Login or register
SecDocs RSS feed

Video details

Title DNS Security In The Broadest Sense
Type Video
Tags security DNS
Abstract The Domain Name System underlies almost any transaction on the internet, from sending email to visiting a web page. Its security and reliability are therefore of paramount importance. This presentation will outline the nature of threats to the DNS, complete with numbers quantifying the risks. In addition, popular and future countermeasures will be discussed, and their impact on DNS. Risks examined include blind spoofing, triggered blind spoofing, NAT-aware blind spoofing, modern cache poisoning techniques and DNS nameserver record dependency exploitation. Additionally, the danger and consequences of man in the middle attacks will be discussed. One of the more interesting conclusions is that despite widespread hype, the famous 'Kaminsky spoof' is very impracticable on a modern DNS resolver, even if it does not implement specific countermeasures. Numbers will be shown to outline why this is so hard. Finally, some words will be spent discussing how DNSSEC could address the problems mentioned above. The hope is that this will lead to constructive discussion later during the event.
Authors Bert Hubert
Submitted October 17, 2009
Rating
Currently 0/5 stars (0 votes).
Correlation
Linked to
Event HAR 2009
Resource ---
Download
Source 294_l3929_DNS_Security_In_The_Broadest_Sense.mp4
Size 296.8 MB
MD5 0eb44e59ed5e3d7fadb9a59c3e4b66af
SHA1 bee689c02c4da3de5364aeb93aa2d1881986f34f

Comments
No comments.
Add new Only logged in users can comment.


Click here to lend your support to: SecDocs and make a donation at www.pledgie.com !