Design, implementation and monitoring of the firewall system for a DNS server protection

Filip Hock, Peter Kortiš · 2016

Today DNS servers run on many different applications and operating systems what means there are many options how to protect DNS server. Each regular application has implemented security mechanisms that protect the system from standard attacks. DNS service works on application layer, however it is possible to prevent many threats already on lower layers. This paper deals about DNS security mechanisms applicable on transport a network layer. The proposed protection technique is based on traffic shaping, flow filtering and prioritization. The presented experiments were performed in subarea of real campus network that is used by students and university staff. Because of implemented security mechanisms the performance of DNS service for internal users has not been affected.

Read the paper · More papers on PaperTik