首页> 外文会议>International Conference on Information and Communication Technology Convergence >A Client Based DNSSEC Validation Mechanism with Recursive DNS Server Separation
【24h】

A Client Based DNSSEC Validation Mechanism with Recursive DNS Server Separation

机译:具有递归DNS服务器分离的基于客户端的DNSSEC验证机制

获取原文

摘要

DNSSEC has been proposed to provide data origin authentication and data integrity between recursive DNS server and authoritative zone server. Although DNSSEC is an effective countermeasure to DNS cache poisoning attack, it still has low deployment rate in the Internet due to the significant workload increase on recursive DNS servers. Moreover, current DNSSEC operation does not cover end clients and the recursive DNS server separation has not been considered so that end users do not intend to use free and powerful public recursive DNS servers due to security concerns. In this paper, we propose a client based DNSSEC validation mechanism with recursive DNS server separation based on query types. DNSSEC related record types such as RRSIG, DNSKEY, DS, etc. will be forwarded to a trusted internal recursive DNS server while normal record types such as A, AAAA, MX, etc. will be forwarded to public recursive DNS server, and eventually, DNSSEC validation will be performed on end clients. Consequently, not only end clients can obtain the benefit of DNSSEC but also the workload increase of internal recursive DNS servers can be mitigated. We implemented a prototype system and evaluated the features on a local experimental network. Based on the results, we confirmed that the prototype system worked effectively and it is possible to prevent end clients from DNS cache poisoning attacks by the proposed mechanism.
机译:已经建议使用DNSSEC在递归DNS服务器和权威区域服务器之间提供数据源身份验证和数据完整性。尽管DNSSEC是针对DNS缓存中毒攻击的有效对策,但由于递归DNS服务器上的大量工作量增加,它在Internet上的部署率仍然较低。此外,当前的DNSSEC操作不覆盖最终客户端,并且未考虑递归DNS服务器的分离,因此出于安全考虑,最终用户不打算使用免费且功能强大的公共递归DNS服务器。在本文中,我们提出了一种基于客户端的DNSSEC验证机制,该机制具有基于查询类型的递归DNS服务器分离。 DNSSEC相关记录类型(例如RRSIG,DNSKEY,DS等)将被转发到受信任的内部递归DNS服务器,而普通记录类型(例如A,AAAA,MX等)将被转发到公共递归DNS服务器,最终, DNSSEC验证将在最终客户端上执行。因此,不仅最终客户可以获得DNSSEC的好处,而且可以减轻内部递归DNS服务器的工作量。我们实施了原型系统,并在本地实验网络上评估了功能。根据结果​​,我们确认该原型系统有效运行,并且可以通过所提出的机制防止最终客户端遭受DNS缓存中毒攻击。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号