Minimizing information leakage in the DNS

Minimizing information leakage in the DNS
复制标题

最大限度地减少 DNS 中的信息泄露

DOI:
--
复制
发表时间:
2008
期刊:
影响因子:
9.3
通讯作者:
A. Nakassis
A. Nakassis
中科院分区:
计算机科学2区
文献类型:
--
作者:
S. Rose;A. Nakassis

文献摘要

被引文献

相似文献

域名系统是网络资源的全局查找服务。为了保护DNS信息,已经开发了DNS安全扩展并部署在DNS的分支上,以使用数字签名提供身份验证和完整性保护。然而,签名的DNS节点被发现有一个不幸的副作用:攻击者可以在攻击特定网络上的主机之前查询它们作为侦察。区域管理员可以通过不同的方式最大限度地减少信息泄漏,同时仍然利用DNSSEC进行完整性和源身份验证。本文描述了风险,并检查了协议和操作选项,并查看了它们的优点和缺点。
The domain name system is the global lookup service for network resources. To protect DNS information, the DNS security extensions have been developed and deployed on branches of the DNS to provide authentication and integrity protection using digital signatures. However, signed DNS nodes were found to have an unfortunate side effect: an attacker can query them as reconnaissance before attacking hosts on a particular network. There are different ways a zone administrator can minimize information leakage and still take advantage of DNSSEC for integrity and source authentication. This article describes the risk and examines the protocol and operational options and looks at their advantages and drawbacks.