DNS - Dooot .com Domain News
Domain Name Registration and Web Hosting

Sec Dom



RSS
:: Domain Industry - News Archive

A Noteworthy Report on Fast Flux Hosting

DNS News - >>

Source: www.circleid.com

This very interesting document was released by ICANN\'s Generic Names Supporting Organization (GNSO) for public comment yesterday. And it asks some fundamental questions while at the same time pointing to sources such as the Honeynet Alliance\'s reports on fast flux.

It also points out the benefits of \"legitimate\" fast flux—such as its use by content distribution networks, or by DDoS protection systems. An additional use is of course a simple attempt at using multiple A records with short (< 1 minute) TTL in a basic attempt to load balance.

It would be interesting to see what registries and registrars can do to suppress malicious fast flux—such as due diligence to prevent fraudulent registration of domains (most if not all malicious fast flux domains are registered using stolen cards, and chargebacks of course hurt registrars far more than the revenue from these, or at least I hope so), and proactive action by registries to block registration of fastflux domains.

A lot of the fast flux domains also—it must be noted—use Whois privacy as a default where it is available (and some registrars have a very bad habit of inserting absolutely fake addresses into the Whois records, for Whois privacy—where others list their own business address and a clear note on the nature of this Whois privacy). Some of that ugly mess of a discussion is quite likely to be relevant here as well.

Questions that get asked in the report—some are quite probably rhetorical, and most of these do have suggested answers in the report—are below:

  • Who benefits from fast flux, and who is harmed?
  • Who would benefit from cessation of the practice and who would be harmed?
  • Are registry operators involved, or could they be, in fast flux hosting activities? If so, how?
  • Are registrars involved in fast flux hosting activities? If so, how?
  • How are registrants affected by fast flux hosting?
  • How are Internet users affected by fast flux hosting?
  • What technical (e.g. changes to the way in which DNS updates operate) and policy (e.g. changes to registry/registrar agreements or rules governing permissible registrant behavior) measures could be implemented by registries and registrars to mitigate the negative effects of fast flux?
  • What would be the impact (positive or negative) of establishing limitations, guidelines, or restrictions on registrants, registrars and/or registries with respect to practices that enable or facilitate fast flux hosting?
  • What would be the impact of these limitations, guidelines, or restrictions to product and service innovation?
  • What are some of the best practices available with regard to protection from fast flux?

Written by Suresh Ramasubramanian, Head, Antispam Operations. Visit the blog maintained by Suresh Ramasubramanian here.



Last changed: Jan 27 2009 at 6:20 AM
.. Back

Exclusive Domain News |

last updated: Jul 29 2010 6:06 PM

www.dooot.com (c) Copyright 2000 - 2010 Irist IST Member of the IST Group. All rights reserved. , RS Domain Names