Securing Domain Name System Combined with MIPv6 for Mobile Hosts

Younchan Jung, Marnel S. Peradilla, W. Atwood
{"title":"Securing Domain Name System Combined with MIPv6 for Mobile Hosts","authors":"Younchan Jung, Marnel S. Peradilla, W. Atwood","doi":"10.1109/TrustCom.2013.26","DOIUrl":null,"url":null,"abstract":"DNS is the standard mechanism for name to IP address resolution. The DNS has been extended to DNSSEC to add security by providing origin authentication and data integrity by the process of creating signatures periodically, which results in intensive computations. Adding digital signatures to a domain increases each record size by 5-7 times, which puts a burden of DNS reply messages on the authoritative name servers. The goal of this paper is to find secure DNS mechanism, which cause relatively low computation loads and reply burden especially for infrastructure mode MANET gateways that are responsible for name resolution services as well as local mobility management for mobile hosts. This paper proposes SECDNS (Secure DNS) mechanism that handles secure query/reply transactions using the one-time session key generated per a query basis. In the proposed SECDNS, burden for securing DNS is distributed for every DNS queries. We analyze how many SECDNS transactions can the session key with a given length handle and suggest the solution of the anti-MITM attack scheme, which protects the name resolution services against the possible MITM attacks and make it useless for the enemy to decrypt the SECDNS reply messages in time.","PeriodicalId":206739,"journal":{"name":"2013 12th IEEE International Conference on Trust, Security and Privacy in Computing and Communications","volume":"6 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2013-07-16","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"2","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2013 12th IEEE International Conference on Trust, Security and Privacy in Computing and Communications","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/TrustCom.2013.26","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 2

Abstract

DNS is the standard mechanism for name to IP address resolution. The DNS has been extended to DNSSEC to add security by providing origin authentication and data integrity by the process of creating signatures periodically, which results in intensive computations. Adding digital signatures to a domain increases each record size by 5-7 times, which puts a burden of DNS reply messages on the authoritative name servers. The goal of this paper is to find secure DNS mechanism, which cause relatively low computation loads and reply burden especially for infrastructure mode MANET gateways that are responsible for name resolution services as well as local mobility management for mobile hosts. This paper proposes SECDNS (Secure DNS) mechanism that handles secure query/reply transactions using the one-time session key generated per a query basis. In the proposed SECDNS, burden for securing DNS is distributed for every DNS queries. We analyze how many SECDNS transactions can the session key with a given length handle and suggest the solution of the anti-MITM attack scheme, which protects the name resolution services against the possible MITM attacks and make it useless for the enemy to decrypt the SECDNS reply messages in time.
移动主机结合MIPv6的安全域名系统
DNS是名称到IP地址解析的标准机制。DNS已经扩展到DNSSEC,通过周期性创建签名的过程提供源认证和数据完整性来增加安全性,但计算量很大。在域名中加入数字签名后,每条记录的大小会增加5-7倍,这会给权威域名服务器增加DNS应答消息的负担。本文的目标是寻找安全的DNS机制,特别是对于负责名称解析服务和移动主机本地移动性管理的基础架构模式MANET网关,该机制的计算负载和应答负担相对较低。本文提出了SECDNS(安全DNS)机制,该机制使用每个查询基础生成的一次性会话密钥来处理安全查询/应答事务。在建议的SECDNS中,保护DNS的负担分配给每个DNS查询。分析了给定长度的会话密钥可以处理多少次SECDNS事务,并提出了反MITM攻击方案的解决方案,该方案保护了名称解析服务免受可能的MITM攻击,使敌方无法及时解密SECDNS应答消息。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信