Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

Members: 

  • Laureen Kapin (Subteam Chair)
  • Carlton Samuels
  • Carlos Raul Gutierrez
  • Gao Mosweu
  • Fabro Stiebel
  • Jamie Hedlund
  • Drew Bagley 
  • David Taylor
  • Calvin Browne 

Mandate: This sub team was created to explore two key areas of the CCT Review as outlined in section 9.3 of the Affirmation of Commitments: "...the extent to which the introduction or expansion of gTLDs has promoted ... consumer trust ... as well as effectiveness of ... safeguards put in place to mitigate issues involved in the introduction or expansion."

 http://mm.icann.org/pipermail/cctreview-safeguards/
 
  • Outline of individual assessments - DOC
  • Revised template - DOC
  • Model issue paper - DOC-PDF
Refer to Safeguards & Trust - Calls for your call schedule and call archives

TOPICS & TEAMS

  • DNS Abuse: Drew Bagley - Calvin Browne - Carlos Raul Gutierrez

  • Impact of Safeguards & Public Interest Commitments: Drew Bagley - Fabro Stiebel - Calvin Browne - Gao Mosweu - Laureen Kapin - Carlton Samuels - David Taylor - Jamie Hedlund: Laureen Kapin - Gao Mosweu
  • Effectiveness of Procedures to enforce safeguards: David Taylor - Jamie Hedlund

  • ACTION ITEMS (warning)

    **Reading List Findings - DEADLINE 24 JUNE 2016 https://docs.google.com/document/d/19IF1WAi66X0yOkPR9vz2EMTfTSfGrWEsmMJmXE3XahM/edit?usp=sharing 

    **Impact of Safeguards & PICs - DEADLINE 30 JUNE 2016

    https://docs.google.com/document/d/1HXITaaEdZ8MlbA-GjCJfDv7eXKuPNIeaVtopU2h4PX8/edit

    • Complete your analysis

    **Work Plan - DEADLINE 1 JULY 2016

    **More reading!

     

    Documents

    DocumentFileComments
    BRAINSTORMING DOCUMENT

    v1 (23 Feb)

    DOC - PDF

    CCT-RT Meeting in LA
    v2/3 (3 March)DOC - PDFCirculated by Drew Bagley
    v4 (4 March)DOC - PDFG-doc

    v5 (10 March)

    Priority list

    DOC- PDF

    DOC - PDF

    G-doc  

    Priority list G-doc

    v6 (31 March)DOC - PDFG-doc  
    v7 (28 April)DOC - PDF 
    v8 (7 June)DOC - PDFG-doc
    WORK PLAN
    v1 (3 May)DOC - PDF 
    v2 (2 June)DOC 
    v3 (23 June)DOC - PDF 
    SAFEGUARDS EFFECTIVENESS MANAGEMENT TABLE

    v1 (27 May)

    DOC - PDF 
    v2 (6 June)DOC - PDF 

    v3 (13 June)

    DOC - PDF 
    v5 (21 June)DOC - PDF 
    OTHER
    Regulated and sensitive strings delegated (29 April 2016)XLS - PDFGAC Category 1 strings and those requiring special safeguards (PDF) classified by delegation date

    Reading List

    Date AddedDocumentFilesResponsible Team MemberUseful Yes/No
    31 March 2016

    Secure Domain Foundation/Business case

    for proactive anti-abuse

    PDF

    DB's analysis/presentation - PDF

    DB 
    31 March 2016

    Knujon March 2016: Internet Limbo Report

    Concerning Issues of Consumer Trust on the Internet

    PDF

    FS's analysis/presentation - PDF

    FS 
    31 March 2016

    ICANN Draft Report New gTLD Program

    Safeguards to Mitigate DNS Abuse

    LINK

    CG' analysis/presentation - PDF

    CG 
    31 March 2016Notice and takedowns in everyday practice - Online takedowns studyPDFDT & CB 
    5 April 2016Consumer Awareness Summary

    DOC - PDF

    CS's analysis/presentation - PDF

    JH & CS 
    14 April 2016APWG Phishing Attack Trends Reports

    LINK

    GM's analysis/presentation - PDF

    GM 
    20 April 2016Compliance-related metricsLINKLK 
    29 April 2016

    The Curse of the URL Shorteners: How safe are they?

    LINKFS 
    29 April 2016What is Spyware?LINKGM 
    29 April 2016

    ICANN Registry Agreements

    LINK

    CAS 
    29 April 2016

    Search Engine Poisoning (SEP)

    LINK

    DT 
    29 April 2016

    Spoofing Attack: IP, DNS & ARP

    LINK

    DT 
    29 April 2016

    Amplified DDoS Attacks: The current biggest threat against the Internet

    LINK

    DB 
    29 April 2016

    DNS Pharming: Someone’s poisoned the water hole!

    LINK

    DB 
    29 April 2016

    APWG News Center

    LINK

    GM 
    29 April 2016

    About the DNS Seal Project

    LINK

    CB 
    29 April 2016

    fTLD Enhanced Security

    LINK

    DT 
    29 April 2016

    ICANN 54 GAC Communiqué

    LINK

    LK 
    29 April 2016

    ICANN53 Buenos Aires GAC Communiqué

    LINK

    LK 
    17 May 2016ICANN GAC Safeguards advice from Beijing forward LK 
    29 April 2016

    Applicant Guidebook

    LINK

    ALL 
    29 April 2016

    CZDS-ZFA Passwords Reports

    LINK

    JH 
    29 April 2016

    WHOIS Accuracy Reporting System (ARS)

    LINK

    DB 
    29 April 2016

    WHOIS Primer

    LINK

    CB 
    29 April 2016

    Afilias Anti-Abuse Policy

    LINK

    CAS 
    29 April 2016

    .RICH Anti-Abuse Policy

    LINK

                       

    CAS 
    29 April 2016

    Contractual Compliance Dashboard for January 2016

    LINK

    LK 
    29 April 2016

    Frequently Asked Questions: Name Collision Occurrence Management Framework for Registries

    LINK

    DT 
    29 April 2016

    DNSSEC Deployment Report

    LINK

    JH 
    29 April 2016

    TLD DNSSEC Report

    LINK

    JH 
    29 April 2016

    Deployment Guide: DNSSEC for Internet Service Providers (ISPs)

    LINK

    JH 
    29 April 2016

    IETF- RFC List

    LINK

    DB 
    29 April 2016

    CloudFlare: How DNSSEC works

    LINK

    JH 
    29 April 2016DNSSEC- What it is and why is it important?

    LINK

    JH 

    29 April 2016

    A Profitless Endeavor- Phishing as a Tragedy of the Commons
    View file
    nameA Profitless Endeavor- Phishing as Tragedy of the Commons.pdf
    height250
    GM 
    29 April 2016Best Practices to Address Online and Mobile Threats
    View file
    nameBest Practices to Address Online and Mobile Threats.pdf
    height250
    FS 
    29 April 2016DNS Stability, Security, and Resiliency
    View file
    nameDNS STABILITY, SECURITY AND RESILIENCY.pdf
    height250
    DB 
    29 April 2016From .academy to .zone- An Analysis of the New gTLD Land Rush
    View file
    nameFrom .academy to .zone- An Analysis of the New TLD Land Rush.pdf
    height250
    FS 
    29 April 2016ICANN Global Consumer Research Report- April 2015
    View file
    nameGlobal Consumer Survey.pdf
    height250
    CAS 
    29 April 2016APWG- Global Phishing Survey: Trends and Domain Name Use in 1H2014
    View file
    nameGlobal Phishing Survey- Trends and Domain Name Use in 1H2014.pdf
    height250
    GM 
    29 April 2016High Security Zone Top-Level Domain Advocacy Group
    View file
    nameHigh Security Zone Top-Level Domain Advisory Group .pdf
    height250
    DT 
    29 April 2016ICANN Contractual Compliance Annual Report 2015
    View file
    nameInternet Corporation for Assigned Names & Numbers Contractual Compliance 2015 Annual Report.pdf
    height250
    LK 
    29 April 2016APWG- Making Waves in the Phisher's Harbor: Exposing the dark side of subdomain registries
    View file
    nameMaking Waves in the Phisher’s Safest Harbor- Exposing the Dark Side of Subdomain Registries .pdf
    height250
    GM 
    29 April 2016Measuring the Global Domain Name System
    View file
    nameMeasuring the Global Domain Name System.pdf
    height250
    JZ 
    29 April 2016Measuring Perpetrators and Funders of Typosquatting
    View file
    nameMeasuring the Perpetrators and Funders of Typosquatting.pdf
    height250
    DT 
    29 April 2016Potential for Phishing in Sensitive-String Top-Level Domains
    View file
    namePotential for Phishing in Sensitive-String Top-Level Domains.pdf
    height250
    LK 
    29 April 2016Program Implementation Review
    View file
    nameProgram Implementation Review.pdf
    height250
    ALL 
    29 April 2016Redirecting DNS for Ads and Profit
    View file
    nameRedirecting DNS for Ads and Profit.pdf
    height250
    FS 
    29 April 2016Mitigating the Risk of DNS Namespace Collisions
    View file
    nameMitigating the Risk of DNS Namespace Collisions .pdf
    height250
    DT 
    29 April 2016Registration Abuse Policies Working Group Final Report
    View file
    nameRegistration Abuse Policies Working Group Final Report.pdf
    height250
    DB 
    29 April 2016SAC 025: SSAC Advisory on Fast Flux Hosting and DNS
    View file
    nameSAC 025 SSAC Advisory on Fast Flux Hosting and DNS .pdf
    height250
    DB 
    29 April 2016SAC041- Recommendation to prohibit use of redirection and synthesized responses by new TLDs
    View file
    nameSAC041- Recommendation to prohibit use of redirection and synthesized responses by new TLDs .pdf
    height250
    CAS 
    29 April 2016SSAC Advisory on DDoS Attacks Leveraging DNS Infrastructure
    View file
    nameSSAC Advisory on DDoS Attacks Leveraging DNS Infrastructure.pdf
    height250
    CB 
    29 April 2016SSAC Advisory on Registrant Protection- Best Practices for Preserving Security and Stability in the Credential Management Lifecycle
    View file
    nameSSAC Advisory on Registrant Protection- Best Practices for Preserving Security and Stability in the Credential Management Lifecycle.pdf
    height250
    CG 
    29 April 2016SSAC Comment on Orphan Glue Records in the Draft Applicant Guidebook 
    View file
    nameSSAC Comment on Orphan Glue Records in the Draft Applicant Guidebook .pdf
    height250
    CB 
    6 June 2016SAC041: Recommendation to prohibit use of redirection and synthesized responses by new TLDs LINKCAS - CG 
    6 June 2016SAC 045 Invalid Top Level Domain Queries at the Root Level of the Domain Name SystemLINKCAS - CG 
    6 June 2016SAC062 SSAC Advisory Concerning the Mitigation of Name Collision RiskLINKCAS - CG 
    6 June 2016SAC066 SSAC Comment Concerning JAS Phase One Report on Mitigating the Risk of DNS Namespace CollisionsLINKCAS - CG 
    6 June 2016SAC074 SSAC Advisory on Registrant Protection: Best Practices for Preserving Security and Stability in the Credential Management LifecycleLINKCAS - CG 
    29 April 2016Symantec Intelligence Report- November 2015
    View file
    nameSymantec Intelligence Report.pdf
    height250
    FS 
    29 April 2016ISTR 20: Internet Security Threat Report
    PDF
    nameISTR 20.pdf
     
    CG 
    29 April 2016Techniques to Break the Botnet Attack
    View file
    nameTechniques to Break the Botnet Attack.pdf
    height250
    CG 
    29 April 2016The NameSENTRY Abuse Report
    View file
    nameThe NAMESENTRY℠ Abuse Report 2015.pdf
    height250
    CG 
    29 April 2016WHOIS Accuracy Reporting System (ARS)
    View file
    nameWHOIS Accuracy Reporting System (ARS) .pdf
    height250
    CB 
    9 May 2016Trust in the Internet Survey 2016, nccgroup and IDG Research ServicesPDFCG 
    19 May 2016

    Verizon 2016 Data Breach Investigations Report

    LINK

    LK 

     

     

    ...

    (warning)Documents are drafts and should not be considered consensus language.

    Assignments/Ownership Post Vienna Meeting

    TOPIC 1 -  Has New gTLD Program put mechanisms in place to improve trustworthiness in the DNS?

    Background of History of GAC Safeguards and new Registry Agreement (template 2)Laureen
    Description of Technical Safeguards and Implementation (template 2)Calvin

     

    Description of Safeguards Applicable to all gTLDs and Implementation (template 2)Laureen
    Description of Safeguards Applicable to sensitive/highly regulated gTLDs and Implementation (template 2)Laureen

     

    Description of Voluntary Public Interest Commitments (template 6, new paper)Laureen/Drew/Jamie
    Description of Rights Protection Mechanisms (templates 7, 8)David


    TOPIC 3 - Have these efforts had an impact on public perception of the DNS?

    What is the level of consumer awareness of the new gTLDs?
    For consumers (template 9)Carlton



    For registrants (template 9)Gao
    Have consumers expressed trust in the new gTLD program efforts?
    For consumers (template 10)Laureen
    For registrants (template 10)Laureen
    Has consumer trust in the DNS improved overall since the introduction of new gTLDs?
    (new template)

    Jamie

     

     


    High level findings
    v1


    TOPIC 2 - Has the New GTLD Program put sufficient mechanisms in place to mitigate risks to the trustworthiness of the DNS?

    Have the Safeguards been Implemented in a Manner that Promotes Effective Enforcement?
    Technical Safeguards (template 2)Calvin
    Implemented GAC Safeguards (templates 2,4,5,11)Laureen
    Voluntary PICs (template 6, new paper)Drew
    RPMsDavid
    Have the New gTLD Operators Complied with:
    Technical Safeguards (templates 4,7)Fabro 
    GAC Implemented Safeguards (templates 4, 7)Fabro 
    RPMs (templates 7, 8)David
    What was the Impact of the New Safeguards on DNS Abuse?
    (template 1, 3, 4, 5)Drew 
    Did the New Rights Protection Mechanisms Mitigate Certain Risks Involved with the Expansion of the gTLD program? (templates 7, 8)David


    Effectiveness of Procedures to Enforce Safeguards

    Are the new procedures effective in enforcing safeguards?

    Carlton

     

     


    Template #s - (Discussion papers FOR VIENNA MEETING)Google drive

    DNS Abuse

    1. Is there more or less DNS Abuse in the new gTLDs Drew (lead), Fabro, Calvin - (g-doc)

    Impact of Safeguards & PICs

    - Technical Category/DNS Abuse

    2. Have the safeguards been fully implemented?Laureen (lead), Carlos, Calvin (g-doc)

    3. What role did the new gTLD safeguards play in preventing DNS abuse? Drew (lead), Fabro, Calvin (g-doc)

    4. Have new gTLD registry operators complied with the safeguards? Fabro (lead), Carlton, David (g-doc)

    - Specification 11

    5.  How was Specification 11 implemented by new gTLD registry operators Paper? Laureen (lead), Carlos, Calvin (g-doc)

    6. Did the use of PICs help prevent DNS abuse? Drew (lead), Carlos, Gao, Fabro (g-doc)

    - Rights Protection Mechanisms

    7. Did the use of Rights Protection Mechanisms mitigate the risks involved with the expansion of the gTLD program? David (lead), Jamie, Fabro (g-doc)

    8. Have the new dispute resolution processes reduced trademark infringement? (TBD) David (lead), Jamie, Carlos (g-doc)

    Consumer End User Behavior

    9.  Are consumers in the global space aware of new gTLDs? Carlton (lead), Gao, Calvin (g-doc)

    10. Do consumers trust new gTLDs? Laureen (lead), Gao, Carlos (g-doc)

    Effectiveness of Procedures to Enforce Safeguards

    11.  Are the new procedures effective in enforcing safeguards? Carlton (lead), Jamie, Laureen (g-doc)


    Documents

    Document

    (Versions in red are latest) 
    File
    BRAINSTORMING DOCUMENT

    v1 (23 Feb)

    v2/3 (3 March)

    v4 (4 March)

    v5 (10 March)

    Priority list

    v6 (31 March)

    v7 (28 April)

    v8 (7 June)

    DOC - PDF

    DOC - PDF

    DOC - PDF - G-doc

    DOC- PDF - G-doc  

    DOC - PDF - Priority list G-doc

    DOC - PDF - G-doc 

    PDF

    DOC - PDF - G-doc

    SAFEGUARDS EFFECTIVENESS MANAGEMENT TABLE

    v1 (27 May)

    v2 (6 June)

    v3 (13 June)

    v5 (21 June)

    DOC - PDF

    DOC - PDF

    DOC - PDF

    DOC - PDF

    SAFEGUARDS ANALYSIS CHART
    v1 (1 August)G-doc
    DISCUSSION PAPERS - TOPIC LIST

    v1 (12 July)

    v2 (20 July)

    DOC - PDF

    DOC - PDF - gDOC 

    SCOPE & MANDATE WITH SUBQUESTIONS

    v1 (28 August)

    v2 (29 August)

    v3 (29 August)

    v4 (30 August)

    v5 (6 September)

    v6 (18 September)

    DOC - PDF

    DOC - PDF

    DOC - PDF

    DOC - PDF

    DOC - PDF

    DOC - PDF 

    VOLUNTARY PICS
    v1 (13 July)DOC - PDF
    OTHER
    Regulated and sensitive strings delegated (29 April 2016)XLS - PDF
     
    ARCHIVES - DOCUMENTS NO LONGER APPLICABLE (error)
    WORK PLAN

    v1 (3 May)

    v2 (2 June)

    v3 (23 June)

    DOC - PDF

    DOC

    DOC - PDF

    (error) No longer applicable