Title :
Securing Domain Name System Combined with MIPv6 for Mobile Hosts
Author :
Younchan Jung ; Peradilla, Marnel ; Atwood, W.
Author_Institution :
Comm. & Electron. Eng., Catholic Univ. of Korea, Bucheon, South Korea
Abstract :
DNS is the standard mechanism for name to IP address resolution. The DNS has been extended to DNSSEC to add security by providing origin authentication and data integrity by the process of creating signatures periodically, which results in intensive computations. Adding digital signatures to a domain increases each record size by 5-7 times, which puts a burden of DNS reply messages on the authoritative name servers. The goal of this paper is to find secure DNS mechanism, which cause relatively low computation loads and reply burden especially for infrastructure mode MANET gateways that are responsible for name resolution services as well as local mobility management for mobile hosts. This paper proposes SECDNS (Secure DNS) mechanism that handles secure query/reply transactions using the one-time session key generated per a query basis. In the proposed SECDNS, burden for securing DNS is distributed for every DNS queries. We analyze how many SECDNS transactions can the session key with a given length handle and suggest the solution of the anti-MITM attack scheme, which protects the name resolution services against the possible MITM attacks and make it useless for the enemy to decrypt the SECDNS reply messages in time.
Keywords :
IP networks; computer network security; mobility management (mobile radio); DNS; DNS mechanism security; IP address resolution; MANET gateways; MIPv6; SECDNS; Secure DNS; anti-MITM attack scheme; authoritative name servers; data integrity; digital signatures; intensive computations; local mobility management; mobile hosts; query basis; securing domain name system; Gold; IP networks; Logic gates; Mobile ad hoc networks; Mobile communication; Security; Servers; DNSSEC; MANET gateway; Mobile Host; One-time Session Key; Resource Record; Secure DNS;
Conference_Titel :
Trust, Security and Privacy in Computing and Communications (TrustCom), 2013 12th IEEE International Conference on
Conference_Location :
Melbourne, VIC
DOI :
10.1109/TrustCom.2013.26