Free Newsletters
InfoWorld Daily

InfoWorld
Log-in | Register
Page 2 of 2  «  Previous Page

The looming threat of pharming

 

You could eliminate this vulnerability by pulling all your DNS in-house, but opinion is divided on the wisdom of doing this. Sam Curry, vice president of eTrust security management at Computer Associates, recommends it. “Typically your ISP gets DNS information from higher up in the hierarchy, where it is much more difficult to poison the cache.” Curry argues that talking directly to the DNS top layer reduces your exposure.

Free IT resource

Hear how top CIOs turn change into a competitive advantage.

Sponsored by HP

Free IT resource

Attend the SOA Executive Forum: Breaking SOA Bottlenecks SOAExecForum.com/may2007

Sponsored by InfoWorld

Return to special report

DOWNLOAD PDF

Click here to download InfoWorld's special report Pharming: A harvest of scams


Jim Stickley, CTO and co-founder of TraceSecurity, a company that helps clients comply with strict security requirements, agrees. “If you lock down all your servers and make sure they are only pulling off root cache servers, it is going to be very difficult for a hacker to pharm you,” he says.

These root servers live at the top of the DNS hierarchy. “You can trust the root servers,” says Dan Golding, an analyst at Burton Group. “There are 13, and they are all run by various governmental, educational, and commercial entities around the world.” Moreover, VeriSign handles security for all the dot-com and dot-net root servers. Ken Silva, CSO of VeriSign, says these have never been compromised.

The trouble with the do-it-yourself approach is that locking down DNS communications all the way to the root-level servers means taking on a lot of responsibility. “You are stuck with all the maintenance and DNS can be very complex,” SANS Institute’s Ullrich says.

According to Michael Hyatt, CEO and president of BlueCat Networks, DNS is a black box that many prefer not to open. “[DNS] is arcane. Configuring BIND is not something you do with a nice GUI. You have to use an ugly, old, and unforgiving language,” he says.

BlueCat makes the Adonis 1000, a network appliance that eases the pain of DNS configuration and management and makes it more secure, while doing double duty as a DHCP server. “IT people should not have to mess with manual updates to BIND and kernel configurations,” Hyatt says. “You need a simple way to propagate DNS changes throughout your network. That is one of the things we do.”

Unbreakable DNS?

There’s an ultimate solution to DNS pharming attacks -- one that has been around for a long time. Most experts agree that DNSSEC (DNS Security), the DNS security protocol hammered out by the IETF 10 years ago, would make DNS close to bulletproof. “DNSSEC encrypts and signs DNS data,” Burton’s Golding says. “It turns a DNS server into a trusted entity.”

That’s the theory. Unfortunately, the practice has less appeal. “DNSSEC is horrendously complex,” Golding explains. “To make it work, you would need to set up a trust relationship between all DNS servers from the root to the enterprise.”

This would mean implementing a PKI on a massive scale, something not likely to happen. “DNSSEC is a great concept,” SANS Institute’s Ullrich says. “But this is not a practical solution. I tried a small-scale implementation and gave up. It is very complex.”

That leaves IT with work to do, not the least of which is getting to know DNS, which many prefer to avoid. Everyone running a DNS server should upgrade to BIND Version 9 and check the configuration of Microsoft DNS servers to ensure that some default mode has not opened up vulnerabilities. Those brave enough might want to bring DNS in-house, but, at the very least, enterprise IT needs to know what sort of DNS infrastructure their ISP is running and how to hold the ISP accountable if pharming occurs. These steps will go a long way in protecting against DNS poisoning.

The distributed structure of the Internet and the current state of DNS make it virtually impossible to stop all pharming. But Burton’s Golding says there is no need to panic. For one thing, pharming is a difficult and expensive hack. “I think the pharming attacks are being somewhat overhyped by the security vendors who want to sell products.”

On the other hand, complacency would be a mistake. “Pharming has not really taken off yet,” TraceSecurity’s Stickley says. “But I think it will for a simple reason: If you look hard enough, you can almost always find a vulnerable DNS server.”


»  Previous Page | 1 | 2 



 

TOP NEWS:


»  Four quick tips for choosing an IM security product
71 percent of businesses will invest in real-time messaging this year. If you're one of them, be sure to protect your enterprise

»  Forrester analysts ID hot IT jobs
Research group finds 16 IT roles with a promising future

»  Nvidia claims 10 hours of HD video on Tegra chip
The Tegra 600 and 650 can be used with hard disk drives and are designed partly for mobile Internet devices

»  Database vendors add Google's MapReduce
Greenplum and Aster Data Systems will support Google's programming technique, developed for parallel processing of large data sets across commodity hardware

»  Network management: Tips for managing costs
New technologies, changing requirements, and ongoing equipment maintenance and upgrades cost money, but there are ways to manage expenses

»  EMC targets SMBs, branch offices with new low-end storage
Celerra NX4 highlights include thin provisioning, snapshot technology for data recovery and backups, and Web-based console for management of storage volumes




FIVE WAYS TO REDUCE IT COSTS IN 2009
The demands on IT have never been greater, particularly in light of lower revenue and uncertain demand for the goods and services. There are many ways that IT can help organizations adjust to this new economic environment. Learn about five key technology trends that can immediately impact your organization's bottom line, and how to build a strategy to implement these technologies within your current budget. Sponsored by: Riverbed

»  Click here to view this Webcast
  Enterprise Data Security Solutions Guide
Data security used to be about outside threats. These days the biggest challenge for data-driven organizations is the management of secure information from the inside out. Data is available on laptops, your network and even USB devices, but not always secure. Read this Solutions Guide to learn the best ways to keep it safe. Sponsored by ISC2

»  Click here to download now

- Special Advertising Partners -
WHITE PAPERS
 

» Technology White Papers Library

Technology White Papers by Topic

Technology White Papers E-mail Alert

Find out when the latest white paper is available:
 
 
INFOWORLD MARKETPLACE
 
» BUY A LINK NOW
 

FIND PRODUCTS AND COMPANIES
» COMPLETE PRODUCT GUIDE



TECHNOLOGY INDEX
• Applications
• Application Development
• Security
• Networking
• Wireless
• Platforms
• Hardware
• Data Management
• Storage
• Web Services
• Business
• Telecom
• Professional Services
• Standards

TECH WATCH 


What's the 411 on GOOG-411?
Just as Google has become synonymous with "performing a Web search," 411 is understood to mean "information" -- as in "what's the 411?" I was thus surprised to discover, from a billboard, no less, that the king of search is taking on the ...

Apple HTML source reveals 'iPhone Extreme'
"This one's a stretch..." reports AppleInsider. Um, yeah. Reporting on HTML code sightings of product names could be called a stretch, but iPhone Extreme has a ring to it. Now, that sounds like the product Apple should have released first, rather ...

COLUMNISTS

Unified under law
Ephraim Schwartz's Column and Blog (InfoWorld) - In the litigious world we live in, deploying a unified communications platform in your enterprise could...
» MORE COLUMNISTS

MORE INFOWORLD BLOGS


Open Sources 
Product Management
When I joined MySQL four years ago, there was quite a lot of debate about product management. We didn't actually have ...

Zero Day 
Botnet herders tending smaller flocks
New research backs up the theory that botnet operators are keeping their networks smaller in a continued effort to keep ...



• Advice Line
• Database Underground
• The Deep End
• Enterprise Mac
• Geeks in Paradise
• Grid Meter
• The Gripe Line
• InfoWorld Daily
• Inside IT
• IT Troubleshooter
• ITXtreme
• Open Sources
• ProdBlog
• Real World SOA
• Reality Check
• Security Adviser
• SMB IT
• The Storage Network
• Tech Watch
• Virtualization Report
• Zero Day

ADVERTISEMENT


RESOURCE CENTERadvertisement 

GOVERNMENT IT & POLICY
'If you don't go after the network, you're never going to stop these guys. Never.'
From the State Department, All the News for Inquiring Minds
TechPresident, the Internet Citizenry's New Consensus Taker



Sponsored Technology Links

 
 
 HOME  NEWS  BLOGS  PODCASTS  VIDEOS  TECHNOLOGIES  TEST CENTER  EVENTS   About | Advertise | Awards | RSS | Contact Us 

Copyright © 2009, Reprints, Permissions, Licensing, IDG Network, Privacy Policy, Terms of Service.
All Rights reserved. InfoWorld is a leading publisher of technology information and product reviews on topics including viruses,
phishing, worms, firewalls, security, servers, storage, networking, wireless, databases, and web services.

CIO :: ComputerWorld :: CSO :: Demo :: GamePro :: Games.net :: IDG Connect :: IDG World Expo
Industry Standard :: IT World :: JavaWorld :: LinuxWorld :: MacUser :: Macworld :: Network World :: PC World :: Playlist
TecChannel :: TecCommunity