DNS servers prove resilient
But the core system is still weak at lower levels
October 27, 2003 12:00 PM ETComputerworld -
In the year since last October's high-profile attacks on the Internet's root Domain Name System servers, improvements in load distribution and processing capacity have made the Internet's core addressing system more resilient.
But the lack of security at lower levels of the DNS stack remains worrisome, according to security experts. And progress on a critical security enhancement designed to add data authentication and integrity services to the DNS protocol remains disappointingly slow, they added.
"The state of it all is somewhat uneven," said Paul Mockapetris, inventor of the DNS and chairman of the board at IP address management vendor Nominum Inc. in Redwood City, Calif.
"The root server operators have created more replicated copies of the root servers. So they are certainly less vulnerable to denial-of-service attacks and the like," he said.
Some of the operators have also strengthened their systems by adding more processing capacity, said Stephen Crocker, head of the security committee at the Internet Corporation for Assigned Names and Numbers in Marina Del Rey, Calif.
But there are some persistent problems that make the security situation "about the same or maybe a little bit worse as you move down the DNS tree," Mockapetris said.
All 13 of the Internet's root DNS serversthree of which are located outside the U.S.were victims of a massive distributed denial-of-service attack on Oct. 21, 2002 (see story).
The attacks did little damage apart from slowing down service in some parts of the world. But they were the first to target root DNS serverson which everything else on the Internet operatesand raised concerns that future attacks could bring down large swaths of the Internet.
Last year's attacks helped raise awareness of the need to bolster defenses, said Suzanne Woolf, senior program manager at the Internet Software Consortium (ISC) in Redwood City, Calif. Like other root server operators, the ISC has over the past year been using a technology approach called anycasting, which is similar to mirroring, to set up multiple copies of existing servers, each with the same IP address.
Anycasting is designed to route DNS queries to the nearest available server in order to mitigate the effects of denial-of-service attacks, explained Crocker.
"It lets us spread out our vulnerabilities and isolate areas as problems arise," Woolf said.
VeriSign Inc., which operates a root server and top-level domains such as .com and .net, has gone a step further.
This summer, the company moved its DNS infrastructure from the widely used Berkeley Internet Name Domain DNS server platform to a proprietary system developed by VeriSign called Atlas. The move was driven by the need to improve the scalabilty, performance and security of VeriSign's DNS services, said Ken Silva, vice president of network and information security at VeriSign in Mountain View, Calif. Atlas is designed to handle more than 100 billion DNS lookups daily and to eliminate single points of failure.
Additional Resources



Learn the important issues you must consider before starting your next mobility initiative. Get your mobility white paper from IDC now, compliments of Sybase.
White Papers & Webcasts
Centralized Data Backup and Your WAN
Is your organization prepared to tackle the massive challenge of protecting your data in a cost effective and timely manner? With a growing...
Why Compliance Pays
This OnDemand webcast explores the relationship that firms with best compliance records have higher revenue, greater customer retention, lower financial losses from data...
An All-in-One Approach to Web Security
Granting web access to employees poses challenges to IT administrators and introduces unique security risks. Even as companies have perfected their security techniques...
Best Practices for Managing Business Risks from the Use of IT
(Source: Symantec) Based on exhaustive benchmarks conducted by the IT Policy Compliance, this session highlights the relationship between business risks and use of...
The Hidden Dangers of Spam
Beyond the well-understood productivity drain that spam inflicts on businesses, threats posed by illicit email circulating through a network are causing many security...
Managing And Protecting Your Ever Increasing Mobile Assets
(Source: Absolute Software) Your users are becoming more mobile each day. This is great for productivity - yet challenging for IT control. Natalie...
Open Source Security Myths Dispelled
(Source: Astaro) Open Source Software is computer software whose source code is available to the general public. This openly viewable nature...
Sun OpenSSO Enterprise Webinar
(Source: Sun) This webinar replay discusses Sun OpenSSO Enterprise innovation--the single, open-source solution that helps your business solve the challenges around internal access...
Best Practices for Backing Up VMware® with Veritas NetBackup™
VMware® is used by enterprises large and small to increase the efficiency and cost-effectiveness of their IT operations. With this in mind, Symantec...
Agile Enterprise Content Management (ECM) for Rapid ROI
(Source: IBM) Content rich business processes are a core feature of daily operations at just about any organization today. Very often these essential...
Subscribe to Computerworld
