Threat of DDoS attacks rises significantly as Microsoft DNS Server use diminishes and DNSSEC adoption grows.
The Measurement Factory’s fifth annual DNS Survey results show an increasing number of name servers on the Internet that are vulnerable to distributed denial of service attacks.
Recent survey results show that DNS configuration and related security practices continue to represent a mixed bag for enterprise IT managers, with certain threats diminishing and others gaining considerable steam.
DNS problem linked to DDoS attacks get worse
DNS flaw-fixed hype addressed
Infoblox, a DNS, DHCP and IP address management appliance maker, works in conjunction with performance testing group The Measurement Factory to determine the security of domain name servers on the public Internet and analyze the practices used to secure DNS systems. Results of the fifth annual DNS Survey show that enterprise IT organizations have heeded the warnings around certain practices associated with DNS, but other threats existing on name servers increased this year.
“Of particular interest is the enormous growth in the number of Internet-connected name servers, largely attributable to the introduction by carriers of customer premises equipment (CPE) with embedded DNS functionality,” said Cricket Liu, vice president of architecture at Infoblox, in a statement. “This equipment represents a significant risk to the rest of the Internet, as without proper access controls, it facilitates enormous DDoS attacks.”
According to the results, 79.6% of the name servers in the random sample were open to recursion, up from 52.1% in 2007. Servers open to recursion are vulnerable to distributed denial of services, or DDoS attacks, Infoblox reports. The company suggests that carriers ensure default configuration and security features on CPE devices prevent this recursion vulnerability. And customers should request adequate security features on such devices and require carriers provide the equipment with secure default configurations.
Other steps enterprise IT managers can take to better secure their DNS servers include upgrading to the most recent version of BIND, choosing separate internal and external name servers, and selecting authoritative and recursive name servers. Other precautions include selecting DNS-related products that perform port randomization to protect again the Kaminsky cache poisoning vulnerability, Infoblox concludes.
This year’s survey also pointed to some positive news, according to Infoblox. For one, the number of Microsoft DNS Servers detected in the random sample was considered “negligible” – down to .37% from 2.74% in 2007, the survey reports. This shows that awareness of the risk of exposing Windows computers to the Internet has significantly risen, Infoblox says. And also positive is the growing number DNSSEC signed zones has increased by 300%.
“I am pleased to see the adoption of DNSSEC accelerating and I hope to see this number increase substantially in the next year as more top-level zones are signed and as simplified solutions help automate management of signed zones,” Liu added.
Interested in freeware and shareware, open source applications and scaled-down versions of commercial software and services? Network World devotes an online forum of free techie stuff. Let me know what you find, what you want to hear more about and what invaluable tools that didn’t cost you a thing at ddubie@nww.com.
Do you Tweet? Follow Denise Dubie on Twitter here.




