• Home
  • Archive
  • Tools
  • Contact Us

The Customize Windows

Technology Journal

  • Cloud Computing
  • Computer
  • Digital Photography
  • Windows 7
  • Archive
  • Cloud Computing
  • Virtualization
  • Computer and Internet
  • Digital Photography
  • Android
  • Sysadmin
  • Electronics
  • Big Data
  • Virtualization
  • Downloads
  • Web Development
  • Apple
  • Android
Advertisement
You are here:Home » Measures to Protect Against DNS Spoofing

By Abhishek Ghosh February 17, 2024 6:19 pm Updated on February 17, 2024

Measures to Protect Against DNS Spoofing

Advertisement

Measures to protect against DNS spoofing are either aimed at including more random information in the DNS message that the attacker has to guess or protecting the message with cryptographic techniques. Since the Kaminsky attack became known, all common name servers have been using source port randomization. In addition to the transaction number, the source port of a DNS request in the UDP header is also randomly selected. Depending on the implementation, this results in an additional 11-16 bits, which the attacker also has to guess correctly.

Another method is 0x20-bit encoding, in which letters in the requested domain name are randomly placed in upper and lower case letters, for example thecustomizewindows.com. When it comes to name resolution, uppercase and lowercase letters are generally equivalent, with RFC 1034 saying that the spelling of the response should correspond to the request name. The length of the additional randomness depends on the number of letters in the domain name.

What these methods have in common is that the message format does not need to be adapted and the methods are therefore largely compatible with the existing DNS infrastructure. DNS spoofing is still feasible in principle, but the increased space of the parameters to be guessed reduces the probability of success of a remote attacker. None of the methods to increase randomness protects against an attacker who can read the DNS request (on-path attacker).

Advertisement

---

Another category of protection measures is to extend the DNS message format with digital signatures or message authentication codes, which are generated and verified using cryptographic methods. An attacker can generate spoofed DNS responses, but without knowledge of the secret key, they cannot generate a matching signature.

Measures to Protect Against DNS Spoofing

A well-known method is DNSSEC, in which resource records are signed with asymmetric cryptosystems. DNSSEC is partly used in practice, but the majority of DNS Internet traffic is not protected by it.

An alternative method to DNSSEC is DNSCurve, in which the communication channel between the resolver and the name server is cryptographically protected instead of resource records. It employs a combination of asymmetric and symmetric cryptosystems. An adaptation of DNSCurve is DNSCrypt, which uses OpenDNS to secure communication between the end user and the resolver.

Similar to DNSCurve or DNSCrypt, TSIG secures communication between two DNS participants. To do this, it uses HMAC with symmetric keys that have to be configured manually. Another method is DNS over HTTPS, in which DNS queries are transmitted encrypted via the HTTPS protocol.

Facebook Twitter Pinterest

Abhishek Ghosh

About Abhishek Ghosh

Abhishek Ghosh is a Businessman, Surgeon, Author and Blogger. You can keep touch with him on Twitter - @AbhishekCTRL.

Here’s what we’ve got for you which might like :

Articles Related to Measures to Protect Against DNS Spoofing

  • Nginx WordPress Installation Guide (All Steps)

    This is a Full Nginx WordPress Installation Guide With All the Steps, Including Some Optimization and Setup Which is Compatible With WordPress DOT ORG Example Settings For Nginx.

  • WordPress & PHP : Different AdSense Units on Mobile Devices

    Here is How To Serve Different AdSense Units on Mobile Devices on WordPress With PHP. WordPress Has Function Which Can Be Used In Free Way.

  • Effectiveness of Flushing DNS Cache to Prevent DNS Cache Poisoning and Spoofing

    Effectiveness of Flushing DNS Cache to Prevent DNS Cache Poisoning and Spoofing Discussed in Details in Plain English Making Readable to All.

  • How to Migrate Name Servers with DNSSEC Record

    You may need to migrate your DNS hosting from one provider to another DNS provider for different reasons and when you have activated DNSSEC Record, then the job is slightly difficult but potential downtime can be avoided if the steps are done correctly. DNSSEC Record is great since no party can run a man-in-the-middle exploit. […]

performing a search on this website can help you. Also, we have YouTube Videos.

Take The Conversation Further ...

We'd love to know your thoughts on this article.
Meet the Author over on Twitter to join the conversation right now!

If you want to Advertise on our Article or want a Sponsored Article, you are invited to Contact us.

Contact Us

Subscribe To Our Free Newsletter

Get new posts by email:

Please Confirm the Subscription When Approval Email Will Arrive in Your Email Inbox as Second Step.

Search this website…

 

vpsdime

Popular Articles

Our Homepage is best place to find popular articles!

Here Are Some Good to Read Articles :

  • Cloud Computing Service Models
  • What is Cloud Computing?
  • Cloud Computing and Social Networks in Mobile Space
  • ARM Processor Architecture
  • What Camera Mode to Choose
  • Indispensable MySQL queries for custom fields in WordPress
  • Windows 7 Speech Recognition Scripting Related Tutorials

Social Networks

  • Pinterest (24.3K Followers)
  • Twitter (5.8k Followers)
  • Facebook (5.7k Followers)
  • LinkedIn (3.7k Followers)
  • YouTube (1.3k Followers)
  • GitHub (Repository)
  • GitHub (Gists)
Looking to publish sponsored article on our website?

Contact us

Recent Posts

  • Cloud-Powered Play: How Streaming Tech is Reshaping Online GamesSeptember 3, 2025
  • How to Use Transcribed Texts for MarketingAugust 14, 2025
  • nRF7002 DK vs ESP32 – A Technical Comparison for Wireless IoT DesignJune 18, 2025
  • Principles of Non-Invasive Blood Glucose Measurement By Near Infrared (NIR)June 11, 2025
  • Continuous Non-Invasive Blood Glucose Measurements: Present Situation (May 2025)May 23, 2025
PC users can consult Corrine Chorney for Security.

Want to know more about us?

Read Notability and Mentions & Our Setup.

Copyright © 2026 - The Customize Windows | dESIGNed by The Customize Windows

Copyright  · Privacy Policy  · Advertising Policy  · Terms of Service  · Refund Policy