Solution report blog — Secure Sphere

Benchmarking a DNS resolver manually is like trying to time a professional sprinter with a handheld stopwatch—it’s prone to error, hard to repeat, and misses the subtle details. During the AIORI-2 Hackathon, team Secure Sphere from the Guru Nanak Institute of Technology changed the game by implementing draft-ietf-bmwg-network-tester-cfg.

By using YANG (Yet Another Next Generation) data modeling, the team automated the entire benchmarking process, turning DNS performance measurement into a standardized, “push-button” operation.

1. The Power of YANG Automation

Traditional benchmarking often relies on custom scripts that break when a tool updates. YANG provides a universal language (RFC 7950) to describe how a test should be configured. Whether you are testing BIND, Unbound, or Knot, the YANG model ensures the instructions remain the same.

  • Standardized Interface: Used pyang and libyang to parse models that define exactly how many queries to send, which DNSSEC records to check, and how long to capture packets.
  • Vendor Neutrality: The same YANG configuration was used to benchmark different resolver softwares, providing a true “apples-to-apples” comparison.

2. Technical Implementation: The AIORI DNSSEC Testbed

The team integrated their automation controller into the AIORI DNSSEC Testbed, focusing on three critical performance vectors:

  1. Query Latency: Measuring the time from “Question” to “Answer” using asynchronous Python scripts.
  2. Cache Efficiency: Tracking how well the resolver remembers previous answers (TTL-based analysis).
  3. DNSSEC Overhead: Quantifying the “security tax”—the extra time it takes for a resolver to verify digital signatures (RRSIG/DNSKEY).

3. Key Performance Outcomes

The automation didn’t just make testing faster; it made the data more reliable. By removing human intervention, the team reduced setup time by over 40%.

Test Scenario Key Metric Technical Observation
Baseline Latency 42.6 ms Extremely consistent results with < 5% variation.
Cache Hit Ratio 78% Significant speedup observed after the first “cold” query.
DNSSEC Penalty +9.3 ms A manageable overhead for the security benefits provided.
Automation Speed < 1.2s Time taken to push a full benchmark config via YANG.

4. Overcoming Challenges: Schema Alignment

The biggest hurdle was “speaking the same language.” The team found that the IETF draft schema sometimes clashed with the native inputs of open-source tools.

“Aligning the YANG model parameters with the existing AIORI framework was a puzzle. It taught us that configuration consistency is just as important as the code itself.” — Debjeet Sen, Integration Lead

5. Impact and Future Work: Towards Post-Quantum DNS

This project serves as a cornerstone for the AIORI-IMN measurement framework. The roadmap for 2026 includes:

  • PQ-DNSSEC: Benchmarking how Post-Quantum digital signatures impact resolver latency.
  • Encrypted Transport: Expanding the YANG models to handle DoH (DNS over HTTPS) and DoT (DNS over TLS) handshake benchmarking.
  • IETF Feedback: Submitting a technical note to the BMWG (Benchmarking Methodology Working Group) with results from these real-world tests.

6. Reflections from the Team

The sprint provided a front-row seat to how Internet standards are built. By moving from theoretical drafts to practical implementation, the team contributed directly to the tools that keep the Internet fast and secure.
Read the full report

Author

Facebook
Twitter
LinkedIn
WhatsApp

Search

Authors List

Authors

  • Advanced Internet Operations Research in India

    View all posts
  • I’m a tech entrepreneur and researcher who thrives on pushing boundaries and finding innovative solutions in the ever-evolving digital landscape. Currently, I’m deeply immersed in the fascinating realm of Internet resiliency, harnessing my expertise to ensure a robust and secure online space for all. 🚀

    View all posts
  • admin
  • I am a researcher working on security, networks, protocols and DNS. I am a quantum computing enthusiast, a fan of Linux and an advocate for Free & Open Source Softwares. #FOSS

    View all posts
  • A Information Technology Practitioner with leadership experience in IT Public Policy, Corporate Industry Forums, Information Technology Standards, & Program Implementation. An experienced Information Technology trainer, keynote speaker, panelist, leader and key influencer for advocacy and outreach, with wide international exposure across stakeholder groups. Finance Degree from ICAI & ICWAI, India; IT Security Degree from ISACA, USA & Internet Governance Certification from University of Aarhus, Germany & Next Generation Leaders Program of Internet Society in association with DIPLO Foundation.

    View all posts
  • Aindri Mukherjee
  • Debayan Mukherjee

Tag Cloud

Newsletter

Leave a Reply

Your email address will not be published. Required fields are marked *