{"title":"Secure domain name service in software defined network","authors":"Vishal Gupta, Shrey Shah, Shantanu Shrivastava","doi":"10.1109/ICCITECHN.2017.8281791","DOIUrl":null,"url":null,"abstract":"Domain Name Service (DNS) is an important service generally used by other application layer protocols of TCP/IP protocol stack. These protocols use DNS to translate human readable web address to machine readable IP address which is then used by other protocols of network stack for communication between computers over the network. The correctness of DNS translation cannot be compromised as it may lead to unsecure transactions with in the network. Because of this, DNS is generally a soft target for attackers and is vulnerable to different security threats including DNS spoofing, DNS cache poisoning, etc. Many solutions for such threats are proposed for traditional IP network. In this paper we talk about security loops in DNS and propose a solution for it in Software Defined Network (SDN) environment.","PeriodicalId":350374,"journal":{"name":"2017 20th International Conference of Computer and Information Technology (ICCIT)","volume":"6 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2017-12-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"4","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2017 20th International Conference of Computer and Information Technology (ICCIT)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICCITECHN.2017.8281791","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 4
Abstract
Domain Name Service (DNS) is an important service generally used by other application layer protocols of TCP/IP protocol stack. These protocols use DNS to translate human readable web address to machine readable IP address which is then used by other protocols of network stack for communication between computers over the network. The correctness of DNS translation cannot be compromised as it may lead to unsecure transactions with in the network. Because of this, DNS is generally a soft target for attackers and is vulnerable to different security threats including DNS spoofing, DNS cache poisoning, etc. Many solutions for such threats are proposed for traditional IP network. In this paper we talk about security loops in DNS and propose a solution for it in Software Defined Network (SDN) environment.
DNS (Domain Name Service)是TCP/IP协议栈中其他应用层协议普遍使用的重要服务。这些协议使用DNS将人类可读的web地址转换为机器可读的IP地址,然后由网络堆栈的其他协议用于网络上计算机之间的通信。DNS转换的正确性不能受到损害,因为它可能导致网络中的不安全事务。因此,DNS通常是攻击者的软目标,容易受到各种安全威胁的攻击,包括DNS欺骗、DNS缓存中毒等。针对这些威胁,传统IP网络提出了许多解决方案。本文讨论了在软件定义网络(SDN)环境下DNS中的安全循环问题,并提出了解决方案。