• English
  • Deutsch
  • Log In
    Password Login
    Research Outputs
    Fundings & Projects
    Researchers
    Institutes
    Statistics
Repository logo
Fraunhofer-Gesellschaft
  1. Home
  2. Fraunhofer-Gesellschaft
  3. Konferenzschrift
  4. Poster: The Unintended Consequences of Algorithm Agility in DNSSEC
 
  • Details
  • Full
Options
November 7, 2022
Conference Paper
Title

Poster: The Unintended Consequences of Algorithm Agility in DNSSEC

Abstract
Cryptographic algorithm agility is an important property for DNSSEC: it allows easy deployment of new algorithms if the existing ones are no longer secure. In this work we show that the cryptographic agility in DNSSEC, although critical for provisioning DNS with strong cryptography, also introduces a vulnerability. We find that under certain conditions, when new algorithms are listed in signed DNS responses, the resolvers do not validate DNSSEC. As a result, domains that deploy new ciphers may in fact cause the resolvers not to validate DNSSEC. We exploit this to develop DNSSEC-downgrade attacks and experimentally and ethically evaluate them against popular DNS resolver implementations, public DNS providers, and DNS services used by web clients worldwide. We find that major DNS providers as well as 45% of DNS resolvers used by web clients are vulnerable to our attacks.
Author(s)
Heftrig, Elias  
Fraunhofer-Institut für Sichere Informationstechnologie SIT  
Shulman, Haya  
Fraunhofer-Institut für Sichere Informationstechnologie SIT  
Waidner, Michael  
Fraunhofer-Institut für Sichere Informationstechnologie SIT  
Mainwork
CCS 2022, ACM SIGSAC Conference on Computer and Communications Security. Proceedings  
Conference
Conference on Computer and Communications Security 2022  
Open Access
DOI
10.1145/3548606.3563517
Language
English
Fraunhofer-Institut für Sichere Informationstechnologie SIT  
  • Cookie settings
  • Imprint
  • Privacy policy
  • Api
  • Contact
© 2024