• Home
  • Search
  • A Secure, Flexible Framework for DNS Authentication in IPv6 Autoconfiguration
  • Cite Icon11
  • https://doi.org/10.1109/nca.2013.37Copy DOI Icon

A Secure, Flexible Framework for DNS Authentication in IPv6 Autoconfiguration

  • Aug 1, 2013
  • Hosnieh Rafiee +1 more
Show More
  • Abstract
  • Literature Map
  • References
  • Citations
  • Similar Papers
Abstract

The Domain Name System (DNS) is an essential part of the Internet on whose function many other protocols rely. One key DNS function is Dynamic Update, which allows hosts on the network to make updates to DNS records dynamically, without the need for restarting the DNS service. Unfortunately, this dynamic process does expose DNS servers to security issues. To address these issues two protocols were introduced: Transaction Signature (TSIG) and Domain Name System Security Extensions (DNSSEC). In Internet Protocol version 4 (IPv4) networks using these protocols eliminated security issues. In Internet Protocol version 6 (IPv6) however, there is an issue with the DNS authentication process when using the Stateless Address Auto Configuration (SLAAC) mechanism (new to IPv6, nonexistent in IPv4). This authentication issue occurs when a node wants to update its resource records on a DNS server, during the DNS update process, or when a client wants to authenticate a DNS resolver to ensure that the DNS response does not contain a spoofed source address or message. In this paper we propose the use of a new mechanism which makes use of asymmetric cryptography to establish a trust relationship with the DNS server. We also consider the use of the current security parameters used to generate IPv6 addresses in a secure manner, i.e. Secure Neighbor Discovery (SeND), for assuring clients and DNS servers that the one they are communicating with is the real owner of this IP address. Since we are extending the RDATA field within the TSIG protocol to accommodate these new security parameters, we will call this new mechanism the CGA-TSIG algorithm.

Similar Papers
  • Book Chapter
  • Citations3

Challenges and Solutions for DNS Security in IPv6

  • Jan 01, 2014
  • Hosnieh Rafiee +2
  • Research Article
  • Citations13

Visualizing and characterizing DNS lookup behaviors via log-mining

  • May 16, 2015
  • Neurocomputing
  • Qingnan Lai +4
  • Conference Article
  • Citations20

A Survey on DNS Security Issues and Mitigation Techniques

  • May 01, 2019
  • Anju Ramdas +1
  • Research Article

Pengujian High Availability pada Asynchronous DNS Berbasis Restknot menggunakan Algoritma Round Robin

  • Jan 10, 2024
  • Jurnal Indonesia : Manajemen Informatika dan Komunikasi
  • I Putu Agus Eka Pratama +2
  • Conference Article
  • Citations64

Analysis of Privacy Disclosure in DNS Query

  • Jan 01, 2007
  • Fangming Zhao +2
  • Research Article
  • Citations4

A Comprehensive Review of DNS-based Distributed Reflection Denial of Service (DRDoS) Attacks: State-of-the-Art

  • Dec 18, 2022
  • International Journal on Advanced Science Engineering and Information Technology
  • Riyadh Rahef Nuiaa +2
  • Research Article
  • Citations33

Load Distributed and Benign-Bot Mitigation Methods for IoT DNS Flood Attacks

  • Oct 25, 2019
  • IEEE Internet of Things Journal
  • Tasnuva Mahjabin +3
  • Book Chapter
  • Citations6

Introduction to the Domain Name System (DNS)

  • Jul 14, 2017
  • Michael Dooley +1
  • Conference Article
  • Citations6

Rapid IP Rerouting with SDN and NFV

  • Dec 01, 2015
  • Jeffrey Lai +2
  • Conference Article
  • Citations6

Taxonomy and Adversarial Strategies of Random Subdomain Attacks

  • Jun 01, 2019
  • Harm Griffioen +1
  • Book Chapter
  • Citations2

DNS Flood Attack Mitigation Utilizing Hot-Lists and Stale Content Updates

  • Jan 01, 2019
  • Tasnuva Mahjabin +1
  • Conference Article
  • Citations3

Bringing DNS Service to 5G Edge for Reduced Latencies in mMTC Applications

  • Apr 04, 2023
  • Ricardo Harrilal-Parchment +4
  • Conference Article
  • Citations11

Achieving host mobility using DNS dynamic updating protocol

  • Oct 01, 2008
  • Bashir Yahya +1
  • Research Article

Mitigasi Serangan DNS Cache Poisoning Pada Local Area Network Berbasis Routerboard Mikrotik

  • Dec 02, 2024
  • Jurnal Ilmiah Informatika Global
  • Dian Novianto +3
  • Book Chapter
  • Citations1

Identities, Anonymity and Information Warfare

  • Jan 01, 2015
  • Stuart Jacobs +2
Cactus Communications logo

Copyright 2026 Cactus Communications. All rights reserved.