Domain Name System still at risk

Global DNS is 'as vulnerable as ever', reports Infoblox

Written by Ian Williams

The Domain Name System (DNS) is still growing strongly, indicating the internet's expansion in terms of infrastructure, users, traffic and applications.

But the annual survey of domain name servers on the public internet by Infoblox suggests that the global DNS is as vulnerable as ever.

DNS servers map domain names to their specific IP address, directing internet inquiries to the appropriate location.

Domain name resolution conducted by these servers is required to perform any internet-related request.

Should an organisation's DNS systems fail, all internet functions, including email, web access, e-commerce and extranets, become unavailable.

The report showed that the DNS infrastructure is modernising and coalescing around the most recent versions of the Berkeley Internet Name Domain (Bind), the most commonly used DNS server software on the internet.

However, the DNS is still vulnerable as many DNS servers are left open to attack from several directions.

More than 50 per cent of internet name servers allow recursive queries, for example, which often require a name server to relay requests to other name servers.

This can leave name servers vulnerable to pharming attacks and allow those servers to be used in DNS amplification attacks that can take down important internet infrastructure.

"For the overall security of the internet, it is good to see movement away from Microsoft DNS Servers for external DNS as well as a growing trend to use the most recent versions of Bind," said Cricket Liu, vice president of architecture at Infoblox.

"However, even with growing adoption of more secure name servers, compromises of these systems are still occurring.

"Organisations need to pay more attention to configurations and deployment architectures that are leaving their DNS infrastructures vulnerable to attacks and outages."

Infoblox reported that internet-facing DNS servers increased to 11.5 million, up from around nine million in 2006 and 7.5 million in 2005, and that use of Bind 9, the latest version, grew to 65 per cent in 2007, up from 61 per cent in 2006.

Furthermore, support for the Sender Policy Framework increased to 12.6 per cent in 2007, up from five per cent in 2006.

SPF allows software to identify and reject forged email addresses and indicates that organisations are taking email fraud seriously.

Tags:

Further reading

McAfee paints grim picture for 2008

Huge rise in web 2.0 attacks and smarter botnets   More...

Agent Trojan targets Asian gamers

Malware attempts to steal usernames and passwords   More...

TechEd 2007: Security should be taught in schools

More user education and better collaboration needed to beat online threats   More...

Phishing scam taps Salesforce data

Customers being bombarded with attacks   More...

Related articles

'Italian job' attacks spread worldwide

10,000 websites now hosting malicious attack code   More...

'Spam King' Soloway arrested in the US

27 year-old accused of using compromised computers to send tens of millions of emails   More...

Microsoft warns of web proxy flaw

Possible risk of 'man-in-the-middle' attack   More...

PC processor shipments hit new record

Levels of unit shipments jumped in 3Q07, according to IDC   More...

Do you agree?

Advertisement

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Watch

16 May 2008

2.97 MBXP on OLPC, broken dreams and Yahoo fights back More...

15 May 2008

3.28 MBDark fibre, mobile TV and solar power More...

14 May 2008

2.66 MBOnline inequality, mobile thumbprints and corporate raids More...

Poll

HOME WORKING

HOME WORKING

Do you let any or all of your employees work from home?

Previous poll results

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Spotlight

OLPC

OLPC to ship with Windows XP

Microsoft teams up with One Laptop per Child project   More...

The Sims

The Sims goes flat-pack with Ikea

Virtual world gets Swedish wood   More...

Advertisement

Microsoft-Yahoo

Yahoo board fights back at Icahn

Investor accused of 'significant misunderstanding' in Microsoft saga   More...

MySpace

Woman charged over MySpace suicide

Lori Drew indicted on federal charges   More...

Advertisement