• Fri frakt över 249 kr
  • •
  • Snabba leveranser
  • •
  • Billiga böcker
Kundservice

Du är på sajten för privatpersoner.

Företag, bibliotek eller offentlig verksamhet?

Du handlar på classic.bokus.com, där alla dina funktioner finns intakta.
Till classic.bokus.com
Bokus logotyp. Gå till startsidan.
  • Erbjudanden
  • Nyheter
  • Student
  • Topplistor
  • Barn & ungdom
  • Bokus Play
  • E-böcker
  • Pocketböcker
  • Spel & pussel

10% rabatt på allt med kod: NYSTART10 →

Sidfot

Mina sidor

    Hjälp

    • Kundservice
    • Vanliga frågor och svar
    • Frakt och leverans
    • Retur vid ångerrätt
    • Reklamera vara
    • Betalning
    • Köpvillkor
    • Allmänna villkor
    • Information om webbplatsens tillgänglighet

    Om Bokus

    • Om oss
    • Pressrum
    • För studenter
    • För företag
    • För bibliotek och offentlig verksamhet
    • För leverantörer
    • Hållbarhet

    Populärt

    • Aktuella erbjudanden
    • Presentkort
    • Studentlitteratur
    • Nya böcker
    • Topplistor
    • Signerade böcker
    • Engelska böcker

    Inspiration

    • Boktips
    • BookTok
    • Populära bokserier
    • Barnbokskaraktärer
    • Populära författare
    Logotyp för Bokus
    Följ oss på Facebook (extern länk)Följ oss på Instagram (extern länk)Följ oss på YouTube (extern länk)Följ oss på TikTok (extern länk)
    bokus @ CookiesAnpassa cookiesIntegritetspolicyKöpvillkor
    Till Citymail hemsida (extern länk)Till Budbee hemsida (extern länk)Till Postnord hemsida (extern länk)Till Schenker hemsida (extern länk)Till Early Bird hemsida (extern länk)Till Walleys hemsida (extern länk)
    1. Data och IT
    2. Nätverk och kommunikation

    DNS Security Management

    AvMichael Dooley,Timothy Rooney

    Inbunden, Engelska, 2017

    Del i serien IEEE Press Series on Network and Service Management

    1 266 kr

    Beställningsvara. Skickas inom 5-8 vardagar. Fri frakt över 249 kr.

    Beskrivning

    An advanced Domain Name System (DNS) security resource that explores the operation of DNS, its vulnerabilities, basic security approaches, and mitigation strategies  DNS Security Management offers an overall role-based security approach and discusses the various threats to the Domain Name Systems (DNS). This vital resource is filled with proven strategies for detecting and mitigating these all too frequent threats. The authors—noted experts on the topic—offer an introduction to the role of DNS and explore the operation of DNS. They cover a myriad of DNS vulnerabilities and include preventative strategies that can be implemented. Comprehensive in scope, the text shows how to secure DNS resolution with the Domain Name System Security Extensions (DNSSEC). In addition, the text includes discussions on security applications facility by DNS, such as anti-spam, SPF, DANE and related CERT/SSHFP records. This important resource: Presents security approaches for the various types of DNS deployments by role (e.g., recursive vs. authoritative)Discusses DNS resolvers including host access protections, DHCP configurations and DNS recursive server IPsExamines DNS data collection, data analytics, and detection strategiesWith cyber attacks ever on the rise worldwide, DNS Security Management offers network engineers a much-needed resource that provides a clear understanding of the threats to networks in order to mitigate the risks and assess the strategies to defend against threats.

    Produktinformation

    • Utgivningsdatum:2017-10-03
    • Mått:152 x 231 x 23 mm
    • Vikt:590 g
    • Format:Inbunden
    • Språk:Engelska
    • Serie:IEEE Press Series on Network and Service Management
    • Antal sidor:324
    • Förlag:John Wiley & Sons Inc
    • ISBN:9781119328278

    Utforska kategorier

    • Nätverk och kommunikation inom Data och IT
    • IT-säkerhet inom Data och IT

    Mer om författaren

    Michael Dooley is responsible for overall operations of the BT Diamond IP division. Mr. Dooley has more than 20 years of experience managing and developing large scale software products and has contributed significantly to the evolution of Internet technologies, particularly related to IP addressing, DHCP and DNS. In 2013 he co-authored the Wiley-IEEE Press title IPv6 Deployment and Management. Timothy Rooney manages BT Diamond IP product development and has led the market introduction of four next-generation IP management systems: NetControl, IPControl, Sapphire appliances and ImageControl. In 2010, he authored the Wiley-IEEE Press title Introduction to IP Address Management and in 2011, IP Address Management Principles and Practice. In 2013 Mr. Rooney co-authored the Wiley-IEEE Press title IPv6 Deployment and Management.

    Innehållsförteckning

    • Preface xiiiAcknowledgments xvii1 INTRODUCTION 1Why Attack DNS? 1Network Disruption 2DNS as a Backdoor 2DNS Basic Operation 3Basic DNS Data Sources and Flows 4DNS Trust Model 5DNS Administrator Scope 6Security Context and Overview 7Cybersecurity Framework Overview 7Framework Implementation 9What’s Next 152 INTRODUCTION TO THE DOMAIN NAME SYSTEM (DNS) 17DNS Overview – Domains and Resolution 17Domain Hierarchy 18Name Resolution 18Zones and Domains 23Dissemination of Zone Information 25Additional Zones 26Resolver Configuration 27Summary 293 DNS PROTOCOL AND MESSAGES 31DNS Message Format 31Encoding of Domain Names 31Name Compression 32Internationalized Domain Names 34DNS Message Format 35DNS Update Messages 43The DNS Resolution Process Revisited 48DNS Resolution Privacy Extension 55Summary 564 DNS VULNERABILITIES 57Introduction 57DNS Data Security 57DNS Information Trust Model 59DNS Information Sources 60DNS Risks 61DNS Infrastructure Risks and Attacks 62DNS Service Availability 62Hardware/OS Attacks 63DNS Service Denial 63Pseudorandom Subdomain Attacks 67Cache Poisoning Style Attacks 67Authoritative Poisoning 71Resolver Redirection Attacks 73Broader Attacks that Leverage DNS 74Network Reconnaissance 75DNS Rebinding Attack 77Reflector Style Attacks 78Data Exfiltration 79Advanced Persistent Threats 81Summary 835 DNS TRUST SECTORS 85Introduction 85Cybersecurity Framework Items 87Identify 87Protect 87Detect 88DNS Trust Sectors 88External DNS Trust Sector 91Basic Server Configuration 93DNS Hosting of External Zones 97External DNS Diversity 97Extranet DNS Trust Sector 98Recursive DNS Trust Sector 99Tiered Caching Servers 100Basic Server Configuration 101Internal Authoritative DNS Servers 103Basic Server Configuration 105Additional DNS Deployment Variants 108Internal Delegation DNS Master/Slave Servers 109Multi-Tiered Authoritative Configurations 109Hybrid Authoritative/Caching DNS Servers 111Stealth Slave DNS Servers 111Internal Root Servers 111Deploying DNS Servers with Anycast Addresses 113Other Deployment Considerations 118High Availability 118Multiple Vendors 118Sizing and Scalability 118Load Balancers 119Lab Deployment 119Putting It All Together 1196 SECURITY FOUNDATION 121Introduction 121Hardware/Asset Related Framework Items 122Identify: Asset Management 122Identify: Business Environment 123Identify: Risk Assessment 124Protect: Access Control 126Protect: Data Security 127Protect: Information Protection 129Protect: Maintenance 130Detect: Anomalies and Events 131Detect: Security Continuous Monitoring 131Respond: Analysis 132Respond: Mitigation 132Recover: Recovery Planning 133Recover: Improvements 133DNS Server Hardware Controls 134DNS Server Hardening 134Additional DNS Server Controls 136Summary 1377 SERVICE DENIAL ATTACKS 139Introduction 139Denial of Service Attacks 139Pseudorandom Subdomain Attacks 141Reflector Style Attacks 143Detecting Service Denial Attacks 144Denial of Service Protection 145DoS/DDoS Mitigation 145Bogus Queries Mitigation 147PRSD Attack Mitigation 148Reflector Mitigation 148Summary 1518 CACHE POISONING DEFENSES 153Introduction 153Attack Forms 154Packet Interception or Spoofing 154ID Guessing or Query Prediction 155Name Chaining 155The Kaminsky DNS Vulnerability 156Cache Poisoning Detection 159Cache Poisoning Defense Mechanisms 160UDP Port Randomization 160Query Name Case Randomization 161DNS Security Extensions 161Last Mile Protection 1679 SECURING AUTHORITATIVE DNS DATA 169Introduction 169Attack Forms 170Resolution Data at Rest 170Domain Registries 170DNS Hosting Providers 171DNS Data in Motion 172Attack Detection 172Authoritative Data 172Domain Registry 173Domain Hosting 173Falsified Resolution 173Defense Mechanisms 174Defending DNS Data at Rest 174Defending Resolution Data in Motion with DNSSEC 176Summary 18610 ATTACKER EXPLOITATION OF DNS 187Introduction 187Network Reconnaissance 187Data Exfiltration 188Detecting Nefarious use of DNS 189Detecting Network Reconnaissance 189DNS Tunneling Detection 190Mitigation of Illicit DNS Use 193Network Reconnaissance Mitigation 193Mitigation of DNS Tunneling 19311 MALWARE AND APTS 195Introduction 195Malware Proliferation Techniques 196Phishing 196Spear Phishing 196Downloads 196File Sharing 197Email Attachments 197Watering Hole Attack 197Replication 197Implantation 197Malware Examples 198Malware Use of DNS 198DNS Fluxing 198Dynamic Domain Generation 202Detecting Malware 202Detecting Malware Using DNS Data 203Mitigating Malware Using DNS 206Malware Extrication 206DNS Firewall 207Summary 21012 DNS SECURITY STRATEGY 213Major DNS Threats and Mitigation Approaches 214Common Controls 214Disaster Defense 214Defenses Against Human Error 220DNS Role-Specific Defenses 220Stub Resolvers 220Forwarder DNS Servers 221Recursive Servers 221Authoritative Servers 222Broader Security Strategy 222Identify Function 223Protect Function 224Detect Function 225Respond Function 226Recover Function 22713 DNS APPLICATIONS TO IMPROVE NETWORK SECURITY 229Safer Web Browsing 230DNS-Based Authentication of Named Entities (DANE) 230Email Security 232Email and DNS 233DNS Block Listing 237Sender Policy Framework (SPF) 238Domain Keys Identified Mail (DKIM) 242Domain-Based Message Authentication, Reporting, andConformance (DMARC) 245Securing Automated Information Exchanges 246Dynamic DNS Update Uniqueness Validation 246Storing Security-Related Information 247Other Security Oriented DNS Resource Record Types 247Summary 25114 DNS SECURITY EVOLUTION 253Appendix A: Cybersecurity Framework Core DNS Example 257Appendix B: DNS Resource Record Types 285Bibliography 291Index 299