netsec-sig - [Security-WG] DNS Serving Stale to the rescue?
Subject: Internet2 Network Security SIG
List archive
- From: Steven Wallace <>
- To: , NTAC <>
- Cc: Kim Milford <>,
- Subject: [Security-WG] DNS Serving Stale to the rescue?
- Date: Thu, 2 Nov 2017 11:00:26 -0400
- Ironport-phdr: 9a23:orfSDhbPpWgNkLd6wTCpNYj/LSx+4OfEezUN459isYplN5qZrsu/bnLW6fgltlLVR4KTs6sC0LuG9fi4EUU7or+5+EgYd5JNUxJXwe43pCcHRPC/NEvgMfTxZDY7FskRHHVs/nW8LFQHUJ2mPw6arXK99yMdFQviPgRpOOv1BpTSj8Oq3Oyu5pHfeQtFiT6+bL9oMBm6sRjau9ULj4dlNqs/0AbCrGFSe+RRy2NoJFaTkAj568yt4pNt8Dletuw4+cJYXqr0Y6o3TbpDDDQ7KG81/9HktQPCTQSU+HQRVHgdnwdSDAjE6BH6WYrxsjf/u+Fg1iSWIdH6QLYpUjm58axlVAHnhzsGNz4h8WHYlMpwjL5AoBm8oxBz2pPYbJ2JOPZ7eK7WYNEUSndbXstJVyJOHoyzYYUSAeQfPuhVtIb9q0cLrRakGQWgGOHixzlVjXH2x6061OEhHBnb0gw8Ad0OrmrbrNPoP6gSS++1yK3Iwi/fYPxIxDzw75PIcgsvoPyXXLJwbNDdxlcyGAPYl1idr5HuMT2S1uQIqWeb7uxgWPqhi24gsQF9uCSgxsApioXRh4Ia1EzE9StjzIYyP924R1Z3Yd+iEJtLqyGaLZZ2Td8+Q2F1oiY11KcKtoK8fCgPzpks2h3Ra+SffoSW/h7vSPudLDJliH9mZr2yhBO/8UauyuHgSsW51UhGoyRAn9TJtn0Byhre4dWdRPRn5EeuwzOP2hjT6u5aJUA0krLWK5s7zb4xkpofq1jMHjPql0nsg6+WbEMk+u+05Oj9Y7Xmu4WQOJFphQHjKqgum8q/DvokMgUWQWSX5fiw2KDm8EHkQ7hFkP47n6zXsJDUOcgXuqu0DxFb34sm7huyDyqq3MwdnXYdLVJFfByHj5LuO1HLOP34Fuy/glq3nTdq2vDKJKPuDYjQLnTbirfuYa5961JAyAo01d1f54pUCr8fL/L9VE/+qsbYAwQ4Mwyy3+boFs991oUAVmKTHKOVKr3dvkKV5ug3OemDeJcVuCrhK/gi//Pui2M5lkUBcqSy2ZsXaWu4Huh9I0mHe3bsg9EBEXsUsQokSuzllkGCXSBJa3msQq08+ykxCJi6AofbWoCtnLuB0T+gHpJIem9GF0qMEXb0d4SEQvsNZi2SL9RlkjwFTrihV5Qh2Q+0uA/7zbpnMvTb+jcetZ39yNh5+fffmg8v+jxpXIyh1DSWQmpphGIUVnop04h+p1Bw0FGOzfI+jvBFUZR129piGlM8KZfX5+18F93oXA/dJJGEREvwEfu8BjRkdc483dIIK3l0H9GrhR2LizGxHJcUivqGCIFiofGU5GT4O8sokyWO76ImlVRzB5IXbWA=
For the last year I’ve been investigating approaches to mitigate the effects of a university-wide Internet outage. Like many universities, IU has systems hosted locally, as well as in the cloud. Sometimes these systems are interdependent. For example, our web single sign-on is hosted locally, however it’s require to access cloud-based applications (e.g., box, canvas, etc.). During an Internet outage, students/faculty/staff wouldn’t be able to access canvas from their home Internet connections, as they wouldn’t be able to access their campus-based web sign-on. On campus, canvas would also be inaccessible, as it’s hosted in the cloud. I’ve categorized mitigation approaches into two broad use cases: providing access to critical applications for users off-campus, and access to applications on-campus. Delivering cloud-based applications to on-campus users during an Internet outage seems straightforward: establish a dedicated/isolated/direct connection to critical cloud providers such as AWS (AWS hosts canvas). On-campus access to canvas fixed!.....not so much. Canvas’s domain is instructure.com. The campus DNS resolver will provide an answer from its cached entry for a while, perhaps an hour, but afterwards the resolver is going to need to actually recursively query instructure.com. That might work for a while...but it get worse. At some point the resolver is going to want to query the TLD server for .com, and ultimately a DNS root server. If the university only has access to AWS (remember all Internet access is down), unless the university is hosting a local root and .TLD (which is an option), the dedicated connection to AWS is going to become useless. It’s going to get better. BIND 9.12 (currently in beta, GA due out end of year?) supports “serve stale” (see: https://tools.ietf.org/html/draft-tale-dnsop-serve-stale-02). Serving Stale Data to Improve DNS Resiliency - does what you’d expect. If the resolver can’t update a cached entry, it responsed with the its current cached entry. BTW, this would have mitigated the October Dyn outage, which left many in the community without access to Box, PayPal, etc., despite the fact that we had working network paths to these service providers. I’m interested to hear if/how others are planning for prolonged Internet disruptions. Would a working group be useful? Thanks, steve |
Attachment:
smime.p7s
Description: S/MIME cryptographic signature
- [Security-WG] DNS Serving Stale to the rescue?, Steven Wallace, 11/02/2017
- [Security-WG] Re: [NTAC] DNS Serving Stale to the rescue?, Bill Owens, 11/03/2017
- [Security-WG] Re: [NTAC] DNS Serving Stale to the rescue?, David Farmer, 11/03/2017
- [Security-WG] Re: [NTAC] DNS Serving Stale to the rescue?, Steven Wallace, 11/03/2017
- [Security-WG] Re: [NTAC] DNS Serving Stale to the rescue?, Akbar Kara, 11/03/2017
- [Security-WG] Re: [NTAC] DNS Serving Stale to the rescue?, Steven Wallace, 11/03/2017
- [Security-WG] Re: [NTAC] DNS Serving Stale to the rescue?, Dave Diller, 11/03/2017
- [Security-WG] Re: [NTAC] DNS Serving Stale to the rescue?, Brad Fleming, 11/03/2017
- [Security-WG] Re: [NTAC] DNS Serving Stale to the rescue?, Steven Wallace, 11/03/2017
- Re: [Security-WG] Re: [NTAC] DNS Serving Stale to the rescue?, David Farmer, 11/03/2017
- [Security-WG] Re: [NTAC] DNS Serving Stale to the rescue?, Brad Fleming, 11/03/2017
- [Security-WG] Re: [NTAC] DNS Serving Stale to the rescue?, Jeff Bartig, 11/03/2017
- [Security-WG] Re: [NTAC] DNS Serving Stale to the rescue?, Dave Diller, 11/03/2017
- [Security-WG] Re: [NTAC] DNS Serving Stale to the rescue?, Steven Wallace, 11/03/2017
- [Security-WG] Re: [NTAC] DNS Serving Stale to the rescue?, Akbar Kara, 11/03/2017
- [Security-WG] Re: [NTAC] DNS Serving Stale to the rescue?, Bill Owens, 11/03/2017
Archive powered by MHonArc 2.6.19.