Making DNS More Secure — One ISP at a Time

Last July I wrote about a serious security flaw in the domain name system (DNS). It was discovered by researcher Dan Kaminsky and got a lot of coverage: It’s Tuesday — Must be Time to Fix DNS

There was two parts to the DNS vulnerability that quickly became known as the Kaminsky flaw. One was related to poor port number randomization, making it easier for criminal elements to hijack DNS queries and redirect them to fraudulent sites. That problem could be addressed with a software patch, and most of the coverage last year focused on the concerted efforts made by companies like Microsoft, Sun, Cisco and many others to distribute the patches.

But there was another part to the flaw that could not be patched, since it was fundamental to the DNS protocol itself. Internet consumers are still at risk of being redirected through something called cache poisoning, which fools a DNS server into thinking a fraudulent site is authentic. Until recently there was little public acknowledgement of this happening, because most companies are loathe to discuss security breaches.

But in April there was a major breach of a Brazilian IPS Virtua and one of its big customers, the Brazilian back Bradesco. Here’s coverage of the incident from the The Register.

Last week my client NeuStar announced Cache Defender, a way for ISPs to protect their customers from this fundamental Internet vulnerability. ISPs can deploy this solution to create a secure DNS link between their customers and the domains NeuStar is authoritative for, including some of the largest Internet brands such as Amazon, Advertising.com, Oracle and Zappos. Cache Defender is designed to be an interim solution until DNSSEC, a more secure version of DNS can be implemented by the global Internet community.

Here’s some coverage of the announcement:

Network World

Telephony

Venture Beat

CIO

Dark Reading

I’ve worked on DNS issues previously in my career, so this news was very exciting and fun to promote. If you’d like to know more, check out a discussion going on over at CircleID, a top online forum for Internet infrastructure discussions. Not surprisingly, some negative comments about Cache Defender are coming from NeuStar competitors. But the company already has one announced ISP deployment, with more in the works.

DNSSEC is no doubt the definitive answer, but probably won’t be widely deployed until 2011 for a number of technical and political reasons. Until then, Cache Defender is an excellent way for ISPs to show they are doing all they can to protect their customers.

Similar Posts

  • Calling Out Bad Reporting

    Share on LinkedinShare on FacebookShare on TwitterShare on Reddit Readers of this blog know that the declining standards of media reporting is a theme I return to periodically on Work, Wine and Wheels. Too many layoffs, too many beats for those that remain, long-time experts in their niches being replaced with new graduates for budget…

  • The Supercookie Debate

    Share on LinkedinShare on FacebookShare on TwitterShare on Reddit Have you heard about the supercookie? Recent articles in the press have outlined how sites including MSN and Hulu are now using an advanced version of the old cookie file to track user behavior. These supercookies are very hard to detect and delete, and can track…

  • 2013 gTLD Update

    Share on LinkedinShare on FacebookShare on TwitterShare on Reddit Previously on this site I’ve written about the generic top level domain (gTLD) debate, which has been contentious from day one. I tried to have some fun with the debate with this animated video from almost two years ago. And in July of 2011 I interviewed…

  • 2018 Retrospective

    Share on LinkedinShare on FacebookShare on TwitterShare on Reddit It’s hard to believe another year has gone by. It doesn’t seem that long ago I was writing about the tenth anniversary of this site at the end of last year. 2018 was a busy year, and running my content marketing firm again took time away…

  • Will the Internet Break Under Peak Load?

    Share on LinkedinShare on FacebookShare on TwitterShare on Reddit An interesting survey came out of the telecom industry’s NXTComm show last week in Las Vegas. It’s been getting a lot of play in trade publications. Attendees to the show were asked a number of questions, including whether they thought the Internet could ever “break” due…

Leave a Reply

Your email address will not be published. Required fields are marked *