1 Current Counter-measures and Responses by the Domain Name System Community Paul Twomey President and CEO 22 April 2007 APEC-OECD Malware Workshop Manila,

Slides:



Advertisements
Similar presentations
The Future of the Internet
Advertisements

MEDEFs View on Dot EU Domain Day – 5 novembre 2002 – Palazzo Stelline – Milano Catherine GABAY – Director Innovation and Research - Medef.
Copyright, Issues from Internet Technologies 3 – Internet Governance Roger Clarke, Xamax Consultancy, Canberra Visiting Prof/Fellow, Unis of.
ICANN Report Presented by: Dr Paul Twomey CEO and President LACNIC, Montevideo 31 March 2004.
The ICANN Experiment ARIN-Calgary 3-April-2000 Borrowed from Andrew McLaughlin by Ken Fockler.
ARIN IP Address Stewardship 3 February About ARIN Regional Internet Registry (RIR) – Established December 1997 by Internet community 100% community.
Prepared by Corporate Affairs September ICANN Update AfriNIC9 26 November 2008 Pointe aux Piments, Mauritius Anne-Rachel Inné ICANN.
The Global Internet ICTFEST 2006 Antigua and Barbuda Jacob Malthouse Liaison Internet Corporation for Assigned Names and Numbers.
1 Contribution of the Postal Sector to Internet Governance Theresa Swinehart Vice President Global and Strategic Partnerships 8 June 2007 The Postal Sector.
The ICANN Experiment ISOC-Israel 13-March-2000 Andrew McLaughlin.
GNSO goals Bruce Tonkin Chair, GNSO Council Sao Paulo, 4 Dec 2006.
Internet Corporation for Assigned Names and Numbers Louis Touton Presentation to the FTAA Joint Public-Private Sector Committee of Experts on the Internet.
ICANN Strategic planning process Draft key priorities for the July 2006 – June 2009 Plan for community comment November 2005.
The ICANN Experiment CainetCainet Andrew McLaughlin.
ICANN Plan for Enhancing Internet Security, Stability and Resiliency.
The At-Large Advisory Committee (ALAC) An Introduction by Dr. Olivier MJ Crépin-Leblond ALAC Chair.
© Copyright International Telecommunication Union (ITU). All Rights Reserved page - 1 Alexander NTOKO Project Manager, ITU Electronic Commerce.
ActionDescription 1Decisions about planning and managing the coast are governed by general legal instruments. 2Sectoral stakeholders meet on an ad hoc.
R I P E N e t w o r k C o o r d i n a t i o n C e n t r e. h t t p : / / w w w. r i p e. n e t. n c r i p e. n e t 1 The Internet Registry System IPv4.
The Role of Governments Caribbean Telecommunications Union Ministerial Seminar May 29, 2012 Heather Dryden Chair - Governmental Advisory Committee, ICANN.
Internet Number Resources 1. Internet IPv4 addresses IPv6 addresses Autonomous System number Fully Qualified Domain Name Key Internet resources.
Internet Governance Community Use Slide Deck Courtesy of ARIN May 2014.
The At-Large Advisory Committee (ALAC) An Introduction by Dr. Olivier MJ Crépin-Leblond ALAC Chair.
ICANN/ccTLD Agreements: Why and How Andrew McLaughlin Monday, January 21, 2002 TWNIC.
Glen de Saint Géry ICANN GNSO Secretariat for Theresa Swinehart Counsel for International Legal Affairs Domain Day Milan.
“ICANN and the Global Internet” ICANN Workshop Wednesday, October 9, 2002 Mexico City.
New gTLD Basics. 2  Overview about domain names, gTLD timeline and the New gTLD Program  Why is ICANN doing this; potential impact of this initiative.
Introduction to ICANN’s new gTLD program. A practical example: the Dot Deloitte case. Jan Corstens, Partner, Deloitte WIPO Moscow, 9 Dec 2011.
IP Address Management The RIR System & IP policy
1 Updated as of 1 July 2014 About ICANN KISA-ICANN Language Localisation Project Module 1.1.
ICANN and the Internet Ecosystem. 2  A network of interactions among organisms, and between organisms and their environment.  The Internet is an ecosystem.
2011 – 2014 ICANN Strategic Plan Development Stakeholder Review 4 November 2010.
Revised Draft Strategic Plan 4 December 2010.
2012 – 2015 ICANN Strategic Plan Development 6 October 2011.
1 ARIN: Mission, Role and Services John Curran ARIN President and CEO.
1 APNIC support for Internet development APT/PITA Regional Meeting on ICT for the Pacific August 2004, Nadi, Fiji Paul Wilson
ICANN LAC Regional Strategy Final Results URUGUAY February 7-8, 2013.
ICANN COMMUNITY STRATEGIC PLANNING DISCUSSION Brussels, June
1 ICANN update Save Vocea APSTAR retreat, Taipei, TW 24 February 2008.
Organizations, Institutions, the Domain Name and addressing system, Internet Governance… D-day 2005 Milan, Italy 24 November 2005 Theresa Swinehart GM,
1 Dr. Olivier MJ Crépin-Leblond ISOC England Chapter Chairman ALAC Chairman at ICANN Presentation at 5th Ukraine Internet Governance Forum.
1 ICANN & Global Partnerships Baher Esmat Manager, Regional Relations Middle East ccTLD Training, Amman Nov, 2007.
New gTLD Basics. 2  Overview about domain names, gTLD timeline and the New gTLD Program  Why is ICANN doing this; potential impact of this initiative.
Multistakeholder Policy- & Decision-making
GNSO Public Forum Dr Bruce Tonkin Chair, GNSO Council Lisbon, 29 March 2007.
1 ICANN... update Pablo Hinojosa Manager, Regional Relations Global and Strategic Partnerships 2007 Caribbean Internet Forum St. Lucia, 5 November 2007.
1 1 The GNSO Role in Internet Governance Presented by: Chuck Gomes Date: 13 May 2010.
IDN UPDATE Tina Dam ICANN Chief gTLD Registry Liaison Public Forum, Wellington 30 March 2006.
1 OVERVIEW OF ICANN, ITU AND OTHER MAJOR PLAYERS – WHAT ARE ROLE FOR EACH Roundtable Disscussion: Internet Governance and Regulation Dr. Andris Virtmanis.
Management of Internet Resources ITU Workshop on Developing a Policy and Regulatory Framework for Developing Economies of the Pacific 1 December 2003 Suva,
Securing Future Growth: Getting Ready for IPv6 NOW! ccTLD Workshop, 8 th April 2011 Noumea, New Caledonia Miwa Fujii, Senior IPv6 Program Specialist, APNIC.
ICANN Regional Outreach Meeting, Dubai 1–3 April Toward a Global Internet Paul Twomey President and CEO 1 April 2008 ICANN Regional Meeting 1–3.
Fostering Multi-Stakeholder Internet Governance Models in the Region Bill Graham, Director, ICANN Board.
Internet Protocol Addresses What are they like and how are the managed? Paul Wilson APNIC.
1 Dr. Olivier MJ Crépin-Leblond ISOC UK England Chair ALAC Chair at ICANN Presentation at 3 nd Ukraine Internet Governance Forum Kyiv, Ukraine,
Keith Mitchellhttp:// RIPE ncc IP Address Space Governance Keith Mitchell Executive Board Chairman, RIPE NCC (Chief Executive, LINX) European.
{ Domain Name System DNS & IP Address Protocols within the Internet Ecosystem. - Amanda Sparling, EMAC 6300.
IANA Stewardship Transition & Enhancing ICANN Accountability Panel and Audience discussion | WSIS Forum | 5 May 2016.
1 27Apr08 Some thoughts on Internet Governance and expansion of the Domain Name space Paul Twomey President and CEO 9 August 2008 Panel on Internet Governance.
Internet Governance: A View From the RIPE NCC Paul Rendek Director External Relations, RIPE NCC Ukrainian Internet Governance Forum 2-3 September 2011.
“ICT Policy for Civil Society” Curriculum Produced by APC and CTO
Getting started with ICANN
ICANN Multi-Stakeholder Model
ICANN’s Policy Development Activities
Unit 36: Internet Server Management
Partnership of Governments, Businesses and Civil Society: the ICANN example in coordinating resources and policy making Dr. Olivier MJ Crépin-Leblond
Rodrigo de la Parra / Laurent Ferrali ICANN org
An Introduction to ICANN
An Introduction by Dr. Olivier MJ Crépin-Leblond EURALO Chair
ICANN: MISSION, STRUCTURE AND CONSTITUENCIES
Presentation transcript:

1 Current Counter-measures and Responses by the Domain Name System Community Paul Twomey President and CEO 22 April 2007 APEC-OECD Malware Workshop Manila, The Philippines

2 What we want you to do today Understand the risks to the Internet as we have known it for over 30 years –Security and stability of addressing and routing Become partners in managing these risks Understand how your interests are affected by ICANNs policy work Get involved in creating the policy that sets how the Net connects you to your customers Understand the opportunities and risks the upcoming liberalising of gTLDs offers

3 Jon Postel 1943–1998 Internets unique identifiers were coordinated through the Internet Address Naming Authority

4 Need for change circa 1996–97 Globalisation of the Internet Commercialisation of the Internet Lack of competition in the domain name space Trademark - domain name conflicts Need for a new model of governance

5 ICANN mission statement To coordinate, overall, the global Internet's system of unique identifiers, and to ensure stable and secure operation of the Internet's unique identifier systems. In particular, ICANN coordinates: 1.Allocation and assignment of the three sets of unique identifiers for the Internet: Domain names (forming a system called the DNS) Internet protocol (IP) addresses and autonomous system (AS) numbers Protocol port and parameter numbers 2.Operation and evolution of the DNS root name server system 3.Policy development reasonably and appropriately related to these technical functions

6 Principles of operation 1.Contribute to stability and security of the unique identifiers system and root management 2.Promote competition and choice for registrants and other users 3.Forum for multi-stakeholder bottom-up development of related policy 4.Ensure on a global basis an opportunity for participation by all interested parties

7 From Thin Pipe to Fat Pipe The greater the demand for Internet- based services, the larger and more complex the Internet ecosystem becomes

8 Explosion in Internet growth

9 Competition in the Domain Name Space ICANN introduced competition to the domain name space Registrars now have a market and a business Consumers have greater choice in price and services Domain name marketplace is even driving how we search – contextually as well as topically – and the scale of sites that can be searched Total registrars = 888 and counting

10 Snapshot of the domain name marketplace More than 120 million domain names registered globally today

11 The Internet ecosystem Some organisations concerned with the Internet Internet Governance Forum

12 Five Regional Internet Registries (AS and IP addresses) ARIN North America – Canada, United States, several islands in the Caribbean Sea and North Atlantic Ocean APNIC Most of Asia Australia/New Zealand Pacific Islands The Internet ecosystem Some organisations concerned with the Internet LACNIC Latin America Caribbean Islands RIPE NCC Europe Middle East North Africa Parts of Asia AfriNIC African Region

13 ICANNs community BOARD OF DIRECTORS ASOGNSOCCNSO Governmental Advisory Committee (GAC) Root Server System Advisory Committee (GAC) Security & Stability Advisory Committee (SSAC) At Large Advisory Committee (ALAC) Technical Liaison Group (TLG) Regional Internet Registries ARIN RIPE NCC LACNIC APNIC AfriNIC gTLD Registries and Registrars Intellectual Property ISPs Businesses Universities Consumers ccTLD registries (e.g.,.us,.uk,.au,.it,.be,.nl, etc.) 17 voting delegates + 6 non-voting delegates Nominating Committee ICANN Staff President and CEO

14 What do we stand for? Ensuring a single, interoperable Internet All can express their own language and identity, but… All can access all others Creativity, development and growth are encouraged Security of the network is maintained to ensure confidence in the model Stability of the experience for application development and consumer experience Efficient deployment of resources in support of a global network All relevant stakeholders have a voice and role Encouraging innovation, particularly at the edge of the network

15 Internet community – a real phenomenon with world changing values Bottom-up technical policy-making and decision-making Participation open to all who wish to do so Legitimacy determined by open participation and the value of the contribution to the joint effort Consensus-based decision making Cooperation, coordination and consultation among participants and groups pushing initiatives forward Yet, very spirited and blunt public debate Private agreement or contract approach to creating and managing linkages among and to the network Global efficiency in the allocation of resources, such as Internet Protocol addresses

16 Where stakeholders find common ground Increasingly, ICANN finds itself one of the few forums in which these issues can be raised so that solutions can be found and implemented within the Internet community

17 Internet infrastructure threats 1.Physical disruption of major lines and switching centers 2.Loss of routing infrastructure continuity and/or fidelity 3.Loss of DNS service continuity and/or fidelity 4.Flooding of network or specific sites, i.e., denial of service attack Not all Internet-based systems are Internet infrastructure…

18 Routing infrastructure Status –Routing information is maintained in routing registries These are reasonably well protected against physical attack –Inputs to the routing registries can be compromised –False routing information can be inserted Potential protection –Secure BGP has been defined and implemented Does not look feasible – too much hardware required Routing security does not fall directly within anyones charter. What is the financial sectors role in engaging ISPs?

19 DNS infrastructure root servers – status Root servers point to top level domains –20 generic TLDs (gTLDs) –.com,.org, etc. U.S. Government has.gov and.mil –243 country codes (ccTLDs) –.de,.jp,.uk, etc. Root servers are heavily replicated –13 independent businesses –Many-fold replication and distribution

20 DNS infrastructure root servers – threats Threats Loss of Service –Network outage –Machine or site failures –Overwhelming traffic (denial of service attack) –Business failure Hijacking –Cache poisoning –False registration –Fake zone transfer –Fake registrar-registry interaction –Private roots Loss of coherence –Unauthorized roots and TLDs –Private character set extensions Countermeasures –Excess capacity –Distribution, replication –Strong connectivity –Multiplicity of businesses –DDoS counters (long term) –Protocol changes, DNSSEC –Tight registrar controls –TSIG (crypto) –Crypto authentication –DNSSEC –DNSSEC; policy/political pressure Lots of work is under way. But threats are growing and this will take more time and money than many expect

21 System threats Denial of service attacks target high-value sites –DNS servers are among the obvious targets –These will get more sophisticated –Action is required – see later slides Domain and address theft is growing –Spammers like to hide their identity –The legal framework doesnt provide protection Address theft, per se, is not actionable(!) Should individual sectors lobby for this (internationally)?

22 The denial of service problem Denial of service attacks are increasing –This will get worse – probably much worse Law enforcement is important but necessarily at the wrong end of the problem Technical changes in the Internet would help a lot

23 Distributed denial of service On 6 February 2007 – most visible since 2002 attack but not as comprehensive as amplified DDoS attack on TLDs of 2006 Six of the 13 root servers that form building blocks of the Internet were affected – two badly The attack highlighted the effectiveness of Anycast load balancing technology More analysis is needed before a full report on what happened can be drawn up – reasons behind the attack are unclear – a wake-up call Root server operators worked together in a fast, effective, and co-ordinated effort Recent SSAC recommendations for improving the security of the domain name system still need to be followed through – other measures should also be considered Coordination and preparation were key Did you notice?

24 ICANN purview ICANN strives to achieve coherence, stability and security Almost all of the operational details are carried out by others, but –The IANA (Internet Assigned Numbers Authority) function is within ICANN –L root Join us in both dialogue and new funding mechanisms – security foundation/gold star service, etc.

25 North Amer South Amer EuropeAfricaAsia - Pacific 8 Policy & Laws 7 6 Response 5 Operations 4 Products/Networks 3 Implementation 2 Protocols 1 Architecture ICANN Advisory role across multiple levels and countries (DNS and addressing only) IAB IETF AUCERT Law Enforcement FBI Root Server Operators NANOG CERT Illustrative

26 DDoS – some technical approaches Identification of sources of traffic –Tighten the routing security Refashion the protocols to know the identity of senders of traffic Distinguish between well managed computers on well managed networks vs others –Well managed means they arent zombies and their configuration is checked regularly Well managed networks quarantine computers which appear to be infected or misbehaving Well managed networks report misbehaviors and accept reports of misbehaviors Traffic among well managed networks gets preference

27 DDoS – customer approaches Pressure on the vendor to supply machines that are safe out of the box Establishment of an ethic that machines should be safe – its the vendors problem, not the users

28 Some ICANN initiatives Agreement on formal relationship between Root Server Operators and ICANN Tightened procedures for distributing changes to the root zone (CRADA report) DNSSEC deployment analysis and road map IPv6 transition road map (re DNS) DNS service robustness enhancements Best practices for ccTLDs

29 Whois database Some businesses see a strong need for unrestricted access to Whois information to –Identify cybersquatters and domain infringement –Investigate online fraud and phishing –Manage domain names and intellectual property –Conduct e-commerce by researching other online entities One major hotel chain recorded 100-plus new domain names registered in its name – or a version thereof – every day –Confusingly similar names led to pay-per-click sites Full registration data would help legitimate businesses shut down fraudulent domains

30 Whois concerns ICANNs Security and Stability Advisory Committee (SSAC) tracking correlation between addresses placed in Whois and incidence of spam –Malware predators use spamming techniques –Spamming uses Whois But, on the Internet, there is never a direct route and thus never a direct cut-off to a particular problem A logical approach in one area of the Internet creates problems in another area

31 Whois policy process Whois issues are being addressed through the General Names Supporting Organisations (GNSOs) policy development process (PDP) Numerous opportunities for public review and comment

32 Recent public comments on Whois Many support full Whois access – –Businesses and trade organisations –Nonprofits engaged in fighting fraud –Law enforcement agencies Opposition to Whois from other advocacy organisations, some government agencies, some Internet users

33 Different views of Whois Privacy commissioners in the European Union Attention in public comments to restricted access, privacy and accuracy of the data

34 Enforcement of existing Whois policy That will remain the case until the Board approves any new policy, if any

35 Next steps on Whois ICANN staff is preparing notes for the GNSO Council on the Task Force Recommendations to – –Identify issues for clarification –Identify issues for further discussion –Identify potential implementation issues –Suggest a framework for further development of the proposal

36 Task force recommendation (1) Nonbinding recommendation to GNSO Council Operational Point of Control (OPoC) proposal – –Registrants could use an OPoC in place of the current administrative and technical contact details –If there was an issue with the domain name, the OPoC would contact the registrant

37 Task force recommendation (2) OPoC includes – –Improved procedure for correcting inaccurate Whois data OPoC does not include – –Procedure for access by rights-holders, law enforcement – suggests use of best practices for dealing with requests

38 Next steps GNSOs Whois Task Force presented Final Task Force Report to GNSO Council March 2007 Council will send its own recommendations to ICANN Board for consideration and decision. ICANN Board will review GNSO recommendations, 2 nd /3 rd quarter of 2007

39 New generic top-level domain timetable Next working group report to Lisbon meeting in late March Potentially GNSO Policy Development Process may be completed by July meeting in Puerto Rico Policy may be concluded by the end of the 3rd Quarter 2007 Next round of new gTLDs in early 2008?

40 Consider the impact of – Unique industry TLDs Industry cross-certified DNSSEC Other anti-phishing tools?

41 Thank You