New Insights into DNSSEC Adoption

    IID (Internet Identity), a provider of technology and services that help organizations secure their Internet presence, recently announced results from a survey of corporate IT security experts on the impact and future of domain name system security extensions (DNSSEC). The survey, conducted in coordination with the Online Trust Alliance, found that half of the respondents either hadn’t heard of DNSSEC or expressed limited familiarity with it. Those who do understand the technology believe key obstacles including lack of training/implementation services, slow ISP resolver rollout and limited client-aware applications will lead to a two to five-year adoption period.

    DNSSEC is an emerging Internet security standard. It is designed to protect Internet users from getting misdirected to unintended Internet destinations by ensuring domain name system (DNS) entries remain unchanged in transit. The Internet’s root servers at the top of the DNS hierarchy added DNSSEC support last July. More than 25 top-level domains — including .gov, .org, .edu and .net — have enabled DNSSEC since then. On March 31, DNSSEC will be enabled on the .com top-level domain, which has more than 80 million registered names according to VeriSign, the operator of .com.

    This slideshow highlights some of the findings of the IID survey.

    New Insights into DNSSEC Adoption - slide 1

    Click through for results from a Domain Name System Security Extensions (DNSSEC) survey conducted by IID, in coordination with Online Trust Alliance.

    New Insights into DNSSEC Adoption - slide 2

    Fifty percent of respondents have never heard of DNSSEC or don’t understand it clearly.

    New Insights into DNSSEC Adoption - slide 3

    Of those who are familiar with DNSSEC, a vast majority correctly identified the key benefit for the technology. When asked, “What is the purpose of DNSSEC?” their top answer was to “prevent cache-poisoning attacks at recursive nameservers.”

    New Insights into DNSSEC Adoption - slide 4

    Of those surveyed, only one percent acknowledged their organization has experienced losses to date due to cache poisoning attacks.

    New Insights into DNSSEC Adoption - slide 5

    The majority of respondents believe it will take two to five years for DNSSEC to become widely adopted in their industry, and all believe that adoption is inevitable.

    New Insights into DNSSEC Adoption - slide 6

    Only five percent of those polled said their organization has already implemented DNSSEC for their domains, while an additional 16 percent plan to implement it.

    New Insights into DNSSEC Adoption - slide 7

    According to those surveyed, the two biggest overall obstacles to DNSSEC adoption today are Internet Service Provider deployment of DNSSEC resolvers and DNSSEC-aware client applications like browsers and email.

    New Insights into DNSSEC Adoption - slide 8

    When asked about the biggest roadblock to individual DNSSEC adoption, the number one answer was, “Not enough vendors offering services to implement it.”

    New Insights into DNSSEC Adoption - slide 9

    In response to “Who would you choose to provide a DNSSEC PUBLISHING (authoritative records and key management)” and “Who would you expect to be able to provide a DNSSEC resolving (running recursive nameservers my employees use) implementation for your organization?”

    Get the Free Newsletter!

    Subscribe to Daily Tech Insider for top news, trends, and analysis.

    Latest Articles