The Business Case for DNSSEC Tunis Tunisia 2013 22 April 2013

Slides:



Advertisements
Similar presentations
1 IEEE Symposium on Security and Privacy, May 2009 Shuo Chen, Ziqing Mao, Yi-Min Wang, Ming Zhang Microsoft Research Purdue University May 20 th, 2009.
Advertisements

Security Issues In Mobile IP
Identity Theft and Online Identity Solutions Heidi Inman May 29, 2008.
The World Wide Web and the Internet MIS XLM.B Jack G. Zheng June 20 th 2005.
The World Wide Web and the Internet MIS XLM.B Jack G. Zheng May 13 th 2008.
AI3 Contact Server Takeshi Usui
From World IPv6 Day to World IPv6 Launch: This time its for real
Presenter: Mark Elkins Topic: Things not getting done.
1 How To Use a Browser A Module of the CYC Course – Computer Basics
Welcome To SPARROW Website URL
1 SLIDE Insurance Company Regulation Division Insurance Market Regulation Division Medical Professional Liability Insurance Claim Reports Online Claim.
Web Hosting. The purpose of this Startup Guide is to familiarize you with Own Web Now's Web Hosting. Own Web Now offers two web hosting platforms, one.
Presented by Brad Jacobson The Publisher on the Web Exploiting the new online sales channels.
Internet Governance Community Use Slide Deck Courtesy of ARIN May 2014.
INTERNET PROTOCOLS Class 9 CSCI 6433 David C. Roberts Entire contents copyright 2011, David C. Roberts, all rights reserved.
November 14, 2012 Securely Manage your devices, applications and data. Deploy your corporate policies on smart devices. Comply with Regulatory Laws. Detroit.
MS Partner Network 2011: LAR Session SARAH ARNOLD – MPN MARKETING MANAGER.
Mechelen - 06/02/2014 Telenet Security Day CYBER scrapings putting our 2 cents in.. Christian Van Heurck CERT.be coordinator CERT.be team.
HTTPS and the Lock Icon Dan Boneh. Goals for this lecture Brief overview of HTTPS: How the SSL/TLS protocol works (very briefly) How to use HTTPS Integrating.
Dave Chaffey, E-Business and E-Commerce Management, 4 th Edition, © Marketing Insights Limited 2009 Slide 1.1 Introduction to e-business and e-commerce.
A S I A P A C I F I C N E T W O R K I N F O R M A T I O N C E N T R E IEPG March 2000 APNIC Certificate Authority Status Report.
Hands-on SQL Injection Attack and Defense HI-TEC July 21, 2013.
- 1 - Defense Security Service Background: During the Fall of 2012 Defense Security Service will be integrating ISFD with the Identity Management (IdM)
State of DNS Security Extensions Edward Lewis February 26, 2001 APRICOT 2001 Panel.
Internet Identity For All.my ccTLD IPv6 Update By Lai Heng Choong Head of Application, Database and Security.my DOMAIN REGISTRY APTLD Member Meeting, 1.
George Tubin Senior Analyst Consumer Banking © 2005 The Tower Group, Inc. May not be reproduced by any means without express permission. All rights reserved.
DNSSEC & Validation Tiger Team DHS Federal Network Security (FNS) & Information Security and Identity Management Committee (ISIMC) Earl Crane Department.
DNSSEC Deployment: Where We Are (and where we need to be) MENOG 10, Dubai 30 April 2012
DNSSEC: Where We Are (and how we get to where we want to be) APNIC 34, Phnom Penh, Cambodia August 2012
Computer Networks: Domain Name System. The domain name system (DNS) is an application-layer protocol for mapping domain names to IP addresses Vacation.
A Third Party Service for Providing Trust on the Internet Work done in 2001 at HP Labs by Michael VanHilst and Ski Ilnicki.
Building Trust in Digital Online World Dr. Shekhar Kirani Vice President VeriSign India 5th June 2009 IBA Conference.
Registrars and Security Greg Rattray Chief Internet Security Advisor.
PKI To The Masses IPCCC 2004 Dan Massey USC/ISI. 1 March PKI Is Necessary l My PKI related actions since arriving at IPCCC n Used an.
Domain Name System | DNSSEC. 2  Internet Protocol address uniquely identifies laptops or phones or other devices  The Domain Name System matches IP.
ICANN’s multi-stakeholder approach OAS-CICTE REMJA/OAS + WEF Cyber Crime Workshop, Montevideo, Uruguay 10 July 2012
The Business Case for DNSSEC InterOp/ION Mumbai October 2012
Computer Networks: Domain Name System. The domain name system (DNS) is an application-layer protocol for mapping domain names to IP addresses Vacation.
DNSSEC: Where We Are (and how we get to where we want to be)
DNSSEC AsiaPKI - Bangkok, Thailand June 2013
1 DNSSEC for the.edu Domain Becky Granger Director, Information Technology and Member Services EDUCAUSE April 29, 2010.
What DNS is Not 0 Kylie Brown, Jordan Eberst, Danielle Franz Drew Hanson, Dennis Kilgore, Charles Newton, Lindsay Romano, Lisa Soros 0 Paul Vixie
Introducción WEB Diseño y programacion en HTML.
DNSSEC: A Game Changer ICCS 2012 January 9, 2012 New York, NY
Andreas Steffen, , 12-DNSSEC.pptx 1 Internet Security 1 (IntSi1) Prof. Dr. Andreas Steffen Institute for Internet Technologies and Applications.
Chapter 1: The Internet and the WWW CIS 275—Web Application Development for Business I.
DNS Security Pacific IT Pros Nov. 5, Topics DoS Attacks on DNS Servers DoS Attacks by DNS Servers Poisoning DNS Records Monitoring DNS Traffic Leakage.
Deploying DNSSEC: From Content to End-customer InterOp Mumbai October 2012
Module 9: Fundamentals of Securing Network Communication.
NETWORKING and the INTERNET
Phil Regnauld Hervey Allen 15 June 2009 Papeete, French Polynesia DNSSEC Tutorial: Bibliography.
FCC CSRIC III Working Group 5 DNSSEC Implementation Practices Steve Crocker CEO, Shinkuro, Inc. March 6, 2013 Working Group 5: DNSSEC.
1 DNSSEC Deployment: Big Steps Forward; Several Steps to Go NANOG 32 Deployment D N S S E C Rob Austein Steve Crocker
DNSSEC 101 IGF 2012, Baku, Azerbaijan 6 November 2012
McLean HIGHER COMPUTER NETWORKING Lesson 8 E-Commerce Explanation of ISP Description of E-commerce Description of E-sales.
Copyright ©2015 WatchGuard Technologies, Inc. All Rights Reserved WatchGuard Training WatchGuard XCS What’s New in version 10.1.
DNS Security Extension 1. Implication of Kaminsky Attack Dramatically reduces the complexity and increases the effectiveness of DNS cache poisoning –No.
Measures to prevent MITM attack and their effectiveness CSCI 5931 Web Security Submitted By Pradeep Rath Date : 23 rd March 2004.
DNSSEC Update SANOG 27 Kathmandu, Nepal January 2016
Security Issues with Domain Name Systems
SaudiNIC Riyadh, Saudi Arabia May 2017
KSK Rollover Update David Conrad, CTO ICANN 59 – GAC 29 June 2017.
Living on the Edge: (Re)focus DNS Efforts on the End-Points
Cybersecurity and Governance
Tallinn, Estonia Sep 2017 Why DNSSEC Tallinn, Estonia Sep 2017
DANE: The Future of Transport Layer Security (TLS)
الوحدة 5 مقدمة في شبكة الانترنت.
IIS.
TRA, UAE May 2017 DNSSEC Introduction TRA, UAE May 2017
The Business Case for DNSSEC
Presentation transcript:

The Business Case for DNSSEC Tunis Tunisia April 2013

The Business Case for DNSSEC Cyber security is becoming a greater concern to enterprises, government, and end users. DNSSEC is a key tool and differentiator. DNSSEC is the biggest security upgrade to Internet infrastructure in over 20 years. It is a platform for new security applications (for those that see the opportunity). DNSSEC infrastructure deployment has been brisk but requires expertise. Getting ahead of the curve is a competitive advantage.

Where DNSSEC fits in DNS converts names ( to numbers ( )..to identify services such as www and ..that identify and link customers to business and visa versa

Where DNSSEC fits in..but CPU and bandwidth advances make legacy DNS vulnerable to MITM attacks DNS Security Extensions (DNSSEC) introduces digital signatures into DNS to cryptographically protect contents With DNSSEC fully deployed a business can be sure a customer gets un-modified data (and visa versa)

The Original Problem: DNS Cache Poisoning Attack DNS Resolver = DNS Server Get page Attacker webserver Username / Password Error Attacker = Login page Password database ISP / ENTERPRISE / END NODE ENTERPRISE Animated slide detailed description at:

DNS Resolver = DNS Server Get page Attacker webserver Username / Password Error Login page Password database Argghh! Now all ISP customers get sent to attacker. Animated slide

The Bad: DNSChanger - ‘Biggest Cybercriminal Takedown in History’ – 4M machines, 100 countries, $14M Nov End-2-end DNSSEC validation would have avoided the problems

The Bad: Brazilian ISP fall victim to a series of DNS attacks 7 Nov End-2-end DNSSEC validation would have avoided the problems

The Bad: Other DNS hijacks* 25 Dec Russian e-Payment Giant ChronoPay Hacked 18 Dec 2009 – Twitter – “Iranian cyber army” 13 Aug Chinese gmail phishing attack 25 Dec 2010 Tunisia DNS Hijack google.* – April Google Puerto Rico sites redirected in DNS attack – May Morocco temporarily seize Google domain name 9 Sep Diginotar certificate compromise for Iranian users SSL / TLS doesn't tell you if you've been sent to the correct site, it only tells you if the DNS matches the name in the certificate. Unfortunately, majority of Web site certificates rely on DNS to validate identity. DNS is relied on for unexpected things though insecure. *A Brief History of DNS Hijacking - Google

The Good: Securing DNS with DNSSEC DNS Resolver with DNSSEC = DNS Server with DNSSEC Get page webserver Username / Password Account Data Login page Attacker = Attacker’s record does not validate – drop it Animated slide

The Good: Resolver only caches validated records DNS Resolver with DNSSEC = DNS Server with DNSSEC Get page webserver Username / Password Account Data Login page ENTERPRISEISP / ENTERPRISE / END NODE Animated slide

DNSSEC interest from governments Sweden, Brazil, Netherlands and others encourage DNSSEC deployment to varying degrees Mar AT&T, CenturyLink (Qwest), Comcast, Cox, Sprint, TimeWarner Cable, and Verizon have pledged to comply and abide by US FCC [1] recommendations that include DNSSEC.. “A report by Gartner found 3.6 million Americans getting redirected to bogus websites in a single year, costing them $3.2 billion.,” [2] US.gov mandate. >60% operational. [3] [1] FCC=Federal Communications Commission=US communications Ministry [2] [3]

Security as Differentiator and Edge Differentiator – Increased cyber security awareness for govts and industry – Major ISP says security now on checklist for customers DNSSEC Service and Support – 102/317 TLDs (e.g.,.jp,.kr,.ru,.com,.in,.nl,..) – Growing ISPs adoption* – Available to 86% of domains – Vendor support (ISC/BIND, Microsoft..) – gTLDs (e.g.,.bank,.search) require it *COMCAST Internet (18M), TeliaSonera SE, Sprint,Vodafone CZ,Telefonica CZ, T-mobile NL, SurfNet NL, SANYO Information Technology Solutions JP, others..

Deployed on 105/317 TLDs (.my.th.mm.in.kg.lk.nc.nz.la.pw.tv.kr.jp.ru.рф.de.my مليسيا.asia.tw 台灣,.kr 한국.com.net,.post, …) Root signed** and audited >86% of domain names could have DNSSEC Required in new gTLDs Growing ISP support* 3 rd party signing solutions: GoDaddy, Binero, VeriSign…*** Growing S/W H/W support: NLNetLabs/NSD+Unbound, ISC/BIND, Microsoft, PowerDNS, Secure64…?openssl, mozilla DANE support? IETF standard on DNSSEC SSL certificates (RFC6698) Growing support from major players…(IOS, ,…) DNSSEC - Where we are *COMCAST Internet (18M), TeliaSonera SE, Sprint,Vodafone CZ,Telefonica CZ, T-mobile NL, SurfNet NL, SANYO Information Technology Solutions JP, others.. **21 TCRs from: TT, BF, RU, CN, US, SE, NL, UG, BR, Benin, PT, NP, Mauritius, CZ, CA, JP, UK, NZ *** Partial list of registrars: 14

VoIP mydomainname.com DNS is a part of all IT ecosystems US-NSTIC effort Smart Electrical Grid OECS ID effort

The Bad: SSL Dilution of Trust The Good: DNSSEC = Global “free” PKI CA Certificate roots ~1482 Login security SSHFP RFC4255 DANE and other yet to be discovered security innovations, enhancements, and synergies Content security Commercial SSL Certificates for Web and Content security “Free SSL” certificates for Web and and “trust agility” Network security IPSECKEY RFC4025 Cross- organizational and trans-national identity and authentication security DKIM RFC4871 DNSSEC root - 1 Domain Names Securing VoIP

Opportunity: New Security Products Improved Web SSL and certificates for all* Secured (S/MIME) for all* Validated remote login SSH, IPSEC* Securing VoIP Cross organizational digital identity systems Secured content delivery (e.g. configurations, updates, keys) Securing Smart Grid efforts A global PKI Increasing trust in e-commerce A good ref *IETF standards complete or currently being developed

DNSSEC: Internet infrastructure upgrade to help address today’s needs and create tomorrow’s opportunity.

The Internet’s Phone Book - Domain Name System (DNS+DNSSEC) Get page webserver Username / Password Account Data DNS Resolver = DNS Server Login page ISP/ HotSpot / Enterprise/ End Node Majorbank.se (Registrant) DNS Server.se (Registry) DNS Server. (Root) Animated slide