1 Threats
1.1 Threats to underlying infrastructure
1.1.1 Business failure Registry business failure As with any business, registry operators must properly manage financial assets, funding and cash flow or face potential financial failure. Businesses and entities interested in entering the registry market should study the examples set by current registry operators in order to understand the business of domain names. Business failure examples include bankruptcy, buy-out, loss of funding, liquidation, management failure, marketing failure, litigation-related or induced failure or termination of payment processing capability Failure modes - vulnerabilities Marketing Failure Litigation-related Failure Termination of payment processing capability General Business Failure Palage White Paper ( ) recommendations -- mitigation All registry operators be required to operate on the current EPP standard ICANN listed as direct beneficiary of data escrow agreement, with active script verification and periodic download ICANN access to zone files Education on existence and function of Auth Codes Bonding requirement Discussion of "thick" vs "thin" registries Registrar business failure
1.1.2 System failure A system failure -- resulting from a hardware or software failure, or configuration error -- could disrupt any or all the services a registrar or registry operator provides. A system failure is likely to be a temporary failure. Applications-cluster processor fails EPP/RRP server processor fails Web server processor fails Database server processor fails Database disk drive fails Database crashes Authentication server fails Whois-cluster processor fails Billing and collections server fails Internet or VPN link fails Router or firewall fails Physical site becomes inoperable for more than 24 hours Both the primary and secondary data centers become inoperable Operating system or application software fails Operating system configuration errors security system configuration errors Name, web, database, and transaction server configuration errors
1.1.3 Government interventions Regulatory-imposed shutdown A court, government or government agency could attempt to order a registry operator to halt its operations. Government Seizure of Registry Operator A government could assume control over a registry operator, either through seizure of registry operations or nationalization of operations. Re-delegation of ccTLDs from individuals to government agencies provide examples of government assumption of control over registry operations. Re-delegation of a registry should include measures to ensure stable transition of registry operations. Political State-sponsored Hacktivism
1.1.4 Physical Government Takeover/Coup A change of government by takeover, revolution or coup could lead to instability or failure for a registry operator. Political instability has not to date had a direct impact on registry operations, but direct intervention by governments into registry operations could occur in the future. Terrorism Acts of war/terror Facility security Natural disaster A natural disaster may have a devastating financial impact on a registry, even if it has a well-developed registry failover plan. This is particularly in the case where a nation is unable to cover the costs of rebuilding key infrastructure needed to maintain registry operations. Earthquakes A strong earthquake could cause a temporary failure for a registry. A registry located in an earthquake-prone location should have contingency plans in place to ensure continuity of operations. Hurricanes Hurricane Katrina (23-31 August 2005) is estimated to be responsible for over $75 billion USD in damages. When Hurricane Katrina hit New Orleans 27-30 August 2005, it caused a temporary failure to ICANN-accredited registrar Intercosmos Media Group. Intercosmos was able to avoid a prolonged outage because it had a plan for the backup of critical registrar resources. Although Intercosmos is a registrar, it may serve as an example for registries facing potential disaster scenarios. Tsunami While no registries are currently located in a tsunami-danger zone, future registry operators in tsunami-prone areas should have contingency plans in place to ensure the stability of registry operations. Blackout/Energy Failure In the future, a similar large-scale power outage could impact registry operators that have not implemented protections against localized outages at registry operations centers. Snowstorm/blizzard/ice-storm Physical disasters
1.1.5 Depletion of IPv4 address pool -- SAC 12 Routing table growth Route fragmentation
1.1.6 Fragmentation of the root -- SAC 9 Alternate DNS roots Root scaling (SAC 46) Intentional or accidental results of DNS blocking (SAC 50)
1.2 Direct Attacks
1.2.1 DDOS SSAC DDOS Advisory -- SAC 8 Securing the edge -- SAC 4 Examples On 6 February 2007, a distributed denial of service attack affected six of the thirteen root servers that form the foundation of the Internet. A factsheet on the attack is available at The use of Anycast ( by root server operators helped prevent a major disruption to Internet operations. In March 2006, a distributed denial of service attack was launched on a number of root servers, registrars and registry operators. The attacks temporarily impacted accredited registrars in Germany and in the United States. and,125554-page,1-c,applicationbugs/article.html. Combined, the registrars had approximately 8,000,000 domain names under management (approximately 11.5% of active domain name registrations as of 11 May 2006). On 31 March 2006, ICANN's SSAC released an advisory on DNS Distributed Denial of Service Attacks (see The advisory made a number of recommendations for Root and TLD Name Server Operators. These recommendations could also be employed by the registry operators. Issue What Cyber activists use DDoS to shut down the servers and networks of political, religious, and corporate organizations. Nations in conflict use crowd sourced denial of service attacks to shut off access to critical web sites in a show of force but also to silence a vocal critic in conjunction with an invasion. Why Cyber criminals attempt to extort cash payments from their targets with the threat of shutting down their business. Small businesses have been known to hire botnets, collections of compromised computers, to shut down a competitor. Who Cyber activists Nations Cyber criminals Small businesses DDOS attacks Botnets owner of a web site may not own the DNS server that provides the critical function of pointing at the web site. Denial of service amplifier (RFC 3833) Open recursive servers (SAC 8) Packet fragmentation (SAC 8) Source address validation (SAC 8) Reflection attacks
1.2.2 Packet Interception Man in the middle Eavesdropping combined with spoofed responses ID Guessing and Query Prediction Generate packets which match the transport protocol parameters, predict ID based on previous traffic, etc.
1.2.3 Recursive vs authoritative nameserver attacks
1.2.4 Authority or authentication compromise
1.2.5 Domain name hijacking/theft - SAC 7 Domain hijacking refers to the wrongful taking of control of a domain name from the rightful name holder.
1.2.6 Registrar impersonation phishing attacks -- SAC 28 Issue statement Phishers exploit many forms of email correspondence that merchants or financial businesses send to customers2. Registrars also use electronic mail for many types of domain name registration-related correspondence, including: • Domain name renewal notices • Domain name order confirmations • Registration request confirmations • Domain information modification confirmations • WHOIS data accuracy reminders • Notices of domain name expiry or cancellation • Promotions, advertising for (new) services and features Phishers exploit the fact that registrars rely on email correspondence. By impersonating (spoofing) a registrar in a phishing attack, the phisher is able to lure a registrar’s customer to a bogus copy of the registrar’s customer login page, where the customer may unwittingly disclose account credentials to the attacker. These credentials provide the phisher with unauthorized access to a domain name management account. Objectives (SAC 28) Domain name hijacking Gain control of "trusted" providers of MX -- for spamming Web-site spoofing -- by using hijacked A and AAAA records Business disruption
1.2.7 Data poisoning (MITM, Cache) Cache poisoning attacks Kaminsky Kaspureff Name Chaining (RFC 3833) Subset of "cache poisoning" attacks. Redirect a victims query to a location of the attacker's choosing. CNAME, NS and DNAME record types are most vulnerable. Victim issues query, attacker injects response, attacker's response injects data into victim's cache. Betrayal by Trusted Server (RFC 3833) Another variant of packet interception. Attack via the server trusted by a stub client. Accidentally (misconfigured) or maliciously delivers answers that are not what the user would expect.
1.2.8 Footprinting The process of building a diagram, or footprint, of a DNS infrastructure by capturing DNS zone data such as domain names, computer names, and IP addresses for sensitive network resources. DNS domain and computer names often indicate the function or location of domains and computers. source - Microsoft Tech net
1.2.9 Fast Flux SSAC advisory on fast flux hosting and DNS -- SAC 25 Issue "Fast flux" is an evasion technique that cyber-criminals and Internet miscreants use to evade identification and to frustrate law enforcement and anticrime efforts aimed at locating and shutting down web sites used for illegal purposes. Fast flux hosting supports a wide variety of cyber-crime activities (fraud, identity theft, online scams) and is considered one of the most serious threats to online activities today. One variant of fast flux hosting, "double flux", exploits the domain name registration and name resolution services. GNSO Fast Flux working group Link to final report
1.2.10 IDN attacks (lookalike characters etc. for standard exploitation techniques) Display and usage of internationalized registration data: support for characters from local languages or scripts (SAC 37)
1.2.11 Authenticated Denial of Domain Name (RFC 3833) Question is whether there is a requirement for authenticating the non-existence of a name.
1.2.12 Gain control of account user/password Targets Registry Registrar Registrant Techniques Guess, phish or apply social engineering techniques on a weak point of contact Block delivery of email notifications to targeted registrants by altering DNS configuration Mitigation Prevent access to domain portfolio Registration verification Improve password-based authentication system Register a PC or IP address from which to administer an account Multi-factor authentication Challenge systems Per-domain access controls Multiple, unique points of contact Change notifications or confirmations SAC 40 Finding (7) Registration service providers rely more heavily on unconfirmed email to deliver security-related correspondence (e.g., change notifications) than email delivery assurance and security characteristics merit. Attackers often defeat this method of correspondence by preventing email delivery when they modify the DNS configuration of domains through compromised registration accounts. 1.2.13 Malicious or unintentional (erroneous) alteration of DNS configuration information SAC 44 Maliciously introduced changes to the DNS name server configuration information associated with a domain name may result in the resolution of the domain name to an IP address(es) other than the address(es) the domain registrant intended. Such changes can result in the loss or disruption of the registrant’s Internet services (e.g., web or email) or the intentional and malicious redirection of visitors away from the registrant’s intended servers to an attacker’s servers, which may host defacement, phishing or other malicious or criminal activities.7 Lack of coordination or administrative error can introduce changes to DNS name server configuration information with the similar consequences as malicious alteration. Such changes can result in the loss or disruption of the registrant’s Internet applications or services, or could expose the registrant’s organization to attack.8 Mitigation Protecting DNS configuration information from abuse Require multi-factor authentication for DNS configuration changes. Require confirmations of change from multiple contacts using email, possibly via media other than email. Deliver notifications to multiple contacts when changes performed. Monitor DNS changes for anomalies or abuse. Reduce scope of the authority of a given account SAC 40 Finding (6) Commonly, once a user is authenticated at a registration account portal or login, the user (or imposter) has global privileges and can modify contact information as well as DNS configuration information. 1.3 Indirect attacks
1.3.1 Email/spam IPv6 -- Spammers hopping from IP to IP -- causing huge numbers of lookups -- volume related threats (perhaps unintentional) -- also may break normal DNS caching (whicha assumes repeated requests for the same thing) Issues around reverse DNS for SMTP servers Botnets Collateral damage Load
1.3.2 Registration abuse -- front-running SAC 22 and 24 Issue statement - SAC 22 This Advisory considers the opportunity for a party with some form of insider informa- tion to track an Internet user’s preference for registering a domain name and preemptive- ly register that name. SSAC likens this activity to front running in stock and commodities markets and calls this behavior domain name front running. In the domain name indus- try, insider information would be information gathered from the monitoring of one or more attempts by an Internet user to check the availability of a domain name.
1.3.3 Registration abuse -- cybersquatting
1.3.4 WHOIS abuse -- harvesting WHOIS data for spam SAC 3 and SAC 23 Issue statement - SAC 3 It is widely believed that the Whois data is a source of email addresses for the delivery of SPAM and other unsolicited and otherwise unwanted email messages. Consequently, many Registrars have started offering their Whois data in random formats to deter harvesting. This is unfortunate because a common format is necessary to ensure that the data is readily accessible and understandable when it is needed. We must encourage not only the use of a common format but the development of mechanisms to prevent the harvesting and mining of Whois data.
1.3.5 WHOIS abuse -- harvesting personal contact information from domain name registration records -- SAC 14