ICANN’s multi-stakeholder approach OAS-CICTE REMJA/OAS + WEF Cyber Crime Workshop, Montevideo, Uruguay 10 July 2012

Slides:



Advertisements
Similar presentations
ICANN Report Presented by: Dr Paul Twomey CEO and President LACNIC, Montevideo 31 March 2004.
Advertisements

The ICANN Experiment ISOC-Israel 13-March-2000 Andrew McLaughlin.
The ICANN Experiment CainetCainet Andrew McLaughlin.
ICANN Plan for Enhancing Internet Security, Stability and Resiliency.
The Business Case for DNSSEC Tunis Tunisia April 2013
Update on ccTLD Agreements Montevideo 9 September, 2001 Andrew McLaughlin.
Managing IP addresses for your private clouds 2013 ASEAN CAS Summit Bangkok, Thailand 7 February 2013 George Kuo Member Services Manager.
Internet Identity For All.my ccTLD IPv6 Update By Lai Heng Choong Head of Application, Database and Security.my DOMAIN REGISTRY APTLD Member Meeting, 1.
© 2003 Public Interest Registry Whois Workshop Introduction to Registry/Registrar Issues Presented by Bruce W. Beckwith VP, Operations June 23, 2003 Serving.
ICANN/ccTLD Agreements: Why and How Andrew McLaughlin Monday, January 21, 2002 TWNIC.
.| The Trusted Channel Centric Marketplace Domain Name Transfers & Domain Delegation.
DNSSEC Deployment: Where We Are (and where we need to be) MENOG 10, Dubai 30 April 2012
DNSSEC: Where We Are (and how we get to where we want to be) APNIC 34, Phnom Penh, Cambodia August 2012
Computer Networks: Domain Name System. The domain name system (DNS) is an application-layer protocol for mapping domain names to IP addresses Vacation.
Glen de Saint Géry ICANN GNSO Secretariat for Theresa Swinehart Counsel for International Legal Affairs Domain Day Milan.
“ICANN and the Global Internet” ICANN Workshop Wednesday, October 9, 2002 Mexico City.
Registrars and Security Greg Rattray Chief Internet Security Advisor.
New gTLD Basics. 2  Overview about domain names, gTLD timeline and the New gTLD Program  Why is ICANN doing this; potential impact of this initiative.
Introduction to ICANN’s new gTLD program. A practical example: the Dot Deloitte case. Jan Corstens, Partner, Deloitte WIPO Moscow, 9 Dec 2011.
Domain Name System | DNSSEC. 2  Internet Protocol address uniquely identifies laptops or phones or other devices  The Domain Name System matches IP.
1 Updated as of 1 July 2014 About ICANN KISA-ICANN Language Localisation Project Module 1.1.
ICANN and the Internet Ecosystem. 2  A network of interactions among organisms, and between organisms and their environment.  The Internet is an ecosystem.
2011 – 2014 ICANN Strategic Plan Development Stakeholder Review 4 November 2010.
Revised Draft Strategic Plan 4 December 2010.
The Business Case for DNSSEC InterOp/ION Mumbai October 2012
Computer Networks: Domain Name System. The domain name system (DNS) is an application-layer protocol for mapping domain names to IP addresses Vacation.
Greg Rattray ICANN Chief Internet Security Advisor
DNSSEC: Where We Are (and how we get to where we want to be)
DNSSEC AsiaPKI - Bangkok, Thailand June 2013
ICANN LAC Regional Strategy Final Results URUGUAY February 7-8, 2013.
DNSSEC: A Game Changer ICCS 2012 January 9, 2012 New York, NY
CcTLD/ICANN Contract for Services (Draft Agreements) A Comparison.
ICANN Mission, Structure and Constituencies Capacity Building Program June
1 Dot KE ccTLD RE-DELEGATION & MANAGEMENT EXPERIENCE Workshop on Internet Governance at the national level 19 th July 2005 Michael Katundu, Communications.
ICANN Update: What Next for Trademark Owners? 22 nd Annual Fordham Int’l IP Law & Policy Conference 25 April 2014.
ICANN COMMUNITY STRATEGIC PLANNING DISCUSSION Brussels, June
Domain Name System. CONTENTS Definitions. DNS Naming Structure. DNS Components. How DNS Servers work. DNS Organizations. Summary.
1 ICANN update Save Vocea APSTAR retreat, Taipei, TW 24 February 2008.
Organizations, Institutions, the Domain Name and addressing system, Internet Governance… D-day 2005 Milan, Italy 24 November 2005 Theresa Swinehart GM,
DNS Security Pacific IT Pros Nov. 5, Topics DoS Attacks on DNS Servers DoS Attacks by DNS Servers Poisoning DNS Records Monitoring DNS Traffic Leakage.
Deploying DNSSEC: From Content to End-customer InterOp Mumbai October 2012
1 ICANN & Global Partnerships Baher Esmat Manager, Regional Relations Middle East ccTLD Training, Amman Nov, 2007.
New gTLD Basics. 2  Overview about domain names, gTLD timeline and the New gTLD Program  Why is ICANN doing this; potential impact of this initiative.
Dedicated to preserving the central coordinating functions of the global Internet for the public good. John L. Crain, Chief Technical Officer, ICANN
Adrian Kinderis – AusRegistry International Best Practices of a ccTLD Registry BEST PRACTICES OF A ccTLD REGISTRY ADRIAN KINDERIS AUSREGISTRY INTERNATIONAL.
DNSSEC 101 IGF 2012, Baku, Azerbaijan 6 November 2012
1 ICANN... update Pablo Hinojosa Manager, Regional Relations Global and Strategic Partnerships 2007 Caribbean Internet Forum St. Lucia, 5 November 2007.
© 2015 ISC November 2013 Sunset for the DLV?. © 2015 ISC Background (c) Interested
1 1 The GNSO Role in Internet Governance Presented by: Chuck Gomes Date: 13 May 2010.
Invitation to ICANN GNSO ISPCP RIPE65 – September, 2012 The Internet Service Providers Connectivity Providers Constituency, ICANN Generic Names Supporting.
Invitation to ICANN GNSO ISPCP ARIN XXX – October, 2012 The Internet Service Providers Connectivity Providers Constituency, ICANN Generic Names Supporting.
New Top Level Domains Geoff Huston IAHC. Top Level Domain Names l Country-code name spaces.au.jp.sg.de l Special purpose name spaces.in-addr.arpa.int.mil.
Securing Future Growth: Getting Ready for IPv6 NOW! ccTLD Workshop, 8 th April 2011 Noumea, New Caledonia Miwa Fujii, Senior IPv6 Program Specialist, APNIC.
ICANN Regional Outreach Meeting, Dubai 1–3 April Toward a Global Internet Paul Twomey President and CEO 1 April 2008 ICANN Regional Meeting 1–3.
Governmental Advisory Committee Public Safety Working Group 1.
Registry Functions Essential components for operating a ccTLD registry.
1 Domain Name Marketplace Patrick Jones Registry Liaison Manager 29 March 2007.
DNSSEC Update SANOG 27 Kathmandu, Nepal January 2016
Update on Consumer Choice, Competition and Innovation (CCI) WG Rosemary Sinclair.
Domain Name System INTRODUCTION to Eng. Yasser Al-eimad
Keith Mitchellhttp:// RIPE ncc IP Address Space Governance Keith Mitchell Executive Board Chairman, RIPE NCC (Chief Executive, LINX) European.
THE LARGEST NAME SERVICE ACTING AS A PHONE BOOK FOR THE INTERNET The Domain Name System click here to next page 1.
{ Domain Name System DNS & IP Address Protocols within the Internet Ecosystem. - Amanda Sparling, EMAC 6300.
IANA Stewardship Transition & Enhancing ICANN Accountability Panel and Audience discussion | WSIS Forum | 5 May 2016.
1 27Apr08 Some thoughts on Internet Governance and expansion of the Domain Name space Paul Twomey President and CEO 9 August 2008 Panel on Internet Governance.
SaudiNIC Riyadh, Saudi Arabia May 2017
Unit 36: Internet Server Management
DANE: The Future of Transport Layer Security (TLS)
Rachel Akisada & Melanie Kingsley
TRA, UAE May 2017 DNSSEC Introduction TRA, UAE May 2017
Presentation transcript:

ICANN’s multi-stakeholder approach OAS-CICTE REMJA/OAS + WEF Cyber Crime Workshop, Montevideo, Uruguay 10 July 2012

What is ICANN? IANA function – coordinate unique identifiers (root and top-level domain names, IP address allocation, protocol number assignments, time zone database, other…) DNS operations (L-root, DNSSEC, ICANN managed domains) Policy and multi-stakeholder support – Facilitator – Delegation of registry and registrar functions – Education/ training/ awareness – Collaboration on other, non-domain name issues

What is ICANN? We are NOT a – Law enforcement agency – Court of law – Government agency ICANN Cannot unilaterally – Suspend domain names – Transfer domain names – Immediately terminate a registrar’s contract ICANN can enforce contracts on registries and registrars

What is ICANN? Security Team is LE contact point Participation via – Government Advisory Council (GAC) – Security Team provides “basic training”, “speak to X for Y”, workshops, collaborate with LE, Security and operational communities – Direct meetings like with any other stakeholder

The Internet’s Phone Book - Domain Name System (DNS) Get page webserver Username / Password Account Data DNS Resolver = DNS Server Login page ISP/Enterprise Majorbank.se (Registrant) DNS Server.se (Registry) DNS Server. (Root)

Caching Responses for Efficiency Get page webserver Username / Password Account Data DNS Resolver = DNS Server Login page

Here is root zone file Just a bunch of zone files courtesy Dave Piscitello, ICANN

DNS 101 continued.. gTLD = Global Top Level Domain.com,.museum…and soon.yourdomainhere... ccTLD = Country Code TLD.uy,.br,.cl,.se,.cn,.ru TLDs operated by Registries Root (ICANN) has entries for TLDs; TLDs have entries for domain names Domains sold to Registrants thru Registrars Registrant  Registrar  Registry  Root google.com  GoDaddy .com . Google Inc  GoDaddy Inc  VeriSign Inc  ICANN background courtesy Kim Davies, ICANN

Why do I care? For example: IP address or domain name of suspect WHOIS protocol Contact owner, Registrar, or Registry Obtain other information collected by Registrar Other examples:

Conficker Created pseudo-random domains/day for C&C across 116 TLDs Instant actions based on established international relationships with ccTLD and gTLDs (Crain) –wow! Unprecedented act of coordination and collaboration (MSFT, ICANN, Registries, AV, researchers) Lessons: private sector collaboration; public- private info sharing; support to LE; legislative reform.

Registrar Accreditation Agreement (RAA) Registrars sign contract /wICANN to become accredited Required for com, gtlds, … Not for ccTLDs Stakeholders: Registrars, LE, privacy, community, ICANN Accurate/validated WHOIS (…also ICANN community efforts for common machine readable format with tiered access) Major progress – LE and Registrars now agree in principle ation-raa-negotiations-summary-03jun12-en.pdf

The Problem: DNS Cache Poisoning Attack DNS Resolver = DNS Server Get page Attacker webserver Username / Password Error Attacker = Login page Password database

Argghh! Now all ISP customers get sent to attacker. DNS Resolver = DNS Server Get page Attacker webserver Username / Password Error Login page Password database

Securing The Phone Book - DNS Security Extensions (DNSSEC) DNS Resolver with DNSSEC = DNS Server with DNSSEC Get page webserver Username / Password Account Data Login page Attacker = Attacker’s record does not validate – drop it

Resolver only caches validated records DNS Resolver with DNSSEC = DNS Server with DNSSEC Get page webserver Username / Password Account Data Login page

DNSSEC Bellovin 1995, Kaminsky 2008 Deployed on root 2010: Biggest security upgrade to Internet in 20 years DNS Changer 2011 Web accounts, SSL certificates, configuration,.. Future innovation and opportunities Only possible with unprecedented international multi-stakeholder, bottom-up managed and trusted root key (including representatives from Uruguay, Brazil, Trinidad)

DNSChanger - ‘Biggest Cybercriminal Takedown in History’ – 4M machines, 100 countries, $14M 9 Nov

DNSSEC: Where we are *COMCAST 18M Internet customers. Others..TeliaSonera SE, Vodafone CZ,Telefonica, CZ, T-mobile NL, SurfNet NL,.. Deployed on 88/313 TLDs (.cl,.br,.cr,.co,.pr,.hn,.us,.lk,.eu,.tw 台灣, 한국,.com,…) Root signed and audited 84% of domain names could have could have DNSSEC deployed on them Large ISPs have or have agreed to support DNSSEC* A few 3 rd party signing solutions (e.g., GoDaddy, VeriSign, Binero,…) Supported by majority of DNS implementations Required for new gTLDs

DNSSEC: Where we are But deployed on < 1% of 2 nd level domains. Many have plans. Few have taken the step (e.g., paypal.com*). DNSChanger and other attacks highlight today’s need. Innovative security solutions (e.g., DANE) highlight tomorrow’s value. Need to raise Registrant and end user awareness * Approx 0.5M have DNSSEC

Unexpected reliance on DNS Web accounts SSL dilution of trust  Diginotar/Comodo Configuration, s/w updates, … Lack of trust in e-commerce  negative economic impact Imagine if you could trust “the ‘Net”?

DNSSEC Future DANE – Improved Web TLS for all – S/MIME for all …and – SSH, IPSEC, VoIP – Digital identity – Other content (e.g. configurations, XML, app updates) – Smart Grid – A global PKI

OECS ID effort

Summary The bottom-up, multi-stakeholder approach works Personal relationships are critical Public Private collaboration is essential

ICANN Security Team: Jeff Moss, VP & Chief Security Officer Geoff Bickers, Director of Security Operations John Crain, Sr. Director, SSR Whitfield Diffie, VP InfoSec & Cryptography Patrick Jones, Sr. Director, Security Dr. Richard Lamb, Sr. Program Manager, DNSSEC Dave Piscitello, Sr. Security Technologist Sean Powell, Information Security Engineer Thank You