Tutorial: Towards a Secure DNS
Section Completed Onsite Workshop

Tutorial: Towards a Secure DNS

Date:
December 13, 2012
Time:
2:00 PM - 5:00 PM
Location:
SBA Research gGmbH, Favoritenstraße 16, 2nd Floor, 1040, Wien, AT
Fee:
Free

About This Event

Haya Shulman  (Department of Computer Science; Bar Ilan University; Ramat Gan, Israel) will give a 3h tutorial on DNS and present her research (and related research of others) on Dec 13, 2pm
(@SBA).


 


 


--- ABSTRACT ---







Most caching DNS resolvers still rely for their security,
against poisoning, on validating that the DNS responses contain some ‘unpredictable’ values, copied from the request.
These values include the 16 bit identifier field, and other fields, randomised
and validated by different ‘patches’ to DNS. We investigate the prominent patches,
and show how off-path attackers can circumvent all of them, exposing the
resolvers to cache poisoning attacks.


We present countermeasures preventing our attacks;
however, we believe that our attacks provide additional motivation for adoption
of DNSSEC (or other MitM-secure defenses).


We then investigate vulnerabilities in DNSSEC
configuration among resolvers and zones, which reduce or even nullify the
protection offered by DNSSEC. Finally we provide our recommendations and countermeasures to prevent the vulnerabilities.


 


 

Additional Information

Maximum Attendees:

15

Quick Info

Organizer:

Section

Chapter:

Section

Free Event

Share This Event

Upcoming Related Events

5th DiGiSect Expert Workshop on Design and Operation of Digitalized Sector-Coupled Energy Systems (DiGiSect 2026)
5th DiGiSect Expert Workshop on Design and Operation of Digitalized Sector-Coupled Energy Systems (DiGiSect 2026)

June 18, 2026

View Details