| 講演抄録/キーワード |
| 講演名 |
2016-01-21 14:15
DNSキャッシュ汚染対策の一方法とその実装 ○湯藤大介・山内雪路(阪工大) NS2015-150 |
| 抄録 |
(和) |
DNSキャッシュシステムにはカミンスキーアタックをはじめとして多数の脆弱性が指摘されている。本論文ではカミンスキーアタックに対する新たな対処方法として、権威DNSサーバから受け取った1度目の問い合わせ結果についてはキャッシュを行わず検証データとしてデータベースなどに保存し、同じドメイン名に対する2度目以降の結果と検証データを比較し、複数回一致した結果をキャッシュすることでキャッシュ汚染率を低減させる方法を提案する。その結果キャッシュ汚染攻撃に対する脆弱性を飛躍的に低減できることを示し、併せてこの方式の採用により生じる問い合わせ負荷の増加量について考察した。 |
| (英) |
Numerous vulnerabilities have been found to the DNS systems and protocols especially since the method of “Kaminsky Attack”, an effective way for DNS cache poisoning, has been disclosed. Multiple solutions has proposed and implemented against the DNS cache poisoning attacks so far.
This paper deals with yet another method to reduce the possibility of cache poisonings including the Kaminsky Attacks. Proposed DNS cache server compares the resolved answer with the previously answered and stored data within the database. In case the resolved record differs from the database due to the DNS round robin, most frequently resolved record is use as the active cached data. System compatibility, server CPU loads, and DNS traffic considerations are also discussed. |
| キーワード |
(和) |
DNS / DNS cache poisoning / / / / / / |
| (英) |
DNS / DNS cache poisoning / / / / / / |
| 文献情報 |
信学技報, vol. 115, no. 404, NS2015-150, pp. 23-27, 2016年1月. |
| 資料番号 |
NS2015-150 |
| 発行日 |
2016-01-14 (NS) |
| ISSN |
Print edition: ISSN 0913-5685 Online edition: ISSN 2432-6380 |
著作権に ついて |
技術研究報告に掲載された論文の著作権は電子情報通信学会に帰属します.(許諾番号:10GA0019/12GB0052/13GB0056/17GB0034/18GB0034) |
| PDFダウンロード |
NS2015-150 |