ICANN 51: DNS Risk Framework

ICANN
ICANNICANN
‱‱
Text 
DNS Risk Framework 
Update 
#ICANN51 
14 October 2014 
John Crain & Jacks Khawaja 
Chief SSR Officer; Enterprise Risk Director
Agenda 
Text 
‱ History 
‱ Moving Forward 
#ICANN51
Text 
History 
#ICANN51
Defined Resiliency Model 
Text 
ASSETS
Text
23 Risks Defined 
Text
Text 
Moving Forward 
#ICANN51
Numbers 
Text 
‱ Examining Risk 
o Typically, step 1 = identify assets 
o Impractical to identify all individual elements of DNS 
‱ Our Approach 
Categorize assets by sphere of influence 
#ICANN51
WTexth ere can ICANN: 
Implement 
Directly Influence 
Indirectly Influence 
?
Text 
Assets directly controlled by ICANN 
‱ Assets that ICANN directly manages or contracts 
to third parties (Example: XXX, XXX) 
‱ ICANN’s own corporate infrastructure 
‱ External-facing services such as websites and 
request management systems 
‱ DNS infrastructure of L.root-servers.net 
‱ Others? 
#ICANN51
Text 
Assets directly influenced by ICANN 
‱ Assets that ICANN can influence through 
contractual agreements (Example: Service Level 
Agreements, etc.) 
‱ Registries or registrars are guided by contracts that 
include Service Level Agreements 
‱ It is their remit as the asset owners to decide how 
they meet those SLAs and how to implement 
mitigation of their risks 
#ICANN51
Text 
‱ The Internet is a “network of networks” and each 
operator of a network or service is ultimately 
responsible for their own risk management 
‱ ICANN and the community can indirectly influence 
these through outreach and awareness efforts 
‱ ISOC’s Deploy360 is an excellent example of this 
#ICANN51 
Assets outside ICANN’s realm
Text 
SSR-001 DDOS (Example) 
#ICANN51
SSR001 Description (abridged) 
Text 
‱ User or organization deprived of service(s) or 
resource(s) they would normally have 
‱ Distributed denial-of-service (DDoS) attack: 
o Multitude of systems (compromised or otherwise) are 
used to attack a single target 
o Flood of incoming messages to the target system 
essentially forces it to shut down. This can take two forms: 
§ Resource Depletion 
§ Resource Disruption 
#ICANN51
What is the Risk? 
Text 
‱ This risk discusses the probability that parts of the 
DNS could be disabled for a sustained period 
‱ To ascertain the likelihood or the effect of such an 
attack, it’s important to first define the assets that 
are affected. This is also critical to understanding 
who owns the risk and who is able to best mitigate 
such risks 
#ICANN51
Look at DNS Assets from Both Sides 
Text 
‱ Publish the data on the authoritative servers (root 
servers, TLD servers, and registrants servers) 
‱ Query the data on the recursive servers (ISP’s, 
corporations, and DNS service providers) 
#ICANN51
Text 
Assets directly controlled by ICANN 
Authoritative 
‱ ICANN: 
o Operates L.root-servers.netICANN runs some infrastructure for TLDs (ARPA, int.) 
o Runs its own network DNS infrastructure 
Recursive 
‱ ICANN runs its own recursive servers for staff 
‱ Risks to these are covered in ICANN’s ERM 
#ICANN51
Text 
Assets directly influenced by ICANN 
Authoritative 
‱ ICANN has an advisory committee (RSSAC) that 
provides Service Level Recommendations for root 
servers 
‱ (Upcoming RSSAC002) 
‱ ICANN has contracts in place with many, but not all 
TLDs. Those contracts contain SLAs 
Recursive 
‱ ?? 
#ICANN51
Text 
Authoritative 
‱ Registrants’ DNS services 
Recursive 
‱ ISPs, corporations, homes and DNS service providers 
‱ Should the community work together to influence these? 
‱ We have SSAC and RSSAC that provide advice 
#ICANN51 
Assets outside ICANN’s realm
Can We Tackle the Root Causes? 
Text 
There are many efforts underway to reduce the 
severity of DDoS attacks 
o Source Address Validation (BCP38) 
o Open Resolver project 
o Botnet dismantling 
o Others 
Should ICANN staff and community 
members play a more active role? 
#ICANN51
Going Forward 
Text 
‱ For each of the 23 risks, we will: 
o Document assets 
o Identify existing mitigation strategies that are in place 
o Suggest areas where new or improved mitigation plans 
may be considered 
‱ How do we involve community expertise? 
o Dedicated workshops? 
o Working Groups? 
o Other suggestions? 
#ICANN51
GDD + Related Sessions 
Text 
Wednesday, 15 October 
o GDD Service Delivery, Customer Service & 
#ICANN51 
Service Level Agreements 
o Universal Acceptance 
Thursday, 16 October 
o DNSSEC Key Rollover Workshop 
o Thick WHOIS Implementation (Working 
Session) 
o Deploying the IETF’s WHOIS Replacement
Text Engage with ICANN on Web & Social Media 
twitter.com/icann 
facebook.com/icannorg 
linkedin.com/company/icann 
gplus.to/icann 
weibo.com/icannorg 
flickr.com/photos/icann 
youtube.com/user/ICANNnews icann.org
1 de 23

Recomendados

What is ICANN? (Russian) por
What is ICANN? (Russian)What is ICANN? (Russian)
What is ICANN? (Russian)ICANN
676 visualizaçÔes‱9 slides
Guide to dark web por
Guide to dark webGuide to dark web
Guide to dark webJspider - Noida
711 visualizaçÔes‱11 slides
E-COMMERCE: The Dark Web por
E-COMMERCE: The Dark Web E-COMMERCE: The Dark Web
E-COMMERCE: The Dark Web rardthebeast
632 visualizaçÔes‱5 slides
I2P (Invisible Internet Project) por
I2P (Invisible Internet Project)I2P (Invisible Internet Project)
I2P (Invisible Internet Project)Shail Shah
1.5K visualizaçÔes‱16 slides
Making domain name and IP address policy at ICANN por
Making domain name and IP address policy at ICANNMaking domain name and IP address policy at ICANN
Making domain name and IP address policy at ICANNStephane Van Gelder
2K visualizaçÔes‱48 slides
The Dark Side of Content Marketing por
The Dark Side of Content MarketingThe Dark Side of Content Marketing
The Dark Side of Content MarketingScripted.com
1.5K visualizaçÔes‱51 slides

Mais conteĂșdo relacionado

Destaque

Dark web by Claudine Impas por
Dark web by Claudine ImpasDark web by Claudine Impas
Dark web by Claudine ImpasClaudine Impas
768 visualizaçÔes‱6 slides
How Much is My Information Worth on the Dark Web? por
How Much is My Information Worth on the Dark Web?How Much is My Information Worth on the Dark Web?
How Much is My Information Worth on the Dark Web?Mark Fisher
1.8K visualizaçÔes‱20 slides
The Dark Net por
The Dark NetThe Dark Net
The Dark NetPaige Rasid
2.6K visualizaçÔes‱10 slides
I2P and the Dark Web por
I2P and the Dark WebI2P and the Dark Web
I2P and the Dark WebJohn Liu
1.4K visualizaçÔes‱33 slides
The Dark side of the Web por
The Dark side of the WebThe Dark side of the Web
The Dark side of the WebPaula Ripoll Cacho
3.3K visualizaçÔes‱12 slides
The Dark Web por
The Dark WebThe Dark Web
The Dark WebConnor Willer
3.2K visualizaçÔes‱31 slides

Destaque(9)

Dark web by Claudine Impas por Claudine Impas
Dark web by Claudine ImpasDark web by Claudine Impas
Dark web by Claudine Impas
Claudine Impas‱768 visualizaçÔes
How Much is My Information Worth on the Dark Web? por Mark Fisher
How Much is My Information Worth on the Dark Web?How Much is My Information Worth on the Dark Web?
How Much is My Information Worth on the Dark Web?
Mark Fisher‱1.8K visualizaçÔes
The Dark Net por Paige Rasid
The Dark NetThe Dark Net
The Dark Net
Paige Rasid‱2.6K visualizaçÔes
I2P and the Dark Web por John Liu
I2P and the Dark WebI2P and the Dark Web
I2P and the Dark Web
John Liu‱1.4K visualizaçÔes
The Dark side of the Web por Paula Ripoll Cacho
The Dark side of the WebThe Dark side of the Web
The Dark side of the Web
Paula Ripoll Cacho‱3.3K visualizaçÔes
The Dark Web por Connor Willer
The Dark WebThe Dark Web
The Dark Web
Connor Willer‱3.2K visualizaçÔes
Dark web markets: from the silk road to alphabay, trends and developments por Andres Baravalle
Dark web markets: from the silk road to alphabay, trends and developmentsDark web markets: from the silk road to alphabay, trends and developments
Dark web markets: from the silk road to alphabay, trends and developments
Andres Baravalle‱2.4K visualizaçÔes
The Dark web - Why the hidden part of the web is even more dangerous? por Pierluigi Paganini
The Dark web - Why the hidden part of the web is even more dangerous?The Dark web - Why the hidden part of the web is even more dangerous?
The Dark web - Why the hidden part of the web is even more dangerous?
Pierluigi Paganini‱22.1K visualizaçÔes
Dark Web and Privacy por Brian Pichman
Dark Web and PrivacyDark Web and Privacy
Dark Web and Privacy
Brian Pichman‱4.1K visualizaçÔes

Similar a ICANN 51: DNS Risk Framework

ICANN 51: Name Collision por
ICANN 51: Name CollisionICANN 51: Name Collision
ICANN 51: Name CollisionICANN
1.2K visualizaçÔes‱36 slides
DNS Openness por
DNS OpennessDNS Openness
DNS OpennessAPNIC
2.1K visualizaçÔes‱41 slides
Name Collision Mitigation Update from ICANN 49 por
Name Collision Mitigation Update from ICANN 49Name Collision Mitigation Update from ICANN 49
Name Collision Mitigation Update from ICANN 49ICANN
1.6K visualizaçÔes‱26 slides
NANOG 84: DNS Openness por
NANOG 84: DNS OpennessNANOG 84: DNS Openness
NANOG 84: DNS OpennessAPNIC
397 visualizaçÔes‱60 slides
Introduction DNSSec por
Introduction DNSSecIntroduction DNSSec
Introduction DNSSecAFRINIC
353 visualizaçÔes‱70 slides
Biznet Gio Presentation - Database Security por
Biznet Gio Presentation - Database SecurityBiznet Gio Presentation - Database Security
Biznet Gio Presentation - Database SecurityYusuf Hadiwinata Sutandar
1.1K visualizaçÔes‱28 slides

Similar a ICANN 51: DNS Risk Framework(20)

ICANN 51: Name Collision por ICANN
ICANN 51: Name CollisionICANN 51: Name Collision
ICANN 51: Name Collision
ICANN‱1.2K visualizaçÔes
DNS Openness por APNIC
DNS OpennessDNS Openness
DNS Openness
APNIC‱2.1K visualizaçÔes
Name Collision Mitigation Update from ICANN 49 por ICANN
Name Collision Mitigation Update from ICANN 49Name Collision Mitigation Update from ICANN 49
Name Collision Mitigation Update from ICANN 49
ICANN‱1.6K visualizaçÔes
NANOG 84: DNS Openness por APNIC
NANOG 84: DNS OpennessNANOG 84: DNS Openness
NANOG 84: DNS Openness
APNIC‱397 visualizaçÔes
Introduction DNSSec por AFRINIC
Introduction DNSSecIntroduction DNSSec
Introduction DNSSec
AFRINIC‱353 visualizaçÔes
Biznet Gio Presentation - Database Security por Yusuf Hadiwinata Sutandar
Biznet Gio Presentation - Database SecurityBiznet Gio Presentation - Database Security
Biznet Gio Presentation - Database Security
Yusuf Hadiwinata Sutandar‱1.1K visualizaçÔes
ICANN Presentation - iWeek2017 por dotZADNA
ICANN Presentation - iWeek2017ICANN Presentation - iWeek2017
ICANN Presentation - iWeek2017
dotZADNA‱283 visualizaçÔes
Fundamentals por Prasenjit Saha
FundamentalsFundamentals
Fundamentals
Prasenjit Saha‱585 visualizaçÔes
2017 Q1 Arcticcon - Meet Up - Adventures in Adversarial Emulation por Scott Sutherland
2017 Q1 Arcticcon - Meet Up - Adventures in Adversarial Emulation2017 Q1 Arcticcon - Meet Up - Adventures in Adversarial Emulation
2017 Q1 Arcticcon - Meet Up - Adventures in Adversarial Emulation
Scott Sutherland‱606 visualizaçÔes
Monitoring for DNS Security por ThousandEyes
Monitoring for DNS SecurityMonitoring for DNS Security
Monitoring for DNS Security
ThousandEyes‱958 visualizaçÔes
Revisiting the Root por APNIC
Revisiting the RootRevisiting the Root
Revisiting the Root
APNIC‱78 visualizaçÔes
ICANN 51: Universal Acceptance por ICANN
ICANN 51: Universal AcceptanceICANN 51: Universal Acceptance
ICANN 51: Universal Acceptance
ICANN‱548 visualizaçÔes
Fundamentals por vamsi1986
FundamentalsFundamentals
Fundamentals
vamsi1986‱232 visualizaçÔes
What Is DNS ? por GTCSYS
What Is DNS ?What Is DNS ?
What Is DNS ?
GTCSYS‱2 visualizaçÔes
DNS Security WebTitan Web Filter - Stop Malware por Dryden Geary
DNS Security WebTitan Web Filter - Stop Malware DNS Security WebTitan Web Filter - Stop Malware
DNS Security WebTitan Web Filter - Stop Malware
Dryden Geary‱134 visualizaçÔes
Understanding and Deploying DNSSEC, by Champika Wijayatunga [APRICOT 2015] por APNIC
Understanding and Deploying DNSSEC, by Champika Wijayatunga [APRICOT 2015]Understanding and Deploying DNSSEC, by Champika Wijayatunga [APRICOT 2015]
Understanding and Deploying DNSSEC, by Champika Wijayatunga [APRICOT 2015]
APNIC‱3.1K visualizaçÔes
Active Directory Fundamentals por Angie Miller
Active Directory FundamentalsActive Directory Fundamentals
Active Directory Fundamentals
Angie Miller‱4 visualizaçÔes
DNS Over HTTPS by Michael Casadevall por Glenn McKnight
DNS Over HTTPS by Michael CasadevallDNS Over HTTPS by Michael Casadevall
DNS Over HTTPS by Michael Casadevall
Glenn McKnight‱200 visualizaçÔes
Demystifying SharePoint Infrastructure – for NON-IT People por SPC Adriatics
 Demystifying SharePoint Infrastructure – for NON-IT People  Demystifying SharePoint Infrastructure – for NON-IT People
Demystifying SharePoint Infrastructure – for NON-IT People
SPC Adriatics‱576 visualizaçÔes

Mais de ICANN

Call for Volunteers: Accountability & Transparency Review Team_PT por
Call for Volunteers: Accountability & Transparency Review Team_PTCall for Volunteers: Accountability & Transparency Review Team_PT
Call for Volunteers: Accountability & Transparency Review Team_PTICANN
2.7K visualizaçÔes‱24 slides
Call for Volunteers: Accountability & Transparency Review Team_ZH por
Call for Volunteers: Accountability & Transparency Review Team_ZHCall for Volunteers: Accountability & Transparency Review Team_ZH
Call for Volunteers: Accountability & Transparency Review Team_ZHICANN
612 visualizaçÔes‱24 slides
Call for Volunteers: Accountability & Transparency Review Team_ES por
Call for Volunteers: Accountability & Transparency Review Team_ESCall for Volunteers: Accountability & Transparency Review Team_ES
Call for Volunteers: Accountability & Transparency Review Team_ESICANN
582 visualizaçÔes‱24 slides
Call for Volunteers: Accountability & Transparency Review Team_AR por
Call for Volunteers: Accountability & Transparency Review Team_ARCall for Volunteers: Accountability & Transparency Review Team_AR
Call for Volunteers: Accountability & Transparency Review Team_ARICANN
533 visualizaçÔes‱24 slides
Call for Volunteers: Accountability & Transparency Review Team_FR por
Call for Volunteers: Accountability & Transparency Review Team_FRCall for Volunteers: Accountability & Transparency Review Team_FR
Call for Volunteers: Accountability & Transparency Review Team_FRICANN
336 visualizaçÔes‱24 slides
Call for Volunteers: Accountability & Transparency Review Team_RU por
Call for Volunteers: Accountability & Transparency Review Team_RUCall for Volunteers: Accountability & Transparency Review Team_RU
Call for Volunteers: Accountability & Transparency Review Team_RUICANN
371 visualizaçÔes‱24 slides

Mais de ICANN(20)

Call for Volunteers: Accountability & Transparency Review Team_PT por ICANN
Call for Volunteers: Accountability & Transparency Review Team_PTCall for Volunteers: Accountability & Transparency Review Team_PT
Call for Volunteers: Accountability & Transparency Review Team_PT
ICANN‱2.7K visualizaçÔes
Call for Volunteers: Accountability & Transparency Review Team_ZH por ICANN
Call for Volunteers: Accountability & Transparency Review Team_ZHCall for Volunteers: Accountability & Transparency Review Team_ZH
Call for Volunteers: Accountability & Transparency Review Team_ZH
ICANN‱612 visualizaçÔes
Call for Volunteers: Accountability & Transparency Review Team_ES por ICANN
Call for Volunteers: Accountability & Transparency Review Team_ESCall for Volunteers: Accountability & Transparency Review Team_ES
Call for Volunteers: Accountability & Transparency Review Team_ES
ICANN‱582 visualizaçÔes
Call for Volunteers: Accountability & Transparency Review Team_AR por ICANN
Call for Volunteers: Accountability & Transparency Review Team_ARCall for Volunteers: Accountability & Transparency Review Team_AR
Call for Volunteers: Accountability & Transparency Review Team_AR
ICANN‱533 visualizaçÔes
Call for Volunteers: Accountability & Transparency Review Team_FR por ICANN
Call for Volunteers: Accountability & Transparency Review Team_FRCall for Volunteers: Accountability & Transparency Review Team_FR
Call for Volunteers: Accountability & Transparency Review Team_FR
ICANN‱336 visualizaçÔes
Call for Volunteers: Accountability & Transparency Review Team_RU por ICANN
Call for Volunteers: Accountability & Transparency Review Team_RUCall for Volunteers: Accountability & Transparency Review Team_RU
Call for Volunteers: Accountability & Transparency Review Team_RU
ICANN‱371 visualizaçÔes
Call for Volunteers: Accountability & Transparency Review Team por ICANN
Call for Volunteers: Accountability & Transparency Review TeamCall for Volunteers: Accountability & Transparency Review Team
Call for Volunteers: Accountability & Transparency Review Team
ICANN‱3.9K visualizaçÔes
ICANN Expected Standards of Behavior | French por ICANN
ICANN Expected Standards of Behavior | FrenchICANN Expected Standards of Behavior | French
ICANN Expected Standards of Behavior | French
ICANN‱688 visualizaçÔes
ICANN Expected Standards of Behavior por ICANN
ICANN Expected Standards of BehaviorICANN Expected Standards of Behavior
ICANN Expected Standards of Behavior
ICANN‱449 visualizaçÔes
ICANN Expected Standards of Behavior | Russian por ICANN
ICANN Expected Standards of Behavior | RussianICANN Expected Standards of Behavior | Russian
ICANN Expected Standards of Behavior | Russian
ICANN‱280 visualizaçÔes
ICANN Expected Standards of Behavior | Arabic por ICANN
ICANN Expected Standards of Behavior | ArabicICANN Expected Standards of Behavior | Arabic
ICANN Expected Standards of Behavior | Arabic
ICANN‱311 visualizaçÔes
ICANN Expected Standards of Behavior | Chinese por ICANN
ICANN Expected Standards of Behavior | ChineseICANN Expected Standards of Behavior | Chinese
ICANN Expected Standards of Behavior | Chinese
ICANN‱294 visualizaçÔes
ICANN Expected Standards of Behavior | Spanish por ICANN
ICANN Expected Standards of Behavior | SpanishICANN Expected Standards of Behavior | Spanish
ICANN Expected Standards of Behavior | Spanish
ICANN‱244 visualizaçÔes
Policy Development Process Infographic Turkish por ICANN
Policy Development Process Infographic TurkishPolicy Development Process Infographic Turkish
Policy Development Process Infographic Turkish
ICANN‱515 visualizaçÔes
Policy Development Process Infographic Russian por ICANN
Policy Development Process Infographic RussianPolicy Development Process Infographic Russian
Policy Development Process Infographic Russian
ICANN‱415 visualizaçÔes
Policy Development Process Infographic Portuguese por ICANN
Policy Development Process Infographic PortuguesePolicy Development Process Infographic Portuguese
Policy Development Process Infographic Portuguese
ICANN‱327 visualizaçÔes
Policy Development Process Infographic Spanish por ICANN
Policy Development Process Infographic SpanishPolicy Development Process Infographic Spanish
Policy Development Process Infographic Spanish
ICANN‱320 visualizaçÔes
Policy Development Process Infographic French por ICANN
Policy Development Process Infographic FrenchPolicy Development Process Infographic French
Policy Development Process Infographic French
ICANN‱299 visualizaçÔes
Policy Development Process Infographic English por ICANN
Policy Development Process Infographic EnglishPolicy Development Process Infographic English
Policy Development Process Infographic English
ICANN‱2K visualizaçÔes
Policy Development Process Infographic Chinese por ICANN
Policy Development Process Infographic ChinesePolicy Development Process Infographic Chinese
Policy Development Process Infographic Chinese
ICANN‱223 visualizaçÔes

Último

Building trust in our information ecosystem: who do we trust in an emergency por
Building trust in our information ecosystem: who do we trust in an emergencyBuilding trust in our information ecosystem: who do we trust in an emergency
Building trust in our information ecosystem: who do we trust in an emergencyTina Purnat
85 visualizaçÔes‱18 slides
Serverless cloud architecture patterns por
Serverless cloud architecture patternsServerless cloud architecture patterns
Serverless cloud architecture patternsJimmy Dahlqvist
17 visualizaçÔes‱52 slides
zotabet.pdf por
zotabet.pdfzotabet.pdf
zotabet.pdfzotabetcasino
6 visualizaçÔes‱1 slide
Audience profile.pptx por
Audience profile.pptxAudience profile.pptx
Audience profile.pptxMollyBrown86
12 visualizaçÔes‱2 slides
childcare.pdf por
childcare.pdfchildcare.pdf
childcare.pdffatma alnaqbi
14 visualizaçÔes‱4 slides
Sustainable Marketing por
Sustainable MarketingSustainable Marketing
Sustainable MarketingTheo van der Zee
9 visualizaçÔes‱50 slides

Último(20)

Building trust in our information ecosystem: who do we trust in an emergency por Tina Purnat
Building trust in our information ecosystem: who do we trust in an emergencyBuilding trust in our information ecosystem: who do we trust in an emergency
Building trust in our information ecosystem: who do we trust in an emergency
Tina Purnat‱85 visualizaçÔes
Serverless cloud architecture patterns por Jimmy Dahlqvist
Serverless cloud architecture patternsServerless cloud architecture patterns
Serverless cloud architecture patterns
Jimmy Dahlqvist‱17 visualizaçÔes
zotabet.pdf por zotabetcasino
zotabet.pdfzotabet.pdf
zotabet.pdf
zotabetcasino‱6 visualizaçÔes
Audience profile.pptx por MollyBrown86
Audience profile.pptxAudience profile.pptx
Audience profile.pptx
MollyBrown86‱12 visualizaçÔes
childcare.pdf por fatma alnaqbi
childcare.pdfchildcare.pdf
childcare.pdf
fatma alnaqbi‱14 visualizaçÔes
Sustainable Marketing por Theo van der Zee
Sustainable MarketingSustainable Marketing
Sustainable Marketing
Theo van der Zee‱9 visualizaçÔes
AI Powered event-driven translation bot por Jimmy Dahlqvist
AI Powered event-driven translation botAI Powered event-driven translation bot
AI Powered event-driven translation bot
Jimmy Dahlqvist‱16 visualizaçÔes
IGF UA - Dialog with I_ organisations - Alena Muavska RIPE NCC.pdf por RIPE NCC
IGF UA - Dialog with I_ organisations - Alena Muavska RIPE NCC.pdfIGF UA - Dialog with I_ organisations - Alena Muavska RIPE NCC.pdf
IGF UA - Dialog with I_ organisations - Alena Muavska RIPE NCC.pdf
RIPE NCC‱15 visualizaçÔes
informing ideas.docx por MollyBrown86
informing ideas.docxinforming ideas.docx
informing ideas.docx
MollyBrown86‱12 visualizaçÔes
Existing documentaries (1).docx por MollyBrown86
Existing documentaries (1).docxExisting documentaries (1).docx
Existing documentaries (1).docx
MollyBrown86‱13 visualizaçÔes
information por khelgishekhar
informationinformation
information
khelgishekhar‱7 visualizaçÔes
UiPath Document Understanding_Day 3.pptx por UiPathCommunity
UiPath Document Understanding_Day 3.pptxUiPath Document Understanding_Day 3.pptx
UiPath Document Understanding_Day 3.pptx
UiPathCommunity‱95 visualizaçÔes
google forms survey (1).pptx por MollyBrown86
google forms survey (1).pptxgoogle forms survey (1).pptx
google forms survey (1).pptx
MollyBrown86‱14 visualizaçÔes
IETF 118: Starlink Protocol Performance por APNIC
IETF 118: Starlink Protocol PerformanceIETF 118: Starlink Protocol Performance
IETF 118: Starlink Protocol Performance
APNIC‱124 visualizaçÔes
Is Entireweb better than Google por sebastianthomasbejan
Is Entireweb better than GoogleIs Entireweb better than Google
Is Entireweb better than Google
sebastianthomasbejan‱10 visualizaçÔes
UiPath Document Understanding_Day 2.pptx por RohitRadhakrishnan8
UiPath Document Understanding_Day 2.pptxUiPath Document Understanding_Day 2.pptx
UiPath Document Understanding_Day 2.pptx
RohitRadhakrishnan8‱282 visualizaçÔes
Opportunities for Youth in IG - Alena Muravska RIPE NCC.pdf por RIPE NCC
Opportunities for Youth in IG - Alena Muravska RIPE NCC.pdfOpportunities for Youth in IG - Alena Muravska RIPE NCC.pdf
Opportunities for Youth in IG - Alena Muravska RIPE NCC.pdf
RIPE NCC‱9 visualizaçÔes
PORTFOLIO 1 (Bret Michael Pepito).pdf por brejess0410
PORTFOLIO 1 (Bret Michael Pepito).pdfPORTFOLIO 1 (Bret Michael Pepito).pdf
PORTFOLIO 1 (Bret Michael Pepito).pdf
brejess0410‱7 visualizaçÔes
đ’đšđ„đšđ«đ–đąđ§đđŹ 𝐂𝐚𝐬𝐞 𝐒𝐭𝐼𝐝đČ por Infosec train
đ’đšđ„đšđ«đ–đąđ§đđŹ 𝐂𝐚𝐬𝐞 𝐒𝐭𝐼𝐝đČđ’đšđ„đšđ«đ–đąđ§đđŹ 𝐂𝐚𝐬𝐞 𝐒𝐭𝐼𝐝đČ
đ’đšđ„đšđ«đ–đąđ§đđŹ 𝐂𝐚𝐬𝐞 𝐒𝐭𝐼𝐝đČ
Infosec train‱7 visualizaçÔes
OMS: Diretrizes para um controle da promoção comercial dos ditos substitutos ... por Prof. Marcus Renato de Carvalho
OMS: Diretrizes para um controle da promoção comercial dos ditos substitutos ...OMS: Diretrizes para um controle da promoção comercial dos ditos substitutos ...
OMS: Diretrizes para um controle da promoção comercial dos ditos substitutos ...
Prof. Marcus Renato de Carvalho‱88 visualizaçÔes

ICANN 51: DNS Risk Framework

  • 1. Text DNS Risk Framework Update #ICANN51 14 October 2014 John Crain & Jacks Khawaja Chief SSR Officer; Enterprise Risk Director
  • 2. Agenda Text ‱ History ‱ Moving Forward #ICANN51
  • 8. Numbers Text ‱ Examining Risk o Typically, step 1 = identify assets o Impractical to identify all individual elements of DNS ‱ Our Approach Categorize assets by sphere of influence #ICANN51
  • 9. WTexth ere can ICANN: Implement Directly Influence Indirectly Influence ?
  • 10. Text Assets directly controlled by ICANN ‱ Assets that ICANN directly manages or contracts to third parties (Example: XXX, XXX) ‱ ICANN’s own corporate infrastructure ‱ External-facing services such as websites and request management systems ‱ DNS infrastructure of L.root-servers.net ‱ Others? #ICANN51
  • 11. Text Assets directly influenced by ICANN ‱ Assets that ICANN can influence through contractual agreements (Example: Service Level Agreements, etc.) ‱ Registries or registrars are guided by contracts that include Service Level Agreements ‱ It is their remit as the asset owners to decide how they meet those SLAs and how to implement mitigation of their risks #ICANN51
  • 12. Text ‱ The Internet is a “network of networks” and each operator of a network or service is ultimately responsible for their own risk management ‱ ICANN and the community can indirectly influence these through outreach and awareness efforts ‱ ISOC’s Deploy360 is an excellent example of this #ICANN51 Assets outside ICANN’s realm
  • 13. Text SSR-001 DDOS (Example) #ICANN51
  • 14. SSR001 Description (abridged) Text ‱ User or organization deprived of service(s) or resource(s) they would normally have ‱ Distributed denial-of-service (DDoS) attack: o Multitude of systems (compromised or otherwise) are used to attack a single target o Flood of incoming messages to the target system essentially forces it to shut down. This can take two forms: § Resource Depletion § Resource Disruption #ICANN51
  • 15. What is the Risk? Text ‱ This risk discusses the probability that parts of the DNS could be disabled for a sustained period ‱ To ascertain the likelihood or the effect of such an attack, it’s important to first define the assets that are affected. This is also critical to understanding who owns the risk and who is able to best mitigate such risks #ICANN51
  • 16. Look at DNS Assets from Both Sides Text ‱ Publish the data on the authoritative servers (root servers, TLD servers, and registrants servers) ‱ Query the data on the recursive servers (ISP’s, corporations, and DNS service providers) #ICANN51
  • 17. Text Assets directly controlled by ICANN Authoritative ‱ ICANN: o Operates L.root-servers.netICANN runs some infrastructure for TLDs (ARPA, int.) o Runs its own network DNS infrastructure Recursive ‱ ICANN runs its own recursive servers for staff ‱ Risks to these are covered in ICANN’s ERM #ICANN51
  • 18. Text Assets directly influenced by ICANN Authoritative ‱ ICANN has an advisory committee (RSSAC) that provides Service Level Recommendations for root servers ‱ (Upcoming RSSAC002) ‱ ICANN has contracts in place with many, but not all TLDs. Those contracts contain SLAs Recursive ‱ ?? #ICANN51
  • 19. Text Authoritative ‱ Registrants’ DNS services Recursive ‱ ISPs, corporations, homes and DNS service providers ‱ Should the community work together to influence these? ‱ We have SSAC and RSSAC that provide advice #ICANN51 Assets outside ICANN’s realm
  • 20. Can We Tackle the Root Causes? Text There are many efforts underway to reduce the severity of DDoS attacks o Source Address Validation (BCP38) o Open Resolver project o Botnet dismantling o Others Should ICANN staff and community members play a more active role? #ICANN51
  • 21. Going Forward Text ‱ For each of the 23 risks, we will: o Document assets o Identify existing mitigation strategies that are in place o Suggest areas where new or improved mitigation plans may be considered ‱ How do we involve community expertise? o Dedicated workshops? o Working Groups? o Other suggestions? #ICANN51
  • 22. GDD + Related Sessions Text Wednesday, 15 October o GDD Service Delivery, Customer Service & #ICANN51 Service Level Agreements o Universal Acceptance Thursday, 16 October o DNSSEC Key Rollover Workshop o Thick WHOIS Implementation (Working Session) o Deploying the IETF’s WHOIS Replacement
  • 23. Text Engage with ICANN on Web & Social Media twitter.com/icann facebook.com/icannorg linkedin.com/company/icann gplus.to/icann weibo.com/icannorg flickr.com/photos/icann youtube.com/user/ICANNnews icann.org