The Canadian Internet Registration Authority (CIRA) manages a 100% up time service - the.ca domain name registry for over 2.



Similar documents
BEST PRACTICES FOR IMPROVING EXTERNAL DNS RESILIENCY AND PERFORMANCE

ANATOMY OF A DDoS ATTACK AGAINST THE DNS INFRASTRUCTURE

THE MASTER LIST OF DNS TERMINOLOGY. First Edition

USING TRANSACTION SIGNATURES (TSIG) FOR SECURE DNS SERVER COMMUNICATION

THE MASTER LIST OF DNS TERMINOLOGY. v 2.0

OVERVIEW OF THE DNS AND GLOSSARY OF TERMS

OVERVIEW OF THE DNS AND GLOSSARY OF TERMS

Computer Networks: Domain Name System

State of the Cloud DNS Report

STATE OF DNS AVAILABILITY REPORT

State of the Cloud DNS Report

Why Managed DNS Services

OpenSRS Quickstart Guide April 15, 2011

5 DNS Security Risks That Keep You Up At Night (And How To Get Back To Sleep)

GLOBAL SERVER LOAD BALANCING WITH SERVERIRON

Four Reasons To Outsource Your DNS

CIRA Corporate Plan Fiscal Year

Microsoft Exam

ATTERCOPIA MANAGED HOSTING & DOMAIN SERVICES TERMS & CONDITIONS

K-Root Name Server Operations

WHITE PAPER. DNS: Key Considerations Before Deploying Your Solution

Copyright

Request Routing, Load-Balancing and Fault- Tolerance Solution - MediaDNS

CIRA Corporate Plan Fiscal Year 2015

F5 Intelligent DNS Scale. Philippe Bogaerts Senior Field Systems Engineer mailto: Mob.:

Best Practices in DNS Anycast Service-Provision Architecture. Version 1.1 March 2006 Bill Woodcock Gaurab Raj Upadhaya Packet Clearing House

CYBERSECURITY INESTIGATION AND ANALYSIS

C u s t o m e r S u p p o r t

CIRA Strategic Plan Summary

High-Performance DNS Services in BIG-IP Version 11

At dincloud, Cloud Security is Job #1

Specifications for Registrars' Interaction with Flexireg Domain Registration System

THE DOMAIN NAME INDUSTRY BRIEF VOLUME 11 ISSUE 1 APRIL 2014

Internet Performance Impacts of Canadian Content Hosting

New gtld Basics New Internet Extensions

Domain Names & Web Hosting. Webpage Design

CAST CENTER FOR ADVANCED SECURITY TRAINING. CAST618 Designing and Implementing Cloud Security CAST

PEQ-DNS A Platform for DNS Quality Monitoring

Baidu: Webmaster Tools Overview and Guidelines

CDN SERVICE ICSS ROUTE MANAGED DNS DEUTSCHE TELEKOM AG INTERNATIONAL CARRIER SALES AND SOLUTIONS (ICSS)

Current Counter-measures and Responses by the Domain Name System Community

Meeting Management Solution. Technology and Security Overview N. Dale Mabry Hwy Suite 115 Tampa, FL Ext 702

The OpenDNS Global Network Delivers a Secure Connection Every Time. Everywhere.

Innovating with the Domain Name System: From Web to Cloud to the Internet of Things

AKAMAI SOLUTION BROCHURE CLOUD SECURITY SOLUTIONS FAST RELIABLE SECURE.

Company Overview. October 2014

Zscaler Internet Security Frequently Asked Questions

The Importance of High Customer Experience

FAQ (Frequently Asked Questions)

Securing DNS Infrastructure Using DNSSEC

System & Service Operations in CNNIC. September 10, 2013

IDP. User Manual v3.0. Section 4: Domain Transfers.

Domain Name Industry. Comparing ZA with the rest

Network Infrastructure for Critical DNS. Steve Gibbard

Security Policy JUNE 1, SalesNOW. Security Policy v v

new gtlds: WHAT DO THEY MEAN FOR YOUR BUSINESS? Jim Reid

DNS Architecture Case Study: Resiliency and Disaster Recovery

Creating Custom Nameservers Contents

Advanced High. Architecture.

DNS Measurements, Monitoring & Quality Control

Active Directory Domain Services on the AWS Cloud: Quick Start Reference Deployment Mike Pfeiffer

Building your Server for High Availability and Disaster Recovery. Witt Mathot Danny Krouk

Infoblox Grid TM. Automated Network Control for. Unifying DNS Management and Extending the Infoblox Grid TM to the F5 Global Traffic Manager

Automated Network Control for

CA Cloud Overview Benefits of the Hyper-V Cloud

Deploying IP Anycast. Core DNS Services for University of Minnesota Introduction and General discussion

Addressing SMTP-based Mass-Mailing Activity Within Enterprise Networks.

How To Use An Ibm Cloud Server For Business

NET0183 Networks and Communications

Global Server Load Balancing

Final. Dr. Paul Twomey President and Chief Executive Officer Internet Corporation for Assigned Names and Numbers (ICANN)

.tirol Anti-Abuse Policy

Network Infrastructure for Critical DNS. Steve Gibbard

Service Level Agreement for Windows Azure operated by 21Vianet

Vodafone Business Product Management Group. Web and Domain Frequently Asked Questions (FAQs)

Measuring the Web: Part I - - Content Delivery Networks. Prof. Anja Feldmann, Ph.D. Dr. Ramin Khalili Georgios Smaragdakis, PhD

Networking Domain Name System

Quick Start Guide: Utilizing Nessus to Secure Microsoft Azure

My Services Online Service Support. User Guide for DNS and NTP services

Appendix E to DIR Contract Number DIR-TSO-2736 CLOUD SERVICES CONTENT (ENTERPRISE CLOUD & PRIVATE CLOUD)

Web Hosting 101. with Patrick McNeil

Ensuring Business Continuity and Disaster Recovery with Coyote Point Systems Envoy

Why is Redundancy Important?

Monitoring the DNS. Gustavo Lozano Event Name XX XXXX 2015

OpenSRS Domain Transfers Guide. October 23, 2008

A Layman's Guide to Global Server Load Balancing

The data which you put into our systems is yours, and we believe it should stay that way. We think that means three key things.

Specifications for Registrars' Interaction with the Domain Registration System During Landrush and General Registration Periods

Securing Your Business with DNS Servers That Protect Themselves

Best Practices for Protecting your Online Brand. Gretchen Olive Baltimore ACC November 15, 2007

YOUR CANADIAN CONNECTION

OpenSRS Reseller s Guide to Domain Name Registration and Management. Version 2.10 August 25, 2007

FortiBalancer: Global Server Load Balancing WHITE PAPER

MAKING ENTERPRISE DNS SERVICES AN OPTION FOR THE ENTIRE WORLD

Load Balancing Microsoft Sharepoint 2010 Load Balancing Microsoft Sharepoint Deployment Guide

The Adoption of Digital Technology by Canadian Small and Medium-sized Enterprises. The Canadian Internet Registration Authority (CIRA)

PLAN FOR ENHANCING INTERNET SECURITY, STABILITY, AND RESILIENCY

Where is Hong Kong in the secure Internet infrastructure development. Warren Kwok, CISSP Internet Society Hong Kong 12 August 2011

How To Understand The Power Of A Content Delivery Network (Cdn)

Transcription:

WHO IS.CA ( CIRA )? The organization responsible for a critical part of the Internet infrastructure; expanding its services to help organizations secure their DNS in Canada The Canadian Internet Registration Authority (CIRA) manages a 100% up time service - the.ca domain name registry for over 2.4 million domains Provide DNS for.ca, answering 3 billion DNS queries per month CIRA is a member-driven organization of over 70 employees and an elected 12-person board CIRA supports the growth of a strong and reliable Internet for all Canadians by investing in Internet projects, and helping to represent Canadian Internet interests around the world

CIRA is More Than a Registry So you know us for.ca, but what else is CIRA up to? D-Zone Anycast DNS Domain Security gtlds

DNS IS MISSION CRITICAL DNS is a mission critical service that requires 100% uptime and low latency During a DNS outage websites, web applications, and email are down DNS outages result in brand damage and/or lost revenue DNS lookups contribute to website performance From Alexa percentage ranking averages municipalities can expect to rank 1,000 10,000 in Canada 50,000 180,000 Globally Primarily Canadian Traffic 75% Canadian 25% International

DNS IS VULNERABLE DNS is vulnerable to failures and attack Numerous Failure Mechanisms - Equipment failure - Network outages - Natural disasters - Need diversity DNS based DDOS Attacks account for 10% of all attacks DNS as the target DNS as the attack vector DNS attacks are easy to generate and hard to defend

STRENGTHEN DNS WITH ANYCAST Anycast DNS has been used for many years for the root servers and many TLDs and provides: Redundancy and fault tolerance High Performance Resiliency to DDOS attacks

ANYCAST DNS VS UNICAST UNICAST Unicast Traditional DNS deployments Nameservers are implemented on single nodes, each with a unique IP address Anycast Adding resiliency to your DNS Nameservers are implemented on a multiple geographically distributed nodes that share a single IP address routing to the closest nameserver Built in redundancy, failover and load distribution ANYCAST

CIRA s D-ZONE - A GLOBAL ANYCAST DNS SERVICE THAT PUTS CANADA AND CANADIAN TRAFFIC FIRST Location Cloud Miami, FL 1 Los Angeles, CA 1 London, UK 1 Hong Kong 1 Calgary, AB 1 Montreal, QC 1 Toronto, ON 1 Winnipeg, MB 1 Location Cloud Vancouver, BC 2 Montreal, QC 2 Toronto, ON 2 Halifax, NS 2

D-Zone Base Pricing Business Value for the cost of a monthly cell phone bill Performance, Security, Reliability D-Zone Anycast DNS Cloud Service Pricing YEAR 1 - $1200 Annual $100/month Includes: up to 500 zones configured Unlimited queries provisioning API available for automation use of D-Zone management interface access to query metrics and ongoing analytics CIRA technical support

Example of DNS Traffic City of Hamilton

Implementing D-Zone D-Zone Secondary DNS Low Risk and Ease of Implementation for IT staff 1 2 3 Zone Transfer Internet D-Zone Hidden Masters 162.219.53.35 162.219.53.235 D-Zone Anycast Clouds ns1.d-zone.ca DNS Queries On Your Primary Name Server Allow zone transfer to 162.219.53.35 162.219.53.235 Enable notify to 162.219.53.35 162.219.53.235 In D-Zone Web Portal - Create your primary name servers - - Create your zone owner - - Create your zone ns2.d-zone.ca At your registrar Add ns1.d-zone.ca and ns2.dzone.ca as authoritative for your domain

CIRA D-ZONE Partners

Domain Name Protection Owning a domain is high risk

Domain Hijacking Domain hijacking describes the act of a hacker using social engineering to trick the technical support workers at a registrar (like GoDaddy, Webnames, Domains at Cost, etc.) into making critical changes to the DNS. It can be done by the malicious act of someone outside or within your organization Registry lock down, Registrar, Registrant EPP API protocol standard

CIRA Registry Lock When Registry Lock is applied to a domain name, no attributes of the domain are changeable and no transfer or deletion transactions can be processed against the domain name, with the exception of renewals..ca,.com, and others all offer this service. If the Registrant wishes to make any changes to their domain, the Registrant must first work with their Registrar, who will in turn work with the.ca Registry. The.CA Registry will respond to any lock and unlock requests in under one hour (typically under 5 mins), on a 24x7 basis, so accessing your.ca domain name is not an administrative burden. Registrant Requests unlocking Registrar Key contacts use admin protocols to authenticate with CIRA CIRA Unlocks the domain for the proscribed period of time

Top tips for managing your domain We learn a lot by managing a technical support desk. These tips are based on the hundreds of calls we field every day. 1. Conduct a good domain name audit 2. Know your Registrar(s) 3. Keep your.ca contact information current 4. Don't lose control: Renew your domain name(s) 5. Use strong passwords 6. Whitelist your registrar and CIRA

New gtlds (protecting your brand)

The Opportunity Canadian Municipalities have a unique opportunity to promote their city brand online in a new way that include.. Municipal Services Attractions & Tourism SME & E-Commerce Policies and By-laws Current Projects and Vision with Municipal Top Level Names.City,.Municipality,.Town

Municipal Top Level Names RoyalFamily.toronto tockexchange carservice.toronto cntower TheLeafs.toronto HighTea MadameTussauds

New gtld market share The market has grown to almost 6 million new gtlds registered globally Big winners are often disguised by the go-to-market strategy.xyz gave them away for a while.science has a low cost strategy at launch

More facts 66 total geographically-focused gtlds (i.e. representing a city) were applied for in the first round 3 of the current top 20 are geo-focused.berlin,.nyc,.london Two are Chinese characters (a type of geo-focusing) web and company The next round of gtld applications is expected in 2018 or 2019 and we know that cities and entrepreneurs will be aggressive You should at least investigate what this means to your municipality

Here is what you can do with it program pages Events Homeowner portals Support local business Create a searchable portal of companies that are all physically in your municipality

The Opportunity Your Community would be complemented by.municipality Municipal Services: Transportation.MUNICIPALITY Attractions & Tourism: Festivals.MUNICIPALITY SME & E-Commerce: Businesses.MUNICIPALITY Policies and By-laws: By-Laws.MUNICIPALITY Projects and Vision: Coming to.municipality Easy to Understand, Easy to Find, Easy to Maintain Municipalities are doing this today!

Municipal Top Level Names

Why are municipalities interested? Branding London s new domain name provides a phenomenal opportunity to link businesses all over the world with our city s powerful brand. London Mayor Boris Johnson Thought Leadership and Technical Innovation o The future of online city branding Revenue Opportunity (or Neutral) o Monetary value of popular names

Why are municipalities interested? Control Establish rules on who can own a.municipality domain Establish policy on acceptable uses Enable improved communications with your citizens Reserve critical names for your own use Reserve before other jurisdictions do

Next steps Champion! Collaboration The next round is still a couple years away (FY2018 or later) Encourage discussion to start in 2015 o.nyc started planning in 2009 (launched in 2014) o CIRA can help lead this discussion

Contact details Shawn Beaton CIRA Business Development & Sales Tel: (613) 793-9366 Shawn.beaton@cira.ca