Reviewing New gtld Program Safeguards Against DNS Abuse. ICANN Operations and Policy Research 28 January 2016

Similar documents
Rights Protection Mechanisms: User Feedback Session

RDAP Implementation. Francisco Arias & Gustavo Lozano 21 October 2015

Congratulations to Registries! New generic toplevel 500+ been delegated as a result of the New gtld Program. Many more gtlds are on the way.

RDAP Implementation. 7 March 2016 Francisco Arias & Gustavo Lozano ICANN 55 7 March 2016

Rolling the Root Zone KSK. Matt Larson ICANN56 (Helsinki ) June 2016

DNS Risk Framework Update

RDAP: What s Next? Francisco Arias & Marc Blanchet ICANN June 2015

ICANN SSR Update. Save Vocea PacNOG17 Samoa 13 July 2015

Deploying the IETF s WHOIS Protocol Replacement

Universal Acceptance

Privacy and Proxy Service Provider Accreditation. ICANN58 Working Meeting 11 March 2017

Mitigating Malicious Conduct. Background - New gtld Program

IGO/INGO Identifiers Protection Policy Implementation. Meeting with the IRT 9 March 2016

Identifier Technology Health Indicators (ITHI) Alain Durand, Christian Huitema 13 March 2018

Name Collision Mitigation Update

LGR Toolset (beta) User Guide. IDN Program 24 October 2017

Update on ICANN Domain Name Registrant Work

DNS Abuse Handling. FIRST TC Noumea New Caledonia. Champika Wijayatunga Regional Security, Stability and Resiliency Engagement Manager Asia Pacific

LGR Toolset (beta) User Guide. IDN Program October 2016

ICANN and the IANA. Elsa Saade and Fahd Batayneh MEAC-SIG August 2016

Rolling the Root Zone DNSSEC Key Signing Key Edward Lewis AFRINIC25 November 2016

Intellectual Property Constituency (IPC)

Registrar Session ICANN Contractual Compliance

Internet Corporation for Assigned Names and Numbers ( ICANN )

Understanding RDAP and the Role it can Play in RDDS Policy. ICANN October 2018

Registry Internet Safety Group (RISG)

Facilitator Guide: Programme X x time

General Data Protection Regulation (GDPR)

Adobe Connect Webinar Software Host

President s Report 2009

Topic LE /GAC position Registrar Position Agreement in Principle 1. Privacy and Proxy services

Registry Outreach. Contractual Compliance ICANN February 2015

2017 DNSSEC KSK Rollover. Guillermo Cicileo LACNIC March 22, 2017

USING DIALOGUE CONFERENCING INTEGRATED AUDIO WITH ADOBE CONNECT SETTING UP YOUR MEETING ROOM WITH YOUR INTEGRATED AUDIO CONFERENCING PROFILE

DNS Fundamentals. Steve Conte ICANN60 October 2017

IDN Program Update to ccnso. Sarmad Hussain IDN Program Sr. Manager 10 Feb. 2015

Quick Reference Guide: SAP CONNECT

Sponsor s Monthly Report for.coop TLD

Mitigation of Abuse in gtlds. GAC PSWG ICANN 57 5 November 2016

Proposed Final Report on the Post-Expiration Domain Name Recovery Policy Development Process Executive Summary

ICANN Contractual Compliance Proforma DNS Infrastructure Abuse November 2018 Registry Audit Request For Information (RFI)*

All Things WHOIS: Now and in the Future

Christmas Island Domain Administration Limited ( cxda)

Next Steps for WHOIS Accuracy Global Domains Division. ICANN June 2015

ICANN Start, Episode 1: Redirection and Wildcarding. Welcome to ICANN Start. This is the show about one issue, five questions:

Progress Report Negotiations on the Registrar Accreditation Agreement Status as of 1 March 2012

Security & Stability Advisory Committee. Update of Activities

gtld Compliance Program Contractual Compliance

Introduction. Prepared by: ICANN Org Published on: 12 January 2018

The IDN Variant TLD Program: Updated Program Plan 23 August 2012

ICANN Contractual Compliance. ALAC Mee(ng. Sunday, 23 March 2014 #ICANN49

Root KSK Roll Update Webinar

WHOIS Accuracy Study Findings, Public Comments, and Discussion

With this vital goal in mind, MarkMonitor believes that the optimal WHOIS model should have, at minimum, these five important characteristics:

Draft Thick RDDS (Whois) Consensus Policy and Implementation Notes

Contractual Compliance. Text. IPC Meeting. Tuesday, 24 June 2014 #ICANN50

The Healthy Domain Initiative (HDI)

General Update Contractual Compliance Initiatives and Improvements Audit Program Update Complaints Handling and Enforcement Summary

Alright, we will continue with Registries and Registrars and our first speaker is Steve who will talk about registrar basics is that correct, Steve?

Registry Outreach. Contractual Compliance ICANN March 2016

Sponsor s Monthly Report for.coop TLD

Open Mee'ng of the Security & Stability Advisory Commi=ee. 26 October 2009

Contracting and Onboarding!

Contractual Compliance Update ICANN 52 February 2015

Proposed Interim Model for GDPR Compliance-- Summary Description

ADOBE CONNECT TECHNICAL CHECK

Registry Outreach. Contractual Compliance ICANN October 2015

.BIZ Agreement Appendix 10 Service Level Agreement (SLA) (22 August 2013)

Draft Applicant Guidebook, v3

Yes. [No Response] General Questions

ICANN Policy Update & KSK Rollover

Protecting High Value Domains

DNS/DNSSEC Workshop. In Collaboration with APNIC and HKIRC Hong Kong. Champika Wijayatunga Regional Security Engagement Manager Asia Pacific

Adobe Connect Online Class Student Guide

BlueJeans Events Instructions for Moderators. October 2017

Fast Flux Hosting Final Report. GNSO Council Meeting 13 August 2009

WHOIS Accuracy Reporting: Phase 1

Yes. [No Response] General Questions

ICANN and Technical Work: Really? Yes! Steve Crocker DNS Symposium, Madrid, 13 May 2017

ICANN and Academia. Fahd Batayneh Manager, Global Stakeholder Engagement, Middle East. December 2017

Matters Related to WHOIS

Exploring Replacements for WHOIS A Next Generation Registration Directory Service (RDS)

SSR REVIEW IMPLEMENTATION REPORT (Public) *DRAFT*

Root KSK Roll Delay Update

Reservationless-Plus Web-enabled Conferencing Leader Guide

gtld Registrar Manual Part III : Registrar Web

1. Anti-Piracy Services. 2. Brand Protection (SAAS) 3. Brand Protection Services. Data Protection and Permitted Purpose. Services

Using Cisco Unified MeetingPlace for IBM Lotus Notes

User Guide For Invitees. All-in-one webinar solution.

TRANSMITTED VIA ELECTRONIC MAIL, FACSIMILE, AND COURIER

Webinar Singapore office 14 August 2014

Keeping DNS parents and children in sync at Internet Speed! Ólafur Guðmundsson

ICANN Update at PacNOG15

.HEALTH REGISTRATION POLICY

New gtld Application Comments Forum User Guide

ICANN Identifier System SSR Update 1H 2015

Cisco WebEx Meeting Center User Guide. This User Guide provides basic instruction on how to setup, use, and manage your Cisco WebEx Meeting Center.

It Internationalized ti Domain Names W3C Track: An International Web

The Internet Big Bang: Implications for Financial Services Brand Owners

Summary of Expert Working Group on gtld Directory Services June 2014 Final Report

Transcription:

Reviewing New gtld Program Safeguards Against DNS Abuse ICANN Operations and Policy Research 28 January 2016

Discussion Details This discussion is being recorded. Recordings and supporting materials will be published at http://newgtlds.icann.org/reviews. Methods of participation: Adobe Connect + audio (Recommended) Adobe Connect listen only + Comments for Discussion pod Phone only + moderator polling Providing input: Moderator will invite you to speak or read your comment from the Comments for Discussion pod. Mute / unmute = *6 (dial star six on your phone) Mute your line when not speaking. Don t use speakerphone. State your name and affiliation prior to giving your input. Chat: Comments will not be read aloud. Use the Comments for Discussion pod to contribute to the dialogue. 2

Agenda 1 Introduction (10 minutes) 2 Defining DNS Abuse (15 minutes) 3 4 5 6 Measuring DNS Abuse Measuring New gtld Program Safeguards Participant Experience with New gtld Program Safeguards Wrap Up: Next Steps and Methods of Additional Input (15 minutes) (20 minutes) (25 minutes) (5 minutes) 3

Topic 1: Defining DNS Abuse Which activities do you consider to be DNS abuse? If you could put forth a globally accepted definition of DNS abuse, what would it be? This definition should be broad enough to cover various malicious uses of the DNS. [15 minutes] 4

Topic 2: Measuring DNS Abuse General What are the most effective methods to measure the prevalence of abusive activities in the DNS? [15 minutes] 5

Topic 3: Measuring New gtld Program Safeguards How do we measure the effectiveness of these safeguards? Safeguard Rationale Vet registry operators To prevent bad actors from running registries [20 minutes] Require DNSSEC deployment To minimize potential for spoofed DNS records Require Thick WHOIS records To ensure accuracy and completeness of WHOIS data Prohibit wild carding To prevent DNS redirection and synthesized DNS responses Remove orphan glue records Centralize Zone file access Document registry- and registrar-level abuse contacts and policies Establish Expedited Registry Security Request Process (ESRP) Create a high-security zone verification program [NB: Not implemented as new gtld safeguard; voluntary for registries] To minimize use of remnant registry records as safe havens for DNS abuse To allow more efficient access to updates on new domains as they are created within a zone To provide a single point of contact to address abuse complaints and to have a publicly-available description of their anti-abuse measures To address security threats that require immediate action by the registry and an expedited response from ICANN To establish a set of criteria to assure trust in TLDs with higher risk of targeting by malicious actors through enhanced operational and security controls 6

Topic 4: Experience with Safeguards in New gtlds What has been your experience, personally or on behalf of an organization, with these safeguards? Which were effective? Ineffective? How so? Why do you believe they were or were not effective? Are there safeguards that you would suggest for consideration? [25 minutes] 7

Wrap Up: Additional Input Think of something else? Unable to fully express your ideas? Use our questionnaire to provide additional input. Responses must be submitted by Wednesday, 3 February at 18:00 UTC. http://survey.clicktools.com/app/survey/go.jsp?iv=1fkefwusw9hjo Want to know when the report has been published? Send an email to brian.aitchison@icann.org with subject line DNS Abuse Notification 8

Engage with ICANN Thank You and Questions Reach us at: Email: brian.aitchison@icann.org Website: icann.org twitter.com/icann gplus.to/icann facebook.com/icannorg weibo.com/icannorg linkedin.com/company/icann flickr.com/photos/icann youtube.com/user/icannnews slideshare.net/icannpresentations 9