Skip Links

Network World

  • Social Web 
  • Email 
  • Close

(Comma separation for multiple addresses)
Your Message:

Will security worries propel DNS into the cloud?

VeriSign, Afilias among vendors beefing up their cloud-based DNS services
By Carolyn Duffy Marsan, Network World
July 15, 2010 07:00 AM ET
  • Share/Email
  • Tweet This
  • Comment
  • Print

Security on the Internet's Domain Name System will be tightened today, with the addition of digital signatures and public-key encryption to the root zone. But will the deployment of DNS Security Extensions (DNSSEC) prompt more enterprises to outsource their DNS operations?

DNS gains added measure of security starting today

That's the opportunity that service providers including VeriSign and Afilias are eyeing with new managed DNS and related security services that they plan to announce in upcoming weeks.

DNS security reaches 'key' milestone

DNSSEC is an emerging Internet standard that prevents spoofing attacks by allowing Web sites to verify their domain names and corresponding IP addresses using digital signatures and public-key encryption.

Once it is fully deployed, DNSSEC will prevent cache poisoning attacks, where traffic is redirected from a legitimate Web site to a fake one without the Web site operator or user knowing. Cache poisoning attacks are the result of a serious flaw in the DNS that was disclosed by security researcher Dan Kaminsky in 2008.

DNSSEC is being deployed across the Internet infrastructure, from the root servers at the top of the DNS hierarchy to the servers that run .com and .net and other top-level domains, and then down to the servers that cache content for individual Web sites.

The DNS root servers will begin supporting DNSSEC on July 15. This will enable secure DNS look-ups for the top-level domains that already support this standard, including .org for non-profits, .se for Sweden, .uk for the United Kingdom, .br for Brazil and .cz for the Czech Republic. Plans are underway for additional top-level domains including .edu for universities, .net and .com for businesses to add DNSSEC support over the next six months.

With the extra layer of encryption, DNSSEC makes DNS significantly more complicated, experts say. That's why service providers believe that more enterprises will begin outsourcing their DNS.

"DNSSEC takes the complexity level and really magnifies it. It's a game changer. It's not 10% harder now; it's twice as hard to manage DNS, and it's twice as hard on the machine size and the bandwidth," says Ben Petro, senior vice president of Network Intelligence and Availability at VeriSign. "We can do all of this work for you and make DNSSEC easy."

"DNSSEC is so complicated. The protocol has worked great, but we see a lot of misconfigurations," said Sean Leach, CTO with Name.com, a domain name registrar that has dozens of customers who are testing DNSSEC. "I really do think that you're going to start seeing outsourced DNS as the norm."

VeriSign, Afilias to offer cloud-based DNS

VeriSign officials said they are developing a cloud-based DNS service that will be sold directly to enterprise customers. VeriSign hosts two of the Internet's 13 root name server clusters and is the registry for the .com and .net domains, operating a massive global DNS infrastructure that the company hopes will attract enterprise customers.

VeriSign is expanding the managed DNS services that the company has offered for several years through channel partners. VeriSign is bundling its cloud-based DNS services with distributed denial of service (DoS) and cyber-intelligence protection services that it already offers.

  • Share/Email
  • Tweet This
  • Comment
  • Print

Comments (9)
Login
Forgot your account info?

Will security worries propel users/employee into the cloud? By Anonymous on July 15, 2010, 11:13 amWould it be better to outsource all users and employees functions to the cloud? There will be no security concern after that

Reply | Read entire comment

No Security Concern?By Anonymous on July 15, 2010, 12:11 pmYou must be planning to host on Cloud 9.

Reply | Read entire comment

Security not an issue with VirnetXBy Anonymous on July 15, 2010, 2:21 pmAll these security issues associated with the internet will soon be overcome with the introduction and adoption of VirnetX (VHC)Gabriel technology. The company just...

Reply | Read entire comment

Thanks for the plug!By Raargh on July 15, 2010, 6:06 pmHi, Yes, cloud9.net is ready for you to outsource all your staff AND users to our cloud! Save $$, make more $$! http://www.cloud9.net/

Reply | Read entire comment

eryhhhBy Anonymous on July 15, 2010, 7:23 pm hi, everybody, take your time and a little bit. Now I introduce a website ======= http://clotheshops.us/======== wholesale shoes,jean,cap,handbag,sunglass,short,ha......

Reply | Read entire comment

Proteus Cloud ServicesBy Anonymous on July 16, 2010, 8:53 amWant to know more about Proteus Cloud Services? http://www.bluecatnetworks.com/proteus-cloud-service

Reply | Read entire comment

View all comments

Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed