Many security experts, including Dan Kaminsky, Director of Penetration Testing
at IOActive, consider DNS Security Extensions (DNSSEC) to be an essential tool
in “sealing” DNS vulnerabilities and mitigating DNS cache poisoning attacks that
undermine the integrity of the DNS system. DNS attackers are able to direct
users to alternate sites enabling collection of credit cards and passwords, redirect
e-mail, and compromise any other Internet application that is dependent on DNS.
DNSSEC implements an automated trust infrastructure enabling systems to verify
the authenticity of DNS information.
Unfortunately, DNSSEC adoption has been hampered by concerns over the
operational complexity of provisioning encryption keys and the processing overhead
required to sign DNS information. Prior to F5’s innovative real-time signing capability,
there were no options to secure the DNS responses from a global server load
balancing system (GSLB). Organizations had to choose between deploying highly
available intelligent DNS systems or securing their DNS infrastructure with DNSSEC.
The combined F5 and Infoblox solution addresses these issues with complementary
solutions, bringing to market a fully integrated and complete DNSSEC solution
including high performance DNS and GSLB functions, all supporting, signed DNSSEC
5
“The lack of DNS security not only
makes the Internet vulnerable, but
is also crippling the scalability of
important security technologies.
DNSSEC offers the most feasible
solution to a serious threat.”
Dan Kaminsky, Director of
Penetration Testing, IOActive
Technical Brief
F5 and Infoblox DNS Integrated Architecture: Offering a Complete Scalable, Secure DNS Solution