Home / Blogs

DNS… Wait a SEC

Elisa Cooper

DNSSEC (Domain Name System Security Extensions) is a set of specifications designed to prevent hackers from intercepting DNS queries and redirecting end users to spoofed sites through a technique known as Cache Poisoning. Complete DNSSEC implementation requires that domains are authenticated at the root by the Registry, and that DNS zones and records are authenticated as well.

Now before I go any further, let me begin by stating that I fully support the development and deployment of DNSSEC and that the vulnerabilities presented by Cache Poisoning are very real, especially for those websites collecting login credentials or other types of sensitive information.

However, DNSSEC is not the "end all, be all" Internet security solution that many believe it to be.

DNSSEC is addressing just one of the many Internet vulnerabilities that still exist today.

The impacts of Cache Poisoning are generally not as wide-spread and are considerably more difficult to detect relative to breaches that occur at the Registry-level or the Registrar-level which affect the global resolution of websites.

Take the Puerto Rican Registry as an example. In August of 2006, .PR announced that they would be the second ccTLD to deploy DNSSEC. While their deployment of DNSSEC certainly may have been helpful in thwarting potential Cache Poisoning attacks, assuming that zones and records were also signed, it did absolutely nothing to protect the .PR Registry when hackers exploited a SQL vulnerability to update and redirect name servers to politically motivated sites.

Other recent domain and DNS exploits include social engineering attacks to reset passwords, SQL attacks against registrars, and breached e-mail accounts to retrieve login credentials. Unfortunately, DNSSEC would not have prevented any of these attacks either.

So while DNSSEC certainly addresses vulnerabilities related to Cache Poisoning, I urge those with the responsibility for securing their presence online to not only implement DNSSEC for their highly-trafficked and valuable domains, but to also ensure that their domains are hardened against social engineering attacks via two-factor authentication, locked at the registry-level where available and continually monitored to remediate registry breaches when they do occur.

By Elisa Cooper, Director of Product Marketing at MarkMonitor. Elisa Cooper also contributes to the MarkMonitor weblog located here.

Related topics: Cyberattack, Cybercrime, DNS, DNS Security, Domain Names, Registry Services, Security

WEEKLY WRAP — Get CircleID's Weekly Summary Report by Email:

Comments

I'm sorry but just who claimed DNSSEC is a be all end all of security? Suresh Ramasubramanian  –  Apr 15, 2010 10:51 AM PDT

People who work on operational security rather than product marketing, that is.

If anybody in such a role said so, I would be interested to hear that.

cheers
srs

To post comments, please login or create an account.

Related Blogs

Related News

Topics

Industry Updates – Sponsored Posts

How the dot-CO Domain Opened the Door to a New Era of Internet Innovation

Nominum Launches 1st Comprehensive Mobile Security Solution That Protects Both Network and End User

Neustar Names Becky Burr as its Chief Privacy Officer

Application Filed for DOT BUDAPEST

Frontline and Nominum Deliver Integrated DNS-Based Platform to Enhance Enterprise Security

Nominum Launches Comprehensive Suite of DNS-Based Security Solutions for Russian Service Providers

Call for Nominations to the Public Interest Registry .ORG Advisory Council

Nominum Sets New Record for Network Speed and Efficiency

Recursive DNS Talk: Round Trip Times, Delegations and Performance

Oman Relaunches .om with the Support of ARI Registry Services

Implementing a Cyber-Security Code of Conduct: Real-Life Lessons From Australia (Webinar)

Domains Ending With .JP.NET Now Available to the General Public at Bargain Prices

Minds+Machines Wins Back-End Registry Services Contract For .BASKETBALL

DDoS Attacks: Top 10 Trends and Truths (Video)

.US Celebrates American Small Business, Surprises Unsuspecting Small Business Owner

Architelos Introduces 'Velocity' to Help TLDs Market in Evolving Domain Name Industry

Nominum Chairman and Chief Scientist, Dr. Paul Mockapetris Inducted into the Internet Hall of Fame

Nominum and Nixu Software to Deliver Centralized DNS and DHCP Management Solution

Minds + Machines Will Host New dot Rugby gTLD

DNS on Defense, DNS on Offense

Hot Topics

Minds + Machines

Top-Level Domains

Sponsored by
Minds + Machines
Afilias

DNS Security

Sponsored by
Afilias
Nominum

IPv6

Sponsored by
Nominum
dotMobi

Mobile

Sponsored by
dotMobi
Neustar UltraDNS

DNS

Sponsored by
Neustar UltraDNS
Verisign

Security

Sponsored by
Verisign