课题基金 / 基金详情

Secure and Proactive DNS

Secure and Proactive DNS
安全且主动的 DNS
批准号:
0129627
负责人:
Giuseppe Ateniese
金额:
$36.63万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2002
资助国家:
美国
项目状态:
已结题
起止时间:
2002-02-15 至 2006-01-31
关键词:

项目摘要

项目成果

Giuseppe Ateniese的其他基金

相似基金

相关文献

中文摘要
翻译
域名系统(DNS)是一个分层分布式数据库,它提供Internet操作的基本信息,例如在人类可读的主机名和Internet协议(IP)地址之间进行转换。由于DNS服务的信息的重要性,在DNS系统内对安全通信有着强烈的需求。当前的(不安全的)DNS不能阻止攻击者修改或注入DNS消息。用户访问互联网上的主机时,需要通过DNS将主机名正确转换为IP地址。一个典型的攻击,被称为DNS欺骗,允许攻击者操纵DNS答案的方式给用户。如果攻击者在单个服务器的DNS表中进行更改,这些更改将在互联网上传播,如病毒感染。 DNS也越来越多地用于在复制的服务器之间执行负载分配。例如,Akamai等公司已经使用DNS来提供Web内容分发。此外,由于DNS是一个可访问的数据库,它可以被用作一个公钥基础设施(PKI),这将使电子商务应用程序。安全的DNS意味着提供数据源认证和完整性保护。 现有的DNS安全建议主要基于公钥加密。在这个提议中,研究者描述了一种基于标准对称(或秘密密钥)密码技术的新方法。研究者引入了DNS对称证书的概念,用于创建从DNS根服务器到对DNS树的一部分具有权威性的服务器的可信路径。这种策略与Davis和Swick提出的策略非常相似,对称证书可以看作是身份验证系统中的一种票据,它通过票据授予服务器创建从认证服务器到目的服务器的可信路径。DNS证书与公钥证书一样易于管理,但它们不能共享,这在DNS系统中通常不需要。 该项目的解决方案能够提供广泛的安全服务,这些服务以前被认为是不切实际或难以管理的,例如相互认证和密钥撤销。此外,与基于公钥密码的方法相比,在计算复杂性、网络流量和存储需求方面的收益令人印象深刻。 本文的研究对如何定义一个基于公钥密码的安全DNS系统有了初步的认识。研究人员建议建立这样一个系统,并公开原型实现。拟议研究的第二部分,将集中在一个尚未解决的问题:DNS服务器代表一个单点攻击,很容易受到损害。研究人员想调查的可能性,分配的作用,一个单一的DNS服务器之间的几个服务器。 该研究提出了一种主动DNS系统,该系统可以通过结合分散存储和动态自维护的标准技术来抵御组件故障(无论是否是恶意的)。研究人员的方法将允许DNS服务器自动从可能的、未被发现的入侵中恢复,然后保持不间断的安全性。 研究人员建议使用主动安全模型,该模型提供了一种方法,即使单个组件被攻击者反复闯入和控制,只要没有太多的服务器同时受到危害,也可以维护系统的整体安全。主动安全模型采用的方法是首先将加密能力分布在多个服务器上,然后让服务器定期参与刷新协议。攻击者在刷新周期之前收集的信息对于将来攻击系统变得无用。研究者提出了一种基于主动安全模型的分布式存储系统、数据存储和编码、动态自维护的DNS服务器体系结构。
英文摘要
The Domain Name System (DNS) is a hierarchically distributeddatabase that provides information fundamental to Internetoperations, such as translating between human readable host namesand Internet Protocol (IP) addresses. Due to the importance ofthe information served by DNS, there is a strong demand forsecuring communication within the DNS system. The current(insecure) DNS does not prevent attackers from modifying orinjecting DNS messages. Users accessing hosts on the Internetrely on the correct translation of host names to IP addresses bythe DNS. A typical attack, referred to as DNS spoofing, allows anattacker to manipulate DNS answers on their way to the users.If an attacker makes changes in the DNS tables of a singleserver, those changes will propagate across the Internet as aviral infection. Increasingly, DNS is also being used to performload distribution among replicated servers. For instance,companies such as Akamai have used DNS to provide Web contentdistribution. Moreover, there is consensus that since DNS is aglobal and available database, it can be employed as a Public KeyInfrastructure (PKI) which would enable e-commerce applications.Securing DNS means providing data origin authentication andintegrity protection. Existing proposals for securing DNS aremainly based on public-key cryptography. In this proposal, the researcherdescribes a new approach based on standard symmetric (orsecret-key) cryptographic techniques. The researcher introduces the concept ofDNS symmetric certificate that are used to create a trusted pathfrom the DNS root server to a server that is authoritative for aportion of the DNS tree. This strategy is very similar to the oneintroduced by Davis and Swick and symmetric certificates can beseen as a sort of tickets in the Kerberos system which create atrusted path from the authentication server to the destinationserver going through the ticket-granting server. DNS symmetriccertificate are as manageable as public-key certificates with theexception that they cannot be shared, which is not generallyrequired in the DNS system. The project solution enables a wide range ofsecure services previously believed impractical or too difficultto manage, such as mutual authentication and key revocation.Moreover, the gain in terms of computational complexity, networktraffic, and storage requirements is impressive when comparedwith public-key cryptography based approaches. The research has clearideas on how to define a secure DNS system based on symmetric-keycryptography. The researcher proposes to build such a system and make publicthe prototype implementation.The second part of the proposed research, would focus on a stillunresolved problem: A DNS server represents a single point ofattack which could easily be compromised. The researcher would like toinvestigate the possibility to distribute the role of a singleDNS server among several servers. The research proposes a proactive DNSsystem that can survive component failures (whether malicious ornot) by combining standard techniques of decentralized storageand dynamic self-maintenance. The researchers approach would allow DNSservers to automatically recover from possible, undetectedbreak-ins and then maintain uninterrupted security. The researchers propose touse the proactive security model, which provides a method formaintaining the overall security of a system even when individualcomponents are repeatedly broken into and controlled by anattacker, as long as not too many servers are compromised at thesame time. The approach employed by the proactive security modelis to first distribute the cryptographic capabilities amongseveral servers, next have the server periodically engage in arefreshment protocol. Information gathered by an attacker beforea refreshment period becomes useless to attack the system in thefuture. The researcher proposes to define, and build, an architecture thatcombines decentralized storage system technologies, dataredundancy and encoding, and dynamic self-maintenance to createsurvivable DNS servers based on the proactive security model.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
TC: Small: Distributed Privacy-Preserving Policy Reconciliation
  • 批准号:
    1018616
  • 项目类别:
    Standard Grant
  • 资助金额:
    $45.7万
  • 财政年份:
    2010
  • 负责人:
    Giuseppe Ateniese
  • 依托单位:
CAREER: Health Information Privacy Protection: System and Social Aspects
  • 批准号:
    0133698
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $37.5万
  • 财政年份:
    2002
  • 负责人:
    Giuseppe Ateniese
  • 依托单位:
海外基金