A group of developers has released open-source software that gives administrators a hand in making the Internet's addressing system less vulnerable to hackers.
The software, called OpenDNSSEC, automates many tasks associated with implementing DNSSEC (Domain Name System Security Extensions), which is a set a set of protocols that allows DNS (Domain Name System) records to carry a digital signature, said John A. Dickinson, a DNS consultant working on the project.
DNS records allow Web sites to be translated from a name into an IP (Internet Protocol) address, which can be queried by a computer. But the DNS system has several flaws dating from its original design that are being increasingly targeted by hackers.
By tampering with a DNS server, it's possible for a user to type in the correct Web site name but be directed to a fraudulent site, a type of attack called cache poisoning. That's one of many concerns that is driving a movement for ISPs and other entities running DNS servers to use DNSSEC.
With DNSSEC, DNS records are cryptographically signed, and those signatures are verified to ensure the information is accurate. Adoption of DNSSEC, however, has been held back by both the complexity of implementation and a lack of simpler tools, Dickinson said.
To sign DNS records, DNSSEC uses public key cryptography, where signatures are created using a public and private key and implemented on a zone level. Part of the problem is management of those keys, since they must be refreshed periodically to maintain a high level of security, Dickinson said. A mistake in managing those keys could cause major problems, which is one of the challenges for administrators.
OpenDNSSEC allows administrators to create policies and then automate managing the keys and signing the records, Dickinson said. The process now involves more manual intervention, which increases the chance for errors.
OpenDNSSEC "takes care of making sure that zone stays signed properly and correctly according to the policy on a permanent basis," Dickinson said. "All of that is completely automated so that the administrator can concentrate on doing DNS and let the security work in the background."
The software also has a key storage feature that lets administrators keep keys in either a hardware or security software module, an additional layer of protection that ensure keys don't end up in the wrong hands, Dickinson said.
The OpenDNSSEC software is available for download, although it is being offered as a technology preview and shouldn't be used yet in production, Dickinson said. Developers will gather feedback on the tool and release improved versions in the near future.
As of earlier this year, most top-level domains, such as those ending in ".com," were not cryptographically signed, and neither were those in the DNS root zone, the master list of where computers can go to look up an address in a particular domain. VeriSign, which is the registry for ".com," said in February it will implement DNSSEC across top-level domains including .com by 2011.
Other organizations are also moving toward using DNSSEC. The U.S. government has committed to using DNSSEC for its ".gov" domain. Other ccTLDs (country-code Top-Level Domains) operators in Sweden (.se), Brazil (.br), Puerto Rico (.pr) and Bulgaria (.bg), are also using DNSSEC.
Security experts argue that DNSSEC should be used sooner rather than later due to existing vulnerabilities in DNS. One of the more serious ones was revealed by security researcher Dan Kaminsky in July 2008. He showed that DNS servers could be quickly filled with inaccurate information, which could be used for a variety of attacks on e-mail systems, software updating systems and password recovery systems on Web sites.
While temporary patches have been deployed, it's not a long-term solution since it just takes longer to perform an attack, according to a white paper published earlier this year by SurfNet, a Dutch research and education organization. SurfNet is among OpenDNSSEC's backers, which also includes the ".uk" registry Nominet, NLnet Labs and SIDN, the ".nl" registry.
Unless DNSSEC is used, "the basic flaw in the Domain Name System -- that there is no way to ensure that answers to queries are genuine -- remains," the paper said.
Latest on Internet Services
- UK registry to implement DNS security protocol
- Apache mulls end of 1.3, 2.0 releases
- DNS problem linked to DDoS attacks gets worse
- Businesses turn to DNS service to filter the Web
- Facebook releases real-time Web server tech as open source
- Tr.im goes open-source, founder questions bit.ly-Twitter link
- Open-source project aims to makes secure DNS easier
- SSL VPN hack vulnerability details to emerge
- NeuStar offers temporary fix for Kaminsky bug
- Study: Operators should use DNSSEC to improve security
Open Source Essentials
- Microsoft 'interested' in open source browser: Ballmer
- Flying high with open source
- Open sourcing code may improve transparency on Wall Street
- Problem-solvers hunt open-source solutions
- Open source advocates hail appeals court ruling
- Open-source software a security risk, study claims
- Insurance company bets health on open source
- Open source stack solid foundation for All Homes
- 20 great Windows open source projects you should get to know
- Via releases laptop design as open source
- Java Web Portal Developer - Front End15/03/2010
Other
I.T. & T
Are you an experieced Java web applications developer with experience in Spring and Web content management systems? - Senior Business Analysts - PCI industry experience15/03/2010
Other
I.T. & T
Excellent opportunity for Senior BA's to work on a new project. 6 Years BA experience - 4 x Business Analyst - IT15/03/2010
Information Technology and Internet
I.T. & T
Experienced IT BA - in various areas, have you worked on large projects? Looking for a stable company and career progression? Apply Now!! - Program Manager15/03/2010
Other
I.T. & T
Heavy hitting Program Manager required for an upcoming need. Good $$$ for the right candidate. Utilities experience advantageous. - Siebel Administrator/Configurator15/03/2010
Other
I.T. & T
Strong Siebel background. Oracle E-business suite expeirence a bonus. Great company name! - Customer Service/Sales Support - IT15/03/2010
Other
I.T. & T
Do you have a passion for IT? Do you take pleasure in advising clients in their product selection? Are you seeking an employer which recognises talent - Information Management Team Lead Oil & Gas15/03/2010
Other
I.T. & T
International Co - Oil & Gas - Great Salary for right candidate. This is not a Records Management role - much more technical and hands on..
Whitepapers
-
The Pathways ICT Leadership Development Program | Turning today’s ICT professionals into tomorrow’s business leaders -
Maximising customer capital -
Beyond PCI Checklists: Securing Cardholder Data with enhanced File Integrity Monitoring -
Legacy Tools: Not Built for Today’s Helpdesk -
Cloud Computing: Tips on differing models, best use, and easy adoption
TechWorld Blogs
Recent blog posts
- Following social networking privacy
- All aboard the Avatar Economy
- Facebook, PayPal tie up ad payments
- Google goes for more markets: too much too quickly?
- Talk about mobile computing
- iPad arrives: can Apple crack the tablet?
- Linux.conf.au 2010 kicks off in New Zealand
- VMware jumps further into SaaS with Zimbra
- Amarok 2.2.2 released – rock on!
- Happy Nexus Year
Recent comments
- Nice informaion
12 min 3 sec ago - Great Indian Developer Awards 2010
7 hours 8 min ago - govt a bunch of wowsers
10 hours 49 min ago - Best way to block these idiotic initatives
1 day 2 hours ago - not for us
3 days 1 hour ago - Any related jobs
3 days 17 hours ago - epic phail
4 days 11 hours ago - We should all be familiar by
4 days 20 hours ago - eFront Rocks!!!
5 days 6 hours ago - I have an eris, and I have
5 days 16 hours ago - I think free offerings are
5 days 23 hours ago - John Lindsay
6 days 12 hours ago - e Front looks best as far as
1 week 5 hours ago - How are they thinking to face to brazilian corruption on telecom
1 week 1 day ago - want free call
1 week 2 days ago - Very Useful information ,
1 week 2 days ago - A challenge to Google?
1 week 3 days ago - Oh come on...
1 week 3 days ago - It doesn't mater what you think
1 week 4 days ago - hi aman i m pankaj, i have
1 week 4 days ago





Comments
Post new comment