Security and Other Technical Concerns Raised by theDNS Filtering Requirements in the PROTECT IP Bill
May 2011Authors: Steve Crocker, Shinkuro, Inc.David Dagon, Georgia TechDan Kaminsky, DKHDanny McPherson, Verisign, Inc.Paul Vixie, Internet Systems Consortium
Affiliations provided for identification only Brief biographies of authors available below
TABLE OF CONTENTS
EXECUTIVE SUMMARY............................................................................................................2
I.
Introduction.............................................................................................................................3
II.
DNS Background....................................................................................................................3
III.
Technical Challenges Raised By Mandatory DNS Filtering..................................................5
A.
DNS Filtering in Tension with DNSSEC...........................................................................5
B.
The Proposed DNS Filters Would Be Circumvented Easily..............................................7
C.
Circumvention Poses Performance and Security Risks....................................................10
1.
Users Will Face Increased Cybersecurity Risk.............................................................10
2.
ISPs Will Lose Visibility into Network Security Threats.............................................12
3.
CDNs Would Likely Face Degraded Performance.......................................................12
D.
DNS Interdependencies Will Lead to Collateral Damage................................................13
IV.
Conclusion............................................................................................................................14
APPENDIX A...............................................................................................................................15
APPENDIX B...............................................................................................................................16
ABOUT THE AUTHORS............................................................................................................17