Uploaded February 2026 | Updated September 2026, 1 week ago
Abstract
The growing complexity of web browsing, driven by the widespread adoption of HTTPS and privacy-enhancing protocols like DNS-over-HTTPS (DoH), introduces significant network overhead. This is caused by a cascade of sequential handshakes and information retrievals—including DNS resolution, TLS setup, and protocol negotiation—that can cause substantial latency before a single byte of content is delivered. As a result, users often experience sub-optimal performance even on high-speed connections.
In this presentation, we demonstrate how leveraging newly standardized DNS HTTPS records (RFC 9460) can significantly reduce this overhead. We will show how a missing link between browser capabilities and web server configurations prevents the full benefits of protocols like QUIC/HTTP/3 from being realized. Through our open-source WebTrafficSphere tool and the apexDNS proof-of-concept, we show how to transparently deliver the necessary endpoint information to the browser, bypassing unnecessary negotiation and reducing packet exchanges by up to 50%.
Levente Csikor:
Levente Csikor is a Senior Scientist at the Institute for Infocomm Research (I²R), A*STAR, Singapore. His research focuses on network security and privacy, aiming to uncover vulnerabilities and strengthen the resilience of secure and trustworthy future communication networks. He is particularly interested in how AI and agentic systems can enhance network hygiene, enable automated threat detection, and improve threat intelligence extraction from the dark web.
nanog.org/events/nanog-96/content/5570
Abstract
The growing complexity of web browsing, driven by the widespread adoption of HTTPS and privacy-enhancing protocols like DNS-over-HTTPS (DoH), introduces significant network overhead. This is caused by a cascade of sequential handshakes and information retrievals—including DNS resolution, TLS setup, and protocol negotiation—that can cause substantial latency before a single byte of content is delivered. As a result, users often experience sub-optimal performance even on high-speed connections.
In this presentation, we demonstrate how leveraging newly standardized DNS HTTPS records (RFC 9460) can significantly reduce this overhead. We will show how a missing link between browser capabilities and web server configurations prevents the full benefits of protocols like QUIC/HTTP/3 from being realized. Through our open-source WebTrafficSphere tool and the apexDNS proof-of-concept, we show how to transparently deliver the necessary endpoint information to the browser, bypassing unnecessary negotiation and reducing packet exchanges by up to 50%.
Levente Csikor:
Levente Csikor is a Senior Scientist at the Institute for Infocomm Research (I²R), A*STAR, Singapore. His research focuses on network security and privacy, aiming to uncover vulnerabilities and strengthen the resilience of secure and trustworthy future communication networks. He is particularly interested in how AI and agentic systems can enhance network hygiene, enable automated threat detection, and improve threat intelligence extraction from the dark web.
nanog.org/events/nanog-96/content/5570










