DNSSEC: Security and availability challenges

DNSSEC: Security and availability challenges
复制标题

DNSSEC:安全性和可用性挑战

DOI:
--
复制
发表时间:
2013
期刊:
IEEE Conference on Communications and Network Security
影响因子:
--
通讯作者:
Haya Schulmann
Haya Schulmann
中科院分区:
--
文献类型:
--
作者:
A. Herzberg;Haya Schulmann

文献摘要

被引文献

相似文献

DNSSEC早在15年前就被提出,但其(正确)采用仍然非常有限。最近的缓存中毒攻击推动了DNSSEC的部署。在这项工作中,我们提出了一个全面的概述DNSSEC的挑战和潜在的陷阱,包括:易受攻击的配置:我们表明,域间引用(通过NS,MX和CNAME记录)提出了DNSSEC部署的挑战,并可能导致易受攻击的配置。由于到目前为止部署有限,预计这些配置将受到欢迎。增量部署:我们讨论了互操作性问题对解析器进行DNSSEC验证的影响,以及由于增量部署的流行做法而增加的漏洞的可能性。超大响应挑战:我们解释了大型DNSSEC启用的DNS响应如何导致互操作性挑战,以及如何被滥用于DoS甚至DNS中毒。
DNSSEC was proposed more than 15 years ago but its (correct) adoption is still very limited. Recent cache poisoning attacks motivate deployment of DNSSEC. In this work we present a comprehensive overview of challenges and potential pitfalls of DNSSEC, including: Vulnerable configurations: we show that inter-domain referrals (via NS, MX and CNAME records) present a challenge for DNSSEC deployment and may result in vulnerable configurations. Due to the limited deployment so far, these configurations are expected to be popular. Incremental Deployment: we discuss implications of interoperability problems on DNSSEC validation by resolvers and potential for increased vulnerability due to popular practices of incremental deployment. Super-sized Response Challenges: we explain how large DNSSEC-enabled DNS responses cause interoperability challenges, and can be abused for DoS and even DNS poisoning.