Product Watch: New DNS Security Service Augments DNSSEC

Internet Identity launches DNS monitoring service for 'extended enterprise'

Dark Reading logo in a gray background | Dark Reading

Domain Name System (DNS) security is in the spotlight these days, with the last of the Internet's root servers going DNSSEC this week. And security services provider Internet Identity also launched a new DNS security monitoring service that can work alongside DNSSEC.

While DNSSEC protects caching so DNS caches can't be poisoned by attackers trying to reroute victims, ActiveTrust DNS service verifies the DNS authority's entries -- something DNSSEC assumes is legitimate even if it's really not, says Rod Rasmussen, CTO for Internet Identity. "We look at this as what's needed to make DNSSEC effective. DNSSEC is great at preventing cache poisoning...it fixes [this] when it's fully deployed, which is still a ways off," Rasmussen says.

But if an attacker alters the DNS entries, then DNSSEC can't detect that. That's where ActiveTrust comes in, he says. "It makes sure the answer you get was from the intended DNS authority," Rasmussen says. "You need reputation and trust as well. Authentication and reputation are the combination of getting close to a trustworthy DNS."

Internet Identity's new DNS service is aimed at the "extended enterprise," Rasmussen says.

The service checks DNS servers 24/7 for its clients to ensure they haven't been tampered with, compromised, or misconfigured. It supports transactions, email, and data transmission, probes the full chain of authoritative DNS servers, and checks caching nameservers at major ISPs worldwide -- all the links in the DNS chain that touch its clients' Internet operations, including those of its business partners.

"[We execute] lightweight queries so it doesn't cause a lot of traffic," Rasmussen says. The service will be priced in the low- to mid-six figures for a large installation of hundreds to thousands of business partners, he says.

"You could have the safest DNS infrastructure of your own, but there are some exposure points you can't control" with your business partners and in the Internet infrastructure, Rasmussen says.

Have a comment on this story? Please click "Discuss" below. If you'd like to contact Dark Reading's editors directly, send us a message.

Read more about:

2010

About the Author

Kelly Jackson Higgins, Editor-in-Chief, Dark Reading

Kelly Jackson Higgins is the Editor-in-Chief of Dark Reading. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise Magazine, Virginia Business magazine, and other major media properties. Jackson Higgins was recently selected as one of the Top 10 Cybersecurity Journalists in the US, and named as one of Folio's 2019 Top Women in Media. She began her career as a sports writer in the Washington, DC metropolitan area, and earned her BA at William & Mary. Follow her on Twitter @kjhiggins.

Keep up with the latest cybersecurity threats, newly discovered vulnerabilities, data breach information, and emerging trends. Delivered daily or weekly right to your email inbox.

You May Also Like


More Insights