Is the Internet Ready for DNSSEC: Evaluating Pitfalls in the Naming Infrastructure

نویسندگان

  • Haya Shulman
  • Michael Waidner
چکیده

We study the challenges of deploying DNSSEC on Domain Name System (DNS) name servers. DNSSEC, a defence mechanism for DNS, was designed to provide cryptographic assurance for DNS records against cache poisoning attacks. Although standardised more than 15 years ago, DNSSEC is still not widely deployed. Multiple efforts are focused on identifying deployment obstacles and it is generally believed that adopting DNSSEC is mainly a matter of motivation. In this work we systematically explore this widely held, folklore belief. Utilising wide-scale measurements of DNS servers in the forward and the reverse DNS trees, we show that a large fraction of servers in popular domains fail with DNSSEC signed DNS requests, hence breaking the backward compatibility property of DNSSEC. This further reduces the motivation for clients to adopt DNSSEC. Our evaluation results indicate that DNSSEC deployment is a cost-benefit decision, and full adoption thereof requires upgrading significant parts of the DNS infrastructure. In particular, deploying DNSSEC on the unsigned domains today would render a large fraction thereof unreachable. Our study shows two intertwined obstacles that impede the adoption of DNSSEC for DNS. One is legacy infrastructure, the other is lack of protocol support.

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Security for Future Internet Architecture - Motivation from DNSSEC

DNS has a long history of being the primary target of malicious network attacks. These attacks take advantage of the weakness that the domain name mapping information is not authenticated. This motivates the need of security global infrastructure for future internet architecture. DNSSEC is a secure extension of DNS, and is considered as one of the most important mechanisms for critical informat...

متن کامل

The Design of Metrics for Quantifying the DNSSEC Deployment

This paper examines the deployment of the DNS Security Extensions (DNSSEC), which adds cryptographic protection to DNS, one of the core components in the Internet infrastructure. We analyze the data collected from the initial DNSSEC deployment which started in 2005, and identify three critical metrics to gauge the deployment: availability, verifiability, and validity. Our results provide the fi...

متن کامل

Challenges and Opportunities In Deploying DNSSEC A progress report on an investigation into DNSSEC deployment

In the process of building a web portal[1] focused on providing real-world deployment information about DNS Security Extensions (DNSSEC), Internet Society staff identified a number of areas where DNSSEC deployment can be simplified for domain name holders, domain name infrastructure operators and domain name consumers (i.e. users of DNSSEC-signed domains). Some areas were predictably around the...

متن کامل

Measuring the Practical Impact of DNSSEC Deployment

DNSSEC extends DNS with a public-key infrastructure, providing compatible clients with cryptographic assurance for DNS records they obtain, even in the presence of an active network attacker. As with many Internet protocol deployments, administrators deciding whether to deploy DNSSEC for their DNS zones must perform cost/benefit analysis. For some fraction of clients — those that perform DNSSEC...

متن کامل

Towards Adoption of DNSSEC: Availability and Security Challenges

DNSSEC deployment is long overdue; however, it seems to be finally taking off. Recent cache poisoning attacks motivate protecting DNS, with strong cryptography, rather than with challenge-response ‘defenses’. Our goal is to motivate and help correct DNSSEC deployment. We discuss the state of DNSSEC deployment, obstacles to adoption and potential ways to increase adoption. We then present a comp...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2016