Appendix C: References and Further Reading¶
This appendix collects every external source cited across the handbook's parts, grouped by category for easy reference.
Standards and Frameworks¶
- RFC 1035, Domain Names - Implementation and Specification
- RFC 4033, DNS Security Introduction and Requirements
- RFC 4034, Resource Records for the DNS Security Extensions
- RFC 4035, Protocol Modifications for the DNS Security Extensions
- RFC 5731, Extensible Provisioning Protocol (EPP) Domain Name Mapping
- RFC 8659, DNS Certification Authority Authorization (CAA) Resource Record
- RFC 9364 (BCP 237), DNS Security Extensions (DNSSEC)
- NIST SP 800-81-2, Secure Domain Name System (DNS) Deployment Guide
- NIST SP 800-61 Revision 2, Computer Security Incident Handling Guide
- NIST SP 800-61 Revision 3, Incident Response Recommendations and Considerations for Cybersecurity Risk Management
- NIST Cybersecurity Framework (CSF) 2.0
- ICANN
- ICANN Security and Stability Advisory Committee (SSAC)
- ICANN SAC115, SSAC Advisory on DNS Abuse
- OWASP Secrets Management Cheat Sheet
- OWASP Smart Contract Security (SCS) Project
- OWASP Web3 Attack Vectors Top 15
- MITRE ATT&CK
- MITRE ATT&CK T1078.004, Valid Accounts: Cloud Accounts
- MITRE ATT&CK T1584.002, Compromise Infrastructure: DNS Server
- MITRE AADAPT Cyber Threat Framework for Digital Assets, fact sheet
- MITRE AADAPT public matrix (GitHub)
- CIS Benchmarks
- AWS Well-Architected Framework, Security Pillar
- EIP-137, Ethereum Domain Name Service - Specification
- EIP-1577, contenthash field for ENS
- EIP-3668, CCIP Read: Secure offchain data retrieval
- ENSIP-8, Interface Discovery
- ENSIP-9, Multichain Address Resolution
- ENSIP-11, EVM-Compatible Chain Address Resolution
- ENSIP-15, ENS Name Normalization Standard
- ENSIP-17, Gasless DNS Resolution
- ENSIP-19, Multichain Primary Names
- IPFS HTTP Gateway Specification
- IPFS Trustless Gateway Specification (CAR format)
- Multiformats
Incidents and Case Studies¶
- Cisco Talos, Sea Turtle DNS hijacking campaign
- Cisco Talos, sustained abuse of IPFS gateways
- CyberScoop, Ether DNS/BGP Amazon Route 53 heist
- Internet Society, "What Happened? The Amazon Route 53 BGP Hijack"
- The Record, KlaySwap crypto users lose funds after BGP hijack
- CertiK, BGP Hijacking: the $1.9M KlaySwap Attack Through Manipulated Network Flow
- Decrypt, Curve Finance DNS Record Attack
- CryptoTimes, Curve Finance Loses $570K Due to DNS Compromise
- rekt.news, Curve Finance
- The Register, MyEtherWallet DNS Hijack
- Namefi, "The 2024 Squarespace DeFi Domain Mass-Hijack"
- SC Media coverage via dnsafrica.org, Squarespace-Registered DeFi Platforms Subjected to DNS Hijacking
- Smart Contract Audit, BadgerDAO hack (2021)
Tools and Documentation¶
- crt.sh, Certificate Transparency search
can-i-take-over-xyzproject (GitHub)- Storacha Network (GitHub)
- ENS Docs: Architecture
- ENS Docs: DNS Registry
- ENS Docs: Universal Resolver
- ENS Docs: Name Wrapper
- ENS blog, How ENS Normalization Works
- Basenames
- IPFS docs: content addressing
- IPFS docs: IPFS gateway
- IPFS docs: nodes and network layer
- IPFS docs: persistence, pinning, and garbage collection
- APNIC Labs, DNSSEC validation measurement
- APNIC blog, How We Measure DNSSEC Validation