한국정보통신 로고

sub visual sub visual sub visual sub visual sub visual sub visual sub visual sub visual sub visual sub visual

DNS Security

ADONIS(Service Platform)

DNS/DHCP Appliance

· DNS/DHCP-dedicated OS with enhanced security
· Provide compatibility on all BIND versions
· IPv4, IPv6 DNS/DHCP supported
· Check DNS&DHCP setting via error check utility
· linkage with certificated systems, including Active Directory, LDAP
· Automated security patches and firmware updates
· Fully centralized management via the Proteus management platform
· High-performance hardware
1.Increase of devices using IP
Increase of end-point devices connected to the network
- Scanner & Printer server and desktops
- Netbook & 3G Phones & Mobile devices
Need transition of IPv4 -> IPv6
- more than 95% use of IPv4 addresses
- IPv4 addresses were all used up in 2012
In transition of IPv4 -> IPv6, integration and management for the mixed IP system is required!



2.DNS Attack
DNS DDoS Attack
- Generate excessive DNS queries through devices infected to the Bot, and overload of the DNS service
Cache Poisoning
- Attacks exploiting the cache information of the DNS server
- Obtain user information by directing to the attacker's website, but not the normal homepage
- Each domain information can be modified through cache poisoning attacks for DDoS attacks
Domain Redirect
- Directed to harmful URL by attackers
- Such as Malware, Exploits attacks
Server Attacks
- DNS Service vulnerabilities
- OS vulnerabilities



3.DNSSEC
DNSSEC
- Domain Name System Security Extensions
- Services
Through authentication using the encrypted key values with the externally open DNS servers, check the reliability each other
Distribution and management of the authentication key values
Challenge
- Need the continuous management, such as periodic key generation, replacement, zone signatures and zone information updates
- Increase of DNS server load due to the increase of the processing amount of data



Feature Characteristics/Merits
Easy GUI Interface fast and convenient DNS/DHCP management via AMC
Support initial installation via wizard fast DNS/DHCP configuration design via setup wizard
Support initial installation via wizard fast DNS/DHCP configuration design via setup wizard
Data Validation validity & error verification on DNS/DHCP setting
( ex : PTR record automatic generation )
Powerful Security Adonis’s basic setting is comprised by DNS security policies
(own firewall, DOS & DNS infecting attack defense, DNSSEC feature, Auto-patch)
Transaction Signature (TSIG) Rapidly implement the most effective feature, TSIG to prevent DNS spoofing
Undo/Redo Support setting feature via Undo/Redo feature
High Availability (xHA) Automation and ensured availability for DNS/DHCP services
Integrated Active Directory Adonis is easily integrated with AD. Adonis provides higher availability and reliability than Windows DNS / DHCP Services

한국정보시스템 로고

22, Gukhoe-daero 70-gil, Yeongdeungpo-gu, Seoul(150-871 Geumgang Bldg. 8F, Yeouido-gu)  TEL : +82-2-2162-1000  FAX : +82-2-2162-1009
Branch Address : 66,210 Dunsanjung-ro, Seo-gu, Daejeon  Branch Tel : +82-42-485-0788  Branch Fax : +82-42-485-0784
www.kis.co.kr  CEO : Won Bae Jeon   Main Businessman registered number: 107-88-02893  Branch Businessman registered number : 314-85-51763
Copyright (C) 2014 KIS All Right Reserved.