首页> 外文期刊>IEICE Transactions on Information and Systems >UDP Large-Payload Capability Detection for DNSSEC
【24h】

UDP Large-Payload Capability Detection for DNSSEC

机译:DNSSEC的UDP大有效负载能力检测

获取原文
获取原文并翻译 | 示例
       

摘要

Domain Name System (DNS) is a major target for the network security attacks due to the weak authentication. A security extension DNSSEC has been proposed to introduce the public-key authentication, but it is still on the deployment phase. DNSSEC assumes IP fragmentation allowance for exchange of its messages over UDP large payloads. IP fragments are often blocked on network packet filters for administrative reasons, and the blockage may prevent fast exchange of DNSSEC messages. In this paper, we propose a scheme to detect the UDP large-payload transfer capability between two DNSSEC hosts. The proposed detection scheme does not require new protocol elements of DNS and DNSSEC, so it is applicable by solely modifying the application software and configuration. The scheme allows faster capability detection to probe the end-to-end communication capability between two DNS hosts by transferring a large UDP DNS message. The DNS software can choose the maximum transmission unit (MTU) on the application level using the probed detection results. Implementation test results show that the proposed scheme shortens the detection and transition time on fragment-blocked transports.
机译:域名系统(DNS)是由于身份验证薄弱而引起网络安全攻击的主要目标。已经提出了安全扩展DNSSEC来引入公钥身份验证,但是它仍处于部署阶段。 DNSSEC假定IP分片允许通过UDP大有效负载交换其消息。 IP碎片通常出于管理原因而在网络数据包筛选器上被阻止,并且这种阻止可能会阻止DNSSEC消息的快速交换。在本文中,我们提出了一种检测两个DNSSEC主机之间的UDP大有效负载传输能力的方案。提议的检测方案不需要DNS和DNSSEC的新协议元素,因此仅通过修改应用程序软件和配置即可适用。该方案允许更快的能力检测,以通过传输大的UDP DNS消息来探测两个DNS主机之间的端到端通信能力。 DNS软件可以使用探测到的检测结果在应用程序级别上选择最大传输单位(MTU)。实施测试结果表明,该方案缩短了片段阻塞传输的检测和过渡时间。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号