Domain Name System still at risk

Global DNS is 'as vulnerable as ever', reports Infoblox

Ian Williams

The Domain Name System (DNS) is still growing strongly, indicating the internet's expansion in terms of infrastructure, users, traffic and applications.

But the annual survey of domain name servers on the public internet by Infoblox suggests that the global DNS is as vulnerable as ever.

Advertisement

DNS servers map domain names to their specific IP address, directing internet inquiries to the appropriate location.

Domain name resolution conducted by these servers is required to perform any internet-related request.

Should an organisation's DNS systems fail, all internet functions, including email, web access, e-commerce and extranets, become unavailable.

The report showed that the DNS infrastructure is modernising and coalescing around the most recent versions of the Berkeley Internet Name Domain (Bind), the most commonly used DNS server software on the internet.

However, the DNS is still vulnerable as many DNS servers are left open to attack from several directions.

More than 50 per cent of internet name servers allow recursive queries, for example, which often require a name server to relay requests to other name servers.

This can leave name servers vulnerable to pharming attacks and allow those servers to be used in DNS amplification attacks that can take down important internet infrastructure.

"For the overall security of the internet, it is good to see movement away from Microsoft DNS Servers for external DNS as well as a growing trend to use the most recent versions of Bind," said Cricket Liu, vice president of architecture at Infoblox.

"However, even with growing adoption of more secure name servers, compromises of these systems are still occurring.

"Organisations need to pay more attention to configurations and deployment architectures that are leaving their DNS infrastructures vulnerable to attacks and outages."

Infoblox reported that internet-facing DNS servers increased to 11.5 million, up from around nine million in 2006 and 7.5 million in 2005, and that use of Bind 9, the latest version, grew to 65 per cent in 2007, up from 61 per cent in 2006.

Furthermore, support for the Sender Policy Framework increased to 12.6 per cent in 2007, up from five per cent in 2006.

SPF allows software to identify and reject forged email addresses and indicates that organisations are taking email fraud seriously.

  • Have your say
  • Send to a friend
  • Print
  • Digg
  • Reddit
  • Share

Tags:

Do you agree?

Further reading

Hacking

McAfee paints grim picture for 2008

Huge rise in web 2.0 attacks and smarter botnets

Agent Trojan targets Asian gamers

Malware attempts to steal usernames and passwords

TechEd 2007: Security should be taught in schools

More user education and better collaboration needed to beat online threats

Phishing scam taps Salesforce data

Customers being bombarded with attacks

Related whitepapers

Related jobs

Most watched

eu flag

V3.co.uk weekly debrief, 6 Nov 09

This week, Europe decides what to do with illegal file sharers

Intel unveils its micro server platform

Small-enclosure systems take aim at hosting market

Analysis and Reports

Remote access - Three steps to getting connected

3.4 million UK professionals now work from home – is your company equipped?

Cost benefits of a global collaboration network

This white paper is a must read for organisations looking for evidence of the bottom-line benefits of high-definition video and voice communications

Poll

Impact of Information Overload poll

Impact of Information Overload poll

What is the biggest problem your firm faces as a result of the data explosion?

View poll results

Advertisement

White paper library

Keep up to date with the latest products, services and technologies from the world's leading IT companies; IThound.com brings you over 6,000 white papers, case studies and analyst reports.

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Spotlight

Alcatel-Lucent logo

Summit: Networks swamped by information overload

Alcatel-Lucent's Neal Tilley talks about how enterprises and carriers can...

EU flag

Breach notification laws get green light

Privacy rights strengthened in Europe

Richard Thomas

Summit: Richard Thomas advises on handling the data deluge

Former Information Commissioner speaks out on government databases and data...

oracle sun

War of words escalates between EU and Oracle

Commission comes out fighting after criticism from Oracle and Washington

Primary Navigation