DocumentCode :
524769
Title :
Protecting the Domain Name System
Author :
Grgic, Snjezana
Author_Institution :
Croatian Personal Data Protection Agency, Republike Austrije 25, Zagreb, Croatia
fYear :
2010
fDate :
24-28 May 2010
Firstpage :
1221
Lastpage :
1225
Abstract :
The Domain Name System (DNS) is the worldwide system that associates a category of digital identifiers, called domains, with a variety of data. The identified threats to DNS communications and components are listed in the Internet Engineering Task Force´s specification (RFC 3833). They are: Packet Interception, ID Guessing and Query Prediction, Cache Poisoning, etc. It is clear therefore that the DNS is still far from secure. Existing flaws can affect public Internet users as well as enterprise users. The ISP´s recursive resolvers, as well as enterprise ones, have to be secured. The aim of this paper is brings the latest changes in this crucial service and possible solutions for verifying the authenticity and protecting the integrity of the DNS data in the communication between the recursive resolvers and authoritative servers as well as explaining DNSSEC the security extension to the DNS that, if deployed, can solve the cache poisoning problem.
Keywords :
Communication system security; Cryptography; Data security; Domain Name System; Internet; Power system security; Protection; Protocols; Tree data structures; Web server;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
MIPRO, 2010 Proceedings of the 33rd International Convention
Conference_Location :
Opatija, Croatia
Print_ISBN :
978-1-4244-7763-0
Type :
conf
Filename :
5533651
Link To Document :
بازگشت