ITPRO

Printed from www.itpro.co.uk

Register to receive our regular email newsletter at http://www.itpro.co.uk/reg/register.

The newsletter contains links to our latest IT news, product reviews, features and how-to guides, plus special offers and competitions.

Skip to navigation

    DNS inventor tackles flaw

The inventor of the internet’s addressing system is working towards new measures designed to plug recently revealed security flaws.

By Miya Knights, 10 Nov 2008 at 13:12

The original designer of the internet’s Domain Name System (DNS) is in the UK to discuss industry responses to security flaws recently uncovered in its handling of internet protocol (IP) addresses.

The DNS vulnerability, first proven by researcher Dan Kamsinky in July 2008, highlighted how criminals can potentially redirect unsuspecting victims to fake websites, even when they type in a genuine web address.

The flaw has since been exploited to poison the servers that translate domain names into internet protocol (IP) addresses, giving malware another attack vector to infect user PCs with malicious code or intercept and edit email.

But Dr Paul Mockapetris - who is now chairman and chief scientist at IP address infrastructure software developer, Nominum - told IT PRO work to tackle the flaw was reaching well beyond the scope of patching the flaw itself.

“Our focus has moved onto additional security measures beyond DNS,” said Mockapetris. “It was never meant to be the only security mechanism for naming data on the internet, but was intended for additional security measures to be added to it later.”

He said the time was right for the introduction of digital signature technology, along the lines of the work being carried out by the European Network and Information Security Agency (ENISA) to implement new standards, like Domain Name System Security Extensions (DNSSEC). Several European and US Country Code Top Level Domain Registries have already adopted the use of the protocol’s origin authentication capability.

“In the DNSSEC era of the future, we will look to digital signatures to distribute the reputation of a web address into the filters used by email and virus filters to remove spam and block spam sites,” he added.

“And we’re seeing the work of ENISA and some political movement towards making this part of the expectation of users who want to have a trusted experience on a website.”

Mockapetris will give a keynote presentation in Brussels later this week at the ENISA “Resilience of Public e-Communication Networks” workshop. “Half of all DNS systems are not yet using DNSSEC,” he said. “So I’ll be urging that we work on interfacing such technologies to as many internet applications as possible.”

Click here to read how ENISA is trying to protect European networks, and here for background on the DNS flaw.

Email to a friend

Print this page

Be the first to comment on this article

You need to Login or Register to comment.

    You may also like...

advertisement
advertisement

    Whitepapers

Want more background on today's hottest IT trends?

Visit IT PRO's whitepaper library for more on virtualisation, encryption and other topics.

    Register for IT PRO

You'll get exclusive member benefits including free whitepapers, downloads, Webinars and weekly newsletters full of the latest IT PRO news, reviews, insight and expertise.

Advertisement
{* ======================================= TRACKING IMAGES ======================================= Tracking images and img counters go below here. REMOVE WHEN TAKING OFF THE SKIN!! *} {literal}