DNS creator says flaws in protocol put firms at risk

DNS flaws pose significant threat to business warn experts

Written by Ian Williams

Businesses will face ever greater threats to their security unless flaws in some of the building blocks of the internet are rectified, security experts have warned.

Weaknesses in the Domain Name System (DNS) desperately need to be addressed as web-based attacks become increasingly sophisticated, the protocol’s creator, Paul Mockapetris, has warned. DNS provides a mechanism to resolve web addresses.

“The problem is pretty clear ­ there is a big internet out there and all the bad guys and the good guys are mixed together,” said Mockapetris, now chief scientist and chairman of DNS firm Nominum.

“The service providers and broadband networks are in the middle and there are the users who are getting more diverse in a lot of ways. First of all, they are not all using computers these days, they may be using other devices that don’t necessarily have the same security mechanisms,” he said.

Earlier this year, security researcher Dan Kaminsky uncovered a DNS flaw that affected millions of computers across the globe.

Mockapetris believes that attacks based on similar principles will become increasingly sophisticated and that the problem needs to be addressed sooner rather than later.

One option for improving the resilience of DNS is through the use of Domain Name System Security Extensions (DNSSEC), which use digital signatures to solve the problem of DNS poisoning.

“It is time to recognise that we need digital signature technology,” Mockapetris said.

“It will take a while to get that technology in place, but it’s time to pay that price,” he added.

Mockapetris said he does not expect deployment of DNSSEC to be widespread before 2014.

reader comments

related articles

British ArmyHardware

Lack of IT standards hampering UK war effort

Proprietary software making it harder to exploit reconnaisance data in Afghanistan 07 Nov 2008

 

IT leaders call for tougher e-crime penalties

Survey reveals widespread cynicism about government response 03 Nov 2008

Case Study: Porttracker earns networking honours at University of Hertfordshire

The management package has made it quicker and easier to monitor and allocate network resources 16 Oct 2008

Hackers overwhelm internet servers in huge attack

At least three of the 13 computers that manage global computer traffic affected 07 Feb 2007

Identity management calls flood help desks

Managing staff forgetting passwords is straining resources 22 Dec 2006

Major DNS flaw revealed

Experts sound alarms over early disclosure 23 Jul 2008

Kaminsky delivers DNS dirt

Researcher explains risks behind flaw 07 Aug 2008

Exploit emerges for DNS flaw

First attack tool created for vulnerability 25 Jul 2008

related whitepapers

today's top stories

What does Windows 7 mean for Microsoft?

With the sting of Vista still fresh, Redmond has to make next Windows work 10 Jul 2009

A smarter way to use BI

Getting the most from business intelligence systems requires not only careful management on the part of IT leaders, but also the committed involvement of decision-makers across the organisation 08 Jul 2009

The truth behind the Google/Microsoft/NHS rumours

Before Monday 6 July, did you know that Google and Microsoft had services for storing health records? Thanks to an article in... 10 Jul 2009

Quenching a thirst for IT modernisation

A substantial restructure at soft drink supplier Nichols -­ purveyor of Vimto - ­led the company to update its software to Sage 1000 to replace its in-house application. This resulted in the streamlining of the IT department and an opportunity to customise the system 08 Jul 2009

How Satyam cleaned up its act

Chief executive CP Gurnani tells Angelica Mari why Tech Mahindra opted to keep the Satyam brand after it bought the scandal-hit services firm, and explains what the deal means for existing and prospective customers 09 Jul 2009

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

More available - click 'submit' to view

Existing User

Newsletter user login:

Advertisement

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Will Google Chrome OS be a genuine alternative to Windows?

Will Google Chrome OS be a genuine alternative to Windows?

Tell us your views on the new operating system rivalry

View poll results

Latest audio and video articles

network cablesVideo

How to maximise the value of your IT networking investment

A panel of experts discuss networking strategies that deliver real value to business 03 Jul 2009

green footprintsVideo

How to manage enterprise energy use - and the role IT can play

A panel of experts explore how firms can get to grips with their carbon footprint and make smarter use of energy 01 Jul 2009

Latest in-depth articles

Google ChromeAnalysis

Lack of enterprise appeal takes shine off Chrome OS

Enterprise buyers unlikely to ditch Windows for Chrome OS in the near term, say experts 09 Jul 2009

Satyam CEO CP GurnaniNews

How Satyam cleaned up its act

Chief executive CP Gurnani tells Angelica Mari why Tech Mahindra opted to keep the Satyam brand after it bought the scandal-hit services firm, and explains what the deal means for existing and prospective customers 09 Jul 2009

Advertisement

Primary Navigation