Title :
Deploying and Monitoring DNS Security (DNSSEC)
Author :
Osterweil, Eric ; Massey, Dan ; Zhang, Lixia
Author_Institution :
UCLA, Los Angeles, CA, USA
Abstract :
SecSpider is a DNSSEC monitoring system that helps identify operational errors in the DNSSEC deployment and discover unforeseen obstacles. It collects, verifies, and publishes the DNSSEC keys for DNSSEC-enabled zones, which enables operators of both authoritative zones and recursive resolvers to deploy DNSSEC immediately, and benefit from its cryptographic protections. In this paper we present the design and implementation of SecSpider as well as several general lessons that stem from its design and implementation.
Keywords :
Internet; cryptography; DNS security monitoring; DNSSEC keys; SecSpider; authoritative zones; cryptographic protections; recursive resolvers; Application software; Computer errors; Computer security; Computerized monitoring; Cryptography; Data security; Domain Name System; Internet; Protection; US Government; DNS; DNSSEC; Internet; distributed; monitoring; security; zones;
Conference_Titel :
Computer Security Applications Conference, 2009. ACSAC '09. Annual
Conference_Location :
Honolulu, HI
Print_ISBN :
978-0-7695-3919-5
DOI :
10.1109/ACSAC.2009.47