A Solution for Packet Validity Check Against DNS Cache Poisoning

Jie Tian · Communications technology · 2010

DNS security is one of the hot issues on the Internet. In recent years, security cases caused by DNS cache poisoning turn up frequently, thus bringing much affection to the stability and reliability of the Internet. In this article, the principle of DNS cache poisoning is analyzed in depth, and a LAN-oriented solution for checking DNS packet validity is proposed. The reverse-direction checking algorithm in the new solution could, without any modification of DNS protocols, work even better in checking the validity of DNS packet. This changes the passive situation that LAN depends mainly on the reliability of higher-layer servers for preventing DNS cache poisoning.

Read the paper · More papers on PaperTik