DNS Security Extensions (DNSSEC)

Part of the TechTarget Network of Enterprise IT Web Sites

Search our IT-specific encyclopedia for:
 
Browse alphabetically:
A B C D E F G H I J K L M N O P Q R S T U V W X Y Z #
All Categories Government IT

DNS Security Extensions (DNSSEC)

DNS Security Extensions (DNSSEC) are a set of Internet Engineering Task Force (IETF) standards created to address vulnerabilities in the Domain Name System (DNS) and protect it from online threats. The purpose of DNSSEC is to increase the security of the Internet as a whole by addressing DNS security weaknesses. Essentially, DNSSEC adds authentication to DNS to make the system more secure.  

The Domain Name System manages Internet navigation by locating domain names and mapping them to IP addresses. DNS, as originally designed, has no means of determining whether domain name data comes from the authorized domain owner or has been forged. This security weakness leaves the system vulnerable to a number of attacks, such as DNS cache poisoning, for example. 

In a DNS cache poisoning attack, an intruder replaces a valid IP address cached in a DNS table with a rogue address. Requests for the valid address are redirected accordingly, and malware -- such as a worm, spyware or browser hijacker -- may be downloaded to the user's computer from the rogue location. DNSSEC employs cryptographic keys and digital signatures to ensure that lookup data is correct and that connections are to legitimate servers.

The core elements of DNSSEC were specified in three IETF Requests for Comments published in March 2005: RFC 4033 - DNS Security Introduction and Requirements, RFC 4034 - Resource Records for the DNS Security Extensions, and RFC 4035 - Protocol Modifications for the DNS Security Extensions.

DNSSEC implementation is somewhat complex and is on a voluntary basis. As a result, adoption has been slow. In the United States, the federal government has mandated DNSSEC implementation for government networks. The National Institute of Standards and Technology (NIST) and the General Services Administration (GSA) have implemented the standards within the top level dot.gov domain. However, most individual agencies have yet to meet the mandate for second-level domains.

DNSSEC is offered as a managed service; DNSSEC appliances that automate the process are also available from some  vendors.

 

Learn more:
> The DNSSEC website offers further explanation of the DNS Security Extensions and associated standards.
> This SURFnet document explains the importance of DNSSEC for Internet hardening.
> Seven Things You Should Know about DSNSEC supplies the short version.
> Richard W. Walker reports on the progress of the government's DNSSEC project.
> Read about a case study of DNSSEC implementation in this article.

Last updated on: Jun 28, 2010
Editorial Director: Margaret Rouse

>  Enterprise Software related Research & News
>  White Papers for the Retail Industry

Are you a Know-IT-All?
This is the certification of a product or specification to indicate that it meets regulatory standards.
a. homologation
b. collocation

word of the day Sign up for the Word of the Day
twitter Follow us on Twitter
Editorial director:


WORD OF THE DAY...
context-aware network access control
LEARN MORE ABOUT...
Windows 8
AccessChk
AccessEnum
Microsoft Windows Server 2008
Windows Server 2008 R2
icacls
mechanical refrigeration
mobile middleware
PCI DSS 2.0
PCI DSS User Group
Raspberry Pi ($35 computer)
HTML 5 client
persistent desktop
nonpersistent desktop
Microsoft System Center Virtual Machine Manager 2012
RemoteFX
Windows Thin PC
polyfill
computer room air handler (CRAH
arc flash
electric arc
WhatIs.com RSS Feeds
About Us   |   Contact Us   |   For Advertisers   |   For Business Partners   |   Reprints   |   RSS   |   Awards
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints




All Rights Reserved, Copyright 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts