Protecting the domain name system
The suggestions are:
- Make copies of the root DNS zone files available, and disperse them
everywhere.
- Create multiple roots for the DNS system.
- Create an early warning system which raises the alarm when it detects
the beginning of a denial of service attack.
- Create a set of canned router filters which can be quickly applied to
protect the root DNS servers in case of an attack.
- Have a plan for moving a root server elsewhere on the Internet should
that server come under attack.
- Create alternative DNS server software, so that not everybody is running bind.
All of these suggestions make sense, of course, in many contexts other than
the domain name system. It is important to replicate crucial data, spread
your vital resources out, have fallback plans, and to have a diverse
software base. We will see whether these ideas are actually heard by the
DNS Powers That Be, however.
