DNS Security

The Domain Name System (DNS) of the Internet helps translate human-readable domain names to IP addresses and has become indispensable for using the Internet. However, DNS is not secure. There are many means, for example, to mislead users visiting a legitimate domain to a malicous IP address.

We have uncovered a vulnerability of DNS (in collaboration with Tsinghua University and the University of Georgia) that affects the large majority of popular DNS implementations. It allows a malicious domain name to stay resolvable long after it has been removed from the upper level DNS servers.

Our publications include the following: