This Article 
   
 Share 
   
 Bibliographic References 
   
 Add to: 
 
Digg
Furl
Spurl
Blink
Simpy
Google
Del.icio.us
Y!MyWeb
 
 Search 
   
The Second International Conference on Availability, Reliability and Security (ARES'07)
Security vulnerabilities in DNS and DNSSEC
Vienna, Austria
April 10-April 13
ISBN: 0-7695-2775-2
Suranjith Ariyapperuma, University of London
Chris J. Mitchell, University of London
We present an analysis of security vulnerabilities in the Domain Name System (DNS) and the DNS Security Extensions (DNSSEC). DNS data that is provided by name servers lacks support for data origin authentication and data integrity. This makes DNS vulnerable to man in the middle (MITM) attacks, as well as a range of other attacks. To make DNS more robust, DNSSEC was proposed by the Internet Engineering Task Force (IETF). DNSSEC provides data origin authentication and integrity by using digital signatures. Although DNSSEC provides security for DNS data, it suffers from serious security and operational flaws. We discuss the DNS and DNSSEC architectures, and consider the associated security vulnerabilities.
Citation:
Suranjith Ariyapperuma, Chris J. Mitchell, "Security vulnerabilities in DNS and DNSSEC," ares, pp.335-342, The Second International Conference on Availability, Reliability and Security (ARES'07), 2007
Usage of this product signifies your acceptance of the Terms of Use.