International Conference on Dependable Systems and Networks, 2004 2004
DOI: 10.1109/dsn.2004.1311912
|View full text |Cite
|
Sign up to set email alerts
|

Secure distributed DNS

Abstract: A correctly working Domain Name System (DNS) is essential for the Internet. Due to its significance and because of deficiencies in its current design, the DNS is vulnerable to a wide range of attacks. This paper presents the design and implementation of a secure distributed name service on the level of a DNS zone. Our service is able to provide fault tolerance and security even in the presence of a fraction of corrupted name servers, avoiding any single point of failure. It further solves the problem of storin… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
1
1
1

Citation Types

0
14
0
2

Year Published

2007
2007
2020
2020

Publication Types

Select...
4
3
3

Relationship

0
10

Authors

Journals

citations
Cited by 25 publications
(16 citation statements)
references
References 18 publications
0
14
0
2
Order By: Relevance
“…While these works suppose that a single logger tracks a stream of ordered events, we have to deal with the race conditions (Counterexample 2) that result from allowing individual RPKI authorities to maintain their own logs (i.e., manifests). The idea of correcting power imbalances in a hierarchical system also appeared in work on distributing certificate authorities [66] and centralized systems like the DNS [1,15,55]; these works distribute the issuance of objects, but we only distribute revocation (since revocation can harm IP prefix reachability).…”
Section: Related Workmentioning
confidence: 99%
“…While these works suppose that a single logger tracks a stream of ordered events, we have to deal with the race conditions (Counterexample 2) that result from allowing individual RPKI authorities to maintain their own logs (i.e., manifests). The idea of correcting power imbalances in a hierarchical system also appeared in work on distributing certificate authorities [66] and centralized systems like the DNS [1,15,55]; these works distribute the issuance of objects, but we only distribute revocation (since revocation can harm IP prefix reachability).…”
Section: Related Workmentioning
confidence: 99%
“…Cachin and Samar report on a design and implementation of a secure distributed name service, on the level of a DNS zone, that is able to provide fault tolerance and security even in the presence of a few corrupted name servers. 37 There are also new protocols with the same service functionality. 38…”
Section: New Developmentsmentioning
confidence: 99%
“…Previous proposals on distributing DNS [7], [8], focused on the DNS nameservers, our goal in this work is to distribute the DNS resolvers. We propose a majority based protocol to securely generate a pool of servers via DNS which does not require any changes to the existing protocols nor infrastructure.…”
Section: Introductionmentioning
confidence: 99%