Quantifying the operational status of the DNSSEC deployment

Quantifying the operational status of the DNSSEC deployment
复制标题

量化 DNSSEC 部署的运行状态

DOI:
10.1145/1452520.1452548
复制
发表时间:
2008
期刊:
--
影响因子:
--
通讯作者:
Lixia Zhang
Lixia Zhang
中科院分区:
--
文献类型:
--
作者:
E. Osterweil;Michael Ryan;D. Massey;Lixia Zhang

文献摘要

被引文献

相似文献

本文研究了DNS安全扩展(DNSSEC)的部署,它为互联网基础设施中的核心组件之一DNS增加了加密保护。我们分析了从2年前开始的初始DNSSEC部署收集的数据,并确定了三个衡量部署的关键指标:可用性、可验证性和有效性。我们的研究结果首次全面考察了DNSSEC的部署,并揭示了设计中没有预料到的一些挑战,但在部署中已经变得很明显。首先,在当今的Internet基础设施中存在的诸如中间盒(防火墙、nat等)之类的障碍已被证明是有问题的,并导致了不可预见的可用性问题。其次,DNSSEC的公钥授权系统并没有像预期的那样发展,目前超过97%的DNSSEC区域是隔离的,无法验证的,除非增加一些外部密钥认证机制。此外,我们的研究结果表明,密码验证不等同于验证;经过验证的数据仍然可能包含错误的值。最后,我们的研究结果证明了监测和测量在DNSSEC部署中的重要作用。我们相信,从DNSSEC部署的观察和经验教训可以为衡量未来互联网规模的加密系统提供见解。
This paper examines the deployment of the DNS Security Extensions (DNSSEC), which adds cryptographic protection to DNS, one of the core components in the Internet infrastructure. We analyze the data collected from the initial DNSSEC deployment which started over 2 years ago, and identify three critical metrics to gauge the deployment: availability, verifiability, and validity. Our results provide the first comprehensive look at DNSSEC's deployment and reveal a number of challenges that were not anticipated in the design but have become evident in the deployment. First, obstacles such as middle-boxes (firewalls, NATs, etc.) that exist in today's Internet infrastructure have proven to be problematic and have resulted in unforeseen availability problems. Second, the public-key delegation system of DNSSEC has not evolved as it was hoped and it currently leaves over 97% of DNSSEC zones isolated and unverifiable, unless some external key authentication mechanism is added. Furthermore, our results show that cryptographic verification is not equivalent to validation; a piece of verified data can still contain the wrong value. Finally, our results demonstrate the essential role of monitoring and measurement in the DNSSEC deployment. We believe that the observations and lessons from the DNSSEC deployment can provide insights into measuring future Internet-scale cryptographic systems.