Welcome!

Blog Feed Post

Ultra AEP warns of on-going danger of ‘dirty domains’

Only 53 per cent of global top level domains 'secure'

Loudwater, UK, 23rd January 2014: Over three years after the world's first top level domains (TLDs) (such as .org, .com and .net) were signed with domain name system security extensions (DNSSEC), nearly half (47 per cent)[1] remain open to malicious tampering. This is potentially leaving millions of the world's internet users open to malicious redirect to fake websites, warns FTSE 250 cyber security company Ultra Electronics AEP.

Some of the world's most advanced Internet economies such as Italy (.it), Spain (.es) and South Africa (.za) remain unsigned, leaving every Internet visitor to a website ending with that extension at risk of being re-routed to a bogus website and potentially being fooled into parting with personal information.

Sonia Freed, Managing Director of Ultra Electronics AEP explains: "This is an issue that affects every Internet user in the world and a poor level of take up of DNSSEC amongst top level domains is a barrier to the evolution of a safer Internet. Unless the top level domain is signed, every single website operating under a national domain can have its DNS spoofed, potentially directing Internet users straight into the hands of cyber criminals via fake websites that often look just like the real thing."

Freed continues: "Whilst many of the domains we are familiar with such as .com, co.uk and .org are secure, it's becoming increasingly common for websites to use extensions from other countries even when they do not have a local presence. Many popular file sharing sites for instance use unsecured domains from tiny Caribbean islands and are using them as a 'flag of convenience'. With this fragmentation, comes potential confusion and an environment in which cyber criminals can thrive."

Richard Lamb at Internet Corporation for Assigned Names and Numbers (ICANN): "It is now three and a half years since the root of the Domain Name System was signed, however our figures show there is still a great deal of work to do. DNSSEC is a leap forward in preventing attackers from redirecting end users to websites under their own control (for account and password collection). We urge the owners of the remaining unsigned TLDs to work with ICANN and help develop a safer web to protect the world's internet users."

Freed highlights the scale of the problem: "DNS cache poisoning continues to affect the world's Internet users. Towards the end of last year, users of Google's Malaysian domain (www.google.com.my) were directed to a fake website in Pakistan.[2] The Syrian Electronic Army (SEA) have also exploited DNS weaknesses to modify DNS entries and redirect users accessing The New York Times and Twitter to propaganda pages."

Freed notes: "Securing the TLD is a major first step but it's also necessary for responsible individual domain name owners to ensure the integrity of their zone data and hence the integrity of their associated web services by implementing a DNSSEC solution and signing their zone DNS resource records. A DNSSEC solution comprises a DNS Server with DNSSEC extensions and cryptographic keys."

DNSSEC uses public key cryptography to digitally sign DNS data. It means that responses to DNS queries are digitally signed by the DNS server using private keys and are automatically verified by the client using the corresponding public key.

Digital signing also guarantees the validity of DNS responses. As such Internet users are protected from the fraudulent DNS responses that could contribute to phishing techniques and other forms of fraud. Using a hardware secure module (HSM) can enhance the security of a DNSSEC solution. In addition to highly secure key generation and storage, HSMs provide fast cryptographic processing, which offload computationally intensive calculations from servers.

AEP Keyper is the only network-attached HSM on the market certified to FIPS 140-2 Level 4 overall, the highest FIPS accreditation.

For further information, please see: http://www.internetsociety.org/deploy360/dnssec/

[1] Figures published by Internet Corporation for Assigned Names and Numbers (ICANN) on 20.01.2014: http://stats.research.icann.org/dns/tld_report/index.html
[2] Source: MYNIC (official registrar of Malaysian internet domains): http://mynic.my/en/news.php?id=162

-Ends-

Notes to editors
On June 16, 2010, AEP Ultra Safe Key Security and Management product signed the DNS root of the internet, the dot, forming part of an elite international circle of trust protecting the web from being hijacked - See more at: http://www.ultra-aep.com/company-overview#sthash.G3DUZ1Q3.dpuf

About Ultra Electronics AEP
AEP provides trusted security everywhere and develops the highest grade security and communication technologies, securing data regardless of device, environment or location, tested and accredited to industry security standards, including FIPS 140-2 Level 4 and CAPS to IL3/IL4. Trusted by businesses, governments and the defence sector, its extensive portfolio of products and solutions protect the integrity of very sensitive data and are extremely reliable, survivable and resilient. AEP is a business unit of Ultra Electronics an internationally successful security, defence and aerospace company with a long, consistent track record of development and growth. Ultra businesses constantly innovate to create solutions to customer requirements that are different from, and better than competitors.

Enquiries
John Bailey, Marketing Manager 01628 642600
David Bell, Vocal Public Relations 07971 845740

Source: RealWire

Read the original blog entry...

More Stories By RealWire News Distribution

RealWire is a global news release distribution service specialising in the online media. The RealWire approach focuses on delivering relevant content to the receivers of our client's news releases. As we know that it is only through delivering relevance, that influence can ever be achieved.

Latest Stories
The WebRTC Summit New York, to be held June 6-8, 2017, at the Javits Center in New York City, NY, announces that its Call for Papers is now open. Topics include all aspects of improving IT delivery by eliminating waste through automated business models leveraging cloud technologies. WebRTC Summit is co-located with 20th International Cloud Expo and @ThingsExpo. WebRTC is the future of browser-to-browser communications, and continues to make inroads into the traditional, difficult, plug-in web ...
In his keynote at 18th Cloud Expo, Andrew Keys, Co-Founder of ConsenSys Enterprise, provided an overview of the evolution of the Internet and the Database and the future of their combination – the Blockchain. Andrew Keys is Co-Founder of ConsenSys Enterprise. He comes to ConsenSys Enterprise with capital markets, technology and entrepreneurial experience. Previously, he worked for UBS investment bank in equities analysis. Later, he was responsible for the creation and distribution of life sett...
20th Cloud Expo, taking place June 6-8, 2017, at the Javits Center in New York City, NY, will feature technical sessions from a rock star conference faculty and the leading industry players in the world. Cloud computing is now being embraced by a majority of enterprises of all sizes. Yesterday's debate about public vs. private has transformed into the reality of hybrid cloud: a recent survey shows that 74% of enterprises have a hybrid cloud strategy.
More and more companies are looking to microservices as an architectural pattern for breaking apart applications into more manageable pieces so that agile teams can deliver new features quicker and more effectively. What this pattern has done more than anything to date is spark organizational transformations, setting the foundation for future application development. In practice, however, there are a number of considerations to make that go beyond simply “build, ship, and run,” which changes how...
WebRTC is the future of browser-to-browser communications, and continues to make inroads into the traditional, difficult, plug-in web communications world. The 6th WebRTC Summit continues our tradition of delivering the latest and greatest presentations within the world of WebRTC. Topics include voice calling, video chat, P2P file sharing, and use cases that have already leveraged the power and convenience of WebRTC.
Without lifecycle traceability and visibility across the tool chain, stakeholders from Planning-to-Ops have limited insight and answers to who, what, when, why and how across the DevOps lifecycle. This impacts the ability to deliver high quality software at the needed velocity to drive positive business outcomes. In his general session at @DevOpsSummit at 19th Cloud Expo, Phil Hombledal, Solution Architect at CollabNet, discussed how customers are able to achieve a level of transparency that e...
Let’s face it, embracing new storage technologies, capabilities and upgrading to new hardware often adds complexity and increases costs. In his session at 18th Cloud Expo, Seth Oxenhorn, Vice President of Business Development & Alliances at FalconStor, discussed how a truly heterogeneous software-defined storage approach can add value to legacy platforms and heterogeneous environments. The result reduces complexity, significantly lowers cost, and provides IT organizations with improved efficienc...
Amazon has gradually rolled out parts of its IoT offerings, but these are just the tip of the iceberg. In addition to optimizing their backend AWS offerings, Amazon is laying the ground work to be a major force in IoT - especially in the connected home and office. In his session at @ThingsExpo, Chris Kocher, founder and managing director of Grey Heron, explained how Amazon is extending its reach to become a major force in IoT by building on its dominant cloud IoT platform, its Dash Button strat...
Internet-of-Things discussions can end up either going down the consumer gadget rabbit hole or focused on the sort of data logging that industrial manufacturers have been doing forever. However, in fact, companies today are already using IoT data both to optimize their operational technology and to improve the experience of customer interactions in novel ways. In his session at @ThingsExpo, Gordon Haff, Red Hat Technology Evangelist, will share examples from a wide range of industries – includin...
"We build IoT infrastructure products - when you have to integrate different devices, different systems and cloud you have to build an application to do that but we eliminate the need to build an application. Our products can integrate any device, any system, any cloud regardless of protocol," explained Peter Jung, Chief Product Officer at Pulzze Systems, in this SYS-CON.tv interview at @ThingsExpo, held November 1-3, 2016, at the Santa Clara Convention Center in Santa Clara, CA.
When it comes to cloud computing, the ability to turn massive amounts of compute cores on and off on demand sounds attractive to IT staff, who need to manage peaks and valleys in user activity. With cloud bursting, the majority of the data can stay on premises while tapping into compute from public cloud providers, reducing risk and minimizing need to move large files. In his session at 18th Cloud Expo, Scott Jeschonek, Director of Product Management at Avere Systems, discussed the IT and busin...
Between 2005 and 2020, data volumes will grow by a factor of 300 – enough data to stack CDs from the earth to the moon 162 times. This has come to be known as the ‘big data’ phenomenon. Unfortunately, traditional approaches to handling, storing and analyzing data aren’t adequate at this scale: they’re too costly, slow and physically cumbersome to keep up. Fortunately, in response a new breed of technology has emerged that is cheaper, faster and more scalable. Yet, in meeting these new needs they...
The cloud promises new levels of agility and cost-savings for Big Data, data warehousing and analytics. But it’s challenging to understand all the options – from IaaS and PaaS to newer services like HaaS (Hadoop as a Service) and BDaaS (Big Data as a Service). In her session at @BigDataExpo at @ThingsExpo, Hannah Smalltree, a director at Cazena, provided an educational overview of emerging “as-a-service” options for Big Data in the cloud. This is critical background for IT and data professionals...
"Once customers get a year into their IoT deployments, they start to realize that they may have been shortsighted in the ways they built out their deployment and the key thing I see a lot of people looking at is - how can I take equipment data, pull it back in an IoT solution and show it in a dashboard," stated Dave McCarthy, Director of Products at Bsquare Corporation, in this SYS-CON.tv interview at @ThingsExpo, held November 1-3, 2016, at the Santa Clara Convention Center in Santa Clara, CA.
Fact is, enterprises have significant legacy voice infrastructure that’s costly to replace with pure IP solutions. How can we bring this analog infrastructure into our shiny new cloud applications? There are proven methods to bind both legacy voice applications and traditional PSTN audio into cloud-based applications and services at a carrier scale. Some of the most successful implementations leverage WebRTC, WebSockets, SIP and other open source technologies. In his session at @ThingsExpo, Da...