Monash University · FACULTY OF CYBERSECURITY

FIT5037 Chap.4 DNS Security and Name Resolution

- one subject, every graph, every model, every mark
5 Chapters3-page Bible
Our own words - no uploaded lecturer files
Updated for this semester
Chapter 4 of 11 · FIT5037

DNS Security and Name Resolution

Define domain name system

The course material gives this chapter a concrete anchor: Week 4 focuses on DNS operation, attacks and security. That domain name system anchor controls how cache poisoning is explained and how DNSSEC is tested in changed practice.

DNS Security and Name Resolution turns domain name system, cache poisoning and DNSSEC into executable reasoning.

The chapter's practical target is to trace a query through stub, recursive and authoritative roles and test spoofing controls, so every explanation should connect syntax to program state, control flow and observable output.

Treat domain name system as a precise program object, not a loose label.

Identify the value or responsibility of domain name system before execution, then trace what can read it, change it or depend on it. This makes state changes visible before they become debugging guesses.

Use cache poisoning to explain the program's next move. Work through one representative cache poisoning input by hand and name the branch, iteration or call that follows.

If the cache poisoning trace cannot be stated, the code may run by accident rather than by understood design.

Trace cache poisoning

Bring in DNSSEC as the test of structure.

Compare normal, boundary and invalid inputs for DNSSEC; state the expected behaviour first; then use the mismatch between expectation and result to localise the defect.

For the application — trace a query through stub, recursive and authoritative roles and test spoofing controls — write the smallest complete example that exposes the rule.

Explain why the DNSSEC result works, what would break it and how the program should signal or recover from that failure.

Before running an example involving domain name system, make a trace table with the important state before and after each operation. Include the value associated with domain name system, the control decision governed by cache poisoning and the output or object affected by DNSSEC.

The domain name system table turns an unexplained result into a sequence that can be tested one transition at a time.

Test three inputs: an ordinary case, a boundary case and an invalid case. State the expected DNSSEC result for each before execution, then compare it with what the program actually does.

A useful test of cache poisoning isolates one rule; changing several conditions at once cannot reveal which condition caused the failure.

Test with DNSSEC

Practise explaining the solution without reading the code.

For fit5037, name the data representation, the control flow, the responsibility of each function or class and the reason the chosen design supports trace a query through stub, recursive and authoritative roles and test spoofing controls.

This DNSSEC rehearsal matters when a written test or interview asks why the program works rather than whether it produces one correct output.

A complete response should make the task visible before the detail: identify what must be decided, define the relevant terms, connect the evidence to cache poisoning, and use DNSSEC to test the result.

The final sentence about DNSSEC should answer the question actually asked rather than merely repeat the topic.

The controlling limit is specific: Dnssec authenticates data but does not by itself provide confidentiality or service availability.

Keep that DNSSEC limit beside the worked example, because it separates a careful fit5037 answer from one that sounds confident but claims more than the task or evidence supports.

For revision, retrieve domain name system, cache poisoning and DNSSEC without notes, explain their relationship aloud, then complete a changed version of the application: trace a query through stub, recursive and authoritative roles and test spoofing controls.

Record the first failed cache poisoning reasoning move and repair it before attempting another case.

In this chapter

What this chapter covers

  • 01

    domain name system

  • 02

    cache poisoning

  • 03

    DNSSEC

  • 04

    Applying domain name system

  • 05

    Limits of cache poisoning and DNSSEC

Worked example · free

Analyse a poisoned resolver

Q [4 marks]. AskSia-authored practice. Users are redirected to a fake bank site after a resolver accepts a forged response. Where can controls act?
  • 1Trace the original query and competing responses.
  • 1Identify cache acceptance and bailiwick checks.
  • 1Apply DNSSEC validation where signed.
  • 1Add monitoring, cache hygiene and endpoint certificate validation.
Resolver hardening and DNSSEC can prevent unauthenticated data acceptance, while TLS identity validation and monitoring provide independent protection if resolution is attacked.
Sia tip — Layered controls matter because name resolution and service authentication are different claims.
Glossary

Key terms

domain name system
Distributed hierarchical system mapping names to resource records through authoritative and recursive resolution. This chapter uses the concept when students trace a query through stub, recursive and authoritative roles and test spoofing controls. Use this definition when the task is to trace a query through stub, recursive and authoritative roles and test spoofing controls.
cache poisoning
Insertion of false DNS data into a resolver cache so later clients receive attacker-chosen answers. It helps explain the reasoning required to trace a query through stub, recursive and authoritative roles and test spoofing controls. Use this definition when the task is to trace a query through stub, recursive and authoritative roles and test spoofing controls.
DNSSEC
Signature framework that authenticates DNS data origin and integrity through a chain of trust. Its limit matters because DNSSEC authenticates data but does not by itself provide confidentiality or service availability. Use this definition when the task is to trace a query through stub, recursive and authoritative roles and test spoofing controls.
FAQ

DNS Security and Name Resolution FAQ

What is the main task in DNS Security and Name Resolution?

Trace a query through stub, recursive and authoritative roles and test spoofing controls.

How do domain name system and cache poisoning work together?

Use domain name system to establish the object or condition, then use cache poisoning to explain how it changes the outcome being analysed.

What must a fit5037 answer qualify here?

Dnssec authenticates data but does not by itself provide confidentiality or service availability.

How should I revise DNS Security and Name Resolution?

Retrieve domain name system, cache poisoning and DNSSEC, apply them to a changed case, and correct the first point where the evidence no longer supports the conclusion.

Study strategy

Assessment move

Reconstruct the relationship among domain name system, cache poisoning and DNSSEC; complete the chapter application without notes; then test the result against this limit: Dnssec authenticates data but does not by itself provide confidentiality or service availability.

Working through DNS Security and Name Resolution in FIT5037? Sia is AskSia’s AI Cybersecurity tutor — ask any FIT5037 DNS Security and Name Resolution question and get a clear, step-by-step explanation grounded in how FIT5037 is taught and assessed. Read this chapter free, then take your hardest questions to Sia.

A+Everything unlocked
Unlocks this Bible + all 69 of your Monash University subjects - and 1,000+ Bibles across every Australian university.
Sia - your FIT5037 tutor, unlimited, worked the way the exam marks it
The full 3-page Bible + practice bank with worked solutions
Chrome extension - sync your LMS so Sia knows your deadlines
Bilingual EN / Chinese on every Bible and every Sia answer
$0.99 Trial
30-day money-back · cancel in one tap · how it works
Unlock the full FIT5037 Bible + 69 Monash University subjects
$0.99 Trial