DNSSEC futue looks bright

DNSSEC futue looks bright

By Robert Westervelt | Sep 14, 2009

DNSSEC isn't a cure-all for DNS security issues. It won't stop drive-by attacks, protect against denial-of-service attacks or any other kind of attacks that piggyback on top of the DNS and depend upon social engineering for success. But it does block cache poisoning attacks and DNS hijacking, a problem that represents a major threat to ecommerce on the Internet. DNSSEC deployments are moving forward. Early adopters are beginning to develop best practices and education materials for upgrading systems and properly configuring devices to handle DNSSEC requests. Federal agencies are required to adopt DNSSEC by the end of the year for .gov domains. .Org was the first domain that signed on to DNSSEC. .Edu signed on to DNSSEC this week with its 6,000 registrants. .Net and .com are expected to sign on by 2011. In this interview, Lance Wolak, director of product management at PIR, which manages the .org domain and Ram Mohan, executive vice president and chief technology officer of Afilias Ltd. share their experiences and the road ahead for DNSSEC deployments.

.Org is the first top-level domain to sign on to DNSSEC. When did the project begin and why was .org the first?
Lance Wolak: The zone signing occurred on June 2 and that was our first step in implementation. This is the start of a testing period for DNSSEC. .Gov had recently taken steps to deploy DNSSEC. While they are a global top-level domain (GTLD), they are a highly restricted GTLD and .org is the first open GTLD to move forward. With 10.5 million names, it is really a significant milestone for the industry for a GTLD of this magnitude to step forward with this.
Ram Mohan: All of .org name servers in 25-plus locations worldwide respond validly to DNSSEC requests coming from any conforming resolver and provide a fluid response back. In addition, .org has also launched a program adding other domain names under .org into the zone one at a time. We're making sure those work properly and we're starting to begin a program that ensures normal transactions in domain names do not get affected. We're making sure things like creating a domain name or transferring a domain name from one registrar to another go through in the same seamless manner as they do today.

 
 

Add comment

Post a Comment

The content of this field is kept private and will not be shown publicly.
  • Web page addresses and e-mail addresses turn into links automatically.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd> <a> <p> <span> <div> <h1> <h2> <h3> <h4> <h5> <h6> <img> <img /> <map> <area> <hr> <br> <br /> <ul> <ol> <li> <dl> <dt> <dd> <table> <tr> <td> <em> <b> <u> <i> <strong> <font> <del> <ins> <sub> <sup> <quote> <blockquote> <pre> <address> <code> <cite> <embed> <object> <strike> <caption>
  • Lines and paragraphs break automatically.
  • Use <!--pagebreak--> to create page breaks.

More information about formatting options

 

Comments

knowledge_central_tab

 
 
Knowledge Central
Today's top security priorities
Attacks based on vulnerabilities in websites are skyrocketing, and not many solutions are available to protect organizations against them. How do you deal with this and other key security issues today?
Taking a holistic business-centric approach to security
Today’s CIOs face multiple challenges, including the need to innovate in an extremely competitive business climate, address highly dynamic regulatory and compliance challenges, speed ROI to counter shrinking IT budgets, and secure their organizations against a wide barrage of sophisticated threats.
 
 
 
UTM product offers Logansport Savings Bank superior protection
Astaro Security Gateway’s IPS was able to block attacks that other intrusion prevention systems (IPS) missed at Logansport Savings Bank.
Hong Leong Financial opts for Juniper Networks at new Malaysia head office, data center
Hong Leong Financial Group Berhad builds complete and seamless data center and office network infrastructure with Juniper switches, security devices and Junos software.