• DocumentCode
    3317190
  • Title

    TrickleDNS: Bootstrapping DNS security using social trust

  • Author

    Sankararaman, Sriram ; Chen, Jay ; Subramanian, Lakshminarayanan ; Ramasubramanian, Venugopalan

  • Author_Institution
    Harvard Univ., Cambridge, MA, USA
  • fYear
    2012
  • fDate
    3-7 Jan. 2012
  • Firstpage
    1
  • Lastpage
    10
  • Abstract
    This paper presents TrickleDNS, a decentralized system for proactive dissemination of DNS data. Unlike prior solutions, which depend on the complete deployment of DNSSEC standard to preserve data integrity, TrickleDNS offers an incrementally deployable solution with a probabilistic guarantee on data integrity that becomes stronger as the adoption of DNSSEC increases. TrickleDNS provides resilience from data corruption attacks and denial of service attacks, including sybil attacks, using three key steps. First, TrickleDNS organizes participating nameservers into a well-connected peer-to-peer Secure Network of Nameservers (SNN) using two types of trust links: (a) strongly trusted social relationships across DNS servers (which exist today); (b) random yet constrained weak trust links between DNS servers, which it introduces. The SNN allows nameservers in the network to reliably broadcast their public-keys to each other without relying on a centralized PKI. Second, TrickleDNS reliably binds domains to their authoritative name servers through independent verification by multiple, randomly chosen peers within the SNN. Finally, TrickleDNS servers proactively disseminate self-certified versions of DNS records to provide faster performance, better availability, and improved security.
  • Keywords
    Internet; computer bootstrapping; computer network security; data integrity; peer-to-peer computing; public key cryptography; social networking (online); trusted computing; DNS security bootstrapping; DNSSEC standard; Nameservers; TrickleDNS; authoritative name servers; centralized PKI; data corruption attacks; data integrity; decentralized system; denial of service attacks; peer-to-peer secure network; proactive DNS data dissemination; public-keys; social trust; strongly trusted social relationships; sybil attacks; weak trust links; Computer crime; Peer to peer computing; Protocols; Public key; Reliability; Resilience; Servers;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Communication Systems and Networks (COMSNETS), 2012 Fourth International Conference on
  • Conference_Location
    Bangalore
  • Print_ISBN
    978-1-4673-0296-8
  • Electronic_ISBN
    978-1-4673-0297-5
  • Type

    conf

  • DOI
    10.1109/COMSNETS.2012.6151334
  • Filename
    6151334