DNSSEC: Security and availability challenges
DNSSEC: Security and availability challenges
复制标题
DNSSEC:安全性和可用性挑战
DOI:
--
复制
发表时间:
2013
期刊:
影响因子:
--
通讯作者:
Haya Schulmann
中科院分区:
文献类型:
--
作者:
A. Herzberg;Haya Schulmann
DNSSEC was proposed more than 15 years ago but its (correct) adoption is still very limited. Recent cache poisoning attacks motivate deployment of DNSSEC. In this work we present a comprehensive overview of challenges and potential pitfalls of DNSSEC, including: Vulnerable configurations: we show that inter-domain referrals (via NS, MX and CNAME records) present a challenge for DNSSEC deployment and may result in vulnerable configurations. Due to the limited deployment so far, these configurations are expected to be popular. Incremental Deployment: we discuss implications of interoperability problems on DNSSEC validation by resolvers and potential for increased vulnerability due to popular practices of incremental deployment. Super-sized Response Challenges: we explain how large DNSSEC-enabled DNS responses cause interoperability challenges, and can be abused for DoS and even DNS poisoning.