首页> 外文会议>IEEE Joint Intelligence and Security Informatics Conference >DNSSEC Misconfigurations: How Incorrectly Configured Security Leads to Unreachability
【24h】

DNSSEC Misconfigurations: How Incorrectly Configured Security Leads to Unreachability

机译:DNSSEC MIRCONFIGURATIONS:配置错误的安全性导致无法达成

获取原文

摘要

DNSSEC offers protection against spoofing of DNS data by providing authentication of its origin, ensuring integrity and giving a way to authenticate denial of existence by using public-key cryptography. Where the relevance of securing a technology as crucial to the Internet as DNS is obvious, the DNSSEC implementation increases the complexity of the deployed DNS infrastructure, which may manifest in misconfiguration. A misconfiguration not only leads to silently losing the expected security, but might result in Internet users being unable to access the network, creating an undesired unreachability problem. In this paper, we measure and analyze the misconfigurations for domains in four zones (.bg, .br, .co and .se). Furthermore, we classify these misconfigurations into several categories and provide an explanation for their possible causes. Finally, we evaluate the effects of misconfigurations on the reachability of a zone's network. Our results show that, although progress has been made in the implementation of DNSSEC, over 4% of evaluated domains show misconfigurations. Of these misconfigured domains, almost 75% were unreachable from a DNSSEC aware resolver. This illustrates that although the authorities of a domain may think their DNS is secured, it is in fact not. Worse still, misconfigured domains are at risk of being unreachable from the clients who care about and implement DNSSEC verification while the publisher may remain unaware of the error and its consequences.
机译:DNSSEC通过提供原始身份验证,确保完整性并提供使用公钥加密拒绝拒绝存在的方法来提供防止DNS数据的保护。在将技术视为互联网的关键作为DNS是显而易见的,DNSSEC实现可以增加部署的DNS基础设施的复杂性,这可能表现出在错误配置中。错误配置不仅导致默默地丢失预期的安全性,而且可能导致互联网用户无法访问网络,从而创建不可预识的不达问题。在本文中,我们测量并分析四个区域中的域的错误配置(.bg,.br,.co和.se)。此外,我们将这些误操作分为几个类别,并为其可能的原因提供解释。最后,我们评估了错误配置对区域网络可达性的影响。我们的结果表明,虽然在执行DNSSEC方面取得了进展,但在4%的评估域中有超过4%显示错误配置。在这些错误配置的域中,近75%的人无法从DNSSec意识到的解析器无法访问。这表明虽然域的当局可能认为他们的DNS是安全的,但事实上没有。更糟糕的是,错误配置的域有可能无法从关心和实施DNSSEC验证的客户无法访问的风险,而出版商可能仍然不知道错误及其后果。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号