GB/T 33562-2017 in English
VALIDInformation security technology―Secure domain name system deployment guide
- Issued on:2017-05-12
- Implemented on:2017-12-01
- File Format:PDF
- Delivery:Via email within 1~3 business days
$243.00
《GB/T 33562-2017信息安全技术 安全域名系统实施指南》由TC260(全国网络安全标准化技术委员会)归口,主管部门为国家标准化管理委员会。
Introduction
National Standard of the People's Republic of China GB/T 33562—2017
Information Security Technology Security Domain Name System Implementation Guide
| Standard Dimensions | Authoritative Domain Name System | Recursive Domain Name System | DNS Transaction Security |
|---|---|---|---|
| Security Requirements | Follow the requirements of 5.1 of GB/T 33134—2016 and ensure that the server is only configured for DNS traffic processing. | Comply with the requirements of 5.2 of GB/T 33134—2016 and restrict the operation of other services. | Data integrity verification is achieved through TSIG specifications and DNSSec mechanisms. |
| Software requirements | Run the latest version of BIND software and pay attention to vulnerability fixes and patch updates. | Use limited user permissions to run recursive domain name system resolution software. | Configure the rejection of version responses to prevent information leakage. |
| Key management | Generate and store public and private key pairs to ensure the safe storage of private keys. | Protect dynamic updates and zone transfer transactions through TSIG specifications. | Regularly rotate keys (ZSK and KSK) and set pre-release policies. |
DNS Security Technical Guide Interpretation
With the development of network attack technology, DNS vulnerabilities have become a major threat to network security. As the core solution to this problem, the DNSSec protocol requires security extensions to be deployed at every step from the root zone to the final domain name.
Authoritative Domain Name System Security Guide
- Authoritative domain name servers need to be security tested and hardened to ensure that only DNS traffic processing is configured.
- The operating system follows the principle of minimum installation and patches are updated in a timely manner.
- Restrict the source of DNS transaction requests through access control lists (ACLs).
Recursive Domain Name System Security Guide
- Recursive domain name servers need to enhance their ability to support large data packets and improve port randomness.
- Configure the time synchronization service (NTP) to ensure clock consistency.
- Restrict client access rights to prevent cache poisoning attacks.
DNS Security Implementation Recommendations
Based on the GB/T 33562-2017 standard, the following implementation recommendations are for reference:
- Key management strategy: Implement a strict key generation, storage and rotation mechanism to ensure the validity period and pre-release strategy of ZSK and KSK.
- Zone file signature: Regularly check the signature status of the zone file, and perform incremental or complete re-signing in a timely manner to avoid the risk of signature expiration.
- Trust chain establishment: Configure my country's DNSSec trust source as a trust anchor point, and verify the authenticity of the public key through DS resource records.
- Monitoring and response: Establish a DNS security event monitoring mechanism to respond to key leaks and attacks in a timely manner.

Loading PDF document...
Error loading PDF. Please make sure the file is valid and try again.
We also recommend
-

GB/T 45240-2025 in English
General requirements for device-independent quantum random number generators
2025-01-24 -

GB/T 15278-1994 in English
Information processing-Data encipherment-Physical layer interoperability requirements
1994-01-02 -

GB/T 32905-2016 in English
Information security technology SM3 cryptographic hash algorithm
2016-08-29 -

GB/T 32213-2015 in English
Information security technology―Public key infrastructure―Specification for remote password authentication and key establishment
2015-12-10 -

GB/T 29828-2013 in English
Information security technology―Trusted computing specification―Trusted connect architecture
2013-11-12 -

GB/T 20979-2019 in English
Information security technology—Technical requirements for iris recognition system
2019-08-30 -

GB/Z 24294.1-2018 in English
Information security technology—Guide of implementation for internet-basede-government information security—Part 1:General
2018-03-15