• DocumentCode
    476307
  • Title

    A secure domain name system based on intrusion tolerance

  • Author

    Zhou, Wei ; Chen, Liu

  • Author_Institution
    Sch. of Comput., Wuhan Univ., Wuhan
  • Volume
    6
  • fYear
    2008
  • fDate
    12-15 July 2008
  • Firstpage
    3535
  • Lastpage
    3539
  • Abstract
    DNS was not designed to be secure. The biggest security hole in DNS is the lack of support for data integrity authentication, source authentication, and authorization. In this paper, a secure DNS scheme based on intrusion tolerance is proposed. This secure DNS is intrusion-tolerant by using Byzantine intrusion tolerant technique and voting mechanism. The scheme provides high integrity, robustness, and availability of service in the presence of arbitrary failures, including failures due to malicious attacks. The proposed scheme consists of 3f+1 tightly coupled replicas per name server and guarantees safety and liveness properties of the system assuming no more than f replicas are faulty. By adding authentication of client and using symmetric key cryptography, the system guarantees a secure communication mechanism by providing a way to detect whether DNS data has been corrupted during communication over the Internet. Experimental results show that the scheme can provide a much higher degree of security and reliability, as well or even better than an implementation of the DNS security extension.
  • Keywords
    Internet; cryptography; data integrity; message authentication; Byzantine intrusion tolerant technique; authorization; data integrity authentication; secure domain name system; source authentication; symmetric key cryptography; voting mechanism; Authentication; Authorization; Availability; Communication system security; Cryptography; Data security; Domain Name System; Robustness; Safety; Voting; Byzantine fault tolerance; DNS; Intrusion tolerance; Voting;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Machine Learning and Cybernetics, 2008 International Conference on
  • Conference_Location
    Kunming
  • Print_ISBN
    978-1-4244-2095-7
  • Electronic_ISBN
    978-1-4244-2096-4
  • Type

    conf

  • DOI
    10.1109/ICMLC.2008.4621016
  • Filename
    4621016