Skip to main content

Understanding the role of registrars in DNSSEC deployment

Publication ,  Conference
Chung, T; Levin, D; Van Rijswijk-Deij, R; Maggs, BM; Wilson, C; Choffnes, D; Mislove, A
Published in: Proceedings of the ACM SIGCOMM Internet Measurement Conference, IMC
November 1, 2017

The Domain Name System (DNS) provides a scalable, flexible name resolution service. Unfortunately, its unauthenticated architecture has become the basis for many security attacks. To address this, DNS Security Extensions (DNSSEC) were introduced in 1997. DNSSEC's deployment requires support from the top-level domain (TLD) registries and registrars, as well as participation by the organization that serves as the DNS operator. Unfortunately, DNSSEC has seen poor deployment thus far: despite being proposed nearly two decades ago, only 1% of.com,.net, and.org domains are properly signed. In this paper, we investigate the underlying reasons why DNSSEC adoption has been remarkably slow. We focus on registrars, as most TLD registries already support DNSSEC and registrars often serve as DNS operators for their customers. Our study uses large-scale, longitudinal DNS measurements to study DNSSEC adoption, coupled with experiences collected by trying to deploy DNSSEC on domains we purchased from leading domain name registrars and resellers. Overall, we find that a select few registrars are responsible for the (small) DNSSEC deployment today, and that many leading registrars do not support DNSSEC at all, or require customers to take cumbersome steps to deploy DNSSEC. Further frustrating deployment, many of the mechanisms for conveying DNSSEC information to registrars are error-prone or present security vulnerabilities. Finally, we find that using DNSSEC with third-party DNS operators such as Cloudfare requires the domain owner to take a number of steps that 40% of domain owners do not complete. Having identified several operational challenges for full DNSSEC deployment, we make recommendations to improve adoption.

Duke Scholars

Altmetric Attention Stats
Dimensions Citation Stats

Published In

Proceedings of the ACM SIGCOMM Internet Measurement Conference, IMC

DOI

Publication Date

November 1, 2017

Volume

Part F131937

Start / End Page

369 / 383
 

Citation

APA
Chicago
ICMJE
MLA
NLM
Chung, T., Levin, D., Van Rijswijk-Deij, R., Maggs, B. M., Wilson, C., Choffnes, D., & Mislove, A. (2017). Understanding the role of registrars in DNSSEC deployment. In Proceedings of the ACM SIGCOMM Internet Measurement Conference, IMC (Vol. Part F131937, pp. 369–383). https://doi.org/10.1145/3131365.3131373
Chung, T., D. Levin, R. Van Rijswijk-Deij, B. M. Maggs, C. Wilson, D. Choffnes, and A. Mislove. “Understanding the role of registrars in DNSSEC deployment.” In Proceedings of the ACM SIGCOMM Internet Measurement Conference, IMC, Part F131937:369–83, 2017. https://doi.org/10.1145/3131365.3131373.
Chung T, Levin D, Van Rijswijk-Deij R, Maggs BM, Wilson C, Choffnes D, et al. Understanding the role of registrars in DNSSEC deployment. In: Proceedings of the ACM SIGCOMM Internet Measurement Conference, IMC. 2017. p. 369–83.
Chung, T., et al. “Understanding the role of registrars in DNSSEC deployment.” Proceedings of the ACM SIGCOMM Internet Measurement Conference, IMC, vol. Part F131937, 2017, pp. 369–83. Scopus, doi:10.1145/3131365.3131373.
Chung T, Levin D, Van Rijswijk-Deij R, Maggs BM, Wilson C, Choffnes D, Mislove A. Understanding the role of registrars in DNSSEC deployment. Proceedings of the ACM SIGCOMM Internet Measurement Conference, IMC. 2017. p. 369–383.

Published In

Proceedings of the ACM SIGCOMM Internet Measurement Conference, IMC

DOI

Publication Date

November 1, 2017

Volume

Part F131937

Start / End Page

369 / 383