« 欧州 EDPB AIプライバシーのリスクと緩和 大規模言語モデル(LLM) (2025.04.10) | Main | JALがIATAの航空保安管理の国際認証(Operating Leve2)取得 (2025.04.10) »

2025.04.14

米国 NIST SP 800-81 Rev.3(初期公開ドラフト)安全なドメインネームシステム(DNS)展開ガイド (2025.04.10)

こんにちは、丸山満彦です。

NISTが SP 800-81 安全なドメインネームシステム(DNS)展開ガイドの第3版の初期ドラフトを公開し、意見募集をしていますね...

SP800-81は、2006年に初版、2010年に改訂第1版、2013年に改訂第2版が公開され、12年ぶりに改訂第3版のドラフトが公開されたというかんじですね...

改訂のポイントは、最新技術の反映(DNSSEC(DNS Security Extensions)の最新仕様や、DoH(DNS over HTTPS)、DoT(DNS over TLS)などの暗号化プロトコルへの対応など)、脅威モデルの更新(例:DDoS攻撃、DNSキャッシュポイズニング、データ改ざん)に対応したリスク評価と対策の追加、自動化と管理の強化、相互運用性の向上、パフォーマンス最適化などのようです...

 

● NIST - ITL

・2025.04.10 NIST SP 800-81 Rev. 3 (Initial Public Draft) Secure Domain Name System (DNS) Deployment Guide

 

NIST SP 800-81 Rev. 3 (Initial Public Draft) Secure Domain Name System (DNS) Deployment Guide NIST SP 800-81 Rev.3(初期公開ドラフト)安全なドメインネームシステム(DNS)展開ガイド
Announcement 発表
The Domain Name System (DNS) plays an integral role in every organization’s security posture by translating domain names into IP addresses. It can serve as an enforcement point for enterprise security policy and an indicator of potential malicious activity on a network. A disruption or attack against the DNS can impact an entire organization ドメインネームシステム(DNS)は、ドメイン名をIPアドレスに変換することにより、あらゆる組織のセキュリティ態勢において不可欠な役割を果たしている。DNSは、エンタープライズ・セキュリティ・ポリシーの実施ポイントとして、またネットワーク上の潜在的な悪意のある活動の指標として機能する。DNSに対する混乱や攻撃は、組織全体に影響を与える可能性がある。
NIST Special Publication (SP) 800-81r3 (Revision 3), Secure Domain Name System (DNS) Deployment Guide, describes the different roles of DNS and gives recommendations for protecting the integrity, availability, and confidentiality of DNS services, including: NIST特別刊行物(SP)800-81r3(改訂3)「安全なドメインネームシステム(DNS)展開ガイド」は、DNSのさまざまな役割を説明し、DNSサービスの完全性、可用性、および機密性を保護するための推奨事項を示している:
1. The role DNS plays in supporting a zero trust architecture, such as serving as both a policy enforcement point (PEP) and a source for information when evaluating access requests 1. DNS がゼロトラスト・アーキテクチャをサポートする上で果たす役割(ポリシー実施 ポイント(PEP)とアクセス要求を評価する際の情報源の両方としての役割など)
2. The role of hosting DNS information (authoritative DNS), including guidance on protecting the integrity and authenticity of DNS information using DNSSEC 2. DNSSEC を使用した DNS 情報の完全性と防御に関するガイダンスを含む、DNS 情報(権威 DNS)をホスティングする役割
3. The role of recursive DNS, including guidance on protecting the confidentiality of client DNS queries 3. クライアントDNSクエリの機密保護に関するガイダンスを含む、再帰DNSの役割
Abstract 概要
This document provides Domain Name System (DNS) deployment guidelines to secure the DNS protocol and infrastructure, mitigate misuse or misconfiguration, and provide an additional layer of network security as part of a zero trust and/or defense-in-depth security risk management approach. This introduction briefly discusses relevant context for DNS and examines the changing threat landscape that has warranted an updated approach to DNS deployment. 本文書は、DNSプロトコルとインフラストラクチャを保護し、誤用や設定ミスを緩和し、 ゼロトラストおよび/または徹底防御のセキュリティリスクマネジメントの一環として、 ネットワークセキュリティの追加レイヤーを提供するためのドメインネームシステム(DNS)展開 ガイドラインを提供する。序文では、DNSに関連する背景を簡単に説明し、DNS展開のアプローチを更新する理由となった 脅威の状況の変化について検討する。

 

・[PDF

20250414-55353

 

エグゼクティブサマリー...

Executive Summary エグゼクティブサマリー
The Domain Name System (DNS) [1][2] is a standardized way of translating machine-readable IP addresses (e.g., 129.6.13.49) to human-readable ones (e.g., nist.gov). It is commonly deployed within an organization's networks to facilitate the internal functions of those intranets. DNS is also deployed and maintained across critical internet infrastructure at a high level to enable the core functionalities of the internet on almost every network at every scale. Its centralized position enables it to act as a foundational layer of network security in zero trust and defense-in-depth security risk management approaches. Such DNS services are often referred to as Protective DNS deployments and are a key consideration in securing organizational networks. ドメインネームシステム(DNS)[1][2]は、機械が読み取り可能なIPアドレス(例:129.6.13.49)を人間が読み取り可能なもの(例:nist.gov)に変換する標準的な方法である。DNSは一般的に組織のネットワーク内に展開され、イントラネットの内部機能を促進する。DNSはまた、重要なインターネットインフラ全体にも高いレベルで展開・維持されており、ほぼすべてのネットワークで、あらゆる規模のインターネットの中核機能を実現している。その一元的な位置づけにより、ゼロトラストおよび徹底防御のセキュリティリスクマネジメントアプローチにおいて、ネットワークセキュリティの基礎層として機能することができる。このようなDNSサービスはしばしば防御DNS展開と呼ばれ、組織ネットワークの安全性を確保する上で重要な考慮事項である。
This revision of Special Publication (SP) 800-81 acknowledges these changes in the role of DNS provides modern guidance on DNS deployments with the following high-level recommendations for network and security owners: この特別公示(SP)800-81の改訂版は、DNSの役割におけるこのような変化を認識し、DNSの展開に関する最新のガイダンスを提供し、ネットワークおよびセキュリティの所有者に対して、以下のハイレベルの推奨を行う:
• Employ Protective DNS wherever technically feasible to provide additional network-wide security capabilities that include: - 技術的に可能な限り防御DNSを採用し、以下のようなネットワーク全体のセキュリティ機能を追加する:
○ Blocking harmful or malicious traffic in real time ○ 有害または悪質なトラフィックをリアルタイムでブロックする
○ Filtering out categories of traffic that do not conform to the organization's policies ○ 組織のポリシーに適合しないトラフィックのカテゴリーをフィルタリングで除外する
○ Generating real-time and historical DNS query and response data to facilitate digital forensics and incident response ○ リアルタイムおよび履歴のDNSクエリおよびレスポンスデータを生成し、デジタルフォレンジックおよびインシデントレスポンスを容易にする
○ Integrating with the wider security ecosystem as part of a defense-in-depth or zero trust approach ○ 深層防御またはゼロトラストアプローチの一環として、より広範なセキュリティエコシステムと統合する
○ Facilitating the organization's responsibility to comply with regulatory or contractual requirements for blocking traffic to disallowed sites (e.g., copyright violations, legal restrictions) 許可されていないサイトへのトラフィックをブロックするための規制上または契約上の要件(著作権違反、法的制限など)を遵守する組織の責任を促進する。
• Encrypt internal and external DNS traffic wherever feasible - 可能な限り、内部および外部のDNSトラフィックを暗号化する
• Deploy dedicated DNS servers to reduce attack surfaces - 攻撃サーフェスを減らすために、専用のDNSサーバを展開する
• Follow all technical guidance on ensuring that DNS deployments and the DNS protocol are as secure and resilient as possible - DNSの展開とDNSプロトコルを可能な限り安全かつレジリエンスに優れたものにするための技術ガイダンスにすべて従う。

 

目次...

Executive Summary エグゼクティブ・サマリー
1. Introduction 1. 序文
1.1. Domain Name Systems 1.1. ドメインネームシステム
1.2. Impact of DNS on Cyber Resiliency, Defense-in-Depth, and Zero Trust 1.2. サイバーレジリエンス、深層防衛、ゼロトラストにおけるDNSの影響
1.2.1. DNS Use Cases for Operational Technology, Internet of Things Devices, and Critical Infrastructure 1.2.1. 運用技術、IoT機器、重要インフラにおける DNS の使用例
1.3. Using This Guide 1.3. 本ガイドの使用
1.4. Audience 1.4. 想定読者
2. DNS as a Component of an Organization's Security Strategy 2. 組織のセキュリティ戦略の構成要素としてのDNS
2.1. Protective DNS 2.1. 防御DNS
2.1.1. Threat Intelligence and Telemetry 2.1.1. 脅威インテリジェンスとテレメトリ
2.1.2. Name Resolution Filtering 2.1.2. 名前解決フィルタリング
2.1.3. DNS for Digital Forensics and Incident Response 2.1.3. デジタルフォレンジックとインシデントレスポンスのためのDNS
2.2. Protecting the DNS Protocol 2.2. DNS プロトコルの防御
2.2.1. Protecting the Integrity of DNS Services 2.2.1. DNS サービスの完全性の防御
2.2.2. Using Encrypted DNS and Authentication to Protect the Protocol 2.2.2. プロトコルを保護するための暗号化DNSと認証の使用
2.2.3. DNS Hygiene and Best Practices 2.2.3. DNSの衛生とベストプラクティス
2.3. Protecting the DNS Service and Infrastructure 2.3. DNSサービスとインフラの防御
2.3.1. Dedicated DNS Services 2.3.1. 専用DNSサービス
2.3.2. Resiliency and High Availability of DNS Servers 2.3.2. DNS サーバーのレジリエンスと高可用性
2.3.3. Interoperability of the Protective DNS Ecosystem 2.3.3. 防御DNSエコシステムの相互運用性
3. Managing Threats to Authoritative Services 3. 認可サービスへの脅威の管理
3.1. Zone Transfer Threats and Protection Approaches 3.1. ゾーン転送の脅威と防御アプローチ
3.1.1. Restricting Zone Transfer Transaction Entities 3.1.1. ゾーン転送のトランザクション事業体の制限
3.2. Zone Content Threats and Protection Approaches 3.2. ゾーンコンテンツの脅威と防御のアプローチ
3.2.1. Lame Delegations 3.2.1. Lame Delegations
3.2.2. Zone Drift and Zone Thrash 3.2.2. ゾーンドリフトとゾーンスラッシュ
3.3. Dynamic Update Threats and Protection Approaches 3.3. 動的更新の脅威と防御アプローチ
3.3.1. Dynamic Update Misuse 3.3.1. 動的更新の悪用
3.3.2. Guidance on Securing Dynamic Updates 3.3.2. 動的アップデートの保護に関する指針
3.4. DNS NOTIFY Threats and Protection Approaches 3.4. DNS NOTIFY 脅威と防御のアプローチ
3.4.1. DNS NOTIFY Misuse Threats 3.4.1. DNS NOTIFY の悪用 脅威
3.4.2. DNS NOTIFY Protection 3.4.2. DNS NOTIFY の防御
3.5. Minimizing Information Leakage 3.5. 情報漏洩の最小化
3.5.1. Resource Record Information 3.5.1. リソースレコード情報
3.6. External Authoritative Domain Integrity 3.6. 外部権威ドメインの完全性
3.6.1. Dangling CNAME Exploitation 3.6.1. Dangling CNAME の悪用
3.6.2. Lame Delegation Exploitation 3.6.2. Lame Delegationの悪用
3.6.3. Look-Alike Domain Exploitation 3.6.3. Look-Alike ドメインの悪用
3.7. Operational Recommendations 3.7. 運用上の推奨事項
3.7.1. Resource Record TTL Value Recommendation 3.7.1. リソースレコードのTTL値に関する推奨事項
3.8. DNSSEC Signing Considerations for Authoritative Service 3.8. 認可サービスにおけるDNSSEC署名の考慮事項
3.8.1. DNSSEC Key Considerations 3.8.1. DNSSEC鍵に関する考察
3.8.2. Using RRSIG Validity Periods to Minimize Key Compromise 3.8.2. 鍵の漏洩を最小化するためのRRSIGの妥当性確認期間の使用
3.8.3. Hashed Authenticated Denial of Existence 3.8.3. ハッシュ認証された存在拒否
3.8.4. DNSSEC Algorithm Migration 3.8.4. DNSSECアルゴリズムの移行
3.8.5. DNSSEC Signing Internal Zones 3.8.5. DNSSEC署名の内部ゾーン
4. Recursive/Forwarding Service and Stub Resolvers 4. 再帰/フォワーディングサービスとスタブリゾルバー
4.1. Threats to Recursive/Forwarding Service 4.1. 再帰/転送サービスに対する脅威
4.2. Recommendations for Protection 4.2. 防御のための推奨事項
4.2.1. Encrypted DNS 4.2.1. 暗号化DNS
4.2.1.1. Encrypted DNS Guidance and Recommendations 4.2.1.1. 暗号化DNSのガイダンスと推奨事項
4.2.1.2. Considerations for Using Encrypted DNS 4.2.1.2. 暗号化DNSの使用に関する考慮事項
4.2.1.3. Cryptographic Guidance 4.2.1.3. 暗号化ガイダンス
4.2.2. Restricting the Use of DNS With Public Providers 4.2.2. 公共プロバイダによるDNS使用の制限
4.2.3. Detecting and Mitigating Data Exfiltration via DNS 4.2.3. DNS経由のデータ流出の検知と緩和
4.2.4. Enabling DNSSEC Validation 4.2.4. DNSSECの妥当性確認の有効化
4.2.5. Maintaining DNSSEC Trust Anchors 4.2.5. DNSSECトラストアンカーの維持
4.3. Operational Recommendations 4.3. 運用上の推奨事項
5. Stub Resolvers 5. スタブリゾルバー
5.1. Securing the Stub Resolver 5.1. スタブリゾルバの保護
5.2. DNSSEC Considerations for Stub Resolver 5.2. スタブリゾルバーのDNSSECに関する考慮事項
5.2.1. Recommendations for Providing Service to Mobile Hosts 5.2.1. モバイルホストにサービスを提供するための推奨事項
References 参考文献
Appendix A. DNS Protocol Tutorial 附属書A. DNSプロトコルチュートリアル
A.1. DNS Namespace and Infrastructure A.1. DNSネームスペースとインフラ
A.2. DNS Queries and Responses A.2. DNSクエリと応答
Appendix B. Glossary 附属書B. 用語集
List of Tables 表の一覧
Table 1. DNSSEC key parameters based on algorithm 表1. アルゴリズムに基づくDNSSECの鍵パラメータ
Table 2. Trust anchor selection 表2. トラストアンカーの選択
List of Figures 図の一覧
Fig.1. Enterprise using cloud-based Protective DNS with a local forwarder 図1. クラウドベースの防御DNSとローカルフォワーダーを使用するエンタープライズ
Fig.2. Mixed use of DoH and Legacy DNS over UDP port 53 (Do53) 図2. UDPポート53(Do53)を介したDoHとレガシーDNSの混在使用
Fig.3. DNS tree 図3. DNSツリー
Fig.4. DNS resolution 図4. DNS resolution

 

ちなみに2006年の初版(廃止されていますが...)はIPAで日本語訳が公表されています...

 

SP 800-81 セキュアなドメインネームシステム(DNS)の配備ガイド
Secure Domain Name System (DNS) Deployment Guide

 

 

|

« 欧州 EDPB AIプライバシーのリスクと緩和 大規模言語モデル(LLM) (2025.04.10) | Main | JALがIATAの航空保安管理の国際認証(Operating Leve2)取得 (2025.04.10) »

Comments

Post a comment



(Not displayed with comment.)


Comments are moderated, and will not appear on this weblog until the author has approved them.



« 欧州 EDPB AIプライバシーのリスクと緩和 大規模言語モデル(LLM) (2025.04.10) | Main | JALがIATAの航空保安管理の国際認証(Operating Leve2)取得 (2025.04.10) »