首页> 外文会议>IEEE/IFIP Network Operations and Management Symposium >Economic incentives on DNSSEC deployment: Time to move from quantity to quality
【24h】

Economic incentives on DNSSEC deployment: Time to move from quantity to quality

机译:DNSSEC部署的经济诱因:从数量转变为质量的时间

获取原文

摘要

The security extensions to the DNS (DNSSEC) currently cover approximately 3% of all domains worldwide. In response to the low deployment of DNSSEC, a few top-level domains started offering 'per-domain' economic incentives to encourage adoption of the protocol by offering a yearly discount on each signed domain. However, it remains unclear whether these incentives are well-balanced and foster the overall security of the infrastructure as well as its deployment at scale. In this paper we argue that, in the presence of fixed costs of deployment, misaligned 'per-domain' incentives may have the collateral effect of encouraging large operators to massively deploy unsecure implementations of DNSSEC, whereas smaller operators, for which the effect of the economic incentive is negligible, may not significantly benefit from it. To investigate this, we study the security of DNSSEC deployment at scale, particularly in TLDs that offer economic incentives. We find that the security of DNSSEC implementations in the wild poorly reflects standard recommendations, particularly for tasks that cannot be solved by triggering a flag in the DNS software service (e.g. key rollover). Further, we find that, on average, large operators deploy weak DNSSEC security more frequently than small DNSSEC operators, suggesting that current incentives are ineffective in promoting a secure adoption and in deterring insecure implementations. We conclude the paper with actionable recommendations for TLD registry operators to improve the alignment of economic incentives with secure DNSSEC requirements.
机译:DNS(DNSSEC)的安全扩展目前覆盖全球所有域的大约3%。为了应对DNSSEC的部署不足,一些顶级域开始提供“每域”经济激励措施,以通过对每个已签名域提供年度折扣来鼓励该协议的采用。但是,目前尚不清楚这些激励措施是否均衡,是否能促进基础设施的整体安全性以及大规模部署。在本文中,我们认为,在存在固定的部署成本的情况下,错位的“每域”激励措施可能会产生附带影响,鼓励大型运营商大规模部署不安全的DNSSEC实现,而较小的运营商则对DNSSEC产生了影响。经济激励措施微不足道,可能无法从中获得重大利益。为了对此进行调查,我们大规模研究了DNSSEC部署的安全性,特别是在提供经济诱因的TLD中。我们发现DNSSEC实施的安全性在本质上不能很好地反映标准建议,尤其是对于那些无法通过触发DNS软件服务中的标志(例如密钥翻转)来解决的任务。此外,我们发现,与小型DNSSEC运营商相比,大型运营商平均会更频繁地部署弱的DNSSEC安全性,这表明当前的激励措施在促进安全采用和阻止不安全的实施方面无效。最后,我们为TLD注册管理机构运营商提供了可行的建议,以改善经济激励措施与安全DNSSEC要求的一致性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号