{"product_id":"dns-security-management-isbn-9781119328278","title":"DNS Security Management","description":"\u003cp\u003e\u003cb\u003eAn advanced Domain Name System (DNS) security resource that explores the operation of DNS, its vulnerabilities, basic security approaches, and mitigation strategies  \u003c\/b\u003e\u003c\/p\u003e \u003cp\u003e\u003ci\u003eDNS Security Management\u003c\/i\u003e offers an overall role-based security approach and discusses the various threats to the Domain Name Systems (DNS). This vital resource is filled with proven strategies for detecting and mitigating these all too frequent threats. The authors—noted experts on the topic—offer an introduction to the role of DNS and explore the operation of DNS. They cover a myriad of DNS vulnerabilities and include preventative strategies that can be implemented. \u003c\/p\u003e \u003cp\u003eComprehensive in scope, the text shows how to secure DNS resolution with the Domain Name System Security Extensions (DNSSEC). In addition, the text includes discussions on security applications facility by DNS, such as anti-spam, SPF, DANE and related CERT\/SSHFP records. This important resource:\u003c\/p\u003e \u003cul\u003e \u003cli\u003ePresents security approaches for the various types of DNS deployments by role (e.g., recursive vs. authoritative)\u003c\/li\u003e \u003cli\u003eDiscusses DNS resolvers including host access protections, DHCP configurations and DNS recursive server IPs\u003c\/li\u003e \u003cli\u003eExamines DNS data collection, data analytics, and detection strategies\u003c\/li\u003e \u003c\/ul\u003e \u003cp\u003eWith cyber attacks ever on the rise worldwide, \u003ci\u003eDNS Security Management \u003c\/i\u003eoffers network engineers a much-needed resource that provides a clear understanding of the threats to networks in order to mitigate the risks and assess the strategies to defend against threats.\u003c\/p\u003e \u003cp\u003ePreface xiii\u003c\/p\u003e \u003cp\u003eAcknowledgments xvii\u003c\/p\u003e \u003cp\u003e\u003cb\u003e1 INTRODUCTION 1\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eWhy Attack DNS? 1\u003c\/p\u003e \u003cp\u003eNetwork Disruption 2\u003c\/p\u003e \u003cp\u003eDNS as a Backdoor 2\u003c\/p\u003e \u003cp\u003eDNS Basic Operation 3\u003c\/p\u003e \u003cp\u003eBasic DNS Data Sources and Flows 4\u003c\/p\u003e \u003cp\u003eDNS Trust Model 5\u003c\/p\u003e \u003cp\u003eDNS Administrator Scope 6\u003c\/p\u003e \u003cp\u003eSecurity Context and Overview 7\u003c\/p\u003e \u003cp\u003eCybersecurity Framework Overview 7\u003c\/p\u003e \u003cp\u003eFramework Implementation 9\u003c\/p\u003e \u003cp\u003eWhat’s Next 15\u003c\/p\u003e \u003cp\u003e\u003cb\u003e2 INTRODUCTION TO THE DOMAIN NAME SYSTEM (DNS) 17\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eDNS Overview – Domains and Resolution 17\u003c\/p\u003e \u003cp\u003eDomain Hierarchy 18\u003c\/p\u003e \u003cp\u003eName Resolution 18\u003c\/p\u003e \u003cp\u003eZones and Domains 23\u003c\/p\u003e \u003cp\u003eDissemination of Zone Information 25\u003c\/p\u003e \u003cp\u003eAdditional Zones 26\u003c\/p\u003e \u003cp\u003eResolver Configuration 27\u003c\/p\u003e \u003cp\u003eSummary 29\u003c\/p\u003e \u003cp\u003e\u003cb\u003e3 DNS PROTOCOL AND MESSAGES 31\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eDNS Message Format 31\u003c\/p\u003e \u003cp\u003eEncoding of Domain Names 31\u003c\/p\u003e \u003cp\u003eName Compression 32\u003c\/p\u003e \u003cp\u003eInternationalized Domain Names 34\u003c\/p\u003e \u003cp\u003eDNS Message Format 35\u003c\/p\u003e \u003cp\u003eDNS Update Messages 43\u003c\/p\u003e \u003cp\u003eThe DNS Resolution Process Revisited 48\u003c\/p\u003e \u003cp\u003eDNS Resolution Privacy Extension 55\u003c\/p\u003e \u003cp\u003eSummary 56\u003c\/p\u003e \u003cp\u003e\u003cb\u003e4 DNS VULNERABILITIES 57\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eIntroduction 57\u003c\/p\u003e \u003cp\u003eDNS Data Security 57\u003c\/p\u003e \u003cp\u003eDNS Information Trust Model 59\u003c\/p\u003e \u003cp\u003eDNS Information Sources 60\u003c\/p\u003e \u003cp\u003eDNS Risks 61\u003c\/p\u003e \u003cp\u003eDNS Infrastructure Risks and Attacks 62\u003c\/p\u003e \u003cp\u003eDNS Service Availability 62\u003c\/p\u003e \u003cp\u003eHardware\/OS Attacks 63\u003c\/p\u003e \u003cp\u003eDNS Service Denial 63\u003c\/p\u003e \u003cp\u003ePseudorandom Subdomain Attacks 67\u003c\/p\u003e \u003cp\u003eCache Poisoning Style Attacks 67\u003c\/p\u003e \u003cp\u003eAuthoritative Poisoning 71\u003c\/p\u003e \u003cp\u003eResolver Redirection Attacks 73\u003c\/p\u003e \u003cp\u003eBroader Attacks that Leverage DNS 74\u003c\/p\u003e \u003cp\u003eNetwork Reconnaissance 75\u003c\/p\u003e \u003cp\u003eDNS Rebinding Attack 77\u003c\/p\u003e \u003cp\u003eReflector Style Attacks 78\u003c\/p\u003e \u003cp\u003eData Exfiltration 79\u003c\/p\u003e \u003cp\u003eAdvanced Persistent Threats 81\u003c\/p\u003e \u003cp\u003eSummary 83\u003c\/p\u003e \u003cp\u003e\u003cb\u003e5 DNS TRUST SECTORS 85\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eIntroduction 85\u003c\/p\u003e \u003cp\u003eCybersecurity Framework Items 87\u003c\/p\u003e \u003cp\u003eIdentify 87\u003c\/p\u003e \u003cp\u003eProtect 87\u003c\/p\u003e \u003cp\u003eDetect 88\u003c\/p\u003e \u003cp\u003eDNS Trust Sectors 88\u003c\/p\u003e \u003cp\u003eExternal DNS Trust Sector 91\u003c\/p\u003e \u003cp\u003eBasic Server Configuration 93\u003c\/p\u003e \u003cp\u003eDNS Hosting of External Zones 97\u003c\/p\u003e \u003cp\u003eExternal DNS Diversity 97\u003c\/p\u003e \u003cp\u003eExtranet DNS Trust Sector 98\u003c\/p\u003e \u003cp\u003eRecursive DNS Trust Sector 99\u003c\/p\u003e \u003cp\u003eTiered Caching Servers 100\u003c\/p\u003e \u003cp\u003eBasic Server Configuration 101\u003c\/p\u003e \u003cp\u003eInternal Authoritative DNS Servers 103\u003c\/p\u003e \u003cp\u003eBasic Server Configuration 105\u003c\/p\u003e \u003cp\u003eAdditional DNS Deployment Variants 108\u003c\/p\u003e \u003cp\u003eInternal Delegation DNS Master\/Slave Servers 109\u003c\/p\u003e \u003cp\u003eMulti-Tiered Authoritative Configurations 109\u003c\/p\u003e \u003cp\u003eHybrid Authoritative\/Caching DNS Servers 111\u003c\/p\u003e \u003cp\u003eStealth Slave DNS Servers 111\u003c\/p\u003e \u003cp\u003eInternal Root Servers 111\u003c\/p\u003e \u003cp\u003eDeploying DNS Servers with Anycast Addresses 113\u003c\/p\u003e \u003cp\u003eOther Deployment Considerations 118\u003c\/p\u003e \u003cp\u003eHigh Availability 118\u003c\/p\u003e \u003cp\u003eMultiple Vendors 118\u003c\/p\u003e \u003cp\u003eSizing and Scalability 118\u003c\/p\u003e \u003cp\u003eLoad Balancers 119\u003c\/p\u003e \u003cp\u003eLab Deployment 119\u003c\/p\u003e \u003cp\u003ePutting It All Together 119\u003c\/p\u003e \u003cp\u003e\u003cb\u003e6 SECURITY FOUNDATION 121\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eIntroduction 121\u003c\/p\u003e \u003cp\u003eHardware\/Asset Related Framework Items 122\u003c\/p\u003e \u003cp\u003eIdentify: Asset Management 122\u003c\/p\u003e \u003cp\u003eIdentify: Business Environment 123\u003c\/p\u003e \u003cp\u003eIdentify: Risk Assessment 124\u003c\/p\u003e \u003cp\u003eProtect: Access Control 126\u003c\/p\u003e \u003cp\u003eProtect: Data Security 127\u003c\/p\u003e \u003cp\u003eProtect: Information Protection 129\u003c\/p\u003e \u003cp\u003eProtect: Maintenance 130\u003c\/p\u003e \u003cp\u003eDetect: Anomalies and Events 131\u003c\/p\u003e \u003cp\u003eDetect: Security Continuous Monitoring 131\u003c\/p\u003e \u003cp\u003eRespond: Analysis 132\u003c\/p\u003e \u003cp\u003eRespond: Mitigation 132\u003c\/p\u003e \u003cp\u003eRecover: Recovery Planning 133\u003c\/p\u003e \u003cp\u003eRecover: Improvements 133\u003c\/p\u003e \u003cp\u003eDNS Server Hardware Controls 134\u003c\/p\u003e \u003cp\u003eDNS Server Hardening 134\u003c\/p\u003e \u003cp\u003eAdditional DNS Server Controls 136\u003c\/p\u003e \u003cp\u003eSummary 137\u003c\/p\u003e \u003cp\u003e\u003cb\u003e7 SERVICE DENIAL ATTACKS 139\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eIntroduction 139\u003c\/p\u003e \u003cp\u003eDenial of Service Attacks 139\u003c\/p\u003e \u003cp\u003ePseudorandom Subdomain Attacks 141\u003c\/p\u003e \u003cp\u003eReflector Style Attacks 143\u003c\/p\u003e \u003cp\u003eDetecting Service Denial Attacks 144\u003c\/p\u003e \u003cp\u003eDenial of Service Protection 145\u003c\/p\u003e \u003cp\u003eDoS\/DDoS Mitigation 145\u003c\/p\u003e \u003cp\u003eBogus Queries Mitigation 147\u003c\/p\u003e \u003cp\u003ePRSD Attack Mitigation 148\u003c\/p\u003e \u003cp\u003eReflector Mitigation 148\u003c\/p\u003e \u003cp\u003eSummary 151\u003c\/p\u003e \u003cp\u003e\u003cb\u003e8 CACHE POISONING DEFENSES 153\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eIntroduction 153\u003c\/p\u003e \u003cp\u003eAttack Forms 154\u003c\/p\u003e \u003cp\u003ePacket Interception or Spoofing 154\u003c\/p\u003e \u003cp\u003eID Guessing or Query Prediction 155\u003c\/p\u003e \u003cp\u003eName Chaining 155\u003c\/p\u003e \u003cp\u003eThe Kaminsky DNS Vulnerability 156\u003c\/p\u003e \u003cp\u003eCache Poisoning Detection 159\u003c\/p\u003e \u003cp\u003eCache Poisoning Defense Mechanisms 160\u003c\/p\u003e \u003cp\u003eUDP Port Randomization 160\u003c\/p\u003e \u003cp\u003eQuery Name Case Randomization 161\u003c\/p\u003e \u003cp\u003eDNS Security Extensions 161\u003c\/p\u003e \u003cp\u003eLast Mile Protection 167\u003c\/p\u003e \u003cp\u003e\u003cb\u003e9 SECURING AUTHORITATIVE DNS DATA 169\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eIntroduction 169\u003c\/p\u003e \u003cp\u003eAttack Forms 170\u003c\/p\u003e \u003cp\u003eResolution Data at Rest 170\u003c\/p\u003e \u003cp\u003eDomain Registries 170\u003c\/p\u003e \u003cp\u003eDNS Hosting Providers 171\u003c\/p\u003e \u003cp\u003eDNS Data in Motion 172\u003c\/p\u003e \u003cp\u003eAttack Detection 172\u003c\/p\u003e \u003cp\u003eAuthoritative Data 172\u003c\/p\u003e \u003cp\u003eDomain Registry 173\u003c\/p\u003e \u003cp\u003eDomain Hosting 173\u003c\/p\u003e \u003cp\u003eFalsified Resolution 173\u003c\/p\u003e \u003cp\u003eDefense Mechanisms 174\u003c\/p\u003e \u003cp\u003eDefending DNS Data at Rest 174\u003c\/p\u003e \u003cp\u003eDefending Resolution Data in Motion with DNSSEC 176\u003c\/p\u003e \u003cp\u003eSummary 186\u003c\/p\u003e \u003cp\u003e\u003cb\u003e10 ATTACKER EXPLOITATION OF DNS 187\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eIntroduction 187\u003c\/p\u003e \u003cp\u003eNetwork Reconnaissance 187\u003c\/p\u003e \u003cp\u003eData Exfiltration 188\u003c\/p\u003e \u003cp\u003eDetecting Nefarious use of DNS 189\u003c\/p\u003e \u003cp\u003eDetecting Network Reconnaissance 189\u003c\/p\u003e \u003cp\u003eDNS Tunneling Detection 190\u003c\/p\u003e \u003cp\u003eMitigation of Illicit DNS Use 193\u003c\/p\u003e \u003cp\u003eNetwork Reconnaissance Mitigation 193\u003c\/p\u003e \u003cp\u003eMitigation of DNS Tunneling 193\u003c\/p\u003e \u003cp\u003e\u003cb\u003e11 MALWARE AND APTS 195\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eIntroduction 195\u003c\/p\u003e \u003cp\u003eMalware Proliferation Techniques 196\u003c\/p\u003e \u003cp\u003ePhishing 196\u003c\/p\u003e \u003cp\u003eSpear Phishing 196\u003c\/p\u003e \u003cp\u003eDownloads 196\u003c\/p\u003e \u003cp\u003eFile Sharing 197\u003c\/p\u003e \u003cp\u003eEmail Attachments 197\u003c\/p\u003e \u003cp\u003eWatering Hole Attack 197\u003c\/p\u003e \u003cp\u003eReplication 197\u003c\/p\u003e \u003cp\u003eImplantation 197\u003c\/p\u003e \u003cp\u003eMalware Examples 198\u003c\/p\u003e \u003cp\u003eMalware Use of DNS 198\u003c\/p\u003e \u003cp\u003eDNS Fluxing 198\u003c\/p\u003e \u003cp\u003eDynamic Domain Generation 202\u003c\/p\u003e \u003cp\u003eDetecting Malware 202\u003c\/p\u003e \u003cp\u003eDetecting Malware Using DNS Data 203\u003c\/p\u003e \u003cp\u003eMitigating Malware Using DNS 206\u003c\/p\u003e \u003cp\u003eMalware Extrication 206\u003c\/p\u003e \u003cp\u003eDNS Firewall 207\u003c\/p\u003e \u003cp\u003eSummary 210\u003c\/p\u003e \u003cp\u003e\u003cb\u003e12 DNS SECURITY STRATEGY 213\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eMajor DNS Threats and Mitigation Approaches 214\u003c\/p\u003e \u003cp\u003eCommon Controls 214\u003c\/p\u003e \u003cp\u003eDisaster Defense 214\u003c\/p\u003e \u003cp\u003eDefenses Against Human Error 220\u003c\/p\u003e \u003cp\u003eDNS Role-Specific Defenses 220\u003c\/p\u003e \u003cp\u003eStub Resolvers 220\u003c\/p\u003e \u003cp\u003eForwarder DNS Servers 221\u003c\/p\u003e \u003cp\u003eRecursive Servers 221\u003c\/p\u003e \u003cp\u003eAuthoritative Servers 222\u003c\/p\u003e \u003cp\u003eBroader Security Strategy 222\u003c\/p\u003e \u003cp\u003eIdentify Function 223\u003c\/p\u003e \u003cp\u003eProtect Function 224\u003c\/p\u003e \u003cp\u003eDetect Function 225\u003c\/p\u003e \u003cp\u003eRespond Function 226\u003c\/p\u003e \u003cp\u003eRecover Function 227\u003c\/p\u003e \u003cp\u003e\u003cb\u003e13 DNS APPLICATIONS TO IMPROVE NETWORK SECURITY 229\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eSafer Web Browsing 230\u003c\/p\u003e \u003cp\u003eDNS-Based Authentication of Named Entities (DANE) 230\u003c\/p\u003e \u003cp\u003eEmail Security 232\u003c\/p\u003e \u003cp\u003eEmail and DNS 233\u003c\/p\u003e \u003cp\u003eDNS Block Listing 237\u003c\/p\u003e \u003cp\u003eSender Policy Framework (SPF) 238\u003c\/p\u003e \u003cp\u003eDomain Keys Identified Mail (DKIM) 242\u003c\/p\u003e \u003cp\u003eDomain-Based Message Authentication, Reporting, and\u003c\/p\u003e \u003cp\u003eConformance (DMARC) 245\u003c\/p\u003e \u003cp\u003eSecuring Automated Information Exchanges 246\u003c\/p\u003e \u003cp\u003eDynamic DNS Update Uniqueness Validation 246\u003c\/p\u003e \u003cp\u003eStoring Security-Related Information 247\u003c\/p\u003e \u003cp\u003eOther Security Oriented DNS Resource Record Types 247\u003c\/p\u003e \u003cp\u003eSummary 251\u003c\/p\u003e \u003cp\u003e\u003cb\u003e14 DNS SECURITY EVOLUTION 253\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eAppendix A: Cybersecurity Framework Core DNS Example 257\u003c\/p\u003e \u003cp\u003eAppendix B: DNS Resource Record Types 285\u003c\/p\u003e \u003cp\u003eBibliography 291\u003c\/p\u003e \u003cp\u003eIndex 299\u003c\/p\u003e \u003cp\u003e \u003c\/p\u003e   \u003cp\u003e\u003cstrong\u003eMichael Dooley\u003c\/strong\u003e is responsible for overall operations of the BT Diamond IP division. Mr. Dooley has more than 20 years of experience managing and developing large scale software products and has contributed significantly to the evolution of Internet technologies, particularly related to IP addressing, DHCP and DNS. In 2013 he co-authored the Wiley-IEEE Press title \u003cem\u003eIPv6 Deployment and Management.\u003c\/em\u003e \u003c\/p\u003e\u003cp\u003e\u003cstrong\u003eTimothy Rooney\u003c\/strong\u003e manages BT Diamond IP product development and has led the market introduction of four next-generation IP management systems: NetControl, IPControl, Sapphire appliances and ImageControl. In 2010, he authored the Wiley-IEEE Press title \u003cem\u003eIntroduction to IP Address Management\u003c\/em\u003e and in 2011, \u003cem\u003eIP Address Management Principles and Practice.\u003c\/em\u003e In 2013 Mr. Rooney co-authored the Wiley-IEEE Press title \u003cem\u003eIPv6 Deployment and Management.\u003c\/em\u003e \u003c\/p\u003e\u003cp\u003e     \u003c\/p\u003e\u003cp\u003e\u003cb\u003eAn advanced Domain Name System (DNS) security resource that explores the operation of DNS, its vulnerabilities, basic security approaches, and mitigation strategies\u003c\/b\u003e  \u003c\/p\u003e\u003cp\u003e\u003ci\u003eDNS Security Management\u003c\/i\u003e offers an overall role-based security approach and discusses the various threats to the Domain Name Systems (DNS). This vital resource is filled with proven strategies for detecting and mitigating these all too frequent threats. The authors—noted experts on the topic—offer an introduction to the role of DNS and explore the operation of DNS. They cover a myriad of DNS vulnerabilities and include preventative strategies that can be implemented.   \u003c\/p\u003e\u003cp\u003e Comprehensive in scope, the text shows how to secure DNS resolution with the Domain Name System Security Extensions (DNSSEC), DNS firewall, server controls, and much more. In addition, the text includes discussions on security applications facilitated by DNS, such as anti-spam, SFP, and DANE. This important resource:  \u003c\/p\u003e\u003cul\u003e \u003cli\u003ePresents security approaches for the various types of DNS deployments by role (e.g., recursive vs. authoritative)\u003c\/li\u003e \u003cli\u003eDiscusses example configurations for leading DNS implementations to illustrate security controls\u003c\/li\u003e \u003cli\u003eExamines DNS data collection, incident detection, and data analytics strategies\u003c\/li\u003e \u003c\/ul\u003e \u003cbr\u003e  \u003cp\u003e With cyber attacks ever on the rise worldwide, \u003cem\u003eDNS Security Management\u003c\/em\u003e offers network engineers a much-needed resource that provides a clear understanding of the threats to networks in order to mitigate the risks and assess the strategies to defend against threats.\u003c\/p\u003e","brand":"Wiley-IEEE Press","offers":[{"title":"Default Title","offer_id":47989079965925,"sku":"NP9781119328278","price":117.95,"currency_code":"USD","in_stock":false}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/1842\/7735\/files\/9781119328278.jpg?v=1761782713","url":"https:\/\/k12savings.com\/es\/products\/dns-security-management-isbn-9781119328278","provider":"K12savings","version":"1.0","type":"link"}