DNS Applications to Improve Network Security
2017
This chapter discusses some of the ways domain name system (DNS) can be used to help improve the overall network security. Numerous applications are enhanced with DNS, and the chapter discusses security applications where DNS plays a key role. DNS can facilitate safer web browsing by enabling website publishers to post information about their Transaction Layer Security (TLS) credentials, used to authenticate and encrypt "secure HTTP" traffic. The DNS-based Authentication of Named Entities (DANE) protocol (80, 81) enables access to a website publisher's certificate or certificate authority (CA) information to protect against spoofed certificates or CAs, which can lead to website hijacking unbeknownst to the user/browser. The Sender Policy Framework (SPF) is currently defined in RFC 7208 (89). The SPF attempts to provide validation of what hosts are configured to send email for a given domain. Domain keys identified mail (DKIM) supports data origin authentication and data integrity verification through the use of digital signatures.