论文标题

域名系统安全和隐私:当代调查

Domain Name System Security and Privacy: A Contemporary Survey

论文作者

Khormali, Aminollah, Park, Jeman, Alasmary, Hisham, Anwar, Afsah, Mohaisen, David

论文摘要

域名系统(DNS)是当今Internet的最重要组成部分之一,是人类可读域名和Internet资源的机器可读IP地址之间的标准命名约定。但是,由于DNS对各种威胁的脆弱性,随着时间的流逝,其安全性和功能性一直受到挑战。尽管研究人员已经解决了文献中DN的各个方面,但仍有许多挑战要解决。为了全面了解DNS脆弱性的根本原因,必须审查研究界在DNS景观方面的各种活动。为此,本文调查了超过170份同行评审的论文,这些论文在过去十年中发表在顶级会议和期刊上,并总结了DNS和相应的对策中的脆弱性。本文不仅关注DNS威胁格局和现有挑战,而且还讨论了使用的数据分析方法,这些方法经常用于解决DNS威胁漏洞。此外,我们从DNS基础架构中所涉及的实体的角度来研究了DNSthreat景观,以指出系统中更脆弱的实体。

The domain name system (DNS) is one of the most important components of today's Internet, and is the standard naming convention between human-readable domain names and machine-routable IP addresses of Internet resources. However, due to the vulnerability of DNS to various threats, its security and functionality have been continuously challenged over the course of time. Although, researchers have addressed various aspects of the DNS in the literature, there are still many challenges yet to be addressed. In order to comprehensively understand the root causes of the vulnerabilities of DNS, it is mandatory to review the various activities in the research community on DNS landscape. To this end, this paper surveys more than 170 peer-reviewed papers, which are published in both top conferences and journals in the last ten years, and summarizes vulnerabilities in DNS and corresponding countermeasures. This paper not only focuses on the DNS threat landscape and existing challenges, but also discusses the utilized data analysis methods, which are frequently used to address DNS threat vulnerabilities. Furthermore, we looked into the DNSthreat landscape from the viewpoint of the involved entities in the DNS infrastructure in an attempt to point out more vulnerable entities in the system.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源