loading...
Enhancing DNS Security using the SSL Trust Infrastructure
Sedona, Arizona February 02-February 04
DOI Bookmark: http://doi.ieeecomputersociety.org/10.1109/WORDS.2005.3310th IEEE International Workshop on O ...
 This Article 
 
PDF
HTML
 
 Share 
   
 Bibliographic References 
   
 Add to: 
 
Digg
Furl
Spurl
Blink
Simpy
Google
Del.icio.us
Y!MyWeb
 
 Search 
   
Christof Fetzer, Dresden University of Technology Department of Computer Science Institute for System Architecture, 01062 Dresden, Germany
Gert Pfeifer, Dresden University of Technology Department of Computer Science Institute for System Architecture, 01062 Dresden, Germany
Trevor Jim, AT&T Labs-Research 180 Park Ave., Florham Park, NJ, 07932, USA

The main functionality of the Domain Name System (DNS) is to translate symbolic names into IP addresses. Due to the criticality of DNS for the proper functioning of the Internet, many improvements have been proposed for DNS in terms of security and dependability. However, the current secure DNS (DNSSEC) standard has still several problems that need further consideration. For example, online updates and denial of service attacks are not suf?ciently addressed. These problems are serious obstacles that might prevent DNSSEC from replacing the traditional DNS. In this paper we discuss several of these technical and economic problems. To address these issues, we propose a simple extension to the existing DNS. It is SSL based and individual domains can decide independently of each other if and when to adopt the extensions. We show how to implement these extensions with the help of a simple proxy DNS server.

Citation:
Christof Fetzer, Gert Pfeifer, Trevor Jim, "Enhancing DNS Security using the SSL Trust Infrastructure," words, pp.21-27, 10th IEEE International Workshop on Object-Oriented Real-Time Dependable Systems, 2005
Usage of this product signifies your acceptance of the Terms of Use.


Suggestions