NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home / News / Security / Server related

Server related


U.S. Plans to Deploy DNSSEC

An official government memo describes new policy regarding DNSSEC implementation

By Lucian Constantin, Web News Editor

29th of August 2008, 13:29 GMT

Adjust text size:


DNSSEC
Enlarge picture
The White House released a memo, signed by Karen Evans, the Administrator for the Office of E-Government and Information Technology, which instructs all government agencies to prepare for securing the federal government’s DNS infrastructure over the next year.

The document outlines a plan for the agencies to deploy the DNSSEC technology in order to secure government networks and communications. In this regard, all top level .gov domains will be secured with DNSSEC by January 2009 and all the .gov sub-domains need to be secured by December 2009.

In order to achieve this, all federal agencies have to develop their own plans of action by October 2008. Such a plan needs to specify the number of second level .gov domains operated by the agency and DNS administration information for each of them (in house, third-party provider, etc.), the currently used DNS server implementations like BIND, NSD etc., infrastructure impediments in DNSSEC deployment and possible resolutions for them.

Eventually, such a plan will contain all information from necessary acquisitions, training, tests, server priorities, to implementation and deployment milestones. The memo explains the necessity of such measures - "The Government’s reliance on the Internet to disseminate and provide access to information has increased significantly over the years, as have the risks associated with potential unauthorized use, compromise, and loss of the .gov domain space".

Earlier this year we reported about a major security vulnerability in the DNS system discovered by security researcher Dan Kaminsky. The flaw can allow attackers to inject fake entries into legit DNS servers. In addition, the patch released to address this issue, which was deployed on the majority of DNS servers world-wide, proved inefficient. One of the alternative solutions that we mentioned was DNSSEC, an encryption-based DNS service that uses public-keys to secure DNS traffic.

Even though already adopted by some governments around the world, DNSSEC requires more resources than regular DNS as well as a more solid infrastructure, requirements which slow down the process of implementation. The recent incidents like the DNS cache poisoning of China NETCOM’s DNS servers in order to distribute malware serve to show the potential dangers users and sensitive information can be exposed to.

TAGS:

DNS | Vulnerability | Cache Poisoning | DNSSEC | United States
Read by 1,761 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
NOT RATED 0 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2009 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


China Netcom Subject to DNS Cache Poisoning Attack

Firefox Extension Boosts Browser Security

Patch for the Internet Core Flaw Is also Flawed

Email Security Threatened by DNS Flaw

FBI, CIA, and DoD Data Compromised

Kaminsky Faces Security and Hacking Community Scorn

Six-Year-Old Internet Vulnerability Still Active

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM