press releaseIssue Date29 August 2008Feed for NominumShare Release |
press releaserelease detailNominum Leapfrogs Industry Response to DNS Vulnerability with New Security PackageNew Release Provides Intelligent, Layered Approach with Built-In “Defense in Depth” Against DNS Cache Poisoning August 29, 2008 — Nominum, the leading provider of network naming and addressing technologies, today announced the availability of a comprehensive new security release for its Vantio caching DNS server platform. The latest Vantio software release provides multi-layer intelligent defenses that defeat DNS cache poisoning and other attacks, including the recently publicized Kaminsky vulnerability. By offering built-in defense-in-depth, the Nominum solution far surpasses the recently released industry standard UDP Source Port Randomization (UDP SPR). In fact, Vantio’s new defenses negate the brute force advantage attackers gained with the latest DNS cache poisoning vulnerability. “Literally one day after details of the Kaminsky cache poisoning attack were revealed, UDP Source Port Randomization was defeated in 10 hours by security researchers using brute-force spoofed responses,” said Dr. Paul Mockapetris, Chairman and Chief Scientist at Nominum and inventor of the DNS. “Nominum’s multi-layered approach eliminates the risk of a successful attack.” Key benefits of new Vantio DNS security features: Protection Well Beyond the Industry Response UDP source port randomization is only a first-step response to the new vulnerability, and network operators need additional deterministic defenses to address important exploits. Cache poisoning attacks rely on many techniques, and response spoofing is only one of them. UDP source port randomization is designed to mitigate risk of spoofing, but is not effective against a determined attacker or other forms of attacks. Response spoofing can be easily subverted when more network resources are available to an attacker that allow for sending many spoofed responses. Nominum’s new defenses are critical to ensuring the attacker does not succeed. "Layered defenses in the DNS system are an effective way to address serious attack scenarios that aren't covered by UDP Source Port Randomization alone," said Dan Kaminsky, the security researcher who discovered the latest DNS vulnerability. "As new DNS vulnerabilities are discovered, a layered approach such as Nominum's will help in ensuring ongoing Internet security." Vantio features the following four security layers with key security features highlighted: - Deterrence Layer: Includes Nominum’s leading UDP Source Port Randomization implementation, the recommended industry response to the Kaminsky threat “Layered security is the only way to defend against the emerging threats to the Internet,” said Tom Tovar, CEO of Nominum. “Our customers, the largest networks in the world, have an obligation to deliver the highest-level of security in delivering Internet service to consumer, enterprise and government users. Nominum’s new software release ensures that our customers can meet that obligation immediately and completely.” Pricing and Availability Tags and Keywords: DNS Security, DNS Vulnerability, cache poisoning, pharming, Internet security, UDP Source Port Randomization, DNS caching, DNS software, network address translation, NAT, Nominum, Vantio, Kaminsky About Nominum Nominum Contact: Media Contact:
|

tweet