1461167810-3a225e09-34c5-4f89-8950-544fd28a2ee7

1. A vehicle arresting unit, usable for arrestment of a vehicle, comprising:
a block of compressible material having top, bottom and side surfaces;
intermediate material, having a resiliency characteristic, positioned above said top surface;
a cap assembly including (i) a top tray of frangible material having a top portion positioned above said intermediate material and edge portions extending downward from the top portion and (ii) tray extensions extending from edge portions of said top tray, the top tray fabricated to readily break during arrestment of said vehicle; and
a bottom tray of water impervious material having a bottom portion positioned below the bottom surface of said block and edge portions extending upward from the bottom portion, the bottom tray configured to impede entry of ground surface moisture.
2. A vehicle arresting unit as in claim 1, wherein said tray extensions comprise sections of flexible fabric, upper parts of which are molded into the frangible material of said top tray.
3. A vehicle arresting unit as in claim 1, wherein the top tray comprises molded plastic material fabricated to readily fracture when contacted by a tire during arrestment of said vehicle.
4. A vehicle arresting unit as in claim 1, further comprising:
a section of sheet material having a central part below said bottom tray and upward extending parts adhered to side surfaces of said block.
5. A vehicle arresting unit, usable for arrestment of a vehicle, comprising
compressible material having top, bottom and side surfaces, said compressible material configured to decelerate said vehicle during arrestment; and
a cap assembly including (i) a top tray having a top portion positioned above the top of said compressible material and (ii) tray extensions extending from said top tray, the top tray fabricated to readily fracture during vehicle arrestment.
6. A vehicle arresting unit as in claim 5, further comprising:
intermediate material positioned between said top surface and said cap assembly and having a resiliency property.
7. A vehicle arresting unit as in claim 5, wherein said tray extensions comprise sections of sheet material joined to the top tray.
8. A vehicle arresting unit as in claim 5, wherein said tray extensions comprise sections of flexible fabric, upper parts of which are embedded in the top tray.
9. A vehicle arresting unit as in claim 5, wherein said tray extensions comprise sections of flexible fabric, upper parts of which are molded into the top tray.
10. A vehicle arresting unit as in claim 5, wherein the top tray comprises molded plastic material fabricated to readily fracture when contacted by a tire during vehicle arrestment.
11. A vehicle arresting unit as in claim 5, further comprising:
a bottom tray having a bottom portion positioned below the bottom surface of said compressible material and side portions extending upward from the bottom portion, the bottom tray configured to impede entry of ground surface moisture.
12. A vehicle arresting unit as in claim 5, wherein said compressible material comprises a block of cellular concrete which is compressible by a tire of said vehicle to decelerate the vehicle during arrestment, which abrupt deceleration.
13. A vehicle arresting unit as in claim 5, further comprising:
a section of sheet material having a central part below said bottom tray and upward extending parts adhered to side surface of said compressible material.
14. A vehicle arresting unit as in claim 1, wherein said bottom tray is shaped to provide transverse channels suitable to accept fork lift prongs.

The claims below are in addition to those above.
All refrences to claim(s) which appear below refer to the numbering after this setence.

1. A method comprising:
receiving a first request for a first network address for a first device having a first name;
looking up said first name in a database, said database being a local database;
finding a first entry in said database, said first entry comprising said first name and an identifier associated with a secure DNS server;
establishing an authenticated session with said secure DNS server using said identifier;
querying said secure DNS server with a query comprising said first name;
receiving said first network address; and
establishing a connection with said first network address.
2. The method of claim 1, said identifier associated with said secure DNS server being a second network address.
3. The method of claim 2 further comprising:
receiving a second request for a third network address for a second device having a second name;
looking up said second name in said database;
not finding said second name in said database; and
querying an unsecured DNS server for said third network address.
4. The method of claim 2 further comprising:
receiving a second request for a third network address for a second device having a second name;
looking up said second name in said database;
finding a second entry in said database, said second entry comprising said second name and a third network address associated with another secure DNS server;
attempting to establish an authenticated session with said other secure DNS server using said third network address;
failing to establish said authenticated session with said other secure DNS server; and
terminating further DNS queries for said second name.
5. The method of claim 2, said authenticated session comprising a Layer 3 security mechanism.
6. The method of claim 5, said Layer 3 security mechanism comprising IPsec.
7. The method of claim 2, said establishing said authenticated session with said secure DNS server comprising transmitting a unique identifier to said secure DNS server.
8. The method of claim 7, said unique identifier being an identifier for a device.
9. The method of claim 7, said unique identifier being an identifier for a user.
10. A client hardware device comprising:
a database comprising at least one secure DNS server address and at least one host name to be resolved by said at least one secure DNS server;
a secure name resolver adapted to:
receive a first request for a first network address for a first device having a first name;
look up said first name in a database, said database being a local database;
find a first entry in said database, said first entry comprising said first name and a second network address associated with a secure DNS server;
establish an authenticated session with said secure DNS server using said second network address;
query said secure DNS server with a query comprising said first name; and
receive said first network address; and

an unsecured name resolver that is used to find said first network address when said first name is not in said database.
11. The client hardware device of claim 10, said secure name resolver further adapted to:
receive a second request for a third network address for a second device having a second name;
look up said second name in said database;
not find said second name in said database; and
perform a DNS query of said unsecured name resolver of said second name.
12. The client hardware device of claim 10, said secure name resolver further adapted to:
receive a second request for a third network address for a second device having a second name;
look up said second name in said database;
find a second entry in said database, said second entry comprising said second name and a fourth network address associated with another secure DNS server;
attempt to establish an authenticated session with said other secure DNS server using said fourth network address;
fail to establish said authenticated session with said other secure DNS server; and
terminate further DNS queries for said second name.
13. The client hardware device of claim 10, said authenticated session comprising a Layer 3 security mechanism.
14. The client hardware device of claim 13, said Layer 3 security mechanism comprising IPsec.
15. The client hardware device of claim 10 wherein said secure name resolver is further adapted to transfer a unique identifier to said secure DNS server as part of said authenticated session.
16. A computer-readable storage device having instructions stored therein for performing operations to resolve names into network addresses, the operations comprising:
receiving a first request for a first network address of a first device having a first name;
looking up the first name in a database, the database being a local database;
identifying within the database a network address of a secure DNS server that is associated with the first entry;
establishing an authenticated session with the secure DNS server using the network address of the secure DNS server;
querying the secure DNS server with a query comprising the first name;
receiving the first network address; and
establishing a connection with the first network address.
17. The computer-readable storage device of claim 16, wherein the operations further comprise:
receiving a second request for a third network address for a second device having a second name;
looking up the second name in the database;
not finding the second name in the database; and
querying an unsecured DNS server for the third network address.
18. The computer-readable storage device of claim 16, wherein the operations further comprise:
receiving a second request for a third network address for a second device having a second name;
looking up the second name in the database;
identifying within the database a third network address of another secure DNS server that is associated with the second entry;
attempting to establish an authenticated session with the other secure DNS server using the third network address;
failing to establish the authenticated session with the other secure DNS server; and
terminating further DNS queries for the second name.
19. The computer-readable storage device of claim 16, wherein authenticated session employs IPsec.
20. The computer-readable storage device of claim 16, wherein establishing the authenticated session with the secure DNS server comprises transmitting a user identifier andor a device identifier to the secure DNS server.