首页> 外文期刊>IEEE Network >Minimizing information leakage in the DNS
【24h】

Minimizing information leakage in the DNS

机译:最大限度地减少DNS中的信息泄漏

获取原文
获取原文并翻译 | 示例
           

摘要

The domain name system is the global lookup service for network resources. To protect DNS information, the DNS security extensions have been developed and deployed on branches of the DNS to provide authentication and integrity protection using digital signatures. However, signed DNS nodes were found to have an unfortunate side effect: an attacker can query them as reconnaissance before attacking hosts on a particular network. There are different ways a zone administrator can minimize information leakage and still take advantage of DNSSEC for integrity and source authentication. This article describes the risk and examines the protocol and operational options and looks at their advantages and drawbacks.
机译:域名系统是网络资源的全局查找服务。为了保护DNS信息,已经开发了DNS安全扩展并将其部署在DNS的分支上,以使用数字签名提供身份验证和完整性保护。但是,发现签名的DNS节点有一个不幸的副作用:攻击者可以在攻击特定网络上的主机之前将其查询为侦查对象。区域管理员可以通过多种方式来最大程度地减少信息泄漏,并仍然利用DNSSEC进行完整性和源身份验证。本文介绍了风险,并检查了协议和操作选项,并探讨了它们的优缺点。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号