FINDING · DEFENSE

DNSSEC validation naturally prevents DNS injection collateral damage: both .de and .kr sign their results, allowing a validating resolver to reject the unsigned injected reply while awaiting the legitimate signed response. The paper identifies DNSSEC deployment at the TLD level as the most robust structural defense against injection-based collateral damage.

From 2012-sparks-collateralThe Collateral Damage of Internet Censorship by DNS Injection · §5 · 2012 · SIGCOMM Computer Communication Review

Implications

Tags

censors
cn
techniques
dns-poisoning

Extracted by claude-sonnet-4-6 — review before relying.