{"id":82,"date":"2013-04-15T18:17:58","date_gmt":"2013-04-15T09:17:58","guid":{"rendered":"http:\/\/dnssec.sekiya-lab.info\/?page_id=82"},"modified":"2013-04-15T23:17:55","modified_gmt":"2013-04-15T14:17:55","slug":"dnssec","status":"publish","type":"page","link":"https:\/\/dnssec.sekiya-lab.info\/?page_id=82","title":{"rendered":"DNSSEC"},"content":{"rendered":"<h1><strong><span style=\"color: #0000ff;\">What is DNSSEC ?<\/span><\/strong><\/h1>\n<p>DNS Security Extensions (DNSSEC) is a security enhancement of Domain Name System. DNSSEC is designed to protect the name lookups from attacks such as DNS cache poisoning and spoofing. DNSSEC ensures<\/p>\n<ol>\n<li>origin of DNS data and<\/li>\n<li>data integrity.<\/li>\n<\/ol>\n<p>If there is no DNSSEC, attackers can spoof DNS queries and victims may leadto incorrect sites.<\/p>\n<p><a href=\"http:\/\/dnssec.sekiya-lab.info\/wp-uploads\/2013\/04\/dnssec1.png\"><img loading=\"lazy\" class=\"aligncenter\" title=\"Introduction of DNSSEC\" src=\"http:\/\/dnssec.sekiya-lab.info\/wp-uploads\/2013\/04\/dnssec1-300x191.png\" alt=\"\" width=\"300\" height=\"191\" \/><\/a><\/p>\n<p>DNSSEC ensures the integrity of DNS database and DNS database has a tree structure, so the trust chains between zones are required for DNSSEC. A parent-zone trusts its child zones and signs the keys.<\/p>\n<p><a href=\"http:\/\/dnssec.sekiya-lab.info\/wp-uploads\/2013\/04\/dnssec2.png\"><img loading=\"lazy\" class=\"size-medium wp-image-86 aligncenter\" title=\"Tree structure of DNS database\" src=\"http:\/\/dnssec.sekiya-lab.info\/wp-uploads\/2013\/04\/dnssec2-300x225.png\" alt=\"\" width=\"300\" height=\"225\" srcset=\"https:\/\/dnssec.sekiya-lab.info\/wp-uploads\/2013\/04\/dnssec2-300x225.png 300w, https:\/\/dnssec.sekiya-lab.info\/wp-uploads\/2013\/04\/dnssec2.png 720w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>If administrators can create and maintain the correct trust chains of DNSSEC, users are protected by spoofing.<\/p>\n<p>However, there are some concerns deploying DNSSEC. DNSSEC requires more traffic bandwidth to exchange information between a DNS server and users, and DNS servers. Moreover, resolver DNS servers with DNSSEC are required more computing resources than non \u00c2\u00a0DNSSEC resolver servers to validate the DNSSEC signatures.<\/p>\n<p style=\"text-align: center;\"><a href=\"http:\/\/dnssec.sekiya-lab.info\/wp-uploads\/2013\/04\/dnssec3.png\"><img loading=\"lazy\" class=\"alignnone size-medium wp-image-89\" title=\"Concerns with DNSSEC\" src=\"http:\/\/dnssec.sekiya-lab.info\/wp-uploads\/2013\/04\/dnssec3-300x225.png\" alt=\"\" width=\"300\" height=\"225\" srcset=\"https:\/\/dnssec.sekiya-lab.info\/wp-uploads\/2013\/04\/dnssec3-300x225.png 300w, https:\/\/dnssec.sekiya-lab.info\/wp-uploads\/2013\/04\/dnssec3.png 720w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p style=\"text-align: left;\">In order to evaluate the impacts of introducing DNSSEC into the existing DNS environments, simulation and evaluation tool for DNSSEC is needed. We would like to develop the simulation tools and provide them freely for DNS administrators and operators.<\/p>\n<p style=\"text-align: left;\">\n","protected":false},"excerpt":{"rendered":"<p>What is DNSSEC ? DNS Security Extensions (DNSSEC) is a security enhancement of Domain Name System. DNSSEC is designed to protect the name lookups from attacks such as DNS cache&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"open","template":"","meta":[],"_links":{"self":[{"href":"https:\/\/dnssec.sekiya-lab.info\/index.php?rest_route=\/wp\/v2\/pages\/82"}],"collection":[{"href":"https:\/\/dnssec.sekiya-lab.info\/index.php?rest_route=\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/dnssec.sekiya-lab.info\/index.php?rest_route=\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/dnssec.sekiya-lab.info\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/dnssec.sekiya-lab.info\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=82"}],"version-history":[{"count":5,"href":"https:\/\/dnssec.sekiya-lab.info\/index.php?rest_route=\/wp\/v2\/pages\/82\/revisions"}],"predecessor-version":[{"id":85,"href":"https:\/\/dnssec.sekiya-lab.info\/index.php?rest_route=\/wp\/v2\/pages\/82\/revisions\/85"}],"wp:attachment":[{"href":"https:\/\/dnssec.sekiya-lab.info\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=82"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}