论文部分内容阅读
域名系统安全是互联网技术的热点之一。近一段时期,由DNS缓存中毒引起的安全案例时有发生,严重影响了互联网的安全性和可靠性。深入分析了缓存中毒的实现机理,提出了一套面向局域网的DNS报文合法性校验方案。新方案中所设计的逆向校验算法,在不必修改DNS协议的前提下,增强了对DNS报文合法性的鉴别能力,改变了底层局域网络只能依靠上层服务器可靠性来预防缓存中毒攻击的被动局面。
Domain name system security is one of the hot spots of Internet technology. In recent times, security cases caused by DNS cache poisoning have occurred, seriously affecting the security and reliability of the Internet. In-depth analysis of the mechanism of cache poisoning, put forward a set of DNS packet legitimacy verification scheme for LAN. The reverse verification algorithm designed in the new scheme enhances the ability to authenticate the validity of DNS packets without modifying the DNS protocol and changes the way that the underlying local network can only rely on the reliability of the upper server to prevent cache poisoning attacks Passive situation.