Thirty Years of DNS Insecurity: Current Issues and Perspectives

Thirty Years of DNS Insecurity: Current Issues and Perspectives
复制标题

DNS 不安全三十年:当前问题和观点

DOI:
10.1109/comst.2021.3105741
复制
发表时间:
2021
影响因子:
35.6
通讯作者:
G. Schmid
G. Schmid
中科院分区:
计算机科学1区
文献类型:
--
作者:
G. Schmid

文献摘要

被引文献

相似文献

当DNS被创建时,没有人想到它会成为数字经济的基础和网络犯罪分子的主要目标。没有人会想到数字经济的一个主要资产是用户的浏览习惯,这会危及他们的隐私。DNS是根据速度、可扩展性和可靠性标准设计和实现的,而安全性和隐私性并不符合这些目标。虽然第一次攻击是在大约30年前构思的,但DNS基础设施-经过一系列改进,但其原始设计-继续在访问服务,数据和设备方面发挥关键作用。而且,尽管近年来DNSSEC安全扩展得到了相当广泛的采用,但DNS攻击正变得越来越频繁、复杂和危险。它们是全球性的,多样的,动态的,可以绕过传统的安全系统,如下一代防火墙和数据丢失预防系统。对DNS假设的重新审视已经以非常不同的方式提出,反映了互联网治理和用户自由方面的不同观点,标准化机构,行业联盟和学术研究正在做出巨大努力,以实现最新的设计和实施。目前的工作概述了最有前途的建议,试图摆脱一些见解DNS的未来。
When DNS was created, nobody expected that it would have become the base for the digital economy and a prime target for cybercriminals. And nobody expected that one main asset of the digital economy would have been users’ browsing habits, putting at risk their privacy. The DNS was designed and implemented according to speed, scalability, and reliability criteria, whereas security and privacy did not fit in the objectives. Although the first attacks were already conceived about thirty years ago, the DNS infrastructure - with a bunch of improvements but its original design - continues to play a pivotal role in enabling access to services, data and devices. And, despite the fairly widespread adoption of DNSSEC security extensions in recent years, DNS attacks are becoming more and more frequent, sophisticated and dangerous. They are global, varied, dynamic and can circumvent traditional security systems such as next-generation firewalls and data loss prevention systems. A revisitation of DNS assumptions has been proposed in very different ways, reflecting diverse point of views in terms of Internet governance and user freedom, and a great effort is in place by standardization bodies, industry consortia and academic research to converge toward an updated design and implementation. The present work overviews the most promising proposals, trying to shed some insight on the future of DNS.