Secure and Proactive DNS
Secure and Proactive DNS
批准号:
0129627
负责人:
Giuseppe Ateniese
金额:
$36.63万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2002
资助国家:
美国
项目状态:
已结题
起止时间:
2002-02-15 至 2006-01-31
中文摘要
点击翻译按钮获取中文摘要
英文摘要
The Domain Name System (DNS) is a hierarchically distributeddatabase that provides information fundamental to Internetoperations, such as translating between human readable host namesand Internet Protocol (IP) addresses. Due to the importance ofthe information served by DNS, there is a strong demand forsecuring communication within the DNS system. The current(insecure) DNS does not prevent attackers from modifying orinjecting DNS messages. Users accessing hosts on the Internetrely on the correct translation of host names to IP addresses bythe DNS. A typical attack, referred to as DNS spoofing, allows anattacker to manipulate DNS answers on their way to the users.If an attacker makes changes in the DNS tables of a singleserver, those changes will propagate across the Internet as aviral infection. Increasingly, DNS is also being used to performload distribution among replicated servers. For instance,companies such as Akamai have used DNS to provide Web contentdistribution. Moreover, there is consensus that since DNS is aglobal and available database, it can be employed as a Public KeyInfrastructure (PKI) which would enable e-commerce applications.Securing DNS means providing data origin authentication andintegrity protection. Existing proposals for securing DNS aremainly based on public-key cryptography. In this proposal, the researcherdescribes a new approach based on standard symmetric (orsecret-key) cryptographic techniques. The researcher introduces the concept ofDNS symmetric certificate that are used to create a trusted pathfrom the DNS root server to a server that is authoritative for aportion of the DNS tree. This strategy is very similar to the oneintroduced by Davis and Swick and symmetric certificates can beseen as a sort of tickets in the Kerberos system which create atrusted path from the authentication server to the destinationserver going through the ticket-granting server. DNS symmetriccertificate are as manageable as public-key certificates with theexception that they cannot be shared, which is not generallyrequired in the DNS system. The project solution enables a wide range ofsecure services previously believed impractical or too difficultto manage, such as mutual authentication and key revocation.Moreover, the gain in terms of computational complexity, networktraffic, and storage requirements is impressive when comparedwith public-key cryptography based approaches. The research has clearideas on how to define a secure DNS system based on symmetric-keycryptography. The researcher proposes to build such a system and make publicthe prototype implementation.The second part of the proposed research, would focus on a stillunresolved problem: A DNS server represents a single point ofattack which could easily be compromised. The researcher would like toinvestigate the possibility to distribute the role of a singleDNS server among several servers. The research proposes a proactive DNSsystem that can survive component failures (whether malicious ornot) by combining standard techniques of decentralized storageand dynamic self-maintenance. The researchers approach would allow DNSservers to automatically recover from possible, undetectedbreak-ins and then maintain uninterrupted security. The researchers propose touse the proactive security model, which provides a method formaintaining the overall security of a system even when individualcomponents are repeatedly broken into and controlled by anattacker, as long as not too many servers are compromised at thesame time. The approach employed by the proactive security modelis to first distribute the cryptographic capabilities amongseveral servers, next have the server periodically engage in arefreshment protocol. Information gathered by an attacker beforea refreshment period becomes useless to attack the system in thefuture. The researcher proposes to define, and build, an architecture thatcombines decentralized storage system technologies, dataredundancy and encoding, and dynamic self-maintenance to createsurvivable DNS servers based on the proactive security model.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
TC: Small: Distributed Privacy-Preserving Policy Reconciliation
-
批准号:1018616
-
项目类别:Standard Grant
-
资助金额:$45.7万
-
财政年份:2010
-
负责人:Giuseppe Ateniese
-
依托单位:
CAREER: Health Information Privacy Protection: System and Social Aspects
-
批准号:0133698
-
项目类别:Continuing Grant
-
资助金额:$37.5万
-
财政年份:2002
-
负责人:Giuseppe Ateniese
-
依托单位:
海外基金