According to a DHS report cited in FT’s Tech Blog, DNS is “the part of U.S. information technology most at risk from a serious attack.” The report lists several “mitigations” of the threats against DNS, including monitoring, infrastructure diversity, anycast (called out by name!) and DNSSEC.
The report “is intended to provide an all-hazards risk profile… to inform resource allocation for research and development and other protective program measures to enhance the security and resiliency of the critical IT Sector functions.” If you’re looking for help in your crusade to bolster your DNS infrastructure by adding geographically distributed name servers, introducing anycast, or rolling out DNSSEC, look no further! Print a copy of this 114-page monster out, highlight section 3.2, and drop it on your boss’s desk.