• DocumentCode
    524769
  • Title

    Protecting the Domain Name System

  • Author

    Grgic, Snjezana

  • Author_Institution
    Croatian Personal Data Protection Agency, Republike Austrije 25, Zagreb, Croatia
  • fYear
    2010
  • fDate
    24-28 May 2010
  • Firstpage
    1221
  • Lastpage
    1225
  • Abstract
    The Domain Name System (DNS) is the worldwide system that associates a category of digital identifiers, called domains, with a variety of data. The identified threats to DNS communications and components are listed in the Internet Engineering Task Force´s specification (RFC 3833). They are: Packet Interception, ID Guessing and Query Prediction, Cache Poisoning, etc. It is clear therefore that the DNS is still far from secure. Existing flaws can affect public Internet users as well as enterprise users. The ISP´s recursive resolvers, as well as enterprise ones, have to be secured. The aim of this paper is brings the latest changes in this crucial service and possible solutions for verifying the authenticity and protecting the integrity of the DNS data in the communication between the recursive resolvers and authoritative servers as well as explaining DNSSEC the security extension to the DNS that, if deployed, can solve the cache poisoning problem.
  • Keywords
    Communication system security; Cryptography; Data security; Domain Name System; Internet; Power system security; Protection; Protocols; Tree data structures; Web server;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    MIPRO, 2010 Proceedings of the 33rd International Convention
  • Conference_Location
    Opatija, Croatia
  • Print_ISBN
    978-1-4244-7763-0
  • Type

    conf

  • Filename
    5533651