
AWS Certified Advanced Networking – Specialty (ANS-C01) Certification Guide
By :

DNS was invented in the 1980s for Advanced Research Projects Agency Network (ARPANET) and predates the internet. As ARPANET was a research network, security and hardening weren’t concerns, which was also reflected in the design of other early protocols. Because of this, DNS is vulnerable to various attacks where an attacker can send the victim the IP address of a malicious website without the victim having any way to verify the information.
DNSSEC addresses this problem by providing authentication of the DNS server and maintaining the integrity of the records. This is done by using a public key infrastructure on top of DNS, where each level of the DNS hierarchy validates the level below it, starting at the root.
In order to make sense of how DNSSEC functions, you will learn about the underlying cryptographic concepts: