Computer Network #02-2. Application Layer : DNS

๊น€์„œ์˜ยท2025๋…„ 4์›” 17์ผ
0

์ปดํ“จํ„ฐ๋„คํŠธ์›Œํฌ

๋ชฉ๋ก ๋ณด๊ธฐ
7/15
post-thumbnail

1. DNS ๊ฐœ์š”

์‚ฌ๋žŒ์€ ์—ฌ๋Ÿฌ ์‹๋ณ„์ž๋ฅผ ์‚ฌ์šฉ (ex. ์ฃผ๋ฏผ ๋“ฑ๋ก ๋ฒˆํ˜ธ, ์—ฌ๊ถŒ ๋ฒˆํ˜ธ)

์ธํ„ฐ๋„ท๋„ ๋งˆ์ฐฌ๊ฐ€์ง€๋กœ ํ˜ธ์ŠคํŠธ(host)์™€ ๋ผ์šฐํ„ฐ(router)์— ์‹๋ณ„์ž ํ•„์š”ํ•จ

  • IP address : ๋„คํŠธ์›Œํฌ ์ƒ ๋ฐ์ดํ„ฐ๊ทธ๋žจ ์ „์†ก์— ์‚ฌ์šฉ
    (ex: 192.168.1.1)
  • domain name : ์‚ฌ๋žŒ์ด ์ดํ•ดํ•˜๊ธฐ ์‰ฌ์šด ์‹๋ณ„์ž
    (ex: cs.umass.edu)

Domain Name System (DNS) ์—ญํ• 

IP ์ฃผ์†Œ โ†” ์ด๋ฆ„ ๋งคํ•‘(mapping)์„ ํ•ด๊ฒฐํ•˜๊ธฐ ์œ„ํ•œ ์‹œ์Šคํ…œ
(DNS๋Š” ๊ด€๋ฆฌ ์ฐจ์›์—์„œ ๋ถ„์‚ฐ ์ €์žฅ)

  • Distributed database (๋ถ„์‚ฐ ๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค) ๊ตฌ์กฐ
    ์ˆ˜๋งŽ์€ Name server๋“ค์ด ๊ณ„์ธต ๊ตฌ์กฐ๋ฅผ ์ด๋ฃธ
  • Application-layer protocol๋กœ ๋™์ž‘
    Name server๋ผ๋ฆฌ ์ด๋ฆ„ ํ•ด์„(name resolution)์„ ์œ„ํ•ด ํ†ต์‹ 

2. DNS์˜ ๊ธฐ๋Šฅ๊ณผ ๊ตฌ์กฐ

DNS ๊ธฐ๋Šฅ(์—ญํ• )

  • ํ˜ธ์ŠคํŠธ ์ด๋ฆ„ โ†’ IP ์ฃผ์†Œ ๋ณ€ํ™˜
  • Host Aliasing (ํ˜ธ์ŠคํŠธ ๋ณ„์นญ ์ง€์›)
    (ex. naver.com์€ ์‹ค์ œ ๋‹ค๋ฅธ ์„œ๋ฒ„ ์ฃผ์†Œ๋ฅผ ๊ฐ€์ง)
  • Load Distribution (๋ถ€ํ•˜ ๋ถ„์‚ฐ)
    ํ•˜๋‚˜์˜ ๋„๋ฉ”์ธ ์ด๋ฆ„์— ์—ฌ๋Ÿฌ IP ์ฃผ์†Œ๋ฅผ ์—ฐ๊ฒฐ
    (ex. www.naver.com์ด ์—ฌ๋Ÿฌ ์„œ๋ฒ„์— ๋ถ„์‚ฐ๋˜์–ด ์—ฐ๊ฒฐ๋จ)

DNS ๊ตฌ์กฐ

DNS๋ฅผ ํ•˜๋‚˜์˜ ์ค‘์•™ ์ง‘์ค‘ํ˜• DNS๋กœ ๋งŒ๋“ค์ง€ ์•Š๋Š” ์ด์œ 

  • ํ•˜๋‚˜ ๊ณ ์žฅ๋‚˜๋ฉด ์ „์ฒด ์‹œ์Šคํ…œ ๋‹ค์šด
  • ํŠธ๋ž˜ํ”ฝ ํญ์ฆ : ์ „ ์„ธ๊ณ„ ์š”์ฒญ ํ•œ ๊ณณ์—์„œ ์ฒ˜๋ฆฌ ํž˜๋“ฆ
  • ๊ฑฐ๋ฆฌ ๋ฌธ์ œ : ๋ฌผ๋ฆฌ์  ๊ฑฐ๋ฆฌ๋กœ ์ธํ•ด ์‘๋‹ต ์†๋„ ๋А๋ฆผ
  • ์œ ์ง€ ๋ณด์ˆ˜ ์–ด๋ ค์›€ : ๊ทœ๋ชจ ์ปค์„œ ๊ด€๋ฆฌ ๋ถˆ๊ฐ€๋Šฅ

3. DNS ๊ณ„์ธต ๊ตฌ์กฐ

  • Root DNS Servers
    ์ตœ์ƒ์œ„ ์„œ๋ฒ„, ์ „์ฒด ๊ตฌ์กฐ์˜ ๋ฃจํŠธ
  • Top-Level Domain (TLD) Servers
    .com, .org, .edu ๊ฐ™์€ ์ตœ์ƒ์œ„ ๋„๋ฉ”์ธ ๋‹ด๋‹น
  • Authoritative DNS Servers
    ์‹ค์ œ ๋„๋ฉ”์ธ (ex: amazon.com) ์ •๋ณด๋ฅผ ๊ฐ€์ง€๊ณ  ์žˆ๋Š” ์„œ๋ฒ„

Example. 'www.amazon.com'์˜ IP ์ฃผ์†Œ๋ฅผ ์ฐพ์„ ๋•Œ

1) ํด๋ผ์ด์–ธํŠธ๊ฐ€ Root Server์— ๋ฌธ์˜
Root DNS Server์—๊ฒŒ ๋ฌผ์–ด๋ณด๋ฉด, .com DNS ์„œ๋ฒ„๋ฅผ ์•Œ๋ ค์คŒ

2) ํด๋ผ์ด์–ธํŠธ๊ฐ€ .com ์„œ๋ฒ„์— ๋ฌธ์˜
'.com' DNS ์„œ๋ฒ„์— ๋ฌผ์–ด๋ณด๋ฉด, amazon.com DNS ์„œ๋ฒ„๋ฅผ ์•Œ๋ ค์คŒ

3) ํด๋ผ์ด์–ธํŠธ๊ฐ€ amazon.com ์„œ๋ฒ„์— ๋ฌธ์˜
'amazon.com DNS ์„œ๋ฒ„'์— ์ตœ์ข…์ ์œผ๋กœ ๋ฌผ์–ด๋ด์„œ
www.amazon.com์˜ ์‹ค์ œ IP ์ฃผ์†Œ๋ฅผ ์–ป์Œ


Root Name Servers

๋‹ค๋ฅธ ๋„ค์ž„ ์„œ๋ฒ„๊ฐ€ ์ด๋ฆ„์„ ํ•ด๊ฒฐํ•  ์ˆ˜ ์—†์„ ๋•Œ, ์ตœ์ข…์ ์œผ๋กœ ๋ฌธ์˜ํ•˜๋Š” ์„œ๋ฒ„

Root ์„œ๋ฒ„ ์—†์œผ๋ฉด ์ธํ„ฐ๋„ท ์ด๋ฆ„ ํ•ด์„ ์ž์ฒด๊ฐ€ ๋ถˆ๊ฐ€๋Šฅ
(๋งค์šฐ ์ค‘์š”ํ•œ ์—ญํ• ์„ ํ•จ)

  • ์ „ ์„ธ๊ณ„์— 13๊ฐœ ์กด์žฌ
    (๋ณต์ œ๋ณธ์ด ์ˆ˜๋ฐฑ๊ฐœ ๋ฐฐ์น˜๋˜์–ด์žˆ๋Š” ์ƒํ™ฉ)


Top-Level Domain (TLD) servers

TLD ์„œ๋ฒ„๋Š” ์ตœ์ƒ์œ„ ๋„๋ฉ”์ธ(top-level domain)์„ ๋‹ด๋‹น

  • ์ผ๋ฐ˜ ๋„๋ฉ”์ธ: .com, .org, .net, .edu, .aero, .jobs
  • ๊ตญ๊ฐ€ ๋„๋ฉ”์ธ: .cn(์ค‘๊ตญ), .uk(์˜๊ตญ), .fr(ํ”„๋ž‘์Šค), .ca(์บ๋‚˜๋‹ค), .jp(์ผ๋ณธ), .kr(ํ•œ๊ตญ)

Authoritative DNS servers

์–ด๋– ํ•œ ์กฐ์ง์ด ์†Œ์œ ํ•˜๊ฑฐ๋‚˜, ์„œ๋น„์Šค ์ œ๊ณต์ž๊ฐ€ ์šด์˜ํ•˜์—ฌ
์ตœ์ข… IP Address ๋งคํ•‘ ์ •๋ณด๋ฅผ ์ œ๊ณตํ•˜๋Š” DNS ์„œ๋ฒ„
(์„œ๋น„์Šค ์—…์ฒด๊ฐ€ ์ง์ ‘ ๊ด€๋ฆฌํ•  ์ˆ˜ ์žˆ์Œ)

  • ํŠน์ • ๋„๋ฉ”์ธ์— ๋Œ€ํ•œ ์ •ํ™•ํ•œ IP Address ์ œ๊ณต
    (ex. amazon.com์— ๋Œ€ํ•ด ์‹ค์ œ IP๋ฅผ ์•Œ๊ณ  ์žˆ๋Š” ์„œ๋ฒ„)

Local DNS servers

DNS ๊ณ„์ธต(hierarchy)์— ์ง์ ‘ ์†ํ•˜์ง€๋Š” ์•Š๊ณ , ISP(์ธํ„ฐ๋„ท ์ œ๊ณต์ž), ํšŒ์‚ฌ, ํ•™๊ต ๋“ฑ์—์„œ ์šด์˜
(Root โ†’ TLD โ†’ Authoritative ๊ตฌ์กฐ ์•ˆ์— ์—†๊ณ  ๋ณ„๋„๋กœ ์กด์žฌ)

Local DNS ์„œ๋ฒ„์˜ ์—ญํ• 

  • ํ˜ธ์ŠคํŠธ์˜ DNS ์งˆ์˜๋Š” Local DNS ์„œ๋ฒ„์— ๋จผ์ € ์ „์†ก๋จ
  • Local DNS๊ฐ€ ์บ์‹œ๋ฅผ ํ™•์ธ
    (Name-IP ๋งคํ•‘ ๊ฒฐ๊ณผ๋ฅผ ์ €์žฅํ•ด๋†“๊ณ , ์žˆ์œผ๋ฉด ๋ฐ”๋กœ ์‘๋‹ต)
    (์—†์œผ๋ฉด, ์ƒ์œ„ DNS์— ๋‹ค์‹œ ์งˆ์˜)
  • ํ”„๋ก์‹œ(proxy)์ฒ˜๋Ÿผ ๋™์ž‘
    (์š”์ฒญ์„ ๋Œ€์‹  ๋ฐ›์•„์„œ ์œ„์ชฝ DNS ์‹œ์Šคํ…œ(hierarchy)์œผ๋กœ ์ „๋‹ฌ)

4. DNS ์งˆ์˜ ๋ฐฉ์‹

Iterated Query (๋ฐ˜๋ณต ์งˆ์˜)

๋ฌธ์˜๋ฐ›์€ ์„œ๋ฒ„๊ฐ€ "๋‚˜๋Š” ๋ชฐ๋ผ, ๋Œ€์‹  ์ด ์„œ๋ฒ„์— ๋ฌผ์–ด๋ด!" ํ•˜๊ณ  ๋‹ค๋ฅธ ์„œ๋ฒ„๋ฅผ ์•Œ๋ ค์คŒ

Local DNS ์„œ๋ฒ„๊ฐ€ ์ง์ ‘ ๋‹ค์Œ ์„œ๋ฒ„์—๊ฒŒ ๋ฌผ์–ด๋ณด๋Š” ๋ฐฉ์‹
(์—ฌ๋Ÿฌ ๋ฒˆ ๋ฌผ์–ด๋ณด๊ธฐ์—, ์‹œ๊ฐ„์ด ๋” ๊ฑธ๋ฆด ์ˆ˜ ์žˆ์Œ)

1) Host โ†’ Local DNS ์„œ๋ฒ„(dns.nyu.edu)์— ์งˆ์˜ ๋ณด๋ƒ„

2) Local DNS ์„œ๋ฒ„ โ†’ Root DNS ์„œ๋ฒ„์— ์งˆ์˜
"๋ชฐ๋ผ, .edu TLD ์„œ๋ฒ„์— ๋ฌผ์–ด๋ด"

3) Local DNS ์„œ๋ฒ„ โ†’ .edu TLD ์„œ๋ฒ„์— ์งˆ์˜
"๋ชฐ๋ผ, umass.edu DNS ์„œ๋ฒ„์— ๋ฌผ์–ด๋ด"

4) Local DNS ์„œ๋ฒ„ โ†’ umass.edu DNS ์„œ๋ฒ„์— ์งˆ์˜
"๋ชฐ๋ผ, cs.umass.edu DNS ์„œ๋ฒ„์— ๋ฌผ์–ด๋ด"

5) Local DNS ์„œ๋ฒ„ โ†’ cs.umass.edu ๊ถŒํ•œ ์„œ๋ฒ„์— ์ตœ์ข… ์งˆ์˜

6) cs.umass.edu ์„œ๋ฒ„๊ฐ€ ์ตœ์ข…์ ์œผ๋กœgaia.cs.umass.edu์˜ IP ์ฃผ์†Œ๋ฅผ ๋ฐ˜ํ™˜

7) Local DNS ์„œ๋ฒ„๊ฐ€ ์ด ๊ฒฐ๊ณผ๋ฅผ ์บ์‹œ์— ์ €์žฅ

8) Host์—๊ฒŒ IP ์ฃผ์†Œ๋ฅผ ๋ฐ˜ํ™˜

Recursive Query (์žฌ๊ท€ ์งˆ์˜)

์š”์ฒญ์„ ๋ฐ›์€ ์„œ๋ฒ„๊ฐ€ ์ง์ ‘ ์ตœ์ข… IP ์ฃผ์†Œ๋ฅผ ์ฐพ์•„์„œ ์š”์ฒญ์ž์—๊ฒŒ ๋‹ต์„ ์คŒ

์š”์ฒญ์ž๋Š”(Local DNS ์„œ๋ฒ„) ํ•œ ๋ฒˆ๋งŒ ์š”์ฒญํ•˜๊ณ  ๊ธฐ๋‹ค๋ฆผ
(์š”์ฒญ๋ฐ›์€ ์„œ๋ฒ„๊ฐ€ ์ „์ฒด ํ•ด์„์„ ์ฑ…์ž„์ง)

  • ์ƒ์œ„ ์„œ๋ฒ„๋“ค(Root, TLD)์—๋Š” ๋ถ€ํ•˜๊ฐ€ ์‹ฌํ•ด์งˆ ์ˆ˜ ์žˆ์Œ

1) Host โ†’ Local DNS ์„œ๋ฒ„(dns.nyu.edu)์—๊ฒŒ ์š”์ฒญ

2) Local DNS ์„œ๋ฒ„๊ฐ€ Root ์„œ๋ฒ„์—๊ฒŒ ์š”์ฒญ

3) Root ์„œ๋ฒ„๊ฐ€ .edu TLD ์„œ๋ฒ„์—๊ฒŒ ์š”์ฒญ

4) TLD ์„œ๋ฒ„๊ฐ€ umass.edu ์„œ๋ฒ„์—๊ฒŒ ์š”์ฒญ

5) umass.edu ์„œ๋ฒ„๊ฐ€ cs.umass.edu ๊ถŒํ•œ ์„œ๋ฒ„์—๊ฒŒ ์š”์ฒญ

6) cs.umass.edu ์„œ๋ฒ„๊ฐ€ ์ตœ์ข…์ ์œผ๋กœ gaia.cs.umass.edu์˜ IP ์ฃผ์†Œ๋ฅผ ์‘๋‹ต

7) ๊ฒฐ๊ณผ๋ฅผ ๊ฑฐ์Šฌ๋Ÿฌ ์˜ฌ๋ผ์™€์„œ Local DNS ์„œ๋ฒ„๊นŒ์ง€ ์ „๋‹ฌ

8) Local DNS ์„œ๋ฒ„๊ฐ€ Host์—๊ฒŒ ์ตœ์ข… IP ์ฃผ์†Œ๋ฅผ ์‘๋‹ต

5. DNS Caching(์บ์‹ฑ) ๋ฐ Updating(๊ฐฑ์‹ )

DNS Caching

๋„ค์ž„ ์„œ๋ฒ„๊ฐ€ Name-IP Address ๋งคํ•‘์„ ์•Œ๊ฒŒ ๋˜๋ฉด,
์บ์‹œ(cache)์— ์ €์žฅํ•ด๋†“๊ณ  ์žฌ์‚ฌ์šฉํ•จ

์ €์žฅ๋œ ์บ์‹œ๋Š” ์ผ์ • ์‹œ๊ฐ„์ด ์ง€๋‚˜๋ฉด ์ž๋™ ์‚ญ์ œ(timeout) ๋จ

TTL (Time To Live)

์บ์‹œ๊ฐ€ ์œ ํšจํ•œ ์‹œ๊ฐ„์„ ๋‚˜ํƒ€๋‚ด๋ฉฐ, ์ผ์ • ์‹œ๊ฐ„ ์ง€๋‚˜๋ฉด ๋ฌดํšจํ™”๋จ

TLD ์„œ๋ฒ„ ์ •๋ณด๋Š” ๋ณดํ†ต Local DNS ์„œ๋ฒ„์— ์ €์žฅ๋ผ์„œ Root ์„œ๋ฒ„๋ฅผ ์ž์ฃผ ๋ฐฉ๋ฌธํ•  ํ•„์š”๊ฐ€ ์—†์Œ

  • out-of-date
    ๋ชจ๋“  TTL์ด ๋งŒ๋ฃŒ๋˜์–ด์•ผ ์ตœ์‹  ์ •๋ณด๋กœ ๊ฐฑ์‹  ๊ฐ€๋Šฅ
    (์„œ๋ฒ„ IP๊ฐ€ ๋ณ€๊ฒฝ๋์–ด๋„ TTL์ด ๋‚จ์•„์žˆ๋‹ค๋ฉด, ๋ณ€๊ฒฝ ์‚ฌ์‹ค ์ „ํŒŒ X)

DNS ์—…๋ฐ์ดํŠธ/์•Œ๋ฆผ ๋ฉ”์ปค๋‹ˆ์ฆ˜

RFC 2136 : DNS ๊ธฐ๋ก ๋ณ€๊ฒฝ ์‹œ ์„œ๋ฒ„ ๊ฐ„ ์•Œ๋ฆผ ๊ธฐ๋Šฅ์„ ํ‘œ์ค€ํ™”
(ํ•˜์ง€๋งŒ ๊ธฐ๋ณธ์ ์œผ๋กœ๋Š” ์—ฌ์ „ํžˆ TTL ์ค‘์‹ฌ์œผ๋กœ ๋™์ž‘)

6. DNS Records

ํŠน์ • ์ด๋ฆ„(name)๊ณผ ๊ทธ์— ๋Œ€์‘๋˜๋Š” ์ •๋ณด(value)๋ฅผ ์ €์žฅํ•œ ๋ฐ์ดํ„ฐ ์กฐ๊ฐ

DNS ๋ ˆ์ฝ”๋“œ๋Š” (name, value, type, ttl) ํ˜•ํƒœ๋กœ ์ €์žฅ๋˜๋ฉฐ,
์—ฌ๋Ÿฌ ์ข…๋ฅ˜์˜ ํƒ€์ž…(A, NS, CNAME, MX)์ด ์žˆ์Œ

RR format (name, value, type, TTL)

A

  • name: hostname
  • value: IP ์ฃผ์†Œ

NS

  • name: ๋„๋ฉ”์ธ ์ด๋ฆ„(e.g., foo.com)
  • value: ์ด ๋„๋ฉ”์ธ ๋‹ด๋‹นํ•˜๋Š” authoritative ์„œ๋ฒ„์˜ ํ˜ธ์ŠคํŠธ๋„ค์ž„

CNAME

  • name: ๋ณ„์นญ(alias) ์ด๋ฆ„
  • value: ์ •์‹(canonical) ์ด๋ฆ„

MX

  • name: ๋„๋ฉ”์ธ ์ด๋ฆ„
  • value: ๋ฉ”์ผ ์„œ๋ฒ„ ์ด๋ฆ„(mailserver)

7. DNS ๋ฉ”์‹œ์ง€ ํฌ๋งท

DNS ๋ฉ”์‹œ์ง€๋Š” query (์งˆ๋ฌธ), reply (์‘๋‹ต)์œผ๋กœ ๋‚˜๋‰จ
(query์™€ reply ๋ฉ”์‹œ์ง€๋Š” ๊ฐ™์€ ํฌ๋งท์„ ์‚ฌ์šฉ)

๋ฉ”์‹œ์ง€ ํ—ค๋” (Message Header)

Identification

ํด๋ผ์ด์–ธํŠธ๋Š” ์‘๋‹ต์ด ์–ด๋–ค ์š”์ฒญ์— ๋Œ€ํ•œ ๊ฒƒ์ธ์ง€ ์•Œ ์ˆ˜ ์žˆ์Œ
(์š”์ฒญ๊ณผ ์‘๋‹ต์„ ๋งค์นญํ•˜๋Š” ID ์—ญํ• )

  • 16๋น„ํŠธ ์ˆซ์ž
  • ํด๋ผ์ด์–ธํŠธ๊ฐ€ ์งˆ์˜ํ•  ๋•Œ ID ๋ถ€์—ฌํ•˜๊ณ , ์„œ๋ฒ„๋Š” ์ด ID๋ฅผ ๊ทธ๋Œ€๋กœ ๋ณต์‚ฌํ•ด์„œ ์‘๋‹ต์— ์‚ฌ์šฉ

Flags

์—ฌ๋Ÿฌ ๊ฐ€์ง€ ์„ธ๋ถ€ ์ •๋ณด ๋“ค์–ด ์žˆ์Œ

  • query/reply : ๋ฉ”์‹œ์ง€๊ฐ€ ์งˆ๋ฌธ์ธ์ง€(1) ๋‹ต๋ณ€์ธ์ง€(0)
  • recursion desired : ํด๋ผ์ด์–ธํŠธ๊ฐ€ ์„œ๋ฒ„์— ์žฌ๊ท€์  ์งˆ์˜๋ฅผ ์š”์ฒญํ–ˆ๋Š”์ง€ ์—ฌ๋ถ€
  • recursion available : ์„œ๋ฒ„๊ฐ€ ์žฌ๊ท€์  ์งˆ์˜๋ฅผ ์ง€์›ํ•˜๋Š”์ง€ ์—ฌ๋ถ€
  • reply is authoritative : ์‘๋‹ต์ด ๊ถŒํ•œ ์žˆ๋Š” ์„œ๋ฒ„์—์„œ ์˜จ ๊ฒƒ์ธ์ง€ ์—ฌ๋ถ€

4๊ฐœ ์˜์—ญ ๋ณธ๋ฌธ ๊ตฌ์„ฑ

Questions

์งˆ์˜ํ•˜๊ณ ์ž ํ•˜๋Š” ์ด๋ฆ„(name)๊ณผ ํƒ€์ž…(type) ์ •๋ณด

Answers

์งˆ์˜์— ๋Œ€ํ•œ ์‹ค์ œ ์‘๋‹ต RR๋“ค (๋‹ต๋ณ€ ๋ ˆ์ฝ”๋“œ)

Authority

๊ถŒํ•œ ์žˆ๋Š” ๋„ค์ž„ ์„œ๋ฒ„์— ๋Œ€ํ•œ ์ •๋ณด ์ œ๊ณต

Additional

์ถ”๊ฐ€์ ์ธ ์œ ์šฉํ•œ ๋ฐ์ดํ„ฐ ํฌํ•จ

8. DNS ๋“ฑ๋ก ๋ฐ ๋ณด์•ˆ

DNS ๋“ฑ๋ก

์ƒˆ๋กœ ์ƒ๊ธด ํšŒ์‚ฌ(ex. Network Utopia)๊ฐ€ DNS ์‹œ์Šคํ…œ ์•ˆ์— ์ž๊ธฐ ๋„๋ฉ”์ธ ์ •๋ณด๋ฅผ ๋“ฑ๋กํ•˜๋Š” ๊ณผ์ •

1) ๋„๋ฉ”์ธ ์ด๋ฆ„ ๋“ฑ๋ก
DNS ๋“ฑ๋ก ๊ธฐ๊ด€์„ ์ด์šฉ
(ex. networkuptopia.com)

2) ์„œ๋ฒ„ ์ •๋ณด ์ œ๊ณต
Primary, Secondary ๋„ค์ž„ ์„œ๋ฒ„ ์ด๋ฆ„๊ณผ IP ์ฃผ์†Œ ์ œ์ถœ
(ex. dns1.networkuptopia.com, 212.212.212.1)

3) ๋“ฑ๋ก๊ธฐ๊ด€์ด TLD ์„œ๋ฒ„์— ๊ธฐ๋ก
๋“ฑ๋ก๊ธฐ๊ด€์ด NS ๋ ˆ์ฝ”๋“œ, A ๋ ˆ์ฝ”๋“œ๋ฅผ TLD ์„œ๋ฒ„์— ์‚ฝ์ž…

4) ๊ถŒํ•œ ์žˆ๋Š” DNS ์„œ๋ฒ„ ๊ตฌ์ถ•

DNS ๋ณด์•ˆ

DNS๋ฅผ ๋…ธ๋ฆฌ๊ณ  ๊ณต๊ฒฉํ•˜๋Š” ๊ฒฝ์šฐ๊ฐ€ ์กด์žฌ

DDoS (Distributed Denial of Service) ๊ณต๊ฒฉ

  • ๋ฃจํŠธ ์„œ๋ฒ„ ํญ๊ฒฉ (Root Servers Bombardment)
    ๋Œ€๋Ÿ‰ ํŠธ๋ž˜ํ”ฝ์œผ๋กœ ๋ฃจํŠธ ์„œ๋ฒ„ ๋งˆ๋น„ ์‹œํ‚ค๊ธฐ
    (ํ˜„์žฌ๊นŒ์ง€ ์„ฑ๊ณตํ•œ ์  ์—†์Œ)
  • TLD ์„œ๋ฒ„ ํญ๊ฒฉ (TLD Servers Bombardment)
    ๋ฃจํŠธ ์„œ๋ฒ„๋ณด๋‹ค ๋” ์œ„ํ—˜ํ•  ์ˆ˜ ์žˆ์Œ
    (TLD ์„œ๋ฒ„๊ฐ€ ์ง์ ‘ ๋„๋ฉ”์ธ ์ •๋ณด๋ฅผ ๊ด€๋ฆฌํ•˜๊ธฐ ๋•Œ๋ฌธ)

Redirect ๊ณต๊ฒฉ

  • Man-in-the-middle (MITM) ๊ณต๊ฒฉ
    ์‚ฌ์šฉ์ž์˜ DNS ์งˆ์˜๋ฅผ ๊ฐ€๋กœ์ฑ„์„œ ์ค‘๊ฐ„์—์„œ ์œ„์กฐ๋œ ์ •๋ณด๋ฅผ ์‘๋‹ต
  • DNS Poisoning (DNS ์บ์‹œ ์˜ค์—ผ)
    ๊ฐ€์งœ ์‘๋‹ต์„ DNS ์„œ๋ฒ„์— ๋ณด๋‚ด ์บ์‹œ์— ์ €์žฅ์‹œํ‚ค๊ธฐ
    ์‚ฌ์šฉ์ž๋“ค์ด ์ž˜๋ชป๋œ IP๋กœ ์—ฐ๊ฒฐ๋˜๊ฒŒ ํ•จ

๋ฐฉ์–ด ๋ฐฉ๋ฒ• : DNSSEC (DNS Security Extensions)

DNS ์‘๋‹ต์— ๋””์ง€ํ„ธ ์„œ๋ช… ์ถ”๊ฐ€ํ•˜์—ฌ, ๋ฐ์ดํ„ฐ๊ฐ€ ์œ„์กฐ๋˜์ง€ ์•Š์•˜์Œ์„ ํ™•์ธํ•  ์ˆ˜ ์žˆ๊ฒŒ ํ•ด์คŒ
(RFC 4033)

profile
์•ˆ๋…•ํ•˜์„ธ์š” :)

0๊ฐœ์˜ ๋Œ“๊ธ€