Resources
Location:

NIST Secure Domain Name System (DNS) Deployment Guide

Title:NIST Secure Domain Name System (DNS) Deployment Guide (ID: CSD5733)
Author(s):Ramaswamy Chandramouli (National Institute of Standards and Technology) and Scott Rose (National Institute of Standards and Technology)
Topics:Authentication, Cybersecurity, Cybersecurity Policy, DNSSEC, Network Security and Applications
Source:National Institute of Standards and Technology
Origin:Community Contributions (02/18/2009)
Type:Government Documents, Laws, Testimonies or Reports
Abstract:

This document provides deployment guidelines for securing DNS within an enterprise. Because DNS data is meant to be public, preserving the confidentiality of DNS data pertaining to publicly accessible IT resources is not a concern. The primary security goals for DNS are data integrity and source authentication, which are needed to ensure the authenticity of domain name information and maintain the integrity of domain name information in transit. This document provides extensive guidance on maintaining data integrity and performing source authentication. Availability of DNS services and data is also very important; DNS components are often subjected to denial-of-service attacks intended to disrupt access to the resources whose domain names are handled by the attacked DNS components. This document presents guidelines for configuring DNS deployments to prevent many denial-of-service attacks that exploit vulnerabilities in various DNS components.

View this resource:

 
© Copyright 1999-2009 EDUCAUSE