{"id":97349,"date":"2020-10-17T14:42:14","date_gmt":"2020-10-17T12:42:14","guid":{"rendered":"https:\/\/prohoster.info\/blog\/administrirovanie\/minimizacziya-riskov-ispolzovaniya-dns-over-tls-dot-i-dns-over-https-doh"},"modified":"2020-10-17T14:42:14","modified_gmt":"2020-10-17T12:42:14","slug":"minimizacziya-riskov-ispolzovaniya-dns-over-tls-dot-i-dns-over-https-doh","status":"publish","type":"post","link":"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/minimizacziya-riskov-ispolzovaniya-dns-over-tls-dot-i-dns-over-https-doh","title":{"rendered":"Minimizimi i rreziqeve t\u00eb p\u00ebrdorimit t\u00eb DNS-over-TLS (DoT) dhe DNS-over-HTTPS (DoH)","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p><img decoding=\"async\" alt=\"Minimizimi i rreziqeve t\u00eb p\u00ebrdorimit t\u00eb DNS-over-TLS (DoT) dhe DNS-over-HTTPS (DoH)\" src=\"\/wp-content\/uploads\/2020\/10\/8a0e2dc9bf2f465277a2284fc595a472.jpg\" style=\"display:block;margin: 0 auto;\" \/>Minimizimi i rreziqeve t\u00eb p\u00ebrdorimit t\u00eb DoH dhe DoT<\/p>\n<h2>Mbrojtja nga DoH dhe DoT<\/h2>\n<p>A kontrolloni trafikun tuaj DNS? Organizatat investojn\u00eb shum\u00eb koh\u00eb, para dhe p\u00ebrpjekje n\u00eb sigurimin e rrjeteve t\u00eb tyre. Megjithat\u00eb, nj\u00eb nga fushat q\u00eb shpesh nuk merret me r\u00ebnd\u00ebsi t\u00eb duhur \u00ebsht\u00eb DNS. <\/p>\n<p>Nj\u00eb p\u00ebrmbledhje e mir\u00eb e rreziqeve q\u00eb sjell DNS \u00ebsht\u00eb <noindex><a rel=\"nofollow\" href=\"https:\/\/www.infosecurityeurope.com\/__novadocuments\/484127\">prezantimi i Verisign<\/a><\/noindex> n\u00eb konferenc\u00ebn Infosecurity. <\/p>\n<p><img decoding=\"async\" alt=\"Minimizimi i rreziqeve t\u00eb p\u00ebrdorimit t\u00eb DNS-over-TLS (DoT) dhe DNS-over-HTTPS (DoH)\" src=\"\/wp-content\/uploads\/2020\/10\/f6ccff28c50acaa63796479ecf74d717.jpg\" style=\"display:block;margin: 0 auto;\" \/>31% e klasave t\u00eb anketuara t\u00eb malware-it p\u00ebrdor\u00ebn DNS p\u00ebr shk\u00ebmbimin e \u00e7el\u00ebsave. Konkluzionet e hulumtimit<\/p>\n<p>31% e klasave t\u00eb anketuara t\u00eb malware-it p\u00ebrdor\u00ebn DNS p\u00ebr shk\u00ebmbimin e \u00e7el\u00ebsave.<\/p>\n<p>Problemi \u00ebsht\u00eb serioz. Sipas laboratorit hulumtues Palo Alto Networks Unit 42, rreth 85% e malware-it p\u00ebrdorin DNS p\u00ebr t\u00eb vendosur nj\u00eb kanal menaxhimi dhe kontrolli, duke lejuar sulmuesit t\u00eb futur me leht\u00ebsi malware n\u00eb rrjetin tuaj dhe gjithashtu t\u00eb vjedhin t\u00eb dh\u00ebna. Q\u00eb nga krijimi i tij, trafik DNS ka qen\u00eb kryesisht i paenkriptuar dhe leht\u00ebsisht i analizuesh\u00ebm nga mekanizmat mbrojt\u00ebse NGFW.&nbsp;<\/p>\n<p>Kan\u00eb dal\u00eb protokolle t\u00eb reja p\u00ebr DNS, t\u00eb dizajnuara p\u00ebr t\u00eb p\u00ebrmir\u00ebsuar intimitetin e lidhjeve DNS. Ato mb\u00ebshteten aktive nga ofruesit kryesor\u00eb t\u00eb shfletuesve dhe ofrues t\u00eb tjer\u00eb t\u00eb softuerit. Shpejt n\u00eb rrjetet e korporatave do t\u00eb filloj\u00eb rritja e trafikut DNS t\u00eb enkriptuar. Trafiku i enkriptuar DNS q\u00eb nuk analizohet si\u00e7 duhet dhe i lejuar p\u00ebrb\u00ebn nj\u00eb k\u00ebrc\u00ebnim sigurie p\u00ebr kompanin\u00eb. P\u00ebr shembull, nj\u00eb k\u00ebrc\u00ebnim t\u00eb till\u00eb p\u00ebrb\u00ebjn\u00eb kriptoloker\u00ebt, t\u00eb cil\u00ebt p\u00ebrdorin DNS p\u00ebr exchange t\u00eb \u00e7el\u00ebsave t\u00eb enkriptimit. Sulmuesit tani k\u00ebrkojn\u00eb nj\u00eb shp\u00ebrblim prej disa milion dollar\u00ebsh p\u00ebr rikthimin e aksesit n\u00eb t\u00eb dh\u00ebnat tuaja. N\u00eb kompanin\u00eb Garmin, p\u00ebr shembull, u paguan 10 milion dollar\u00eb.<\/p>\n<p>Me konfigurimin e duhur, NGFW mund t\u00eb ndalojn\u00eb ose mbrojn\u00eb p\u00ebrdorimin e DNS-over-TLS (DoT) dhe mund t\u00eb p\u00ebrdoren p\u00ebr t\u00eb ndaluar p\u00ebrdorimin e DNS-over-HTTPS (DoH), duke lejuar analizimin e gjith\u00eb trafikut DNS n\u00eb rrjetin tuaj.<\/p>\n<h2>\u00c7far\u00eb \u00ebsht\u00eb DNS e enkriptuar?<\/h2>\n<p>\u00c7far\u00eb \u00ebsht\u00eb DNS<\/p>\n<p>Sistemi i emrave t\u00eb domeleve (DNS) shnd\u00ebrron emrat e domeleve t\u00eb lexuesh\u00ebm nga njeriu (p\u00ebr shembull, adresa&nbsp;<noindex><a rel=\"nofollow\" href=\"http:\/\/www.paloaltonetworks.com\/\">www.paloaltonetworks.com<\/a><\/noindex>&nbsp;) n\u00eb IP-adresa (p.sh., n\u00eb 34.107.151.202). Kur p\u00ebrdoruesi shkruan nj\u00eb em\u00ebr domeni n\u00eb shfletuesin e uebit, shfletuesi d\u00ebrgon nj\u00eb k\u00ebrkes\u00eb DNS n\u00eb serverin DNS, duke k\u00ebrkuar IP-n\u00eb q\u00eb lidhet me k\u00ebt\u00eb em\u00ebr domeni. N\u00eb p\u00ebrgjigje, serveri DNS kthen IP-n\u00eb q\u00eb do t\u00eb p\u00ebrdor\u00eb ky shfletues.<\/p>\n<p>K\u00ebrkesat dhe p\u00ebrgjigjet DNS d\u00ebrgohen n\u00eb rrjet si tekst t\u00eb thjesht\u00eb n\u00eb form\u00eb t\u00eb pakriptuar, \u00e7ka e b\u00ebn at\u00eb t\u00eb ndjesh\u00ebm ndaj spiunazhit ose ndryshimeve n\u00eb p\u00ebrgjigje dhe p\u00ebr\u00e7ues nga shfletuesi n\u00eb server\u00eb t\u00eb d\u00ebmsh\u00ebm. Kriptimi DNS e b\u00ebn m\u00eb t\u00eb v\u00ebshtir\u00eb ndjekjen e k\u00ebrkesave DNS ose ndryshimin e tyre gjat\u00eb transmetimit. Kriptimi i k\u00ebrkesave dhe p\u00ebrgjigjeve DNS ju mbron nga sulmet Man-in-the-Middle, duke ruajtur funksionet e nj\u00ebjt\u00eb q\u00eb ka protokolli tradicional DNS (sistemi i emrave t\u00eb domen\u00ebve) n\u00eb tekst t\u00eb hapur.&nbsp;<\/p>\n<p>Gjat\u00eb disa viteve t\u00eb fundit jan\u00eb implementuar dy protokolle t\u00eb kriptimit DNS:<\/p>\n<ol>\n<li>\n<p>DNS-over-HTTPS (DoH)<\/p>\n<\/li>\n<li>\n<p>DNS-over-TLS (DoT) <\/p>\n<\/li>\n<\/ol>\n<p>K\u00ebta protokoll\u00eb kan\u00eb nj\u00eb ve\u00e7ori t\u00eb p\u00ebrbashk\u00ebt: q\u00ebllimisht fshehin k\u00ebrkesat DNS nga \u00e7do kapje\u2026 duke p\u00ebrfshir\u00eb edhe nga siguria e organizat\u00ebs. Protokoll\u00ebt kryesisht p\u00ebrdorin protokollin TLS (Transport Layer Security) p\u00ebr t\u00eb vendosur nj\u00eb lidhje t\u00eb enkriptuar midis klientit, i cili b\u00ebn k\u00ebrkesa, dhe serverit, i cili zgjidh k\u00ebrkesat DNS, p\u00ebrmes nj\u00eb porte q\u00eb zakonisht nuk p\u00ebrdoret p\u00ebr trafikun DNS.<\/p>\n<p>Privat\u00ebsia e k\u00ebrkesave DNS \u00ebsht\u00eb nj\u00eb p\u00ebrfitim i madh i k\u00ebtyre protokolleve. Megjithat\u00eb, ato krijojn\u00eb probleme p\u00ebr siguruesit q\u00eb duhet t\u00eb ndjekin trafikun e rrjetit dhe t\u00eb zbulojn\u00eb dhe bllokojn\u00eb lidhjet e d\u00ebmshme. Duke qen\u00eb se protokollet ndryshojn\u00eb n\u00eb implementim, metodat e analiz\u00ebs do t\u00eb jen\u00eb t\u00eb ndryshme p\u00ebr DoH dhe DoT.<\/p>\n<h2>DNS over HTTPS (DoH)<\/h2>\n<p><img decoding=\"async\" alt=\"Minimizimi i rreziqeve t\u00eb p\u00ebrdorimit t\u00eb DNS-over-TLS (DoT) dhe DNS-over-HTTPS (DoH)\" src=\"\/wp-content\/uploads\/2020\/10\/e22b3de1268de10d51471a734ae4b783.jpg\" style=\"display:block;margin: 0 auto;\" \/>DNS brenda HTTPS<\/p>\n<p>DoH p\u00ebrdor portin e njohur 443 p\u00ebr HTTPS, p\u00ebr t\u00eb cilin n\u00eb RFC \u00ebsht\u00eb specifikuar se q\u00ebllimi \u00ebsht\u00eb \"t\u00eb p\u00ebrzihet trafiku DoH me trafikun tjet\u00ebr HTTPS n\u00eb t\u00eb nj\u00ebjt\u00ebn lidhje\", \"t\u00eb v\u00ebshtir\u00ebsohet analizimi i trafikut DNS\" dhe, n\u00eb k\u00ebt\u00eb m\u00ebnyr\u00eb, t\u00eb anashkalohen masat e kontrollit korporativ (&nbsp;<noindex><a rel=\"nofollow\" href=\"https:\/\/tools.ietf.org\/html\/rfc8484#section-8.1\">RFC 8484 DoH, seksioni 8.1<\/a><\/noindex>&nbsp;). Protokolli DoH p\u00ebrdor kriptimin TLS dhe sintaks\u00ebn e k\u00ebrkesave t\u00eb ofruar nga standardet e zakonshme HTTPS dhe HTTP\/2, duke shtuar k\u00ebrkesat dhe p\u00ebrgjigjet DNS mbi k\u00ebrkesat standarde HTTP.<\/p>\n<h2>Rreziqet q\u00eb lidhen me DoH<\/h2>\n<p>N\u00ebse nuk mund t\u00eb dalloni trafikun e zakonsh\u00ebm HTTPS nga k\u00ebrkesat DoH, aplikacionet brenda organizat\u00ebs suaj mund (dhe do) t\u00eb anashkalojn\u00eb cil\u00ebsimet lokale DNS, duke drejtuar k\u00ebrkesat n\u00eb server\u00eb t\u00eb jasht\u00ebm q\u00eb p\u00ebrgjigjen p\u00ebr k\u00ebrkesat DoH, duke anashkaluar \u00e7do monitorim, p\u00ebrkat\u00ebsisht duke shkat\u00ebrruar mund\u00ebsin\u00eb e kontrollit mbi trafikun DNS. N\u00eb m\u00ebnyr\u00eb ideale, duhet t\u00eb kontrolloni DoH duke p\u00ebrdorur funksionet e dekriptimit t\u00eb HTTPS.&nbsp;<\/p>\n<p>DHE&nbsp;<noindex><a rel=\"nofollow\" href=\"https:\/\/blog.mozilla.org\/blog\/2020\/02\/25\/firefox-continues-push-to-bring-dns-over-https-by-default-for-us-users\/\">Google dhe Mozilla kan\u00eb implementuar mund\u00ebsi DoH<\/a><\/noindex>&nbsp;n\u00eb versionin e fundit t\u00eb shfletuesve t\u00eb tyre, dhe t\u00eb dy kompanit\u00eb po punojn\u00eb p\u00ebr t\u00eb p\u00ebrdorur DoH si parazgjedhje p\u00ebr t\u00eb gjith\u00eb k\u00ebrkesat DNS.&nbsp;<noindex><a rel=\"nofollow\" href=\"https:\/\/techcommunity.microsoft.com\/t5\/networking-blog\/windows-will-improve-user-privacy-with-dns-over-https\/ba-p\/1014229\">Microsoft gjithashtu po zhvillon plane<\/a><\/noindex>&nbsp;p\u00ebr integrimin e DoH n\u00eb sistemet e saj operative. Nj\u00eb penges\u00eb \u00ebsht\u00eb se jo vet\u00ebm kompanit\u00eb e respektuara t\u00eb zhvilluesve t\u00eb softuerit, por edhe keqb\u00ebr\u00ebsit kan\u00eb filluar t\u00eb p\u00ebrdorin DoH si nj\u00eb mjet p\u00ebr t\u00eb anashkaluar masat tradicionale t\u00eb firewall-it n\u00eb korporat\u00eb. ( P\u00ebr shembull, shikoni artikujt e m\u00ebposht\u00ebm:&nbsp;<noindex><a rel=\"nofollow\" href=\"https:\/\/www.proofpoint.com\/us\/threat-insight\/post\/psixbot-now-using-google-dns-over-https-and-possible-new-sexploitation-module\">PsiXBot tani p\u00ebrdor Google DoH<\/a><\/noindex>&nbsp;,&nbsp;<noindex><a rel=\"nofollow\" href=\"https:\/\/www.proofpoint.com\/us\/threat-insight\/post\/psixbot-continues-evolve-updated-dns-infrastructure\">PsiXBot vazhdon t\u00eb zhvillohet me nj\u00eb infrastruktur\u00eb t\u00eb azhurnuar DNS<\/a><\/noindex>&nbsp;dhe&nbsp;<noindex><a rel=\"nofollow\" href=\"https:\/\/blog.netlab.360.com\/an-analysis-of-godlua-backdoor-en\/\">analiza e backdoor-it Godlua<\/a><\/noindex>&nbsp;.) N\u00eb \u00e7do rast, si trafiku i mir\u00eb, ashtu edhe ai i d\u00ebmsh\u00ebm DoH do t\u00eb mbesin t\u00eb pap\u00ebrfillsh\u00ebm, duke l\u00ebn\u00eb organizat\u00ebn t\u00eb verbuar ndaj p\u00ebrdorimit t\u00eb keq t\u00eb DoH si nj\u00eb kanal p\u00ebr menaxhimin e malware-it (C2) dhe vjedhjen e t\u00eb dh\u00ebnave t\u00eb ndjeshme.<\/p>\n<h2>Sigurimi i dukshm\u00ebris\u00eb dhe kontrollit t\u00eb trafikut DoH<\/h2>\n<p>Si zgjidhja m\u00eb e mir\u00eb p\u00ebr kontrollin e DoH ne rekomandojm\u00eb t\u00eb konfiguroni dekriptimin e trafikut HTTPS dhe bllokimin e trafikut DoH n\u00eb NGFW (emri i aplikacionit: dns-over-https).&nbsp;<\/p>\n<p>S\u00eb pari, sigurohuni q\u00eb NGFW t\u00eb jet\u00eb i konfiguruar p\u00ebr dekriptimin e HTTPS, sipas&nbsp;<noindex><a rel=\"nofollow\" href=\"https:\/\/docs.paloaltonetworks.com\/best-practices\/9-0\/decryption-best-practices.html\">udh\u00ebzimeve p\u00ebr metodologjin\u00eb m\u00eb t\u00eb mir\u00eb t\u00eb dekriptimit<\/a><\/noindex>.<\/p>\n<p>S\u00eb dyti, krijoni nj\u00eb rregull p\u00ebr trafikun e aplikacionit 'dns-over-https', si\u00e7 \u00ebsht\u00eb treguar m\u00eb posht\u00eb:<\/p>\n<p><img decoding=\"async\" alt=\"Minimizimi i rreziqeve t\u00eb p\u00ebrdorimit t\u00eb DNS-over-TLS (DoT) dhe DNS-over-HTTPS (DoH)\" src=\"\/wp-content\/uploads\/2020\/10\/7876ec3c8af4177e9a81433eec91d419.jpg\" style=\"display:block;margin: 0 auto;\" \/>Rregulli NGFW i Palo Alto Networks p\u00ebr t\u00eb bllokuar DNS-over-HTTPS<\/p>\n<p>Si alternativ\u00eb e p\u00ebrkohshme (n\u00ebse organizata juaj nuk ka implementuar plot\u00ebsisht dekriptimin e HTTPS), NGFW mund t\u00eb konfigurohet p\u00ebr t\u00eb aplikuar veprimin 'ndalo' p\u00ebr identifikimin e aplikacionit 'dns-over-https', por efekti do t\u00eb jet\u00eb i kufizuar n\u00eb bllokimin e server\u00ebve t\u00eb njohur DoH sipas emrit t\u00eb tyre t\u00eb domain-it, pasi pa dekriptimin e HTTPS, trafiku DoH nuk mund t\u00eb verifikohet n\u00eb t\u00ebr\u00ebsi (shih.&nbsp;&nbsp;<noindex><a rel=\"nofollow\" href=\"https:\/\/applipedia.paloaltonetworks.com\/\">Applipedia nga Palo Alto Networks<\/a><\/noindex>&nbsp;&nbsp; dhe k\u00ebrkoni p\u00ebr fraz\u00ebn 'dns-over-https').<\/p>\n<h2>DNS mbi TLS (DoT)<\/h2>\n<p><img decoding=\"async\" alt=\"Minimizimi i rreziqeve t\u00eb p\u00ebrdorimit t\u00eb DNS-over-TLS (DoT) dhe DNS-over-HTTPS (DoH)\" src=\"\/wp-content\/uploads\/2020\/10\/1ce6c475d123f807971bbc286915349a.jpg\" style=\"display:block;margin: 0 auto;\" \/>DNS brenda TLS<\/p>\n<p>Nd\u00ebrsa protokolli DoH p\u00ebrpiqet t\u00eb p\u00ebrzihet me trafik tjet\u00ebr n\u00eb t\u00eb nj\u00ebjtin port, DoT p\u00ebrdor n\u00eb vend t\u00eb saj p\u00ebr her\u00eb t\u00eb par\u00eb nj\u00eb port t\u00eb ve\u00e7ant\u00eb, t\u00eb rezervuar p\u00ebr k\u00ebt\u00eb q\u00ebllim t\u00eb vet\u00ebm, duke ndaluar madje p\u00ebrdorimin e t\u00eb nj\u00ebjtit port p\u00ebr trafikun tradicional t\u00eb pap\u00ebrcjell\u00eb DNS (&nbsp;<noindex><a rel=\"nofollow\" href=\"https:\/\/tools.ietf.org\/html\/rfc7858#section-3.1\">RFC 7858, Seksioni 3.1<\/a><\/noindex>&nbsp;).<\/p>\n<p>Protokolli DoT p\u00ebrdor protokollin TLS p\u00ebr t\u00eb siguruar enkriptimin, i cili inkapsulon k\u00ebrkesat standarde t\u00eb protokollit DNS, me trafik q\u00eb p\u00ebrdor portin e njohur 853 (&nbsp;<noindex><a rel=\"nofollow\" href=\"https:\/\/tools.ietf.org\/html\/rfc7858#section-6\">RFC 7858, seksioni 6<\/a><\/noindex>&nbsp;). Protokolli DoT u zhvillua p\u00ebr t\u00eb leht\u00ebsuar organizatat t\u00eb bllokojn\u00eb trafikun p\u00ebrmes portit, ose t\u00eb pranojn\u00eb p\u00ebrdorimin e tij, por t\u00eb aktivizojn\u00eb dekodimin n\u00eb k\u00ebt\u00eb port.<\/p>\n<h2>Rreziqet q\u00eb lidhen me DoT<\/h2>\n<p>Google implementoi DoT n\u00eb klientin e tij&nbsp;<noindex><a rel=\"nofollow\" href=\"https:\/\/android-developers.googleblog.com\/2018\/04\/dns-over-tls-support-in-android-p.html\">Android 9 Pie dhe versionet e m\u00ebvonshme<\/a><\/noindex>&nbsp;, me k\u00ebt\u00eb parametrin p\u00ebr nj\u00eb p\u00ebrdorim automatik t\u00eb DoT aktivizuar si parazgjedhje, n\u00ebse \u00ebsht\u00eb i disponuesh\u00ebm. N\u00ebse keni vler\u00ebsuar rreziqet dhe jeni t\u00eb gatsh\u00ebm t\u00eb p\u00ebrdorni DoT n\u00eb nivel organizate, at\u00ebher\u00eb administrator\u00ebt e rrjetit duhet t\u00eb lejojn\u00eb qart\u00eb trafikun e dalsh\u00ebm n\u00eb portin 853 p\u00ebrmes p\u00ebrimetrin e tyre p\u00ebr k\u00ebt\u00eb protokoll t\u00eb ri.<\/p>\n<h2>Sigurimi i shikueshm\u00ebris\u00eb dhe kontrollit t\u00eb trafikut DoT<\/h2>\n<p>Si nj\u00eb praktik\u00eb m\u00eb e mir\u00eb p\u00ebr kontrollin e DoT ne rekomandojm\u00eb ndonj\u00eb nga t\u00eb m\u00ebposhtmet, n\u00eb var\u00ebsi t\u00eb k\u00ebrkesave t\u00eb organizat\u00ebs tuaj:<\/p>\n<ul>\n<li>\n<p>Konfiguroni NGFW p\u00ebr dekryptimin e t\u00eb gjitha trafik\u00ebve p\u00ebr portin e destinacionit 853. Me dekryptimin e trafikut, DoT do t\u00eb shfaqet si nj\u00eb aplikacion DNS, p\u00ebr t\u00eb cilin mund t\u00eb aplikoni \u00e7do veprim, p\u00ebr shembull, t\u00eb aktivizoni nj\u00eb abonim.&nbsp;<noindex><a rel=\"nofollow\" href=\"https:\/\/docs.paloaltonetworks.com\/pan-os\/9-0\/pan-os-admin\/threat-prevention\/dns-security\/enable-dns-security\">Palo Alto Networks DNS Security<\/a><\/noindex>&nbsp;p\u00ebr kontrollin e domain-eve DGA ose tashm\u00eb t\u00eb ekzistueshme&nbsp;<noindex><a rel=\"nofollow\" href=\"https:\/\/safebdv.blogspot.com\/2019\/11\/dga.html\">DNS Sinkholing&nbsp;<\/a><\/noindex>dhe anti-spyware.<\/p>\n<\/li>\n<li>\n<p>Si alternativ\u00eb, mund t\u00eb bllokoni krejt\u00ebsisht trafikun 'dns-over-tls' p\u00ebrmes portit 853 duke p\u00ebrdorur motorin App-ID. Zakonisht ai bllokohet n\u00eb m\u00ebnyr\u00eb default, nuk k\u00ebrkohet asnj\u00eb veprim (n\u00ebse nuk e keni lejuar ve\u00e7mas aplikacionin 'dns-over-tls' ose trafikun p\u00ebrmes portit 853).<\/p>\n<\/li>\n<\/ul>\n<p>Burimi: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/post\/523676\/\">habr.com<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041c\u0438\u043d\u0438\u043c\u0438\u0437\u0430\u0446\u0438\u044f \u0440\u0438\u0441\u043a\u043e\u0432 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u044f DoH \u0438 DoT \u0417\u0430\u0449\u0438\u0442\u0430 \u043e\u0442 DoH \u0438 DoT \u041a\u043e\u043d\u0442\u0440\u043e\u043b\u0438\u0440\u0443\u0435\u0442\u0435 \u043b\u0438 \u0432\u044b \u0441\u0432\u043e\u0439 DNS \u0442\u0440\u0430\u0444\u0438\u043a? \u041e\u0440\u0433\u0430\u043d\u0438\u0437\u0430\u0446\u0438\u0438 \u0432\u043a\u043b\u0430\u0434\u044b\u0432\u0430\u044e\u0442 \u043c\u043d\u043e\u0433\u043e \u0432\u0440\u0435\u043c\u0435\u043d\u0438, \u0434\u0435\u043d\u0435\u0433 \u0438 \u0443\u0441\u0438\u043b\u0438\u0439 \u0432 \u043e\u0431\u0435\u0441\u043f\u0435\u0447\u0435\u043d\u0438\u0435 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u0441\u0432\u043e\u0438\u0445 \u0441\u0435\u0442\u0435\u0439. \u041e\u0434\u043d\u0430\u043a\u043e, \u043e\u0434\u043d\u043e\u0439 \u0438\u0437 \u043e\u0431\u043b\u0430\u0441\u0442\u0435\u0439, \u043a\u043e\u0442\u043e\u0440\u043e\u0439 \u0447\u0430\u0441\u0442\u043e \u043d\u0435 \u0443\u0434\u0435\u043b\u044f\u0435\u0442\u0441\u044f \u0434\u043e\u043b\u0436\u043d\u043e\u0433\u043e \u0432\u043d\u0438\u043c\u0430\u043d\u0438\u044f, \u044f\u0432\u043b\u044f\u0435\u0442\u0441\u044f DNS. \u0425\u043e\u0440\u043e\u0448\u0438\u043c \u043e\u0431\u0437\u043e\u0440\u043e\u043c \u0440\u0438\u0441\u043a\u043e\u0432, \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u043f\u0440\u0438\u043d\u043e\u0441\u0438\u0442 DNS \u044f\u0432\u043b\u044f\u0435\u0442\u0441\u044f \u043f\u0440\u0435\u0437\u0435\u043d\u0442\u0430\u0446\u0438\u044f Verisign \u043d\u0430 \u043a\u043e\u043d\u0444\u0435\u0440\u0435\u043d\u0446\u0438\u0438 Infosecurity. 31% \u043e\u0431\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u043d\u043d\u044b\u0445 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":97350,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[688],"tags":[],"class_list":["post-97349","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-administrirovanie"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041c\u0438\u043d\u0438\u043c\u0438\u0437\u0430\u0446\u0438\u044f \u0440\u0438\u0441\u043a\u043e\u0432.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/minimizacziya-riskov-ispolzovaniya-dns-over-tls-dot-i-dns-over-https-doh\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"sq_AL\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u041c\u0438\u043d\u0438\u043c\u0438\u0437\u0430\u0446\u0438\u044f \u0440\u0438\u0441\u043a\u043e\u0432 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u044f DNS-over-TLS (DoT) \u0438 DNS-over-HTTPS (DoH) | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041c\u0438\u043d\u0438\u043c\u0438\u0437\u0430\u0446\u0438\u044f \u0440\u0438\u0441\u043a\u043e\u0432.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/minimizacziya-riskov-ispolzovaniya-dns-over-tls-dot-i-dns-over-https-doh\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2020-10-17T12:42:14+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-10-17T12:42:14+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Minimizimi i rreziqeve t\u00eb p\u00ebrdorimit t\u00eb DNS-over-TLS (DoT) dhe DNS-over-HTTPS (DoH) | ProHoster","description":"Minimizimi i rreziqeve.","canonical_url":"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/minimizacziya-riskov-ispolzovaniya-dns-over-tls-dot-i-dns-over-https-doh","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"sq_AL","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u041c\u0438\u043d\u0438\u043c\u0438\u0437\u0430\u0446\u0438\u044f \u0440\u0438\u0441\u043a\u043e\u0432 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u044f DNS-over-TLS (DoT) \u0438 DNS-over-HTTPS (DoH) | ProHoster","og:description":"\u041c\u0438\u043d\u0438\u043c\u0438\u0437\u0430\u0446\u0438\u044f \u0440\u0438\u0441\u043a\u043e\u0432.","og:url":"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/minimizacziya-riskov-ispolzovaniya-dns-over-tls-dot-i-dns-over-https-doh","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2020-10-17T12:42:14+00:00","article:modified_time":"2020-10-17T12:42:14+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"97349","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 10:22:33","updated":"2022-09-28 02:55:30","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/97349","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/comments?post=97349"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/97349\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media\/97350"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media?parent=97349"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/categories?post=97349"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/tags?post=97349"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}