DocumentCode :
3516903
Title :
WSEC DNS: Protecting recursive DNS resolvers from poisoning attacks
Author :
Perdisci, Roberto ; Antonakakis, Manos ; Luo, Xiapu ; Lee, Wenke
Author_Institution :
Damballa, Inc., Atlanta, GA, USA
fYear :
2009
fDate :
June 29 2009-July 2 2009
Firstpage :
3
Lastpage :
12
Abstract :
Recently, a new attack for poisoning the cache of Recursive DNS (RDNS) resolvers was discovered and revealed to the public. In response, major DNS vendors released a patch to their software. However, the released patch does not completely protect DNS servers from cache poisoning attacks in a number of practical scenarios. DNSSEC seems to offer a definitive solution to the vulnerabilities of the DNS protocol, but unfortunately DNSSEC has not yet been widely deployed. In this paper, we proposeWild-card SECure DNS (WSEC DNS), a novel solution to DNS cache poisoning attacks. WSEC DNS relies on existing properties of the DNS protocol and is based on wild-card domain names. We show that WSEC DNS is able to decrease the probability of success of cache poisoning attacks by several orders of magnitude. That is, with WSEC DNS in place, an attacker has to persistently run a cache poisoning attack for years, before having a non-negligible chance of success. Furthermore, WSEC DNS offers complete backward compatibility to DNS servers that may for any reason decide not to implement it, therefore allowing an incremental large-scale deployment. Contrary to DNSSEC, WSEC DNS is deployable immediately because it does not have the technical and political problems that have so far hampered a large-scale deployment of DNSSEC.
Keywords :
Internet; security of data; cache poisoning attack; recursive DNS resolver; software patch; wild-card domain name system; wild-card secure DNS protocol; Computer crime; Data security; Domain Name System; Educational institutions; Electronic mail; Internet; Large-scale systems; Protection; Protocols; Web server;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Dependable Systems & Networks, 2009. DSN '09. IEEE/IFIP International Conference on
Conference_Location :
Lisbon
Print_ISBN :
978-1-4244-4422-9
Electronic_ISBN :
978-1-4244-4421-2
Type :
conf
DOI :
10.1109/DSN.2009.5270363
Filename :
5270363
Link To Document :
بازگشت