SlideShare uma empresa Scribd logo
1 de 11
Baixar para ler offline
Why Implement DNSSEC
ION 2015
Capetown, SA
8 September 2015
Simon M. Balthazar
DNS Refresher
● DNS converts names (www.gumtree.co.za) to
numbers (23.214.106.52)
● To identify services such as www and emails.
● Serves as a link between customers and online
businesses and vice versa
● DNS is a critical infrastructure that is a part of
all IT ecosystems. i.e. e-government, online
banking, e-commerce, social networks etc.
DNS Data Flow
DNS Vulnerabilities
DNS: The Problem
● DNS data published by the registry is being
replaced on its path between the server and the
client.
● Kaminsky Bug (2008) reveals a DNS Flaw that
allows hackers to redirect traffic from the
legitimate website to the fake one without
website operator or end user knowing.
● These vulnerabilities calls for a permanent fix!
DNSSEC: It is happening ...
● DNSChanger: The Biggest
Cybercriminal Takedown in History –
4M Machines, 100 Countries, $14M
● End-to-end DNSSEC Validation would
have avoided the problems
DNSSEC
● DNSSEC secures the name to address
mapping
● DNSSEC introduces digital signatures into DNS
to cryptographically protect its records
● It ensures authentic DNS source and no
modification of data between server and client
● With DNSSEC fully deployed a business can be
sure that a customer gets un-modified data and
vice versa
Why DNSSEC?
● With more and more of the world economy and
transactions depending on the Internet
cybersecurity is becoming a major concern for
governments, businesses and end users.
● They expect service providers such as
registrars, registries, and ISPs to invest in
strong security measures.
● They also desire solutions that are easy to
understand, quickly usable and easily
manageable.
DNSSEC: Standout from the rest
● Businesses may use DNSSEC offering as a
differentiator and a competitive advantage
against other businesses
● Marketplace has evolved the need to guide
corporate behaviour based on online-safety for
businesses and end users
● Safety, Quality and Stability are essential for the
proper functioning of the DNS marketplace
● Fundamentals requires that we go for values
based competition over price based competition
DNSSEC: Save your business
● As Internet becomes essential to the success
and failure of companies, a move to more
secure model is inevitable
● This happens as companies willingly pay
hundreds of dollars to provide enhanced
security for their customers i.e. Online
transaction security using SSL
● Once companies realize that DNSSEC will
protect their domain names against DNS
spoofing then they will adopt
Thank You!
● simon [at] tznic.or.tz
● +255 754 711 104

Mais conteúdo relacionado

Destaque

Destaque (17)

ION Trinidad and Tobago - The Business Case for DNSSEC
ION Trinidad and Tobago - The Business Case for DNSSECION Trinidad and Tobago - The Business Case for DNSSEC
ION Trinidad and Tobago - The Business Case for DNSSEC
 
ION Bangladesh - IPv6 Experiences at Sri Lanka Telecom
ION Bangladesh - IPv6 Experiences at Sri Lanka TelecomION Bangladesh - IPv6 Experiences at Sri Lanka Telecom
ION Bangladesh - IPv6 Experiences at Sri Lanka Telecom
 
ION Bangladesh - ISOC Dhaka Chapter Welcome
ION Bangladesh - ISOC Dhaka Chapter WelcomeION Bangladesh - ISOC Dhaka Chapter Welcome
ION Bangladesh - ISOC Dhaka Chapter Welcome
 
ION Bangladesh - MANRS & Routing Security
ION Bangladesh - MANRS & Routing SecurityION Bangladesh - MANRS & Routing Security
ION Bangladesh - MANRS & Routing Security
 
ION Sri Lanka - IPv6 Deployment Update
ION Sri Lanka - IPv6 Deployment UpdateION Sri Lanka - IPv6 Deployment Update
ION Sri Lanka - IPv6 Deployment Update
 
ION Cape Town - Opening Remarks
ION Cape Town - Opening RemarksION Cape Town - Opening Remarks
ION Cape Town - Opening Remarks
 
ION Trinidad and Tobago - Opening Slides
ION Trinidad and Tobago - Opening SlidesION Trinidad and Tobago - Opening Slides
ION Trinidad and Tobago - Opening Slides
 
ION Sri Lanka - IPv6 Deployment in Uganda and Africa (IPv6 Panel)
ION Sri Lanka - IPv6 Deployment in Uganda and Africa (IPv6 Panel)ION Sri Lanka - IPv6 Deployment in Uganda and Africa (IPv6 Panel)
ION Sri Lanka - IPv6 Deployment in Uganda and Africa (IPv6 Panel)
 
ION Bangladesh - Closing Remarks
ION Bangladesh - Closing RemarksION Bangladesh - Closing Remarks
ION Bangladesh - Closing Remarks
 
ION Bangladesh - IPv6 Deployment Status in Bangladesh
ION Bangladesh - IPv6 Deployment Status in BangladeshION Bangladesh - IPv6 Deployment Status in Bangladesh
ION Bangladesh - IPv6 Deployment Status in Bangladesh
 
ION Trinidad and Tobago - IPv6 Global Connectivity Three Years After World IP...
ION Trinidad and Tobago - IPv6 Global Connectivity Three Years After World IP...ION Trinidad and Tobago - IPv6 Global Connectivity Three Years After World IP...
ION Trinidad and Tobago - IPv6 Global Connectivity Three Years After World IP...
 
ION Sri Lanka - Why Implement DNSSEC?
ION Sri Lanka - Why Implement DNSSEC?ION Sri Lanka - Why Implement DNSSEC?
ION Sri Lanka - Why Implement DNSSEC?
 
DANE/DNSSEC/TLS Testing in the go6Lab - ION Cape Town
DANE/DNSSEC/TLS Testing in the go6Lab - ION Cape TownDANE/DNSSEC/TLS Testing in the go6Lab - ION Cape Town
DANE/DNSSEC/TLS Testing in the go6Lab - ION Cape Town
 
ION Bangladesh - Secure BGP and Operational Report of Bangladesh
ION Bangladesh - Secure BGP and Operational Report of BangladeshION Bangladesh - Secure BGP and Operational Report of Bangladesh
ION Bangladesh - Secure BGP and Operational Report of Bangladesh
 
ION Cape Town - Closing Remarks
ION Cape Town - Closing RemarksION Cape Town - Closing Remarks
ION Cape Town - Closing Remarks
 
ION Cape Town - Welcome from ISOC Gauteng Chapter
ION Cape Town - Welcome from ISOC Gauteng ChapterION Cape Town - Welcome from ISOC Gauteng Chapter
ION Cape Town - Welcome from ISOC Gauteng Chapter
 
ION Sri Lanka - Operators and the IETF
ION Sri Lanka - Operators and the IETFION Sri Lanka - Operators and the IETF
ION Sri Lanka - Operators and the IETF
 

Mais de Deploy360 Programme (Internet Society)

Mais de Deploy360 Programme (Internet Society) (20)

ION Belgrade - Jordi Palet Martinez IPv6 Success Stories
ION Belgrade - Jordi Palet Martinez IPv6 Success StoriesION Belgrade - Jordi Palet Martinez IPv6 Success Stories
ION Belgrade - Jordi Palet Martinez IPv6 Success Stories
 
ION Belgrade - ISOC Serbia Belgrade Chapter Presentation
ION Belgrade - ISOC Serbia Belgrade Chapter PresentationION Belgrade - ISOC Serbia Belgrade Chapter Presentation
ION Belgrade - ISOC Serbia Belgrade Chapter Presentation
 
ION Belgrade - IETF Update
ION Belgrade - IETF UpdateION Belgrade - IETF Update
ION Belgrade - IETF Update
 
ION Belgrade - Opening Slides
ION Belgrade - Opening SlidesION Belgrade - Opening Slides
ION Belgrade - Opening Slides
 
ION Belgrade - MANRS by Serbian Open eXchange (SOX)
ION Belgrade - MANRS by Serbian Open eXchange (SOX)ION Belgrade - MANRS by Serbian Open eXchange (SOX)
ION Belgrade - MANRS by Serbian Open eXchange (SOX)
 
ION Belgrade - Closing Slides
ION Belgrade - Closing SlidesION Belgrade - Closing Slides
ION Belgrade - Closing Slides
 
AusNOG - Two Years of Good MANRS
AusNOG - Two Years of Good MANRSAusNOG - Two Years of Good MANRS
AusNOG - Two Years of Good MANRS
 
ION Malta - IETF Update
ION Malta - IETF UpdateION Malta - IETF Update
ION Malta - IETF Update
 
ION Malta - MANRS Introduction
ION Malta - MANRS IntroductionION Malta - MANRS Introduction
ION Malta - MANRS Introduction
 
ION Malta - Introduction to DNSSEC
ION Malta - Introduction to DNSSECION Malta - Introduction to DNSSEC
ION Malta - Introduction to DNSSEC
 
ION Malta - DANE: The Future of TLS
ION Malta - DANE: The Future of TLSION Malta - DANE: The Future of TLS
ION Malta - DANE: The Future of TLS
 
ION Malta - IANA Transition Roles & Accountability
ION Malta - IANA Transition Roles & AccountabilityION Malta - IANA Transition Roles & Accountability
ION Malta - IANA Transition Roles & Accountability
 
ION Malta - IPv6 Case Study: Finland
ION Malta - IPv6 Case Study: FinlandION Malta - IPv6 Case Study: Finland
ION Malta - IPv6 Case Study: Finland
 
ION Malta - Seeweb Thoughts on IPv6 Transition
ION Malta - Seeweb Thoughts on IPv6 TransitionION Malta - Seeweb Thoughts on IPv6 Transition
ION Malta - Seeweb Thoughts on IPv6 Transition
 
ION Malta - Seeweb Why MANRS is good for you
ION Malta - Seeweb Why MANRS is good for youION Malta - Seeweb Why MANRS is good for you
ION Malta - Seeweb Why MANRS is good for you
 
ION Malta - Opening Slides
ION Malta - Opening SlidesION Malta - Opening Slides
ION Malta - Opening Slides
 
ION Malta - Closing Slides
ION Malta - Closing SlidesION Malta - Closing Slides
ION Malta - Closing Slides
 
ION Durban - How peering behaviour affects growth of the internet
ION Durban - How peering behaviour affects growth of the internetION Durban - How peering behaviour affects growth of the internet
ION Durban - How peering behaviour affects growth of the internet
 
ION Durban - Introduction to ISOC Gauteng Chapter
ION Durban - Introduction to ISOC Gauteng ChapterION Durban - Introduction to ISOC Gauteng Chapter
ION Durban - Introduction to ISOC Gauteng Chapter
 
ION Durban - What's Happening at the IETF?
ION Durban - What's Happening at the IETF?ION Durban - What's Happening at the IETF?
ION Durban - What's Happening at the IETF?
 

Último

Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Victor Rentea
 
Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire business
panagenda
 
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
?#DUbAI#??##{{(☎️+971_581248768%)**%*]'#abortion pills for sale in dubai@
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Safe Software
 

Último (20)

Biography Of Angeliki Cooney | Senior Vice President Life Sciences | Albany, ...
Biography Of Angeliki Cooney | Senior Vice President Life Sciences | Albany, ...Biography Of Angeliki Cooney | Senior Vice President Life Sciences | Albany, ...
Biography Of Angeliki Cooney | Senior Vice President Life Sciences | Albany, ...
 
Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...
Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...
Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...
 
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ..."I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
 
presentation ICT roal in 21st century education
presentation ICT roal in 21st century educationpresentation ICT roal in 21st century education
presentation ICT roal in 21st century education
 
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
 
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
 
Platformless Horizons for Digital Adaptability
Platformless Horizons for Digital AdaptabilityPlatformless Horizons for Digital Adaptability
Platformless Horizons for Digital Adaptability
 
Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024
 
Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire business
 
Elevate Developer Efficiency & build GenAI Application with Amazon Q​
Elevate Developer Efficiency & build GenAI Application with Amazon Q​Elevate Developer Efficiency & build GenAI Application with Amazon Q​
Elevate Developer Efficiency & build GenAI Application with Amazon Q​
 
CNIC Information System with Pakdata Cf In Pakistan
CNIC Information System with Pakdata Cf In PakistanCNIC Information System with Pakdata Cf In Pakistan
CNIC Information System with Pakdata Cf In Pakistan
 
FWD Group - Insurer Innovation Award 2024
FWD Group - Insurer Innovation Award 2024FWD Group - Insurer Innovation Award 2024
FWD Group - Insurer Innovation Award 2024
 
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
 
Exploring Multimodal Embeddings with Milvus
Exploring Multimodal Embeddings with MilvusExploring Multimodal Embeddings with Milvus
Exploring Multimodal Embeddings with Milvus
 
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, AdobeApidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
 
Rising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdf
Rising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdfRising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdf
Rising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdf
 
Introduction to Multilingual Retrieval Augmented Generation (RAG)
Introduction to Multilingual Retrieval Augmented Generation (RAG)Introduction to Multilingual Retrieval Augmented Generation (RAG)
Introduction to Multilingual Retrieval Augmented Generation (RAG)
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
 

ION Cape Town - Why Implement DNSSEC?

  • 1. Why Implement DNSSEC ION 2015 Capetown, SA 8 September 2015 Simon M. Balthazar
  • 2. DNS Refresher ● DNS converts names (www.gumtree.co.za) to numbers (23.214.106.52) ● To identify services such as www and emails. ● Serves as a link between customers and online businesses and vice versa ● DNS is a critical infrastructure that is a part of all IT ecosystems. i.e. e-government, online banking, e-commerce, social networks etc.
  • 5. DNS: The Problem ● DNS data published by the registry is being replaced on its path between the server and the client. ● Kaminsky Bug (2008) reveals a DNS Flaw that allows hackers to redirect traffic from the legitimate website to the fake one without website operator or end user knowing. ● These vulnerabilities calls for a permanent fix!
  • 6. DNSSEC: It is happening ... ● DNSChanger: The Biggest Cybercriminal Takedown in History – 4M Machines, 100 Countries, $14M ● End-to-end DNSSEC Validation would have avoided the problems
  • 7. DNSSEC ● DNSSEC secures the name to address mapping ● DNSSEC introduces digital signatures into DNS to cryptographically protect its records ● It ensures authentic DNS source and no modification of data between server and client ● With DNSSEC fully deployed a business can be sure that a customer gets un-modified data and vice versa
  • 8. Why DNSSEC? ● With more and more of the world economy and transactions depending on the Internet cybersecurity is becoming a major concern for governments, businesses and end users. ● They expect service providers such as registrars, registries, and ISPs to invest in strong security measures. ● They also desire solutions that are easy to understand, quickly usable and easily manageable.
  • 9. DNSSEC: Standout from the rest ● Businesses may use DNSSEC offering as a differentiator and a competitive advantage against other businesses ● Marketplace has evolved the need to guide corporate behaviour based on online-safety for businesses and end users ● Safety, Quality and Stability are essential for the proper functioning of the DNS marketplace ● Fundamentals requires that we go for values based competition over price based competition
  • 10. DNSSEC: Save your business ● As Internet becomes essential to the success and failure of companies, a move to more secure model is inevitable ● This happens as companies willingly pay hundreds of dollars to provide enhanced security for their customers i.e. Online transaction security using SSL ● Once companies realize that DNSSEC will protect their domain names against DNS spoofing then they will adopt
  • 11. Thank You! ● simon [at] tznic.or.tz ● +255 754 711 104