Site icon Converge Digest

Nominum Defends Against DNS Cache Poisoning

Nominum has released a security update to its Vantio caching DNS server platform, adding multi-layer intelligent defenses that defeat DNS cache poisoning and other attacks, including the recently publicized Kaminsky vulnerability. Vantio, which is an alternative to open-source DNS, enables broadband providers to deliver new services by leveraging DNS as a key control point in the network . Nominum’s many ISP and carrier customers support an estimated 120 million broadband subscribers.

Key benefits of new Vantio DNS security features include:

In the recent cache poisoning threat, Nominum said its customers were instrumental in implementing and deploying UDP SPR. However, UDP source port randomization is only a first-step response to the new vulnerability, and network operators need additional deterministic defenses to address important exploits.

“Literally one day after details of the Kaminsky cache poisoning attack were revealed, UDP Source Port Randomization was defeated in 10 hours by security researchers using brute-force spoofed responses,” said Dr. Paul Mockapetris, Chairman and Chief Scientist at Nominum and inventor of the DNS. “Nominum’s multi-layered approach eliminates the risk of a successful attack.”

Vantio features the following four security layers with key security features highlighted:

http://www.nominum.com

Exit mobile version