DNSSEC as a service – A prototype implementation

Adnath Hemanthindra, A. Phokeer, V. Ramsurrun, Panagiota Katsina, Sumit Anantwar, A. Seeam
{"title":"DNSSEC as a service – A prototype implementation","authors":"Adnath Hemanthindra, A. Phokeer, V. Ramsurrun, Panagiota Katsina, Sumit Anantwar, A. Seeam","doi":"10.1109/ICM50269.2020.9331810","DOIUrl":null,"url":null,"abstract":"Domain Name System (DNS) plays a massive role in today’s technological era. While initially designed to facilitate communications over the Internet and over networks, the DNS in itself is not secure enough considering the type and criticality of information being shared today. Considering its worldwide acceptance and popularity, securing the DNS without breaking its operation has become vital. DNSSEC is seen as a viable option to protect the integrity of the data and prevent on the fly modifications. However, its adoption rate is not encouraging. Research shows that complexity associated with currently proposed solutions were major turn off for organizations. This paper proposes the creation of a DNSSEC signing service whereby customers register themselves with the service provider and the latter deploys a signing environment for them which includes a DNSSEC signer, a database and web services for access purposes. Customers will only have to use the web services to create and manage their zones and the zone signing can be done automatically or with a simple click of a button. Signed zones are sent back to customer authoritative DNS servers securely using Transaction SIGnature (TSIG) and incoming DNS requests are signed. This solution involves open-source tools and service providers make use of Linux containers for customer environment and space for resource efficiency. All the complexity and additional maintenance involving the system are taken off the customer’s shoulders and managed by the provider while also facilitating their tasks through GUI operations.","PeriodicalId":243968,"journal":{"name":"2020 32nd International Conference on Microelectronics (ICM)","volume":"46 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2020-12-14","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2020 32nd International Conference on Microelectronics (ICM)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICM50269.2020.9331810","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

Abstract

Domain Name System (DNS) plays a massive role in today’s technological era. While initially designed to facilitate communications over the Internet and over networks, the DNS in itself is not secure enough considering the type and criticality of information being shared today. Considering its worldwide acceptance and popularity, securing the DNS without breaking its operation has become vital. DNSSEC is seen as a viable option to protect the integrity of the data and prevent on the fly modifications. However, its adoption rate is not encouraging. Research shows that complexity associated with currently proposed solutions were major turn off for organizations. This paper proposes the creation of a DNSSEC signing service whereby customers register themselves with the service provider and the latter deploys a signing environment for them which includes a DNSSEC signer, a database and web services for access purposes. Customers will only have to use the web services to create and manage their zones and the zone signing can be done automatically or with a simple click of a button. Signed zones are sent back to customer authoritative DNS servers securely using Transaction SIGnature (TSIG) and incoming DNS requests are signed. This solution involves open-source tools and service providers make use of Linux containers for customer environment and space for resource efficiency. All the complexity and additional maintenance involving the system are taken off the customer’s shoulders and managed by the provider while also facilitating their tasks through GUI operations.
DNSSEC即服务——原型实现
域名系统(DNS)在当今的技术时代发挥着巨大的作用。虽然最初的设计是为了促进互联网和网络上的通信,但考虑到今天共享的信息的类型和重要性,DNS本身不够安全。考虑到它的全球接受度和受欢迎程度,在不破坏其运行的情况下保护DNS已变得至关重要。DNSSEC被视为保护数据完整性和防止动态修改的可行选择。然而,它的采用率并不令人鼓舞。研究表明,与当前提出的解决方案相关的复杂性是组织的主要障碍。本文建议创建一个DNSSEC签名服务,客户在服务提供商那里注册自己,后者为他们部署一个签名环境,其中包括一个DNSSEC签名者、一个数据库和用于访问的web服务。客户只需要使用web服务来创建和管理他们的区域,区域签名可以自动完成,或者只需点击一个按钮即可完成。签名区域使用事务签名(Transaction SIGnature, TSIG)安全地发送回客户权威DNS服务器,并对传入的DNS请求进行签名。该解决方案涉及开源工具和服务提供商,它们利用Linux容器为客户提供环境和空间,以提高资源效率。涉及系统的所有复杂性和额外维护都由客户承担,并由提供商管理,同时还通过GUI操作促进他们的任务。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信