A group of developers has released open-source software that gives administrators a hand in making the Internet's addressing system less vulnerable to hackers.
The software, called OpenDNSSEC, automates many tasks associated with implementing DNSSEC (Domain Name System Security Extensions), which is a set a set of protocols that allows DNS (Domain Name System) records to carry a digital signature, said John A. Dickinson, a DNS consultant working on the project.
DNS records allow Web sites to be translated from a name into an IP (Internet Protocol) address, which can be queried by a computer. But the DNS system has several flaws dating from its original design that are being increasingly targeted by hackers.
By tampering with a DNS server, it's possible for a user to type in the correct Web site name but be directed to a fraudulent site, a type of attack called cache poisoning. That's one of many concerns that is driving a movement for ISPs and other entities running DNS servers to use DNSSEC.
With DNSSEC, DNS records are cryptographically signed, and those signatures are verified to ensure the information is accurate. Adoption of DNSSEC, however, has been held back by both the complexity of implementation and a lack of simpler tools, Dickinson said.
To sign DNS records, DNSSEC uses public key cryptography, where signatures are created using a public and private key and implemented on a zone level. Part of the problem is management of those keys, since they must be refreshed periodically to maintain a high level of security, Dickinson said. A mistake in managing those keys could cause major problems, which is one of the challenges for administrators.
OpenDNSSEC allows administrators to create policies and then automate managing the keys and signing the records, Dickinson said. The process now involves more manual intervention, which increases the chance for errors.
OpenDNSSEC "takes care of making sure that zone stays signed properly and correctly according to the policy on a permanent basis," Dickinson said. "All of that is completely automated so that the administrator can concentrate on doing DNS and let the security work in the background."
The software also has a key storage feature that lets administrators keep keys in either a hardware or security software module, an additional layer of protection that ensure keys don't end up in the wrong hands, Dickinson said.
The OpenDNSSEC software is available for download, although it is being offered as a technology preview and shouldn't be used yet in production, Dickinson said. Developers will gather feedback on the tool and release improved versions in the near future.
As of earlier this year, most top-level domains, such as those ending in ".com," were not cryptographically signed, and neither were those in the DNS root zone, the master list of where computers can go to look up an address in a particular domain. VeriSign, which is the registry for ".com," said in February it will implement DNSSEC across top-level domains including .com by 2011.
Other organizations are also moving toward using DNSSEC. The U.S. government has committed to using DNSSEC for its ".gov" domain. Other ccTLDs (country-code Top-Level Domains) operators in Sweden (.se), Brazil (.br), Puerto Rico (.pr) and Bulgaria (.bg), are also using DNSSEC.
Security experts argue that DNSSEC should be used sooner rather than later due to existing vulnerabilities in DNS. One of the more serious ones was revealed by security researcher Dan Kaminsky in July 2008. He showed that DNS servers could be quickly filled with inaccurate information, which could be used for a variety of attacks on e-mail systems, software updating systems and password recovery systems on Web sites.
While temporary patches have been deployed, it's not a long-term solution since it just takes longer to perform an attack, according to a white paper published earlier this year by SurfNet, a Dutch research and education organization. SurfNet is among OpenDNSSEC's backers, which also includes the ".uk" registry Nominet, NLnet Labs and SIDN, the ".nl" registry.
Unless DNSSEC is used, "the basic flaw in the Domain Name System -- that there is no way to ensure that answers to queries are genuine -- remains," the paper said.
Latest on Internet Services
- UK registry to implement DNS security protocol
- Apache mulls end of 1.3, 2.0 releases
- DNS problem linked to DDoS attacks gets worse
- Businesses turn to DNS service to filter the Web
- Facebook releases real-time Web server tech as open source
- Tr.im goes open-source, founder questions bit.ly-Twitter link
- Open-source project aims to makes secure DNS easier
- SSL VPN hack vulnerability details to emerge
- NeuStar offers temporary fix for Kaminsky bug
- Study: Operators should use DNSSEC to improve security
Open Source Essentials
- Microsoft 'interested' in open source browser: Ballmer
- Flying high with open source
- Open sourcing code may improve transparency on Wall Street
- Problem-solvers hunt open-source solutions
- Open source advocates hail appeals court ruling
- Open-source software a security risk, study claims
- Insurance company bets health on open source
- Open source stack solid foundation for All Homes
- 20 great Windows open source projects you should get to know
- Via releases laptop design as open source
- Lead Business Analyst - Equities (P4)11/03/2010
Other
I.T. & T
Lead Business Analyst - Equities (P4) - Project Scheduler11/03/2010
Other
I.T. & T
Project Scheduler - Middleware Enterprise Architect - 2 Month Contract11/03/2010
Other
I.T. & T
Middleware Enterprise Architect - 2 Month Contract - Test Analyst - Financial Services - Perm -Sydney CBD11/03/2010
Other
I.T. & T
Test Analyst - Financial Services - Perm -Sydney CBD - MAJOR BUSINESS DEVELOPMENT - NSW STATE GOVERNMENT VERTICAL11/03/2010
Other
I.T. & T
MAJOR BUSINESS DEVELOPMENT - NSW STATE GOVERNMENT VERTICAL - SNR SECURITY GURU - APPLICATIONS11/03/2010
Other
I.T. & T
SNR SECURITY GURU - APPLICATIONS - SAP MAM Consultant11/03/2010
Other
I.T. & T
SAP MAM Consultant
Whitepapers
-
Keeping your SQL Server Going 24x7 -
Computerworld Strategy Guide: Business Intelligence -
Business Continuity: A Guide to Choosing the Right Technology Solution -
The Pathways ICT Leadership Development Program | Turning today’s ICT professionals into tomorrow’s business leaders -
Making the move to Ethernet | A DECISION GUIDE
TechWorld Blogs
Recent blog posts
- All aboard the Avatar Economy
- Facebook, PayPal tie up ad payments
- Google goes for more markets: too much too quickly?
- Talk about mobile computing
- iPad arrives: can Apple crack the tablet?
- Linux.conf.au 2010 kicks off in New Zealand
- VMware jumps further into SaaS with Zimbra
- Amarok 2.2.2 released – rock on!
- Happy Nexus Year
- So long 2009, and thanks for another decade in tech
Recent comments
- eFront Rocks!!!
9 hours 41 sec ago - I have an eris, and I have
19 hours 9 min ago - I think free offerings are
1 day 1 hour ago - John Lindsay
1 day 14 hours ago - e Front looks best as far as
2 days 7 hours ago - How are they thinking to face to brazilian corruption on telecom
3 days 3 hours ago - want free call
4 days 4 hours ago - Very Useful information ,
4 days 7 hours ago - A challenge to Google?
5 days 17 hours ago - Oh come on...
5 days 17 hours ago - It doesn't mater what you think
6 days 7 hours ago - hi aman i m pankaj, i have
1 week 51 min ago - Fax over the internet
1 week 10 hours ago - With the use of femtocell
1 week 11 hours ago - Hi all,
There is hype on the
1 week 12 hours ago - free call
1 week 2 days ago - hi
1 week 2 days ago - touch screen
1 week 2 days ago - Google Go
1 week 2 days ago - Don't miss out - Copy... Paste ..Earn (shocking truth)
1 week 2 days ago







Comments
Post new comment