DNSSEC in stats. GC-SEC Global Cyber Security Center. Andrea Rigoni. CENTR Bruxelles, 7th October Global Cyber Security Center Director General
|
|
- Abigayle Gordon
- 8 years ago
- Views:
Transcription
1 Global Cyber Security Center DNSSEC in stats CENTR Bruxelles, 7th October 2010 Andrea Rigoni Global Cyber Security Center Director General
2 On the 7 th of May 2010 Poste Italiane founded GC-SEC, the Global Cyber Security Center a not-for-profit Foundation entirely dedicated to Cyber Security Objectives of GC-SEC General Benefits of GC-SEC Contribute to international innovation and policy agenda on cyber security topics Develop and disseminate a culture of Cyber Security through International Cooperation, Education and Research Provision to national and international partners and other organizations awareness / knowledge on cyber security topics Contribute to enhance Security of Governments and Private Companies in Europe and Worldwide 2
3 Global Cyber Security Center - Introduction Rome, 30 june 2010 The Center is based on a Multi Stakeholder model. Many organizations are joining the Center as members or partners 3 Ministry of Interior / Postal Police Italian Ministry of Economic Development - ISCOM Other Accademia National Institutions George Mason University Royal Holloway University of London, Carnegie Mellon University RUSI - Royal United Services Institute (London) University of Rome University of Milan Università La Sapienza SANS Institute Polytechnic of Milan MIP Business School Global Cyber Security Center Develop and disseminate a culture of Cyber Security through International Cooperation, Education and Research Poste Italiane International Institutions Private Sector Partners US Secret Service Universal Postal Union Department of Homeland Security European Commission / ENISA / JRC NICC (the Netherlands) SEMA (Swedish Emergency Management Agency) Centre for Strategic International Telecomms Union ITU Switzerland IMPACT Policia/Guardia Civil (Spain) ENEL Microsoft SAP Mastercard IBM Cisco Systems Booz & Company Symantec
4 Global Cyber Security Center - Introduction Rome, 30 june 2010 The GC-SEC will perform various core activities International Policy and Cooperation Support to the formulation of new policies And support new initiatives On International Cooperation Education & Training Conduct of highly specialized training and Provide high-level Education program The International Center Information Sharing GC-SEC will promote information Sharing at International Level Between Governments, Academia and Private Sector Research Applied Research on members selected projects 4
5 Agenda Setting the context cctld adoption status DNSSEC zones and TLD situation Performance stats and issues DNSSEC query traffic pattern DNSSEC computing resource overhead Registrars preparedness and issues Future developments and conclusions 5
6 cctld adoption status dnssec-deployment.org Brazil, Bulgaria, Czech Republic, Puerto Rico and Sweden early adopters DNSSEC deployed at ROOT level on July 15,
7 DNSSEC zones and TLD situation 294 TLDs in the root zone in total, of which: 53 TLDs are signed 42 TLDs have trust anchors published as DS records in the root zone 9 TLDs have trust anchors published in the IANA ITAR 11 TLDs have trust anchors published in the ISC DLV Repository 7 SecSpider DNSSEC Monitoring
8 Signed TLDs: 53!! Unsigned: DS record in Root DS record in IANA ITAR DS record in ISC DLV Newly signed; not yet in any repository: 9 10/6/10 8
9 Interval between consecutive queries* for org's DNSKEY per IP 9 Courtesy of Shinkuro
10 Some stats from Comcast 1 Peak queries per second against our DNSSEC-validating resolvers: up 500% since July 2010 [Keep in mind, the query volumes are minuscule on a relative basis, which makes the % look better than reality.] 2 Queries hitting DNSSEC-validating resolvers represents % of our total peak recursive server query volume. This is a natural reflection of the fact that we have a huge network and we're only in trial phase. 3 Queries hitting our authoritative servers for DNSSEC-related records (DNSKEY, DS, NSEC, RRSIG) represents < % of queries of these servers. 10
11 DNSSEC query traffic patterns.uk 11 Still low volume of DNSKEY queries (about 2% resolvers do validation), but slowly increasing Estimated 100 unique individual validating resolvers worldwide
12 DNSSEC computing resource overhead Bandwidth estimation basedon key size RIPE NCC Little impact on CPU load Memory footprint can be considerable but not an issue for authoritative servers running on commodity hardware Bandwidth usage increase can be significant (possible increase by 2 or 3 times) 12
13 Registrars preparedness and issues 1 Factors that registrars say are impeding DNSSEC implementation: Lack of customer demand Developing a process of key management, including storage and rollover Lack of internal expertise Most registrars (69%) will not offer DNSSEC services until 2011 or beyond: 37% planned to offer DNSSEC in % have no plan to offer DNSSEC within the next 12 months. Approximately 15% are going to offer DNSSEC services by the end of AFILIAS Registrar DNSSEC Readiness Report
14 Conclusions DNS is a critical service for Internet and for modern ICT networks Some areas of DNS Security need to be further analyzed and developed, therefore there is a need for new research projects DNS Security Metrics and Governance model DNSSEC implementation business cases GCSEC is willing to invest on DNS Security through: Organization of a DNSSEC Training in December 2010 and/or February 2011 Application to EU Funds for a DNS Security Research Project 14
15 How to stay updated on GC-SEC GCSEC Global Cyber Security Center (GC-SEC) 15
Overview of DNSSEC deployment worldwide
The EURid Insights series aims to analyse specific aspects of the domainname environment. The reports are based on surveys, studies and research conducted by EURid in cooperation with industry experts
More informationDNSSEC - Why Network Operators Should Care And How To Accelerate Deployment
DNSSEC - Why Network Operators Should Care And How To Accelerate Deployment Dan York, CISSP Senior Content Strategist, Internet Society Eurasia Network Operators' Group (ENOG) 4 Moscow, Russia October
More informationDNSSEC in your workflow
DNSSEC in your workflow Presentation roadmap Overview of problem space Architectural changes to allow for DNSSEC deployment Deployment tasks Key maintenance DNS server infrastructure Providing secure delegations
More informationDeploying DNSSEC: From End-Customer To Content
Deploying DNSSEC: From End-Customer To Content March 28, 2013 www.internetsociety.org Our Panel Moderator: Dan York, Senior Content Strategist, Internet Society Panelists: Sanjeev Gupta, Principal Technical
More informationDNS Cache Poisoning Vulnerability Explanation and Remedies Viareggio, Italy October 2008
DNS Cache Poisoning Vulnerability Explanation and Remedies Viareggio, Italy October 2008 Kim Davies Internet Assigned Numbers Authority Internet Corporation for Assigned Names & Numbers Agenda How do you
More informationThe Impact of DNSSEC. Matthäus Wander. on the Internet Landscape. <matthaeus.wander@uni-due.de> Duisburg, June 19, 2015
The Impact of DNSSEC on the Internet Landscape Matthäus Wander Duisburg, June 19, 2015 Outline Domain Name System Security problems Attacks in practice DNS Security Extensions
More informationRoot zone update for TLD managers Mexico City, Mexico March 2009
Root zone update for TLD managers Mexico City, Mexico March 2009 Kim Davies Manager, Root Zone Services Internet Corporation for Assigned Names & Numbers A quick census 280 delegated 11 testing 280 delegated
More informationCurrent Counter-measures and Responses by the Domain Name System Community
Current Counter-measures and Responses by the Domain Name System Community Paul Twomey President and CEO 22 April 2007 APEC-OECD Malware Workshop Manila, The Philippines 1 What I want to do today in 15
More informationSecuring DNS Infrastructure Using DNSSEC
Securing DNS Infrastructure Using DNSSEC Ram Mohan Executive Vice President, Afilias rmohan@afilias.info February 28, 2009 Agenda Getting Started Finding out what DNS does for you What Can Go Wrong A Survival
More informationNext Steps In Accelerating DNSSEC Deployment
Next Steps In Accelerating DNSSEC Deployment Dan York, CISSP Senior Content Strategist, Internet Society DNSSEC Deployment Workshop, ICANN 45 Toronto, Canada October 17, 2012 Internet Society Deploy360
More information2008 DNS Cache Poisoning Vulnerability Cairo, Egypt November 2008
2008 DNS Cache Poisoning Vulnerability Cairo, Egypt November 2008 Kim Davies Manager, Root Zone Services Internet Corporation for Assigned Names & Numbers How does the DNS work? A typical DNS query The
More informationDNS Security: New Threats, Immediate Responses, Long Term Outlook. 2007 2008 Infoblox Inc. All Rights Reserved.
DNS Security: New Threats, Immediate Responses, Long Term Outlook 2007 2008 Infoblox Inc. All Rights Reserved. A Brief History of the Recent DNS Vulnerability Kaminsky briefs key stakeholders (CERT, ISC,
More informationDistributed Denial of Service Attacks
Distributed Denial of Service Attacks Steve Crocker Chair, SSAC June 25, 2007 San Juan, Puerto Rico 1 Agenda Types of Attacks DDoS attacks Amplified DDoS attacks - 2006 Estonia - May 2007 What do Do 2
More informationDNSSec Operation Manual for the.cz and 0.2.4.e164.arpa Registers
DNSSec Operation Manual for the.cz and 0.2.4.e164.arpa Registers version 1.9., valid since 1 January 2010 Introduction This material lays out operational rules that govern the work of the CZ.NIC association
More informationNANOG DNS BoF. DNS DNSSEC IPv6 Tuesday, February 1, 2011 NATIONAL ENGINEERING & TECHNICAL OPERATIONS
NANOG DNS BoF DNS DNSSEC IPv6 Tuesday, February 1, 2011 NATIONAL ENGINEERING & TECHNICAL OPERATIONS The Role Of An ISP In DNSSEC Valida;on ISPs act in two different DNSSEC roles, both signing and valida;ng
More informationDomain Name System Security (DNSSEC)
Dept. of Homeland Security Science & Technology Directorate Domain Name System Security (DNSSEC) CA CISO Lecture Series Sacramento, CA December 15, 2009 Douglas Maughan, Ph.D. Program Manager, CCI douglas.maughan@dhs.gov
More informationDNSSEC Briefing for GAC and ccnso
DNSSEC Briefing for GAC and ccnso Steve Crocker Chair, SSAC October 30, 2007 Los Angeles, CA, USA 1 Topics Infrastructure Security Taxonomy DNSSEC walk through IANA Progress -- Richard Lamb Issues and
More informationDNSSEC for Everybody: A Beginner s Guide
DNSSEC for Everybody: A Beginner s Guide San Francisco, California 14 March 2011 4:00 to 5:00 p.m. Colonial Room The Schedule 2 This is Ugwina. She lives in a cave on the edge of the Grand Canyon... This
More informationDNSSEC Policy Statement Version 1.1.0. 1. Introduction. 1.1. Overview. 1.2. Document Name and Identification. 1.3. Community and Applicability
DNSSEC Policy Statement Version 1.1.0 This DNSSEC Practice Statement (DPS) conforms to the template included in RFC 6841. 1. Introduction The approach described here is modelled closely on the corresponding
More informationHow To Use Dnsec
Jakob-Haringer-Str. 8/V Tel.: +43 662 46 69-0 Fax: +43 662 46 69-19 5020 Salzburg, Austria E-Mail:service@nic.at Web: www.nic.at DNSSEC Policy & Practice Statement (DPS) for.at A: Bank Austria Creditanstalt
More informationDNSSEC: A Vision. Anil Sagar. Additional Director Indian Computer Emergency Response Team (CERT-In)
DNSSEC: A Vision Anil Sagar Additional Director Indian Computer Emergency Response Team (CERT-In) Outline DNS Today DNS Attacks DNSSEC: An Approach Countering DNS Attacks Conclusion 2 DNS Today DNS is
More informationPresented by Greg Lindsay Technical Writer Windows Server Information Experience. Presented at: Seattle Windows Networking User Group April 7, 2010
Presented by Greg Lindsay Technical Writer Windows Server Information Experience Presented at: Seattle Windows Networking User Group April 7, 2010 Windows 7 DNS client DNS devolution Security-awareness:
More informationEDU DNSSEC Testbed. Shumon Huque, University of Pennsylvania Larry Blunk, MERIT Network
EDU DNSSEC Testbed Shumon Huque, University of Pennsylvania Larry Blunk, MERIT Network Internet2 Joint Techs Conference Salt Lake City, Utah February 2nd 2010 1 DNSSEC DNS Security Extensions A system
More informationMonitoring the DNS. Gustavo Lozano Event Name XX XXXX 2015
Monitoring the DNS Gustavo Lozano Event Name XX XXXX 2015 Agenda 1 2 3 Components of the DNS Monitoring gtlds Monitoring other components of the DNS 4 5 Monitoring system Conclusion 2 Components of the
More informationPart 5 DNS Security. SAST01 An Introduction to Information Security 2015-09-21. Martin Hell Department of Electrical and Information Technology
SAST01 An Introduction to Information Security Part 5 DNS Security Martin Hell Department of Electrical and Information Technology How DNS works Amplification attacks Cache poisoning attacks DNSSEC 1 2
More informationXN--P1AI (РФ) DNSSEC Policy and Practice Statement
XN--P1AI (РФ) DNSSEC Policy and Practice Statement XN--P1AI (РФ) DNSSEC Policy and Practice Statement... 1 INTRODUCTION... 2 Overview... 2 Document name and identification... 2 Community and Applicability...
More informationDNSSEC Deployment a case study
DNSSEC Deployment a case study Olaf M. Kolkman Olaf@NLnetLabs.nl RIPE NCCs Project Team: Katie Petrusha, Brett Carr, Cagri Coltekin, Adrian Bedford, Arno Meulenkamp, and Henk Uijterwaal Januari 17, 2006
More informationKim Davies Internet Assigned Numbers Authority
Introducing IANA Baltic Region and Eastern Europe International Seminar The Internet & the post-wsis environment: enhancing dialogue among the stakeholders Riga 2006 Kim Davies Internet Assigned Numbers
More informationDNS & IPv6. Agenda 4/14/2009. MENOG4, 8-9 April 2009. Raed Al-Fayez SaudiNIC CITC rfayez@citc.gov.sa, www.nic.net.sa. DNS & IPv6.
DNS & IPv6 MENOG4, 8-9 April 2009 Raed Al-Fayez SaudiNIC CITC rfayez@citc.gov.sa, www.nic.net.sa Agenda DNS & IPv6 Introduction What s next? SaudiNIC & IPv6 About SaudiNIC How a cctld Registry supports
More informationDNSSEC Practice Statement (DPS)
DNSSEC Practice Statement (DPS) 1. Introduction This document, "DNSSEC Practice Statement ( the DPS ) for the zones under management of Zodiac Registry Limited, states ideas of policies and practices with
More informationA versatile platform for DNS metrics with its application to IPv6
A versatile platform for DNS metrics with its application to IPv6 Stéphane Bortzmeyer AFNIC bortzmeyer@nic.fr RIPE 57 - Dubai - October 2008 1 A versatile platform for DNS metrics with its application
More informationweb hosting and domain names
web hosting and domain names web hosting An internet service provider (ISP) provides internet services A common internet service is web hosting web hosting means storing your website on a public server
More informationIANA Functions to cctlds Sofia, Bulgaria September 2008
IANA Functions to cctlds Sofia, Bulgaria September 2008 Kim Davies Internet Assigned Numbers Authority Internet Corporation for Assigned Names & Numbers What is IANA? Internet Assigned Numbers Authority
More informationDNS Security Survey for National Computer Security Incident Response Teams December 2010
DNS Security Survey for National Computer Security Incident Response Teams December 2010 Summary As referenced during the ICANN meeting in Brussels, Belgium in June 2010, ICANN developed a survey on DNS
More informationDNSSEC Policy and Practice Statement.amsterdam
DNSSEC Policy and Practice Statement.amsterdam Contact T +31 26 352 55 00 support@sidn.nl www.sidn.nl Offices Meander 501 6825 MD Arnhem Mailing address Postbus 5022 6802 EA Arnhem May 24, 2016 Public
More informationInternet-Praktikum I Lab 3: DNS
Kommunikationsnetze Internet-Praktikum I Lab 3: DNS Mark Schmidt, Andreas Stockmayer Sommersemester 2015 kn.inf.uni-tuebingen.de Motivation for the DNS Problem IP addresses hard to remember for humans
More informationDomainWire. Edition 11 Q1 2015. Council of European National Top level Domain Registries - www.centr.org
DomainWire Edition 11 Q1 2015 Global TLD Stat Report DomainWire Stat Report is CENTR s quarterly publication covering status and trends in global top-level domains with a focus on European cctlds (country
More informationMEMORANDUM Date Our reference Page Measures based on the action plan for improved Internet security
MEMORANDUM Date Our reference Page 13 Feb. 2008 File ref: 08-630 1(12) Network Security Department Björn Scharin +46(0)8-678 55 98 bjorn.scharin@pts.se Ministry of Enterprise, Energy and Communications
More informationNetworking Domain Name System
IBM i Networking Domain Name System Version 7.2 IBM i Networking Domain Name System Version 7.2 Note Before using this information and the product it supports, read the information in Notices on page
More informationDRDoS Attacks: Latest Threats and Countermeasures. Larry J. Blunk Spring 2014 MJTS 4/1/2014
DRDoS Attacks: Latest Threats and Countermeasures Larry J. Blunk Spring 2014 MJTS 4/1/2014 Outline Evolution and history of DDoS attacks Overview of DRDoS attacks Ongoing DNS based attacks Recent NTP monlist
More informationA Survey of cctld DNS Vulnerabilities. ITU cctld Workshop March 3, 2003 Jim.Reid@nominum.com
A Survey of cctld DNS Vulnerabilities ITU cctld Workshop March 3, 2003 Jim.Reid@nominum.com RATIONALE Health-check on DNS infrastructure > Now becoming a critical national resource Attacks on DNS servers
More informationWHITE PAPER. Best Practices DNSSEC Zone Management on the Infoblox Grid
WHITE PAPER Best Practices DNSSEC Zone Management on the Infoblox Grid What Is DNSSEC, and What Problem Does It Solve? DNSSEC is a suite of Request for Comments (RFC) compliant specifications developed
More informationCS 355. Computer Networking. Wei Lu, Ph.D., P.Eng.
CS 355 Computer Networking Wei Lu, Ph.D., P.Eng. Chapter 2: Application Layer Overview: Principles of network applications? Introduction to Wireshark Web and HTTP FTP Electronic Mail: SMTP, POP3, IMAP
More informationComments on Docket Number 0810021307-81308-1, Enhancing the Security and Stability of the Internet s Domain Name and Addressing System
The Office of International Affairs National Telecommunications and Information Administration U.S. Department of Commerce Ms. Fiona Alexander Comments on Docket Number 0810021307-81308-1, Enhancing the
More informationThe IANA Functions. An Introduction to the Internet Assigned Numbers Authority (IANA) Functions
The IANA Functions An Introduction to the Internet Assigned Numbers Authority (IANA) Functions Contents SECTION 1: INTRODUCTION 4 SECTION 2: POLICY, STAKEHOLDERS AND STEWARDSHIP IMPLEMENTATION 6 SECTION
More informationIPv6 Around the World
IPv6 Around the World IPv6 deployment is increasing its momentum globally, and IPv4 address exhaustion is approaching rapidly. Many parts of the world are engaged in efforts to increase broadband penetration,
More informationDNSSEC and DNS Proxying
DNSSEC and DNS Proxying DNS is hard at scale when you are a huge target 2 CloudFlare DNS is big 3 CloudFlare DNS is fast 4 CloudFlare DNS is always under attack 5 CloudFlare A secure reverse proxy for
More informationDEVELOPMENT PLAN FOR THE DEPLOYMENT OF INTERNET PROTOCOL VERSION 6 (IPv6) IN SPAIN. 29th April 2011
DEVELOPMENT PLAN FOR THE DEPLOYMENT OF INTERNET PROTOCOL VERSION 6 (IPv6) IN SPAIN 29th April 2011 1 Table of Contents PLAN APPROVAL AND OBJECTIVE 3 THE IPv4 PROTOCOL 4, 5 DEPLOYMENT OF IPv6 PROTOCOL 6,
More informationDNSSEC: INFRASTRUCTURE A PROTOCOL TOWARD SECURING THE INTERNET
BY AMY FRIEDLANDER, ALLISON MANKIN, W. DOUGLAS MAUGHAN, AND STEPHEN D. CROCKER DNSSEC: A PROTOCOL TOWARD SECURING THE INTERNET INFRASTRUCTURE DNSSEC is properly understood as a component in an ecology
More informationTopics of Interest Iraklion, Greece June 2008
Topics of Interest Iraklion, Greece June 2008 Kim Davies Internet Assigned Numbers Authority Internet Corporation for Assigned Names & Numbers Agenda ICANN Budget for 2009 Interim Trust Anchor Repository
More informationA Best Practices Architecture for DNSSEC
WHITEPAPER A Best Practices Architecture for DNSSEC Cricket Liu, Vice President of Architecture Background The Domain Name System is the Internet s standard naming service. DNS is responsible for mapping
More informationTHE MASTER LIST OF DNS TERMINOLOGY. First Edition
THE MASTER LIST OF DNS TERMINOLOGY First Edition DNS can be hard to understand and if you re unfamiliar with the terminology, learning more about DNS can seem as daunting as learning a new language. To
More informationThe DOMAIN NAME INDUSTRY BRIEF VOLUME 8 - ISSUE 3 - AUGUST 2011
The DOMAIN NAME INDUSTRY BRIEF VOLUME 8 - ISSUE 3 - AUGUST 2011 THE VERISIGN DOMAIN REPORT As the global registry operator for.com and.net, Verisign reviews the state of the domain name industry through
More informationAmerican International Group, Inc. DNS Practice Statement for the AIG Zone. Version 0.2
American International Group, Inc. DNS Practice Statement for the AIG Zone Version 0.2 1 Table of contents 1 INTRODUCTION... 6 1.1 Overview...6 1.2 Document Name and Identification...6 1.3 Community and
More informationTelecom and Internet Regulatory Challenges and Opportunities Names, Numbers, Internet Governance
Telecom and Internet Regulatory Challenges and Opportunities Names, Numbers, Internet Governance Global Forum ICT & The Future of Internet Bucharest, Romania, 19-20 October 2009 Theresa Swinehart Vice-President
More informationDNS Amplification Attacks as a DDoS Tool and Mitigation Techniques
DNS Amplification Attacks as a DDoS Tool and Mitigation Techniques Klaus Steding-Jessen jessen@cert.br! Computer Emergency Response Team Brazil - CERT.br Network Information Center Brazil - NIC.br Brazilian
More informationDNS Risks, DNSSEC. Olaf M. Kolkman and Allison Mankin. olaf@nlnetlabs.nl and mankin@psg.com. http://www.nlnetlabs.nl/ 8 Feb 2006 Stichting NLnet Labs
DNS Risks, DNSSEC Olaf M. Kolkman and Allison Mankin olaf@nlnetlabs.nl and mankin@psg.com 8 Feb 2006 Stichting NLnet Labs DNSSEC evangineers of the day Allison: Independent consultant Member of the Internet2
More informationF-Root's DNSSEC Signing Plans. Keith Mitchell Internet Systems Consortium DNS-OARC NANOG48, Austin, 24 th Feb 2010
F-Root's DNSSEC Signing Plans Keith Mitchell Internet Systems Consortium DNS-OARC NANOG48, Austin, 24 th Feb 2010 What is ISC? Internet Systems Consortium, Inc. Headquartered in Redwood City, California
More informationA Case for Comprehensive DNSSEC Monitoring and Analysis Tools
A Case for Comprehensive DNSSEC Monitoring and Analysis Tools Casey Deccio Sandia National Laboratories ctdecci@sandia.gov Jeff Sedayao and Krishna Kant Intel Corporation {jeff.sedayao,krishna.kant}@intel.com
More informationDNSSEC Root Zone. High Level Technical Architecture
DNSSEC Root Zone Prepared by the Root DNSSEC Design Team Joe Abley David Blacka David Conrad Richard Lamb Matt Larson Fredrik Ljunggren David Knight Tomofumi Okubo Jakob Schlyter Version 1.4 June 7, 2010
More informationPLAN FOR ENHANCING INTERNET SECURITY, STABILITY, AND RESILIENCY
PLAN FOR ENHANCING INTERNET SECURITY, STABILITY, AND RESILIENCY June 2009 Table of Contents Executive Summary... 1 ICANN s Role... 2 ICANN Security, Stability and Resiliency Programs... 3 Plans to Enhance
More informationService Expectations of Root Servers
Service Expectations of Root Servers RSSAC- 001 1, 2013-05- 02 Table of Contents Revision History... 2 1. Introduction... 2 2. Service Provided by Root Servers... 3 3. Expectations of Root Server Operators...
More informationDNS/Hostmaster Architecture for the Greek Network of Health
DNS/Hostmaster Architecture for the Greek Network of Health and Welfare Services Petros Lampsas, Aristides Vagelatos, Dimitris Sofotassios, Christos Papanikolaou, Christos Manolopoulos Computer Technology
More informationSummary - ENUM functions that maps telephone numbers to Internet based addresses - A description and the possible introduction to Sweden
DATE REFERENCE NO. 30 March 2001 01-9734 Summary - ENUM functions that maps telephone numbers to Internet based addresses - A description and the possible introduction to Sweden AUTHOR Joakim Strålmark
More informationDNS and BIND. David White
DNS and BIND David White DNS: Backbone of the Internet Translates Domains into unique IP Addresses i.e. developcents.com = 66.228.59.103 Distributed Database of Host Information Works seamlessly behind
More informationSecurity in the Network Infrastructure - DNS, DDoS,, etc.
Security in the Network Infrastructure - DNS, DDoS,, etc. GTER, São Paulo December 8, 2006 Steve Crocker, steve@shinkuro.com Russ Mundy, mundy@sparta.com Proactive Security Build security into the infrastructure
More informationWhere is Hong Kong in the secure Internet infrastructure development. Warren Kwok, CISSP Internet Society Hong Kong 12 August 2011
The Internet is for Everyone. Become an ISOC Member. Cyber Security Symposium 2011 Where is Hong Kong in the secure Internet infrastructure development Warren Kwok, CISSP Internet Society Hong Kong 12
More informationComputer Networks: Domain Name System
Computer Networks: Domain Name System Domain Name System The domain name system (DNS) is an application-layer protocol for mapping domain names to IP addresses DNS www.example.com 208.77.188.166 http://www.example.com
More informationHow To Understand The Effect Of A Domain Name Extension On A Network Attack On A Domain Names Server (Dns)
DNSSEC and Its Potential for DDoS Attacks A Comprehensive Measurement Study Roland van Rijswijk-Deij University of Twente and SURFnet bv r.m.vanrijswijk@utwente.nl Anna Sperotto University of Twente a.sperotto@utwente.nl
More informationUse Domain Name System and IP Version 6
Use Domain Name System and IP Version 6 What You Will Learn The introduction of IP Version 6 (IPv6) into an enterprise environment requires some changes both in the provisioned Domain Name System (DNS)
More informationSupporting CSIRTs in the EU Marco Thorbruegge Head of Unit Operational Security European Union Agency for Network and Information Security
Supporting CSIRTs in the EU Marco Thorbruegge Head of Unit Operational Security European Union Agency for Network and Information Security www.enisa.europa.eu European Union Agency for Network and Information
More informationICANN STRATEGIC PLAN JULY 2012 JUNE 2015
ICANN STRATEGIC PLAN JULY 2012 JUNE 2015 One World. One Internet. One World. One Internet. ICANN is the global organization that coordinates the Internet s unique identifier systems for worldwide public
More informationDNSSEC. Introduction. Domain Name System Security Extensions. AFNIC s Issue Papers. 1 - Organisation and operation of the DNS
AFNIC s Issue Papers DNSSEC Domain Name System Security Extensions 1 - Organisation and operation of the DNS 2 - Cache poisoning attacks 3 - What DNSSEC can do 4 - What DNSSEC cannot do 5 - Using keys
More informationDNSSEC Root Zone. High Level Technical Architecture
DNSSEC Root Zone Prepared by the Root DNSSEC Design Team Joe Abley David Blacka David Conrad Richard Lamb Matt Larson Fredrik Ljunggren David Knight Tomofumi Okubo Jakob Schlyter Version 1.2.1 October
More informationRIPE Policy Development Process
RIPE Policy Development Process And some recent topics 1 Overview RIPE RIPE Policy Development Process (PDP) Current Topics - IPv4 Depletion - IPv6 Deployment 2 RIPE Folks in Europe talking about TCP/IP
More informationHow To Understand The Role Of Internet Governance
NIDA Role of ICANN and Global Internet Governance July 10, 2007 Kelly Hye-Young Kang Manager of International Affairs National Internet Development Agency of Korea (NIDA) Contents Prologue Birth of ICANN
More informationDNSSEC Deployment Activity in Japan - Introduction of DNSSEC Japan - Yoshiki Ishida, Yoshiro Yoneya, Tsuyoshi Toyono, Miki Takata DNSSEC Japan
DNSSEC Deployment Activity in Japan - Introduction of DNSSEC Japan - Yoshiki Ishida, Yoshiro Yoneya, Tsuyoshi Toyono, Miki Takata DNSSEC Japan Agenda Background Introduction of DNSSEC Japan Accomplishments
More informationResilience improving features of MPLS, IPv6 and DNSSEC
Resilience improving features of MPLS, IPv6 and DNSSEC So?ris Ioannidis Ins%tute of Computer Science (ICS) Founda%on for Research and Technology Hellas (FORTH) Crete, Greece MPLS, IPv6 and DNSSEC MPLS
More informationCS 557 - Lecture 22 DNS Security
CS 557 - Lecture 22 DNS Security DNS Security Introduction and Requirements, RFC 4033, 2005 Fall 2013 The Domain Name System Virtually every application uses the Domain Name System (DNS). DNS database
More informationDNSSEC - Tanzania
DNSSEC Policy & Practice Statement for.tz Zone Version 1.1 Effective Date: January 1, 2013 Tanzania Network Information Centre 14107 LAPF Millenium Towers, Ground Floor, Suite 04 New Bagamoyo Road, Dar
More informationDNSSEC Applying cryptography to the Domain Name System
DNSSEC Applying cryptography to the Domain Name System Gijs van den Broek Graduate Intern at SURFnet Overview First half: Introduction to DNS Attacks on DNS Second half: DNSSEC Questions: please ask! DNSSEC
More informationIPv6 support in the DNS
IPv6 support in the DNS How important is the DNS? Getting the IP address of the remote endpoint is necessary for every communication between TCP/IP applications Humans are unable to memorize millions of
More informationInternet Technical Governance: Orange s view
Internet Technical Governance: Orange s view 1 Internet Technical Governance: Orange s view With the increasing use of IP technologies in the electronic communication networks and services, Internet Technical
More informationInternet Security and Resiliency: A Collaborative Effort
Internet Security and Resiliency: A Collaborative Effort Baher Esmat Manager, Regional Relations Middle East MENOG 4 Manama, 9 April 2009 1 WHAT IS THIS PRESENTATION ABOUT? ICANN s effort in enhancing
More informationA Review of Administrative Tools for DNSSEC Spring 2010
Page 1 (29) Andreas Nilsson Certezza AB Stockholm 2010-05-31 A Review of Administrative Tools for DNSSEC Spring 2010 Kornhamnstorg 61, 2 tr SE-111 27 Stockholm Sweden Telefon: +46 (0)8 791 92 00 Telefon:
More informationmydnsipv6 Success Story
Internet Identity For All mydnsipv6 Success Story By Norsuzana Harun Manager, Technology and Innovation Dept. 20 th July 2009 Agenda 1. About mydnsipv6 mydnsipv6 Roadmap (2006 2010) 2. mydnsipv6 Test Bed
More informationD o m a in Name. Council of European National Top level Domain Registries - www.centr.org. Edition 4 - May 2013
Edition 4 - May 23 D o m a in Name Stat Report DomainWire Stat Report is CENTR s biannual publication covering basic domain name statistics with a focus on European cctlds (country code Top Level Domains).
More informationOperation of the Root Name Servers
Operation of the Root Name Servers Lars-Johan Liman, i.root-servers.net John Crain, l.root-servers.net Suzanne Woolf, f.root-servers.net Bill Manning, b.root-servers.net Axel Pawlik, Rob Blokzijl, k.root-servers.net
More informationTHE MASTER LIST OF DNS TERMINOLOGY. v 2.0
THE MASTER LIST OF DNS TERMINOLOGY v 2.0 DNS can be hard to understand and if you re unfamiliar with the terminology, learning more about DNS can seem as daunting as learning a new language. To help people
More informationPrepared by: National Institute of Standards and Technology SPARTA, Inc. Shinkuro, Inc.
Signing the Domain Name System Root Zone: Technical Specification Prepared for: Science and Technology Directorate US Department of Homeland Security Prepared by: National Institute of Standards and Technology
More informationPROPOSAL 20. Resolution 130 of Marrakesh on the role of ITU in information and communication network security
PROPOSAL 20 Resolution 130 of Marrakesh on the role of ITU in information and network security Submitted by the following Member States: Germany (Federal Republic of), Austria, Belarus (Republic of), Bulgaria
More informationRoot Zone KSK: The Road Ahead. Edward Lewis DNS-OARC & RIPE DNSWG May 2015 edward.lewis@icann.org
Root Zone KSK: The Road Ahead Edward Lewis DNS-OARC & RIPE DNSWG May 2015 edward.lewis@icann.org Agenda Setting the scene Change of Hardware Security Modules (HSMs) Roll (change) the Key Signing Key (KSK)
More informationDNS security: poisoning, attacks and mitigation
DNS security: poisoning, attacks and mitigation The Domain Name Service underpins our use of the Internet, but it has been proven to be flawed and open to attack. Richard Agar and Kenneth Paterson explain
More informationSection 1 Overview... 4. Section 2 Home... 5
ecogent User Guide 2012 Cogent Communications, Inc. All rights reserved. Every effort has been made to ensure that the information in this User Guide is accurate. Information in this document is subject
More informationDNSSEC Explained. Marrakech, Morocco June 28, 2006
DNSSEC Explained Marrakech, Morocco June 28, 2006 Ram Mohan rmohan@afilias.info Agenda Getting Started Finding out what DNS does for you What Can Go Wrong A Survival Guide to DNSSEC Why Techies Created
More informationDNS Measurements, Monitoring & Quality Control
DNS Measurements, Monitoring & Quality Control Universität Bielefeld pk@techfak.uni-bielefeld.de CENTR General Assembly Budapest, 2003-06-02 CENTR GA 2003-06-02 DNS Monitoring 1 of 18 The Monitor Some
More informationDNSSEC: The Antidote to DNS Cache Poisoning and Other DNS Attacks
F5 Technical Brief DNSSEC: The Antidote to DNS Cache Poisoning and Other DNS Attacks Domain Name System (DNS) provides one of the most basic but critical functions on the Internet. If DNS isn t working,
More informationSIDN Server Measurements
SIDN Server Measurements Yuri Schaeffer 1, NLnet Labs NLnet Labs document 2010-003 July 19, 2010 1 Introduction For future capacity planning SIDN would like to have an insight on the required resources
More informationDNSSEC. Matthäus Wander. Erlangen, April 20, 2015. and the Hassle of Negative Responses. <matthaeus.wander@uni-due.de>
DNSSEC and the Hassle of Negative Responses Matthäus Wander Erlangen, April 20, 2015 Security Goal of DNSSEC Query: www? ftp mail ns1 www Matthäus Wander 2 Security Goal of
More informationHow to Install the Active Directory Domain Services (AD DS) Role in Windows Server 2008 R2 and Promote a Server to a Domain Controller
How to Install the Active Directory Domain Services (AD DS) Role in Windows Server 2008 R2 and Promote a Server to a Domain Controller I am not responsible for your actions or their outcomes, in any way,
More information