Semnătură de domeniu (DNSSEC)
De ce
Mai jos găsiți câteva linkuri către descrieri ale unor incidente cunoscute pe care DNSSEC probabil le-ar fi putut preveni.
- "Cache-poisoning attack snares top Brazilian bank"
- "Eircom reveals ‘cache poisoning’ attack by hacker led to outages"
- "DNS cache poisonings foist malware attacks on Brazilians"
- "Cache Poisoning of Mail Handling Domains Revisited"
- "Neither Snow Nor Rain Nor MITM... An Empirical Analysis of Email Delivery Security"
Mai jos urmează un citat din ultima publicație de cercetare menționată:
Mail security, like that of many other protocols, is intrinsically tangled with the security of DNS resolution. Rather than target the SMTP protocol, an active network attacker can spoof the DNS records of a destination mail server to redirect SMTP connections to a server under the attacker’s control. [...] We find evidence that 178,439 out of 8,860,639(2.01%) publicly accessible DNS servers provided invalid IPs or MX records for one or more of these domains.
Statistici de utilizare
- Pulse - DNSSEC metric de Internet Society
- .nl statistics on DNSSEC de SIDN Labs
- DNSSEC Validation Measurement de APNIC
- DNSSEC Deployment Report
Informații de context
- FAQ on DNSSEC de SIDN
- ISOC's Deploy360 on DNSSEC
- DNSSEC.net
- Wikipedia on DNSSEC
- Knowledge-Sharing and Instantiating Norms for DNS and Naming Security (KINDNS)
Specificații
- RFC 4033: DNS Security Introduction and Requirements
- RFC 4034: Resource Records for the DNS Security Extensions
- RFC 4035: Protocol Modifications for the DNS Security Extensions
- RFC 8624: Algorithm Implementation Requirements and Usage Guidance for DNSSEC
- RFC 9276: Guidance for NSEC3 Parameter Settings