SHARE
Follow this article on Twitter Facebook LinkedIn Bookmark and Share
Home >> Security >> Hacking and Viruses

Budget constraints might hamper DNS security

Budget constraints might hamper DNS security

By:  Denise Dubie  On: 31 Dec 2008 For: Network World (U.S.) (NA) Creator

With the year coming to a close, DNS experts worry that security projects aimed at fixing critical flaws with take a backseat to cost-cutting measures

The discovery of a major DNS flaw in mid-2008 landed the technology in many headlines, but with economic concerns weighing on many in IT, industry watchers worry that revamping systems and security around domain name servers could be put on hold in 2009.

The vulnerability discovered by director of penetration testing at IOActive Dan Kaminsky motivated numerous vendors to upgrade their products to protect enterprise networks against cache poisoning and other DNS attacks, such as distributed denial-of-service (DDoS). IT directors were encouraged to upgrade their DNS systems to guard against potential threats, but a survey by The Measurement Group revealed that about 25 per cent of servers had yet to be upgraded by mid-November.

Now, with the year coming to a close, DNS experts worry the projects will take a back seat to cost-cutting measures.

"These name servers are trivially vulnerable to the Kaminsky attack. With an effective exploit script, a hacker can insert arbitrary data into the cache of one of these names servers in about 10 seconds," says Cricket Liu, vice president of architecture at Infoblox.

A separate survey of 466 enterprise online customers conducted by DNSstuff in September revealed that 9.6 per cent hadn't patched their DNS servers and 21.9 per cent didn't know if they were patched. The findings show that despite the DNS community's and several vendors' efforts, a significant number of server administrators have yet to take action. As for the reasons behind the lack of patches, more than 45 per cent cited a lack of internal resources, 30 per cent said they were unaware of the vulnerability and 24 per cent reported they didn't have enough knowledge of DNS to take the appropriate steps.

DNSstuff's customer research also found that the most common DNS issues among respondents include e-mail downtime for 69 per cent, DDoS attacks and cache-poisoning attacks for nearly half and spoofing for 18.5 per cent.

That's why the IP address management vendor is looking to dispel what it calls a handful of myths around DNS and get people paying attention to the technology in 2009, despite economic worries.

For one, Infoblox says there is a misconception that DNS is a trivial part of the network. It performs a critical function by mapping domain names to IP addresses and directing Internet inquiries to the appropriate location. "Should an enterprise's DNS systems fail … all Internet functions, including e-mail, Web access, e-commerce and extranets become unavailable," according to Infoblox.


Sign up for our Newsletters












Print |  Views: 1333   |   Rating:offoffoffoffoff  (0 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




Denise Dubie Denise Dubie is a contributor to the International Data Group (IDG) News Service, which publishes global technology stories from bureaus around the world to more than 300 publications in more than 60 countries.

Comments (0)

No Comments!
Name: (required) eMail: (optional)

Your email address will not appear online and will be used only if the editor wishes to contact you personally for additional comments.