What is DNS Security Extensions (DNSSEC)? - Definition from WhatIs.com

Definition

DNS Security Extensions (DNSSEC)

Part of the Government IT glossary:

DNS Security Extensions (DNSSEC) are a set of Internet Engineering Task Force (IETF) standards created to address vulnerabilities in the Domain Name System (DNS) and protect it from online threats. The purpose of DNSSEC is to increase the security of the Internet as a whole by addressing DNS security weaknesses. Essentially, DNSSEC adds authentication to DNS to make the system more secure.  

The Domain Name System manages Internet navigation by locating domain names and mapping them to IP addresses. DNS, as originally designed, has no means of determining whether domain name data comes from the authorized domain owner or has been forged. This security weakness leaves the system vulnerable to a number of attacks, such as DNS cache poisoning, for example. 

In a DNS cache poisoning attack, an intruder replaces a valid IP address cached in a DNS table with a rogue address. Requests for the valid address are redirected accordingly, and malware -- such as a worm, spyware or browser hijacker -- may be downloaded to the user's computer from the rogue location. DNSSEC employs cryptographic keys and digital signatures to ensure that lookup data is correct and that connections are to legitimate servers.

The core elements of DNSSEC were specified in three IETF Requests for Comments published in March 2005: RFC 4033 - DNS Security Introduction and Requirements, RFC 4034 - Resource Records for the DNS Security Extensions, and RFC 4035 - Protocol Modifications for the DNS Security Extensions.

DNSSEC implementation is somewhat complex and is on a voluntary basis. As a result, adoption has been slow. In the United States, the federal government has mandated DNSSEC implementation for government networks. The National Institute of Standards and Technology (NIST) and the General Services Administration (GSA) have implemented the standards within the top level dot.gov domain. However, most individual agencies have yet to meet the mandate for second-level domains.

DNSSEC is offered as a managed service; DNSSEC appliances that automate the process are also available from some  vendors.

 

Learn more:
> The DNSSEC website offers further explanation of the DNS Security Extensions and associated standards.
> This SURFnet document explains the importance of DNSSEC for Internet hardening.
> Seven Things You Should Know about DSNSEC supplies the short version.
> Richard W. Walker reports on the progress of the government's DNSSEC project.
> Read about a case study of DNSSEC implementation in this article.

This was last updated in June 2010
Posted by: Margaret Rouse

Related Terms

Definitions

  • transparency

    - Transparency, in the context of governance, means being open and honest in all official activities. The implication is that all activities are scrupulous enough that they could bear public scrutiny. (WhatIs.com)

  • accountability

    - Accountability means being held responsible or answerable for one's actions (or perhaps lack of action where one should have been taken). Accountability and transparency are generally considered th... (WhatIs.com)

  • Centers for Disease Control and Prevention (CDC)

    - Promoting a healthy general public and sharing data about chronic diseases are main goals of the Centers for Disease Control and Prevention (CDC). (SearchHealthIT.com)

Glossaries

  • Government IT

    - Terms related to government IT, including definitions about specific federal, state and local government programs as well as words and phrases about policy and compliance.

  • Internet applications

    - This WhatIs.com glossary contains terms related to Internet applications, including definitions about Software as a Service (SaaS) delivery models and words and phrases about web sites, e-commerce ...

Ask a Question. Find an Answer.Powered by ITKnowledgeExchange.com

Ask An IT Question

Get answers from your peers on your most technical challenges

Ask Question

Tech TalkComment

Share
Comments

    Results

    Contribute to the conversation

    All fields are required. Comments will appear at the bottom of the article.