Proceedings 2015 Network and Distributed System Security Symposium 2015
DOI: 10.14722/ndss.2015.23211
|View full text |Cite
|
Sign up to set email alerts
|

NSEC5: Provably Preventing DNSSEC Zone Enumeration

Abstract: We use cryptographic techniques to study zone enumeration in DNSSEC. DNSSEC is designed to prevent attackers from tampering with domain name system (DNS) messages. The cryptographic machinery used in DNSSEC, however, also creates a new vulnerability, zone enumeration, enabling an adversary to use a small number of online DNSSEC queries combined with offline dictionary attacks to learn which domain names are present or absent in a DNS zone. We prove that the current DNSSEC standard, with NSEC and NSEC3 records,… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
3
1
1

Citation Types

0
21
0

Year Published

2015
2015
2021
2021

Publication Types

Select...
6

Relationship

1
5

Authors

Journals

citations
Cited by 32 publications
(22 citation statements)
references
References 40 publications
0
21
0
Order By: Relevance
“…In our companion paper [36], we prove two very important facts about non-interactive PSR systems. The first is that f -ZK, where f (R) is the cardinality of the set R, implies prevention of zone enumeration, i.e.…”
Section: Zero-knowledgementioning
confidence: 90%
See 4 more Smart Citations
“…In our companion paper [36], we prove two very important facts about non-interactive PSR systems. The first is that f -ZK, where f (R) is the cardinality of the set R, implies prevention of zone enumeration, i.e.…”
Section: Zero-knowledgementioning
confidence: 90%
“…UOWHFs in turn can be constructed from one-way functions [68]. PSR systems imply identification schemes, as shown in our companion paper [36], which in turn imply the existence of one-way functions, as shown by Impagliazzo and Luby [45] (see also [44]). …”
Section: Psr Systems Based On One-time Signaturesmentioning
confidence: 95%
See 3 more Smart Citations