Skip to main navigation Skip to search Skip to main content

A performance view on DNSSEC migration

  • Orange Labs

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

In July 2008, the Kaminsky attack showed that DNS is sensitive to cache poisoning, and DNSSEC is considered the long term solution to mitigate this attack. A lot of technical documents provide configuration and security guide lines to deploy DNSSEC on organization's servers. However, such documents do not provide ISP or network administrators inputs to plan or evaluate the cost of the migration. This paper describes current deployment of DNSSEC and provides key elements to consider when planning DNSSEC deployment. Then we focus our work on performance aspects and provide experimental measurements for both DNS and DNSSEC architecture. Experimental results evaluate the cost of DNSSEC for authoritative and recursive server with different implementations.

Original languageEnglish
Title of host publicationProceedings of the 2010 International Conference on Network and Service Management, CNSM 2010
Pages469-474
Number of pages6
DOIs
Publication statusPublished - 1 Dec 2010
Event2010 International Conference on Network and Service Management, CNSM 2010 - Niagara Falls, ON, Canada
Duration: 25 Oct 201029 Oct 2010

Publication series

NameProceedings of the 2010 International Conference on Network and Service Management, CNSM 2010

Conference

Conference2010 International Conference on Network and Service Management, CNSM 2010
Country/TerritoryCanada
CityNiagara Falls, ON
Period25/10/1029/10/10

Keywords

  • DNS
  • DNSSEC
  • Migration
  • Performance

Fingerprint

Dive into the research topics of 'A performance view on DNSSEC migration'. Together they form a unique fingerprint.

Cite this