The Wayback Machine - https://web.archive.org/web/20071219045322/http://citeseer.ist.psu.edu:80/bellovin95using.html
Using the Domain Name System for System Break-ins (1995)  (Make Corrections)  (27 citations)
Steven M. Bellovin



  Home/Search   Context   Related

 
View or download:
att.com/~smb/papers/dnshack.ps
purdue.edu/homes/c...ystem_Breakins.ps
cert.dfn.de/pub/docs/cr...dnshack.ps.gz
Cached:  PS.gz  PS  PDF   Image  Update  Help
Problem Downloading?
From:  counterpane.com/biblio...authorB (more)
(Enter author homepages)

Rate this article: (best)
  Comment on this article  
(Enter summary)

Abstract: The DARPA Internet uses the Domain Name System (DNS), a distributed database, to map host names to network addresses, and vice-versa. Using a vulnerability first noticed by P.V. Mockapetris, we demonstrate how the DNS can be abused to subvert system security. We also show what tools are useful to the attacker. Possible defenses against this attack, including one implemented by Berkeley in response to our reports of this problem, are discussed, and the limitations on their applicability are... (Update)

Cited by:   More
On the Performance and Analysis of DNS Security Extensions - Reza Curtmola Aniello   (Correct)
Network Working Group R. Atkinson - Request For Comments   (Correct)
Impact of Configuration Errors on DNS Robustness - Pappas, Xu, Lu, Massey.. (2004)   (Correct)

Active bibliography (related documents):   More   All
0.5:   Limitations of the Kerberos Authentication System - Bellovin, Merritt (1991)   (Correct)
0.2:   A Formal-Specification Based Approach for Protecting the.. - Cheung, Levitt   (Correct)
0.2:   An Intrusion Tolerance Approach for Protecting Network.. - Cheung (1999)   (Correct)

Similar documents based on text:   More   All
0.2:   Privacy-Enhanced Searches Using Encrypted Bloom Filters - Steven Bellovin Smb (2004)   (Correct)
0.1:   EIDs, IPsec, and HostNAT - Bellovin (1998)   (Correct)
0.0:   Security Problems in the TCP/IP Protocol Suite - Bellovin (1989)   (Correct)

Related documents from co-citation:   More   All
8:   DNS and BIND security issues (context) - Vixie - 1995
7:   Domain Names - Concepts and Facilities (context) - Mockapetris - 1987
7:   RFC 1034: Domain names --- concepts and facilities (context) - Mockapetris - 1987

BibTeX entry:   (Update)

Steven M. Bellovin. Using the Domain Name System for System Breakins. AT&T; Bell Laboratories, Murray Hill, New Jersey, 1990. (unpublished technical report). http://citeseer.ist.psu.edu/bellovin95using.html   More

@inproceedings{ bellovinbellovinusing,
    author = "Steven M. Bellovin",
    title = "Using the Domain Name System for System Break-Ins",
    pages = "199--208",
    url = "citeseer.ist.psu.edu/bellovin95using.html" }
Citations (may not include all citations):
178   Kerberos: An authentication service for computer networks (context) - Neuman, Ts'o - 1994
136   The kerberos network authentication service - Kohl, Neuman - 1993
85   Simple network management protocol SNMP (context) - Case, Davin et al. - 1989
78   Security problems in the TCP/IP protocol suite - Bellovin - 1989  ACM
63   Kerberos: An authentication service for open network systems (context) - Steiner, Neuman et al. - 1988  DBLP
61   Kerberos authentication and authorization system - Miller, Neuman et al. - 1987
31   Internet Engineering Task Force (context) - Mockapetris, implementation et al. - 1987
31   Internet Engineering Task Force (context) - Mockapetris, concepts et al. - 1987
18   The Cuckoo's Egg: Tracking a Spy Through the Maze of Compute.. (context) - Stoll - 1989  ACM
15   Domain name system protocol security extensions (context) - Eastlake, Charles et al. - 1996
12   Computing Science Technical Report (context) - Morris, in et al. - 1985
11   DNS and BIND security issues (context) - Vixie - 1995
7   Addressing weaknesses in the domain name system protocol - Schuba, Spafford - 1993
5   Pseudo-network drivers and virtual networks - Bellovin - 1990
2   Designing an authentication system: A dialogue in four scene.. (context) - Bryant - 1988



The graph only includes citing articles where the year of publication is known.


Documents on the same site (http://www.counterpane.com/biblio/author-B.html):   More
Time-Stamping with Binary Linking Schemes - Buldas, Laud, Lipmaa, Villemson (1998)   (Correct)
Limitations of the Kerberos Authentication System - Bellovin, Merritt (1991)   (Correct)
A Brief Review on the Impossibility of Quantum Bit Commitment - Brassard, Crépeau (1997)   (Correct)

Online articles have much greater impact   More about CiteSeer.IST   Add search form to your site   Submit documents   Feedback  

CiteSeer.IST - Copyright Penn State and NEC