In-depth

Q&A: DNS inventor Paul Mockapetris

Four months after serious flaws in the internet’s addressing system were proven, its inventor is looking beyond the threats to help bolster web security.

Earlier this year, researcher Dan Kaminsky outlined flaws in the internet Domain Name System (DNS), which led to massive efforts on behalf of multiple vendors to patch vulnerable systems.

The flaw, which has been used by hackers to poison the servers that translate web addresses into internet protocol addresses and redirect unsuspecting users to spoofed malicious sites to infect their PCs, has also led to political action.

Authorities, including the European Union (EU) agencies, have been involved in promoting the adoption of standard technologies like Multiprotocol Label Switching (MPLS), IPv6 and Domain Name System Security Extensions (DNSSEC) to combat the vulnerability.

Dr. Paul Mockapetris, the inventor of DNS and chairman and chief scientist at IP address infrastructure software vendor Nominum, has been working alongside other security experts and agencies at the same time to tackle the flaw.

Earlier this week, he spoke to IT PRO about the issues involved and the challenges the IT industry faces to strengthen DNS and web security overall.

IT PRO: The DNS attack vector outlined by Dan Kaminsky in June has been one of the major web security issues of 2008. Given your involvement in the first ever DNS implementation, what are you working on towards successfully patching this flaw?

Mockapetris: We develop with DNS and DCHP [Dynamic Host Configuration Protocol] software for large carriers that provide services to a total 150 million broadband subscribers worldwide. When it comes to the Kaminsky attack, we're part of the consortium of vendors and organisations that have addressed ways to put new security layers over the DNS system.

Our carriers demand it of us and it's our job to meet or exceed those expectations beyond what might be expected in say, the open source world.

We saw many attacks launched against us, but have successfully dealt with every one. And our focus has now moved onto additional security measures, beyond DNS. For instance, in the DNSSEC [DNS Security Extensions] era of the future, it will be possible to distribute reputation information using digital signature technology to the filters used by email and virus filters to remove spam and block malicious or pornographic sites.

In some places, like New York State and California, they are developing them as part of regulations to ensure it's possible for people to expect to have a trusted experience of the internet. And we're seeing the work of ENISA and political movement towards making this part of the expectation of users who want to have a trusted experience on a website too.

Looking back, were you surprised that the system you originally designed for distributing naming data could be subverted in such a high-profile way?

I was the inventor' of DNS in that I designed it and deployed the first implementation 25 years ago. But I would say that design only goes up through floors one and two of its development.

Featured Resources

How to be an MSP: Seven steps to success

Building your business from the ground up

Download now

The smart buyer’s guide to flash

Find out whether flash storage is right for your business

Download now

How MSPs build outperforming sales teams

The definitive guide to sales

Download now

The business guide to ransomware

Everything you need to know to keep your company afloat

Download now

Recommended

Cyber attacks on manufacturing up 300% in a year
Security

Cyber attacks on manufacturing up 300% in a year

11 May 2021
US fuel pipeline hackers reveal their motive
ransomware

US fuel pipeline hackers reveal their motive

11 May 2021
Trend Micro and Snyk team up to combat open source flaws
vulnerability

Trend Micro and Snyk team up to combat open source flaws

10 May 2021
Virtual desktops and apps for dummies
Whitepaper

Virtual desktops and apps for dummies

10 May 2021

Most Popular

KPMG offers staff 'four-day fortnight' in hybrid work plans
flexible working

KPMG offers staff 'four-day fortnight' in hybrid work plans

6 May 2021
16 ways to speed up your laptop
Laptops

16 ways to speed up your laptop

29 Apr 2021
How to move Windows 10 from your old hard drive to SSD
operating systems

How to move Windows 10 from your old hard drive to SSD

30 Apr 2021