Skip Links

Network World

  • Social Web 
  • Email 
  • Close

It's time for a DNS check-up, experts warn

Have you checked your DNS servers lately?
By Carolyn Duffy Marsan , Network World , 02/21/2007
  • Share/Email
  • Comment
  • Print

Have you checked your DNS servers lately? If not, you may be putting your company’s entire network at risk.

The Internet’s DNS is a global distributed database that matches domain names with corresponding IP addresses. The DNS is critical for every Internet application, from Web surfing and e-mail to VoIP and video streaming.

If DNS doesn’t work, the Internet doesn’t work. That’s why you need to make sure that your DNS systems are robust, scalable and secure.

The vulnerability of DNS was demonstrated this month by a distributed denial-of-service attack that affected three out of the 13 root servers that run the DNS. While that attack failed to take down the Internet’s DNS, it showed that DNS continues to be a target for hackers.

"DNS serving capacity is of increasing importance with the advent of increasingly deadly attacks of the distributed DoS variety," says Richard Kagan, vice president of marketing with Infoblox, which sells DNS appliances.

Whether you run your DNS systems yourself – using software or appliances – or you outsource the job to a service provider, you need to make sure that your DNS service is resilient enough to withstand today’s high-powered hacking attacks and capable enough to support new DNS-intensive applications.

Many companies, however, don’t pay enough attention to their DNS systems.

"For a lot of companies, DNS runs in a closet. It runs on old, underpowered computers and it runs on old software," says Albert Gouyet, vice president of marketing with Nominum, which sells carrier-class DNS software.

Kagan says few IT executives realize that their networks and all of their applications will cease to work if core networks services such as DNS aren’t operating.

"It’s surprising how often we go into environments with very experienced IT people who aren’t fully aware of the impact that these core services have on their applications," Kagan says. "Most organizations don’t have a disaster recovery plan for DNS."

Several trends are driving DNS traffic up dramatically for service providers and corporations:

* The amount of spam is up dramatically, which drives up e-mail volumes. Every e-mail requires a DNS look-up.

* Some types of antispam filters produce as much as 10 or 20 DNS queries for each message.

  • Share/Email
  • Comment
  • Print
Comment
Login
Forgot your account info?
Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed
Get instant email notification when white papers, webcasts, executive guides are added to our library. Stay informed and up-to-date with the latest on IT Technologies with Network World's Resource Alerts.
Network World,to go. Wherever you are. Breaking news delivered to your mobile device. Select the hottest topics in networking and start receiving Network World on your mobile device today.