2 cissp ® Official Study Guide Eighth Edition



Download 19,3 Mb.
Pdf ko'rish
bet436/881
Sana08.04.2023
Hajmi19,3 Mb.
#925879
1   ...   432   433   434   435   436   437   438   439   ...   881
Bog'liq
(CISSP) Mike Chapple, James Michael Stewart, Darril Gibson - CISSP Official Study Guide-Sybex (2018)

Record
Type
Description
A
Address record
Links an FQDN to an IPv4 address
AAAA
Address record
Links an FQDN to an IPv6 address
PTR
Pointer record
Links an IP address to a FQDN (for reverse 
lookups)
CNAME
Canonical name
Links an FQDN alias to another FQDN
MX
Mail exchange
Links a mail- and messaging-related FQDN to 
an IP address
NS
Name server record
Designates the FQDN and IP address of an 
authorized name server
SOA
Start of authority record
Specifies authoritative information about the 
zone file, such as primary name server, serial 
number, time-outs, and refresh intervals


468
Chapter 11 

Secure Network Architecture and Securing Network Components
Originally, DNS was handled by a static local file known as the 
HOSTS file
. This file 
still exists, but a dynamic DNS query system has mostly replaced it, especially for large pri-
vate networks as well as the internet. When client software points to an FQDN, the proto-
col stack initiates a DNS query in order to resolve the name into an IP address that can be 
used in the construction of the IP header. The resolution process first checks the local DNS 
cache to see whether the answer is already known. The DNS cache consists of preloaded 
content from the local HOSTS file plus any DNS queries performed during the current boot 
session (that haven’t timed out). If the needed answer isn’t in the cache, a DNS query is 
sent to the DNS server indicated in the local IP configuration. The process of resolving the 
query is interesting and complex, but most of it isn’t relevant to the (ISC)
2
CISSP exam.
DNS operates over TCP and UDP port 53. TCP port 53 is used for zone transfers. 
These are zone file exchanges between DNS servers, for special manual queries, or when a 
response exceeds 512 bytes. UDP port 53 is used for most typical DNS queries.
Domain Name System Security Extensions (DNSSEC) 
is a security improvement to the 
existing DNS infrastructure. The primary function of DNSSEC is to provide reliable authen-
tication between devices during DNS operations. DNSSEC has been implemented across a 
significant portion of the DNS system. Each DNS server is issued a digital certificate, which 
is then used to perform mutual certificate authentication. The goal of DNSSEC is to prevent 
a range of DNS abuses where false data can be injected into the resolution process. Once 
fully implemented, DNSSEC will significantly reduce server-focused DNS abuses.
Further reading on dNS
For an excellent primer to advanced discussion on DNS, its operation, known issues, and 
the Dan Kaminsky vulnerability, please visit “An Illustrated Guide to the Kaminsky DNS 
Vulnerability”:
http://unixwiz.net/techtips/iguide-kaminsky-dns-vuln.html
For a look into the future of DNS, specifically the defense against the Kaminsky vulner-
ability, visit 
www.dnssec.net
.
DNS Poisoning
DNS poisoning
is the act of falsifying the DNS information used by a client to reach a 
desired system. It can take place in many ways. Whenever a client needs to resolve a DNS 
name into an IP address, it may go through the following process:

Download 19,3 Mb.

Do'stlaringiz bilan baham:
1   ...   432   433   434   435   436   437   438   439   ...   881




Ma'lumotlar bazasi mualliflik huquqi bilan himoyalangan ©hozir.org 2024
ma'muriyatiga murojaat qiling

kiriting | ro'yxatdan o'tish
    Bosh sahifa
юртда тантана
Боғда битган
Бугун юртда
Эшитганлар жилманглар
Эшитмадим деманглар
битган бодомлар
Yangiariq tumani
qitish marakazi
Raqamli texnologiyalar
ilishida muhokamadan
tasdiqqa tavsiya
tavsiya etilgan
iqtisodiyot kafedrasi
steiermarkischen landesregierung
asarlaringizni yuboring
o'zingizning asarlaringizni
Iltimos faqat
faqat o'zingizning
steierm rkischen
landesregierung fachabteilung
rkischen landesregierung
hamshira loyihasi
loyihasi mavsum
faolyatining oqibatlari
asosiy adabiyotlar
fakulteti ahborot
ahborot havfsizligi
havfsizligi kafedrasi
fanidan bo’yicha
fakulteti iqtisodiyot
boshqaruv fakulteti
chiqarishda boshqaruv
ishlab chiqarishda
iqtisodiyot fakultet
multiservis tarmoqlari
fanidan asosiy
Uzbek fanidan
mavzulari potok
asosidagi multiservis
'aliyyil a'ziym
billahil 'aliyyil
illaa billahil
quvvata illaa
falah' deganida
Kompyuter savodxonligi
bo’yicha mustaqil
'alal falah'
Hayya 'alal
'alas soloh
Hayya 'alas
mavsum boyicha


yuklab olish