="Shuai Wang">
         <organization>Zhongguancun Laboratory</organization>
      </author>
      <author initials="L." surname="Chen" fullname="Li Chen">
         <organization>Zhongguancun Laboratory</organization>
      </author>
      <author initials="D." surname="Li" fullname="Dan Li">
         <organization>Tsinghua University</organization>
      </author>
      <author initials="B." surname="Liu" fullname="Baojun Liu">
         <organization>Tsinghua University</organization>
      </author>
      <date month="April" day="7" year="2025" />
      <abstract>
	 <t>   Due to the prevalence of DNSSEC (Domain Name System Security
   Extensions) misconfigurations, many domain administrators
   troubleshoot the records of DNSSEC-signed domains via queries with CD
   (Checking Disabled) bit set.  However, as DNS resolvers are not
   forced to perform DNSSEC validation for CD=1 queries, the unvalidated
   data introduced during troubleshooting could be mixed up with the
   routine ones in the resolver cache.  Recent research has revealed
   that the reuse of the cached unvalidated data in subsequent
   resolutions could lead to the risk of Denial-of-Service (DoS).  This
   document clarifies the definition of unvalidated data in the context
   of DNSSEC.  Then, it demonstrates the DoS vulnerabilities of current
   DNS resolver implementations due to the reuse of cached unvalidated
   data.  Accordingly, it provides several recommendations for DNSSEC-
   validating resolvers to handle the unvalidated data and mitigate the
   risk of DoS, so as to improve the availability of DNSSEC-signed
   domains.

	 </t>
      </abstract>
   </front>
   <seriesInfo name="Internet-Draft" value="draft-zhang-dnsop-dnssec-unvalidated-data-00" />
   
</reference>
