English

Take up DNSSEC When Needed

Cryptography and Security 2016-02-29 v1

Abstract

The threats of caching poisoning attacks largely stimulate the deployment of DNSSEC. Being a strong but demanding cryptographical defense, DNSSEC has its universal adoption predicted to go through a lengthy transition. Thus the DNSSEC practitioners call for a secure yet lightweight solution to speed up DNSSEC deployment while offering an acceptable DNSSEC-like defense. This paper proposes a new defense against cache poisoning attacks, still using but lightly using DNSSEC. In the solution, DNS operates in the DNSSEC-oblivious mode unless a potential attack is detected and triggers a switch to the DNSSEC-aware mode. The performance of the defense is analyzed and validated. The modeling checking results demonstrate that only a small DNSSEC query load is needed to ensure a small enough cache poisoning success rate.

Keywords

Cite

@article{arxiv.1602.08459,
  title  = {Take up DNSSEC When Needed},
  author = {Zheng Wang},
  journal= {arXiv preprint arXiv:1602.08459},
  year   = {2016}
}
R2 v1 2026-06-22T12:58:52.343Z