Threat Analysis of the Domain Name System
RFC 3833, “Threat Analysis of the Domain Name System”, is an Informational document published in August 2004 by D. Atkins, R. Austein. The canonical text is published by the RFC Editor.
Abstract
Although the DNS Security Extensions (DNSSEC) have been under development for most of the last decade, the IETF has never written down the specific set of threats against which DNSSEC is designed to protect. Among other drawbacks, this cart-before-the-horse situation has made it difficult to determine whether DNSSEC meets its design goals, since its design goals are not well specified. This note attempts to document some of the known threats to the DNS, and, in doing so, attempts to measure to what extent (if any) DNSSEC is a useful tool in defending against these threats. This memo provides information for the Internet community.
What “Informational” means
Published for the general information of the community. It does not define an IETF standard and carries no standards-track status.
The canonical text of RFC 3833 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 3832 Remote Service Discovery in the Service Location Protocol via DNS SRV
- RFC 3834 Recommendations for Automatic Responses to Electronic Mail
- RFC 3831 Transmission of IPv6 Packets over Fibre Channel
- RFC 3835 An Architecture for Open Pluggable Edge Services
- RFC 3830 MIKEY: Multimedia Internet KEYing
- RFC 3836 Requirements for Open Pluggable Edge Services Callout Protocols
- RFC 3829 Lightweight Directory Access Protocol Authorization Identity Request and Response Controls
- RFC 3837 Security Threats and Risks for Open Pluggable Edge Services