Challenges in securing the domain name system
Chandramouli, R.; Rose, S.
Security & Privacy, IEEE
Volume 4, Issue 1, Jan.-Feb. 2006 Page(s): 84 - 87
Digital Object Identifier 10.1109/MSP.2006.8
Summary: Two main security threats exist for DNS in the context of query/response transactions. Attackers can spoof authoritative name servers responding to DNS queries and alter DNS responses in transit through man-in-the-middle attacks, and alter the DNS responses stored in caching name servers. The IETF has defined the digital signature-based DNSSEC for protecting DNS query/response transactions through a series of requests for comments.
View citation and abstract |