SlideShare a Scribd company logo
1 of 33
Download to read offline
1
Regional Internet Registries (RIRs)
and Law Enforcement Agencies
UN INCB - Expert Group Meeting on Dangerous Substance Trafficking
through Social Media and other Internet-related Services
1 July 2020
Jamie Gillespie, Security Specialist at APNIC
jamie@apnic.net
whois: Jamie Gillespie
• Jamie Gillespie
– jamie@apnic.net
– Security Specialist @ APNIC
– Community engagement, CERT building, InfoSec training, awareness
• Work history
– 8 years at AusCERT, Australia’s national CERT
– Google
– Macquarie Telecom / Cloud Services
2
5
Internet and IP Basics
Internet Basics
• Every device on the Internet needs an address, to be found by other
devices
– IPv4: 66.220.144.0
– IPv6: 2a03:2880:11:2f83:face:b00c:0:25de
• Humans are not good with numbers. We have domain names that
translate to address: www.facebook.com → 69.171.239.12
6
The Internet is a Series of Networks
• The Network of Networks
7
Names and Numbers
8
The Internet
2001:0C00:8888:: 2001:0400::
www.apnic.net
202.112.0.46
2001:0400::
My Computer www.apnic.net
www.apnic.net
202.112.0.46
2001:0400::
9
Who is Who in the Internet
Acronyms and Initialisms
• Before we go any further, we should probably define what a
bunch of common acronyms and initialisms mean
– IETF - Internet Engineering Task Force
– IANA - Internet Assigned Numbers Authority
– ICANN - Internet Corporate for Assigned Names and Numbers
– TLD - Top Level Domain
– gTLD - Generic Top Level Domain
– ccTLD - Country Code Top Level Domain
– RIR - Regional Internet Registry
10
Where do IP addresses come from?
11
RIRs from a Global Perspective
12
Regional Internet Registries
13
How APNIC and the RIRs Operate
• APNIC is the Regional Internet Registry
(RIR) for the Asia Pacific region
• Membership-based, not-for-profit
• Industry self-regulatory body
– Open
– Consensus-based
– Transparent
• Delegates and manages Internet
number resources
– IPv4 and IPv6 addresses
• Diagram on next slide
– AS numbers
14
APNIC’s Roles and Services
• Delegates and manages Internet resources
– IPv4 & IPv6 addresses, AS Numbers
• Maintains the APNIC Whois Database
• Manages reverse DNS delegations
– But is NOT a domain name registry
• Facilitates IP address policy development
• Provides capacity building through training, workshops,
conferences, fellowships, and grants
– resource management, routing, IPv6 deployment, and security
• Research, measurements, publications
• Supports Internet infrastructure development
– Root server deployment, Internet Exchange Points (IXPs)
15
So who gets IP address and AS numbers?
• National Internet Registry
• Telcos, ISPs, Mobile Operators
• Hosting Company (Amazon/AWS, Azure, GCP, Linode)
• Universities, Government Departments, Banks
16
How APNIC and the RIRs work with LEAs
• APNIC provides LEAs with publicly available registry information
to help them respond to malicious activity on the Internet
• APNIC coordinates with the global technical community to share
information and develop trusted relationships to ensure
coordinated responses to major network security incidents
• APNIC has dedicated legal and network security experts to
support LEA requests
• APNIC’s legal and network security experts provide training to
LEOs, investigators, and the justice sector
(in addition to network operators and CSIRTs)
18
19
https://www.apnic.net/community/security/security-cooperation/#LEAs
Working with INTERPOL/Europol/FBI
Improving Whois data quality and accuracy
20
How LEAs can Participate with RIRs
• Attend RIR and other industry meetings
– Each RIR runs open meeting and conferences each year
– Network Operator Groups (NOGs)
– Trusted community conferences (UE / RISE, FIRST, M3AAWG…)
• Request training sessions with RIRs
• Participate in the Policy Development Process
– Submit policy proposals, discuss other proposals
• Report invalid contacts from whois records
21
25
Whois Databases
Important – About Whois DB
• Number vs Domain Whois
o Two different types of databases
o APNIC and the other RIRs operate the numbers whois DBs
o Top level domains and registrars operate domain whois DBs
• Other Databases
– Reputation
– Data enrichment
• e.g. http://www.team-cymru.com/IP-ASN-mapping.html
26
What are the numbers Whois databases?
• Public network management database
– Operated by Internet Registries (like APNIC!)
• Public data only
– Tracks network resources
• IP Addresses, ASNs, Reverse DNS Delegations, Routing Policies
• Records administrative information
– Contact information (persons/roles)
– Authorization for updating this info
– Network abuse handling (IRT)
27
IP Address Delegation
28
Whois Database Accuracy
• Accurate & Reliable
• Responsiveness
– Stop / Mitigate on going attack
– Reduce impact / exposure of incidents
– Do not have to go through various loops & hoops
• Ideally
– Ability to provide assistance or do something about it
– Escalation
• Features
– Mechanism for reporting invalid contacts
– Trigger other actions
• Other Databases?
– FIRST, APCERT, Trusted Introducer, etc
32
irt: IRT-APNIC-IS-AP
address: South Brisbane, Australia
e-mail: helpdesk@apnic.net
abuse-mailbox: helpdesk@apnic.net
admin-c: AIC1-AP
tech-c: AIC1-AP
auth: # Filtered
remarks: APNIC Infrastructure Services
mnt-by: MAINT-APNIC-IS-AP
changed: hm-changed@apnic.net 20110704
source: APNIC
Which Whois to Use?
• APNIC
– Asia Pacific
– APNIC Whois Database (previous slide)
• AFRINIC
– Africa
– https://www.afrinic.net/whois-web/public
• RIPE NCC
– Europe, Central Asia and the Middle East
– https://apps.db.ripe.net
• ARIN
– Northern America
– http://whois.arin.net
• LACNIC
– Latin America and the Caribbean
– http://lacnic.net/cgi-bin/lacnic/whois
33
Regional Internet Registries (RIRs)
The APNIC Whois Database
• Holds IP address records within the AP region
• Can use this database to track down the source of the
network abuse
– IP addresses, ASNs, Reverse Domains, Routing policies
• Can find contact details of the relevant network
administrators
– not the individual users
– use administrators log files to contact the individual involved
35
Whois Database Access
• APNIC website
– https://www.apnic.net/manage-ip/using-whois/searching
• Whois search tool
– https://wq.apnic.net/whois-search/static/search.html
• Whois client, query tool, or RDAP
– Point the tools at whois.apnic.net
36
What if Whois info is invalid?
• Members (ISPs and Network Operators) are responsible for
reporting changes to APNIC
– Under formal membership agreement
• Anyone can report invalid ISP/NetOp contacts to APNIC
– http://www.apnic.net/invalidcontact
– APNIC will contact member and update registration details
• Each RIR has a similar process for handling invalid contacts
37
Whois Output
38
Whois Output
39
Future of Whois
• RDAP – Registration Data Access Protocol
• RDAP is a newer standard for accessing whois information
– Uses standardised queries and responses (JSON)
– Internationalisation
– Redirection for seamless referrals to other registries
• Working now but still under development for NIR data
– www.apnic.net/about-apnic/whois_search/about/rdap/
– www.openrdap.org (GoLang client)
• APNIC is also developing a Network ToolBox
– https://netox.apnic.net (let me know your feedback & suggestions!)
42
Reverse DNS
• Reverse DNS translates the IP number back to a name
• Reverse DNS answers are optional for network operators
– The internet works without it
dig -x 202.55.92.5
;; ANSWER SECTION:
5.92.55.202.in-addr.arpa. 5 IN PTR fnet5-m92-access.vqbn.com.sg.
• You can now use whois and other tools/techniques to look
up contact details for vqbn.com.sg
57
Current Challenges
• Fraudulent acquisition and transfer of IPv4 addresses
• Route hijacking
• Leasing, buying, and selling of IPv4 addresses outside of
the registry system
• Invalid contact information
58
Questions?
Jamie Gillespie
jamie@apnic.net
59

More Related Content

Similar to UN INCB: RIRs and LEAs

Regional Internet Registry and Whois
Regional Internet Registry and WhoisRegional Internet Registry and Whois
Regional Internet Registry and WhoisAPNIC
 
apnic handling-network-abuse
apnic handling-network-abuseapnic handling-network-abuse
apnic handling-network-abuseAPNIC
 
Whois - Addressing the Asia Pacifc
Whois - Addressing the Asia PacifcWhois - Addressing the Asia Pacifc
Whois - Addressing the Asia PacifcAPNIC
 
ARIN on the Road
ARIN on the RoadARIN on the Road
ARIN on the RoadARIN
 
Internet Operations and the RIRs
Internet Operations and the RIRsInternet Operations and the RIRs
Internet Operations and the RIRsARIN
 
KHNOG 5: APNIC Services
KHNOG 5: APNIC ServicesKHNOG 5: APNIC Services
KHNOG 5: APNIC ServicesAPNIC
 
Law Enforcement engagement capacity building
Law Enforcement engagement capacity buildingLaw Enforcement engagement capacity building
Law Enforcement engagement capacity buildingAPNIC
 
Cybersecurity Opportunities Challenges APNIC
Cybersecurity Opportunities Challenges APNICCybersecurity Opportunities Challenges APNIC
Cybersecurity Opportunities Challenges APNICAPNIC
 
How APNIC can support law enforcement agencies in cybercrime investigtaion
How APNIC can support law enforcement agencies in cybercrime investigtaionHow APNIC can support law enforcement agencies in cybercrime investigtaion
How APNIC can support law enforcement agencies in cybercrime investigtaionAPNIC
 
Internet Resource Management Tutorial at SANOG 24
Internet Resource Management Tutorial at SANOG 24Internet Resource Management Tutorial at SANOG 24
Internet Resource Management Tutorial at SANOG 24APNIC
 
4th ICANN APAC-TWNIC Engagement Forum and 39th TWNIC OPM:APNIC Vulnerability ...
4th ICANN APAC-TWNIC Engagement Forum and 39th TWNIC OPM:APNIC Vulnerability ...4th ICANN APAC-TWNIC Engagement Forum and 39th TWNIC OPM:APNIC Vulnerability ...
4th ICANN APAC-TWNIC Engagement Forum and 39th TWNIC OPM:APNIC Vulnerability ...APNIC
 
PCTA Convention 2023: APNIC Introduction
PCTA Convention 2023: APNIC IntroductionPCTA Convention 2023: APNIC Introduction
PCTA Convention 2023: APNIC IntroductionAPNIC
 
PCTA Convention 2023: APNIC Introduction
PCTA Convention 2023: APNIC IntroductionPCTA Convention 2023: APNIC Introduction
PCTA Convention 2023: APNIC IntroductionAPNIC
 
APNIC Report - APStar retreat
APNIC Report - APStar retreatAPNIC Report - APStar retreat
APNIC Report - APStar retreatAPNIC
 
23rd PITA AGM and Conference: Internet number registry services - the next ge...
23rd PITA AGM and Conference: Internet number registry services - the next ge...23rd PITA AGM and Conference: Internet number registry services - the next ge...
23rd PITA AGM and Conference: Internet number registry services - the next ge...APNIC
 
IPv4 Transfers, Taiwan Internet Forum
IPv4 Transfers, Taiwan Internet ForumIPv4 Transfers, Taiwan Internet Forum
IPv4 Transfers, Taiwan Internet ForumAPNIC
 
Intrusion detection 2001
Intrusion detection 2001Intrusion detection 2001
Intrusion detection 2001eaiti
 
DNS Abuse Handling
DNS Abuse HandlingDNS Abuse Handling
DNS Abuse HandlingAPNIC
 

Similar to UN INCB: RIRs and LEAs (20)

Regional Internet Registry and Whois
Regional Internet Registry and WhoisRegional Internet Registry and Whois
Regional Internet Registry and Whois
 
apnic handling-network-abuse
apnic handling-network-abuseapnic handling-network-abuse
apnic handling-network-abuse
 
Whois - Addressing the Asia Pacifc
Whois - Addressing the Asia PacifcWhois - Addressing the Asia Pacifc
Whois - Addressing the Asia Pacifc
 
ARIN on the Road
ARIN on the RoadARIN on the Road
ARIN on the Road
 
Internet Operations and the RIRs
Internet Operations and the RIRsInternet Operations and the RIRs
Internet Operations and the RIRs
 
KHNOG 5: APNIC Services
KHNOG 5: APNIC ServicesKHNOG 5: APNIC Services
KHNOG 5: APNIC Services
 
Law Enforcement engagement capacity building
Law Enforcement engagement capacity buildingLaw Enforcement engagement capacity building
Law Enforcement engagement capacity building
 
Cybersecurity Opportunities Challenges APNIC
Cybersecurity Opportunities Challenges APNICCybersecurity Opportunities Challenges APNIC
Cybersecurity Opportunities Challenges APNIC
 
How APNIC can support law enforcement agencies in cybercrime investigtaion
How APNIC can support law enforcement agencies in cybercrime investigtaionHow APNIC can support law enforcement agencies in cybercrime investigtaion
How APNIC can support law enforcement agencies in cybercrime investigtaion
 
Internet Resource Management Tutorial at SANOG 24
Internet Resource Management Tutorial at SANOG 24Internet Resource Management Tutorial at SANOG 24
Internet Resource Management Tutorial at SANOG 24
 
4th ICANN APAC-TWNIC Engagement Forum and 39th TWNIC OPM:APNIC Vulnerability ...
4th ICANN APAC-TWNIC Engagement Forum and 39th TWNIC OPM:APNIC Vulnerability ...4th ICANN APAC-TWNIC Engagement Forum and 39th TWNIC OPM:APNIC Vulnerability ...
4th ICANN APAC-TWNIC Engagement Forum and 39th TWNIC OPM:APNIC Vulnerability ...
 
PCTA Convention 2023: APNIC Introduction
PCTA Convention 2023: APNIC IntroductionPCTA Convention 2023: APNIC Introduction
PCTA Convention 2023: APNIC Introduction
 
PCTA Convention 2023: APNIC Introduction
PCTA Convention 2023: APNIC IntroductionPCTA Convention 2023: APNIC Introduction
PCTA Convention 2023: APNIC Introduction
 
ICANN Engagement Update
ICANN Engagement UpdateICANN Engagement Update
ICANN Engagement Update
 
APNIC Report - APStar retreat
APNIC Report - APStar retreatAPNIC Report - APStar retreat
APNIC Report - APStar retreat
 
23rd PITA AGM and Conference: Internet number registry services - the next ge...
23rd PITA AGM and Conference: Internet number registry services - the next ge...23rd PITA AGM and Conference: Internet number registry services - the next ge...
23rd PITA AGM and Conference: Internet number registry services - the next ge...
 
IPv4 Transfers, Taiwan Internet Forum
IPv4 Transfers, Taiwan Internet ForumIPv4 Transfers, Taiwan Internet Forum
IPv4 Transfers, Taiwan Internet Forum
 
09 (IDNOG01) Introduction about APNIC by Wita Laksono
09 (IDNOG01) Introduction about APNIC by Wita Laksono09 (IDNOG01) Introduction about APNIC by Wita Laksono
09 (IDNOG01) Introduction about APNIC by Wita Laksono
 
Intrusion detection 2001
Intrusion detection 2001Intrusion detection 2001
Intrusion detection 2001
 
DNS Abuse Handling
DNS Abuse HandlingDNS Abuse Handling
DNS Abuse Handling
 

More from APNIC

APNIC Policy Roundup, presented by Sunny Chendi at the 5th ICANN APAC-TWNIC E...
APNIC Policy Roundup, presented by Sunny Chendi at the 5th ICANN APAC-TWNIC E...APNIC Policy Roundup, presented by Sunny Chendi at the 5th ICANN APAC-TWNIC E...
APNIC Policy Roundup, presented by Sunny Chendi at the 5th ICANN APAC-TWNIC E...APNIC
 
APNIC Updates presented by Paul Wilson at ARIN 53
APNIC Updates presented by Paul Wilson at ARIN 53APNIC Updates presented by Paul Wilson at ARIN 53
APNIC Updates presented by Paul Wilson at ARIN 53APNIC
 
DDoS In Oceania and the Pacific, presented by Dave Phelan at NZNOG 2024
DDoS In Oceania and the Pacific, presented by Dave Phelan at NZNOG 2024DDoS In Oceania and the Pacific, presented by Dave Phelan at NZNOG 2024
DDoS In Oceania and the Pacific, presented by Dave Phelan at NZNOG 2024APNIC
 
'Future Evolution of the Internet' delivered by Geoff Huston at Everything Op...
'Future Evolution of the Internet' delivered by Geoff Huston at Everything Op...'Future Evolution of the Internet' delivered by Geoff Huston at Everything Op...
'Future Evolution of the Internet' delivered by Geoff Huston at Everything Op...APNIC
 
On Starlink, presented by Geoff Huston at NZNOG 2024
On Starlink, presented by Geoff Huston at NZNOG 2024On Starlink, presented by Geoff Huston at NZNOG 2024
On Starlink, presented by Geoff Huston at NZNOG 2024APNIC
 
Networking in the Penumbra presented by Geoff Huston at NZNOG
Networking in the Penumbra presented by Geoff Huston at NZNOGNetworking in the Penumbra presented by Geoff Huston at NZNOG
Networking in the Penumbra presented by Geoff Huston at NZNOGAPNIC
 
IP addressing and IPv6, presented by Paul Wilson at IETF 119
IP addressing and IPv6, presented by Paul Wilson at IETF 119IP addressing and IPv6, presented by Paul Wilson at IETF 119
IP addressing and IPv6, presented by Paul Wilson at IETF 119APNIC
 
draft-harrison-sidrops-manifest-number-01, presented at IETF 119
draft-harrison-sidrops-manifest-number-01, presented at IETF 119draft-harrison-sidrops-manifest-number-01, presented at IETF 119
draft-harrison-sidrops-manifest-number-01, presented at IETF 119APNIC
 
Making an RFC in Today's IETF, presented by Geoff Huston at IETF 119
Making an RFC in Today's IETF, presented by Geoff Huston at IETF 119Making an RFC in Today's IETF, presented by Geoff Huston at IETF 119
Making an RFC in Today's IETF, presented by Geoff Huston at IETF 119APNIC
 
IPv6 Operational Issues (with DNS), presented by Geoff Huston at IETF 119
IPv6 Operational Issues (with DNS), presented by Geoff Huston at IETF 119IPv6 Operational Issues (with DNS), presented by Geoff Huston at IETF 119
IPv6 Operational Issues (with DNS), presented by Geoff Huston at IETF 119APNIC
 
Is DNS ready for IPv6, presented by Geoff Huston at IETF 119
Is DNS ready for IPv6, presented by Geoff Huston at IETF 119Is DNS ready for IPv6, presented by Geoff Huston at IETF 119
Is DNS ready for IPv6, presented by Geoff Huston at IETF 119APNIC
 
Benefits of doing Internet peering and running an Internet Exchange (IX) pres...
Benefits of doing Internet peering and running an Internet Exchange (IX) pres...Benefits of doing Internet peering and running an Internet Exchange (IX) pres...
Benefits of doing Internet peering and running an Internet Exchange (IX) pres...APNIC
 
APNIC Update and RIR Policies for ccTLDs, presented at APTLD 85
APNIC Update and RIR Policies for ccTLDs, presented at APTLD 85APNIC Update and RIR Policies for ccTLDs, presented at APTLD 85
APNIC Update and RIR Policies for ccTLDs, presented at APTLD 85APNIC
 
NANOG 90: 'BGP in 2023' presented by Geoff Huston
NANOG 90: 'BGP in 2023' presented by Geoff HustonNANOG 90: 'BGP in 2023' presented by Geoff Huston
NANOG 90: 'BGP in 2023' presented by Geoff HustonAPNIC
 
DNS-OARC 42: Is the DNS ready for IPv6? presentation by Geoff Huston
DNS-OARC 42: Is the DNS ready for IPv6? presentation by Geoff HustonDNS-OARC 42: Is the DNS ready for IPv6? presentation by Geoff Huston
DNS-OARC 42: Is the DNS ready for IPv6? presentation by Geoff HustonAPNIC
 
APAN 57: APNIC Report at APAN 57, Bangkok, Thailand
APAN 57: APNIC Report at APAN 57, Bangkok, ThailandAPAN 57: APNIC Report at APAN 57, Bangkok, Thailand
APAN 57: APNIC Report at APAN 57, Bangkok, ThailandAPNIC
 
Lao Digital Week 2024: It's time to deploy IPv6
Lao Digital Week 2024: It's time to deploy IPv6Lao Digital Week 2024: It's time to deploy IPv6
Lao Digital Week 2024: It's time to deploy IPv6APNIC
 
AINTEC 2023: Networking in the Penumbra!
AINTEC 2023: Networking in the Penumbra!AINTEC 2023: Networking in the Penumbra!
AINTEC 2023: Networking in the Penumbra!APNIC
 
CNIRC 2023: Global and Regional IPv6 Deployment 2023
CNIRC 2023: Global and Regional IPv6 Deployment 2023CNIRC 2023: Global and Regional IPv6 Deployment 2023
CNIRC 2023: Global and Regional IPv6 Deployment 2023APNIC
 
AFSIG 2023: APNIC Foundation and support for Internet development
AFSIG 2023: APNIC Foundation and support for Internet developmentAFSIG 2023: APNIC Foundation and support for Internet development
AFSIG 2023: APNIC Foundation and support for Internet developmentAPNIC
 

More from APNIC (20)

APNIC Policy Roundup, presented by Sunny Chendi at the 5th ICANN APAC-TWNIC E...
APNIC Policy Roundup, presented by Sunny Chendi at the 5th ICANN APAC-TWNIC E...APNIC Policy Roundup, presented by Sunny Chendi at the 5th ICANN APAC-TWNIC E...
APNIC Policy Roundup, presented by Sunny Chendi at the 5th ICANN APAC-TWNIC E...
 
APNIC Updates presented by Paul Wilson at ARIN 53
APNIC Updates presented by Paul Wilson at ARIN 53APNIC Updates presented by Paul Wilson at ARIN 53
APNIC Updates presented by Paul Wilson at ARIN 53
 
DDoS In Oceania and the Pacific, presented by Dave Phelan at NZNOG 2024
DDoS In Oceania and the Pacific, presented by Dave Phelan at NZNOG 2024DDoS In Oceania and the Pacific, presented by Dave Phelan at NZNOG 2024
DDoS In Oceania and the Pacific, presented by Dave Phelan at NZNOG 2024
 
'Future Evolution of the Internet' delivered by Geoff Huston at Everything Op...
'Future Evolution of the Internet' delivered by Geoff Huston at Everything Op...'Future Evolution of the Internet' delivered by Geoff Huston at Everything Op...
'Future Evolution of the Internet' delivered by Geoff Huston at Everything Op...
 
On Starlink, presented by Geoff Huston at NZNOG 2024
On Starlink, presented by Geoff Huston at NZNOG 2024On Starlink, presented by Geoff Huston at NZNOG 2024
On Starlink, presented by Geoff Huston at NZNOG 2024
 
Networking in the Penumbra presented by Geoff Huston at NZNOG
Networking in the Penumbra presented by Geoff Huston at NZNOGNetworking in the Penumbra presented by Geoff Huston at NZNOG
Networking in the Penumbra presented by Geoff Huston at NZNOG
 
IP addressing and IPv6, presented by Paul Wilson at IETF 119
IP addressing and IPv6, presented by Paul Wilson at IETF 119IP addressing and IPv6, presented by Paul Wilson at IETF 119
IP addressing and IPv6, presented by Paul Wilson at IETF 119
 
draft-harrison-sidrops-manifest-number-01, presented at IETF 119
draft-harrison-sidrops-manifest-number-01, presented at IETF 119draft-harrison-sidrops-manifest-number-01, presented at IETF 119
draft-harrison-sidrops-manifest-number-01, presented at IETF 119
 
Making an RFC in Today's IETF, presented by Geoff Huston at IETF 119
Making an RFC in Today's IETF, presented by Geoff Huston at IETF 119Making an RFC in Today's IETF, presented by Geoff Huston at IETF 119
Making an RFC in Today's IETF, presented by Geoff Huston at IETF 119
 
IPv6 Operational Issues (with DNS), presented by Geoff Huston at IETF 119
IPv6 Operational Issues (with DNS), presented by Geoff Huston at IETF 119IPv6 Operational Issues (with DNS), presented by Geoff Huston at IETF 119
IPv6 Operational Issues (with DNS), presented by Geoff Huston at IETF 119
 
Is DNS ready for IPv6, presented by Geoff Huston at IETF 119
Is DNS ready for IPv6, presented by Geoff Huston at IETF 119Is DNS ready for IPv6, presented by Geoff Huston at IETF 119
Is DNS ready for IPv6, presented by Geoff Huston at IETF 119
 
Benefits of doing Internet peering and running an Internet Exchange (IX) pres...
Benefits of doing Internet peering and running an Internet Exchange (IX) pres...Benefits of doing Internet peering and running an Internet Exchange (IX) pres...
Benefits of doing Internet peering and running an Internet Exchange (IX) pres...
 
APNIC Update and RIR Policies for ccTLDs, presented at APTLD 85
APNIC Update and RIR Policies for ccTLDs, presented at APTLD 85APNIC Update and RIR Policies for ccTLDs, presented at APTLD 85
APNIC Update and RIR Policies for ccTLDs, presented at APTLD 85
 
NANOG 90: 'BGP in 2023' presented by Geoff Huston
NANOG 90: 'BGP in 2023' presented by Geoff HustonNANOG 90: 'BGP in 2023' presented by Geoff Huston
NANOG 90: 'BGP in 2023' presented by Geoff Huston
 
DNS-OARC 42: Is the DNS ready for IPv6? presentation by Geoff Huston
DNS-OARC 42: Is the DNS ready for IPv6? presentation by Geoff HustonDNS-OARC 42: Is the DNS ready for IPv6? presentation by Geoff Huston
DNS-OARC 42: Is the DNS ready for IPv6? presentation by Geoff Huston
 
APAN 57: APNIC Report at APAN 57, Bangkok, Thailand
APAN 57: APNIC Report at APAN 57, Bangkok, ThailandAPAN 57: APNIC Report at APAN 57, Bangkok, Thailand
APAN 57: APNIC Report at APAN 57, Bangkok, Thailand
 
Lao Digital Week 2024: It's time to deploy IPv6
Lao Digital Week 2024: It's time to deploy IPv6Lao Digital Week 2024: It's time to deploy IPv6
Lao Digital Week 2024: It's time to deploy IPv6
 
AINTEC 2023: Networking in the Penumbra!
AINTEC 2023: Networking in the Penumbra!AINTEC 2023: Networking in the Penumbra!
AINTEC 2023: Networking in the Penumbra!
 
CNIRC 2023: Global and Regional IPv6 Deployment 2023
CNIRC 2023: Global and Regional IPv6 Deployment 2023CNIRC 2023: Global and Regional IPv6 Deployment 2023
CNIRC 2023: Global and Regional IPv6 Deployment 2023
 
AFSIG 2023: APNIC Foundation and support for Internet development
AFSIG 2023: APNIC Foundation and support for Internet developmentAFSIG 2023: APNIC Foundation and support for Internet development
AFSIG 2023: APNIC Foundation and support for Internet development
 

Recently uploaded

pdfcoffee.com_business-ethics-q3m7-pdf-free.pdf
pdfcoffee.com_business-ethics-q3m7-pdf-free.pdfpdfcoffee.com_business-ethics-q3m7-pdf-free.pdf
pdfcoffee.com_business-ethics-q3m7-pdf-free.pdfJOHNBEBONYAP1
 
Call Girls Sangvi Call Me 7737669865 Budget Friendly No Advance BookingCall G...
Call Girls Sangvi Call Me 7737669865 Budget Friendly No Advance BookingCall G...Call Girls Sangvi Call Me 7737669865 Budget Friendly No Advance BookingCall G...
Call Girls Sangvi Call Me 7737669865 Budget Friendly No Advance BookingCall G...roncy bisnoi
 
"Boost Your Digital Presence: Partner with a Leading SEO Agency"
"Boost Your Digital Presence: Partner with a Leading SEO Agency""Boost Your Digital Presence: Partner with a Leading SEO Agency"
"Boost Your Digital Presence: Partner with a Leading SEO Agency"growthgrids
 
Pirangut | Call Girls Pune Phone No 8005736733 Elite Escort Service Available...
Pirangut | Call Girls Pune Phone No 8005736733 Elite Escort Service Available...Pirangut | Call Girls Pune Phone No 8005736733 Elite Escort Service Available...
Pirangut | Call Girls Pune Phone No 8005736733 Elite Escort Service Available...SUHANI PANDEY
 
20240508 QFM014 Elixir Reading List April 2024.pdf
20240508 QFM014 Elixir Reading List April 2024.pdf20240508 QFM014 Elixir Reading List April 2024.pdf
20240508 QFM014 Elixir Reading List April 2024.pdfMatthew Sinclair
 
VIP Model Call Girls NIBM ( Pune ) Call ON 8005736733 Starting From 5K to 25K...
VIP Model Call Girls NIBM ( Pune ) Call ON 8005736733 Starting From 5K to 25K...VIP Model Call Girls NIBM ( Pune ) Call ON 8005736733 Starting From 5K to 25K...
VIP Model Call Girls NIBM ( Pune ) Call ON 8005736733 Starting From 5K to 25K...SUHANI PANDEY
 
Katraj ( Call Girls ) Pune 6297143586 Hot Model With Sexy Bhabi Ready For S...
Katraj ( Call Girls ) Pune  6297143586  Hot Model With Sexy Bhabi Ready For S...Katraj ( Call Girls ) Pune  6297143586  Hot Model With Sexy Bhabi Ready For S...
Katraj ( Call Girls ) Pune 6297143586 Hot Model With Sexy Bhabi Ready For S...tanu pandey
 
All Time Service Available Call Girls Mg Road 👌 ⏭️ 6378878445
All Time Service Available Call Girls Mg Road 👌 ⏭️ 6378878445All Time Service Available Call Girls Mg Road 👌 ⏭️ 6378878445
All Time Service Available Call Girls Mg Road 👌 ⏭️ 6378878445ruhi
 
Wagholi & High Class Call Girls Pune Neha 8005736733 | 100% Gennuine High Cla...
Wagholi & High Class Call Girls Pune Neha 8005736733 | 100% Gennuine High Cla...Wagholi & High Class Call Girls Pune Neha 8005736733 | 100% Gennuine High Cla...
Wagholi & High Class Call Girls Pune Neha 8005736733 | 100% Gennuine High Cla...SUHANI PANDEY
 
best call girls in Hyderabad Finest Escorts Service 📞 9352988975 📞 Available ...
best call girls in Hyderabad Finest Escorts Service 📞 9352988975 📞 Available ...best call girls in Hyderabad Finest Escorts Service 📞 9352988975 📞 Available ...
best call girls in Hyderabad Finest Escorts Service 📞 9352988975 📞 Available ...kajalverma014
 
Nanded City ( Call Girls ) Pune 6297143586 Hot Model With Sexy Bhabi Ready ...
Nanded City ( Call Girls ) Pune  6297143586  Hot Model With Sexy Bhabi Ready ...Nanded City ( Call Girls ) Pune  6297143586  Hot Model With Sexy Bhabi Ready ...
Nanded City ( Call Girls ) Pune 6297143586 Hot Model With Sexy Bhabi Ready ...tanu pandey
 
在线制作约克大学毕业证(yu毕业证)在读证明认证可查
在线制作约克大学毕业证(yu毕业证)在读证明认证可查在线制作约克大学毕业证(yu毕业证)在读证明认证可查
在线制作约克大学毕业证(yu毕业证)在读证明认证可查ydyuyu
 
VIP Call Girls Pollachi 7001035870 Whatsapp Number, 24/07 Booking
VIP Call Girls Pollachi 7001035870 Whatsapp Number, 24/07 BookingVIP Call Girls Pollachi 7001035870 Whatsapp Number, 24/07 Booking
VIP Call Girls Pollachi 7001035870 Whatsapp Number, 24/07 Bookingdharasingh5698
 
( Pune ) VIP Baner Call Girls 🎗️ 9352988975 Sizzling | Escorts | Girls Are Re...
( Pune ) VIP Baner Call Girls 🎗️ 9352988975 Sizzling | Escorts | Girls Are Re...( Pune ) VIP Baner Call Girls 🎗️ 9352988975 Sizzling | Escorts | Girls Are Re...
( Pune ) VIP Baner Call Girls 🎗️ 9352988975 Sizzling | Escorts | Girls Are Re...nilamkumrai
 
Wadgaon Sheri $ Call Girls Pune 10k @ I'm VIP Independent Escorts Girls 80057...
Wadgaon Sheri $ Call Girls Pune 10k @ I'm VIP Independent Escorts Girls 80057...Wadgaon Sheri $ Call Girls Pune 10k @ I'm VIP Independent Escorts Girls 80057...
Wadgaon Sheri $ Call Girls Pune 10k @ I'm VIP Independent Escorts Girls 80057...SUHANI PANDEY
 
20240507 QFM013 Machine Intelligence Reading List April 2024.pdf
20240507 QFM013 Machine Intelligence Reading List April 2024.pdf20240507 QFM013 Machine Intelligence Reading List April 2024.pdf
20240507 QFM013 Machine Intelligence Reading List April 2024.pdfMatthew Sinclair
 

Recently uploaded (20)

Call Girls in Prashant Vihar, Delhi 💯 Call Us 🔝9953056974 🔝 Escort Service
Call Girls in Prashant Vihar, Delhi 💯 Call Us 🔝9953056974 🔝 Escort ServiceCall Girls in Prashant Vihar, Delhi 💯 Call Us 🔝9953056974 🔝 Escort Service
Call Girls in Prashant Vihar, Delhi 💯 Call Us 🔝9953056974 🔝 Escort Service
 
pdfcoffee.com_business-ethics-q3m7-pdf-free.pdf
pdfcoffee.com_business-ethics-q3m7-pdf-free.pdfpdfcoffee.com_business-ethics-q3m7-pdf-free.pdf
pdfcoffee.com_business-ethics-q3m7-pdf-free.pdf
 
Call Girls Sangvi Call Me 7737669865 Budget Friendly No Advance BookingCall G...
Call Girls Sangvi Call Me 7737669865 Budget Friendly No Advance BookingCall G...Call Girls Sangvi Call Me 7737669865 Budget Friendly No Advance BookingCall G...
Call Girls Sangvi Call Me 7737669865 Budget Friendly No Advance BookingCall G...
 
"Boost Your Digital Presence: Partner with a Leading SEO Agency"
"Boost Your Digital Presence: Partner with a Leading SEO Agency""Boost Your Digital Presence: Partner with a Leading SEO Agency"
"Boost Your Digital Presence: Partner with a Leading SEO Agency"
 
Pirangut | Call Girls Pune Phone No 8005736733 Elite Escort Service Available...
Pirangut | Call Girls Pune Phone No 8005736733 Elite Escort Service Available...Pirangut | Call Girls Pune Phone No 8005736733 Elite Escort Service Available...
Pirangut | Call Girls Pune Phone No 8005736733 Elite Escort Service Available...
 
20240508 QFM014 Elixir Reading List April 2024.pdf
20240508 QFM014 Elixir Reading List April 2024.pdf20240508 QFM014 Elixir Reading List April 2024.pdf
20240508 QFM014 Elixir Reading List April 2024.pdf
 
VIP Model Call Girls NIBM ( Pune ) Call ON 8005736733 Starting From 5K to 25K...
VIP Model Call Girls NIBM ( Pune ) Call ON 8005736733 Starting From 5K to 25K...VIP Model Call Girls NIBM ( Pune ) Call ON 8005736733 Starting From 5K to 25K...
VIP Model Call Girls NIBM ( Pune ) Call ON 8005736733 Starting From 5K to 25K...
 
Katraj ( Call Girls ) Pune 6297143586 Hot Model With Sexy Bhabi Ready For S...
Katraj ( Call Girls ) Pune  6297143586  Hot Model With Sexy Bhabi Ready For S...Katraj ( Call Girls ) Pune  6297143586  Hot Model With Sexy Bhabi Ready For S...
Katraj ( Call Girls ) Pune 6297143586 Hot Model With Sexy Bhabi Ready For S...
 
All Time Service Available Call Girls Mg Road 👌 ⏭️ 6378878445
All Time Service Available Call Girls Mg Road 👌 ⏭️ 6378878445All Time Service Available Call Girls Mg Road 👌 ⏭️ 6378878445
All Time Service Available Call Girls Mg Road 👌 ⏭️ 6378878445
 
Wagholi & High Class Call Girls Pune Neha 8005736733 | 100% Gennuine High Cla...
Wagholi & High Class Call Girls Pune Neha 8005736733 | 100% Gennuine High Cla...Wagholi & High Class Call Girls Pune Neha 8005736733 | 100% Gennuine High Cla...
Wagholi & High Class Call Girls Pune Neha 8005736733 | 100% Gennuine High Cla...
 
valsad Escorts Service ☎️ 6378878445 ( Sakshi Sinha ) High Profile Call Girls...
valsad Escorts Service ☎️ 6378878445 ( Sakshi Sinha ) High Profile Call Girls...valsad Escorts Service ☎️ 6378878445 ( Sakshi Sinha ) High Profile Call Girls...
valsad Escorts Service ☎️ 6378878445 ( Sakshi Sinha ) High Profile Call Girls...
 
best call girls in Hyderabad Finest Escorts Service 📞 9352988975 📞 Available ...
best call girls in Hyderabad Finest Escorts Service 📞 9352988975 📞 Available ...best call girls in Hyderabad Finest Escorts Service 📞 9352988975 📞 Available ...
best call girls in Hyderabad Finest Escorts Service 📞 9352988975 📞 Available ...
 
Nanded City ( Call Girls ) Pune 6297143586 Hot Model With Sexy Bhabi Ready ...
Nanded City ( Call Girls ) Pune  6297143586  Hot Model With Sexy Bhabi Ready ...Nanded City ( Call Girls ) Pune  6297143586  Hot Model With Sexy Bhabi Ready ...
Nanded City ( Call Girls ) Pune 6297143586 Hot Model With Sexy Bhabi Ready ...
 
6.High Profile Call Girls In Punjab +919053900678 Punjab Call GirlHigh Profil...
6.High Profile Call Girls In Punjab +919053900678 Punjab Call GirlHigh Profil...6.High Profile Call Girls In Punjab +919053900678 Punjab Call GirlHigh Profil...
6.High Profile Call Girls In Punjab +919053900678 Punjab Call GirlHigh Profil...
 
在线制作约克大学毕业证(yu毕业证)在读证明认证可查
在线制作约克大学毕业证(yu毕业证)在读证明认证可查在线制作约克大学毕业证(yu毕业证)在读证明认证可查
在线制作约克大学毕业证(yu毕业证)在读证明认证可查
 
VIP Call Girls Pollachi 7001035870 Whatsapp Number, 24/07 Booking
VIP Call Girls Pollachi 7001035870 Whatsapp Number, 24/07 BookingVIP Call Girls Pollachi 7001035870 Whatsapp Number, 24/07 Booking
VIP Call Girls Pollachi 7001035870 Whatsapp Number, 24/07 Booking
 
( Pune ) VIP Baner Call Girls 🎗️ 9352988975 Sizzling | Escorts | Girls Are Re...
( Pune ) VIP Baner Call Girls 🎗️ 9352988975 Sizzling | Escorts | Girls Are Re...( Pune ) VIP Baner Call Girls 🎗️ 9352988975 Sizzling | Escorts | Girls Are Re...
( Pune ) VIP Baner Call Girls 🎗️ 9352988975 Sizzling | Escorts | Girls Are Re...
 
Wadgaon Sheri $ Call Girls Pune 10k @ I'm VIP Independent Escorts Girls 80057...
Wadgaon Sheri $ Call Girls Pune 10k @ I'm VIP Independent Escorts Girls 80057...Wadgaon Sheri $ Call Girls Pune 10k @ I'm VIP Independent Escorts Girls 80057...
Wadgaon Sheri $ Call Girls Pune 10k @ I'm VIP Independent Escorts Girls 80057...
 
Low Sexy Call Girls In Mohali 9053900678 🥵Have Save And Good Place 🥵
Low Sexy Call Girls In Mohali 9053900678 🥵Have Save And Good Place 🥵Low Sexy Call Girls In Mohali 9053900678 🥵Have Save And Good Place 🥵
Low Sexy Call Girls In Mohali 9053900678 🥵Have Save And Good Place 🥵
 
20240507 QFM013 Machine Intelligence Reading List April 2024.pdf
20240507 QFM013 Machine Intelligence Reading List April 2024.pdf20240507 QFM013 Machine Intelligence Reading List April 2024.pdf
20240507 QFM013 Machine Intelligence Reading List April 2024.pdf
 

UN INCB: RIRs and LEAs

  • 1. 1 Regional Internet Registries (RIRs) and Law Enforcement Agencies UN INCB - Expert Group Meeting on Dangerous Substance Trafficking through Social Media and other Internet-related Services 1 July 2020 Jamie Gillespie, Security Specialist at APNIC jamie@apnic.net
  • 2. whois: Jamie Gillespie • Jamie Gillespie – jamie@apnic.net – Security Specialist @ APNIC – Community engagement, CERT building, InfoSec training, awareness • Work history – 8 years at AusCERT, Australia’s national CERT – Google – Macquarie Telecom / Cloud Services 2
  • 4. Internet Basics • Every device on the Internet needs an address, to be found by other devices – IPv4: 66.220.144.0 – IPv6: 2a03:2880:11:2f83:face:b00c:0:25de • Humans are not good with numbers. We have domain names that translate to address: www.facebook.com → 69.171.239.12 6
  • 5. The Internet is a Series of Networks • The Network of Networks 7
  • 6. Names and Numbers 8 The Internet 2001:0C00:8888:: 2001:0400:: www.apnic.net 202.112.0.46 2001:0400:: My Computer www.apnic.net www.apnic.net 202.112.0.46 2001:0400::
  • 7. 9 Who is Who in the Internet
  • 8. Acronyms and Initialisms • Before we go any further, we should probably define what a bunch of common acronyms and initialisms mean – IETF - Internet Engineering Task Force – IANA - Internet Assigned Numbers Authority – ICANN - Internet Corporate for Assigned Names and Numbers – TLD - Top Level Domain – gTLD - Generic Top Level Domain – ccTLD - Country Code Top Level Domain – RIR - Regional Internet Registry 10
  • 9. Where do IP addresses come from? 11
  • 10. RIRs from a Global Perspective 12
  • 12. How APNIC and the RIRs Operate • APNIC is the Regional Internet Registry (RIR) for the Asia Pacific region • Membership-based, not-for-profit • Industry self-regulatory body – Open – Consensus-based – Transparent • Delegates and manages Internet number resources – IPv4 and IPv6 addresses • Diagram on next slide – AS numbers 14
  • 13. APNIC’s Roles and Services • Delegates and manages Internet resources – IPv4 & IPv6 addresses, AS Numbers • Maintains the APNIC Whois Database • Manages reverse DNS delegations – But is NOT a domain name registry • Facilitates IP address policy development • Provides capacity building through training, workshops, conferences, fellowships, and grants – resource management, routing, IPv6 deployment, and security • Research, measurements, publications • Supports Internet infrastructure development – Root server deployment, Internet Exchange Points (IXPs) 15
  • 14. So who gets IP address and AS numbers? • National Internet Registry • Telcos, ISPs, Mobile Operators • Hosting Company (Amazon/AWS, Azure, GCP, Linode) • Universities, Government Departments, Banks 16
  • 15. How APNIC and the RIRs work with LEAs • APNIC provides LEAs with publicly available registry information to help them respond to malicious activity on the Internet • APNIC coordinates with the global technical community to share information and develop trusted relationships to ensure coordinated responses to major network security incidents • APNIC has dedicated legal and network security experts to support LEA requests • APNIC’s legal and network security experts provide training to LEOs, investigators, and the justice sector (in addition to network operators and CSIRTs) 18
  • 17. Working with INTERPOL/Europol/FBI Improving Whois data quality and accuracy 20
  • 18. How LEAs can Participate with RIRs • Attend RIR and other industry meetings – Each RIR runs open meeting and conferences each year – Network Operator Groups (NOGs) – Trusted community conferences (UE / RISE, FIRST, M3AAWG…) • Request training sessions with RIRs • Participate in the Policy Development Process – Submit policy proposals, discuss other proposals • Report invalid contacts from whois records 21
  • 20. Important – About Whois DB • Number vs Domain Whois o Two different types of databases o APNIC and the other RIRs operate the numbers whois DBs o Top level domains and registrars operate domain whois DBs • Other Databases – Reputation – Data enrichment • e.g. http://www.team-cymru.com/IP-ASN-mapping.html 26
  • 21. What are the numbers Whois databases? • Public network management database – Operated by Internet Registries (like APNIC!) • Public data only – Tracks network resources • IP Addresses, ASNs, Reverse DNS Delegations, Routing Policies • Records administrative information – Contact information (persons/roles) – Authorization for updating this info – Network abuse handling (IRT) 27
  • 23. Whois Database Accuracy • Accurate & Reliable • Responsiveness – Stop / Mitigate on going attack – Reduce impact / exposure of incidents – Do not have to go through various loops & hoops • Ideally – Ability to provide assistance or do something about it – Escalation • Features – Mechanism for reporting invalid contacts – Trigger other actions • Other Databases? – FIRST, APCERT, Trusted Introducer, etc 32 irt: IRT-APNIC-IS-AP address: South Brisbane, Australia e-mail: helpdesk@apnic.net abuse-mailbox: helpdesk@apnic.net admin-c: AIC1-AP tech-c: AIC1-AP auth: # Filtered remarks: APNIC Infrastructure Services mnt-by: MAINT-APNIC-IS-AP changed: hm-changed@apnic.net 20110704 source: APNIC
  • 24. Which Whois to Use? • APNIC – Asia Pacific – APNIC Whois Database (previous slide) • AFRINIC – Africa – https://www.afrinic.net/whois-web/public • RIPE NCC – Europe, Central Asia and the Middle East – https://apps.db.ripe.net • ARIN – Northern America – http://whois.arin.net • LACNIC – Latin America and the Caribbean – http://lacnic.net/cgi-bin/lacnic/whois 33 Regional Internet Registries (RIRs)
  • 25. The APNIC Whois Database • Holds IP address records within the AP region • Can use this database to track down the source of the network abuse – IP addresses, ASNs, Reverse Domains, Routing policies • Can find contact details of the relevant network administrators – not the individual users – use administrators log files to contact the individual involved 35
  • 26. Whois Database Access • APNIC website – https://www.apnic.net/manage-ip/using-whois/searching • Whois search tool – https://wq.apnic.net/whois-search/static/search.html • Whois client, query tool, or RDAP – Point the tools at whois.apnic.net 36
  • 27. What if Whois info is invalid? • Members (ISPs and Network Operators) are responsible for reporting changes to APNIC – Under formal membership agreement • Anyone can report invalid ISP/NetOp contacts to APNIC – http://www.apnic.net/invalidcontact – APNIC will contact member and update registration details • Each RIR has a similar process for handling invalid contacts 37
  • 30. Future of Whois • RDAP – Registration Data Access Protocol • RDAP is a newer standard for accessing whois information – Uses standardised queries and responses (JSON) – Internationalisation – Redirection for seamless referrals to other registries • Working now but still under development for NIR data – www.apnic.net/about-apnic/whois_search/about/rdap/ – www.openrdap.org (GoLang client) • APNIC is also developing a Network ToolBox – https://netox.apnic.net (let me know your feedback & suggestions!) 42
  • 31. Reverse DNS • Reverse DNS translates the IP number back to a name • Reverse DNS answers are optional for network operators – The internet works without it dig -x 202.55.92.5 ;; ANSWER SECTION: 5.92.55.202.in-addr.arpa. 5 IN PTR fnet5-m92-access.vqbn.com.sg. • You can now use whois and other tools/techniques to look up contact details for vqbn.com.sg 57
  • 32. Current Challenges • Fraudulent acquisition and transfer of IPv4 addresses • Route hijacking • Leasing, buying, and selling of IPv4 addresses outside of the registry system • Invalid contact information 58