SlideShare a Scribd company logo
1 of 25
{
Strengthen DNS
Through
Infrastructure Design
Id-NS Project – The National Secure DNS Initiatives
Muhammad Salahuddien – Deputy of Operation and Network Security
 Growth, 90+ M users, 45+ M students, 200+ Gb/s
traffic (transit, IX, CDN), 200% rising local content
 Mobile: 155+ M data users, 30+ M internet banking,
99%+ district coverage, 60+ M gadget/year
 Price War, $5 unlimited/monthly, $200 smartphone
price, $300- tablet/netbook (bundled internet ready)
 Always On, 60+ M social media (4th largest), 15+ M
online media visitors daily, 10+ M online gamers,
500+ M e-commerce transaction yearly
 400% rising reported DNS related incident: malware
domain, phishing sites, SPAM host, DDOS
Recent Profiles
 More than 30+ Network Access Provider (NAP)
with multiple fiber optic links in conjunction to
VSAT and wireless terrestrial distribution
 More than 300+ nation wide licensed Internet
Service Provider (ISP) and 15 cellular operators
 5 major internet local exchange (IX) operate by
internet community and Internet Association
 33 Province IX operate by government agency
(not yet operation due to political reason)
Existing Providers
 Recent DNS exploitation attack are increasing
 Rare but the impact of actual event are serious
 i.e. DNS amplification and DDOS during the
national election last year, malware domains are also
increasing more than 400% last year
 DNS protection features is not a mandatory
standard, it is difficult to leverage security to
prevent common vulnerabilities
 This project will employ and to combine most
available security features and protection measures
and impose it as single robust infrastructure to
assure DNS security at every level
Background
 Provide secure managed DNS shared service
 To improve national DNS traffic efficiency
 To utilize and maximized existing DNS service
 To improve and leverage national internet core
infrastructure, security, robustness, availability
 Integration of all national DNS resources to
simplified management and maintenance
Project Objectives
 DNS Hijacking
 DNS Amplification
 DNS Cache Poisoning
 Man in The Middle Attack
 Distributed Denial of Services
 Malware domain, SPAM host, phishing sites
To Prevent Threat/Attack
 Distributed Secure DNS Peering
 DNS Security Extension service
 Secure DNS Cache Resolver service
 Secure DNS Secondary free service
 DNS Based Content Filtering service
 DNS Based Anti SPAM Filtering service
 DNS Based Anti Phishing Filtering service
 DNS BL malware/malicious/bot site detection
Managed Shared Services
DNSSEC
TSIG, HSM
Content Filter
DNS IP RBL
Dashboard
Interface
ROOT .id
F, I and L
.id Secondary
Authoritative
Cache
Resolver
Anti
SPAM
Anti
Phishing
National
Honey Net
Core System Component
 DNS content filtering, mirror from NAWALA
 DNS and Open Relay blacklist (updated)
 Exploits and Malware blacklist (updated)
 RBL, SBL, PBL, Phishing blacklist (updated)
 Malicious sites feed from National Honey Net
 IP’s/domains black list, feed from Id-SPAM
 Public’s reported suspected IP’s/domains
 Optional (upon request) DNS White List
 Optional (upon request) DNS Geo Location
Content/IP Filter
 Mandated by Law or Court Order i.e. any kind
of pornography, gambling, fraud, defamation,
threat/extortion, hatred, racism and bigotry
 Any others content violating Indonesian laws
and or forbidden by the authority i.e. illegal
foods and drugs product, investment scheme
 Any others harmful material causing system
and or data interference i.e. malware, SPAM
 Content are beyond Indonesia jurisdiction and
not negotiable to take down suspected host
Content Policy (Filtering)
 A leading content filtering initiatives since 2009
 DNS based filter, open to public and free to use
 ANYCAST IP 180.131.144.144 , 180.131.145.145
 Multi host: Singapore, Indonesia at 3 different
sites BATAM, JAKARTA, SURABAYA and co-
hosted by APJII and many others organization
 Widely used by 120+ countries, Asia, Africa and
middle east. More than 4 billion query per day
 NAWALA is an NGO, not for profit foundation
NAWALA in Brief
 Provide Transaction Signature (TSIG) service
 Provide Hardware Security Module (HSM) key
 Provide DNS Security (DNSSEC) Extension
 Provide (optional) DNS Curve tunnel service
 Provide secure client AAA and VPN access
 Only connected within pre registered IP’s
 Reference RFC 2845 (TSIG), RFC 3833 (threat)
Security Features
 Integrated logs analysis, SIEM’s and NMS
 Interface for DNS Statistics Analysis (web)
 Interface for DNS Managed Services (web)
 Interface for DNS Management System (web)
 Interface for Public Interaction (web portal)
 Others interfaces needed (SSH, console etc.)
Dashboard and NMS
 Normally, a DNS request resolved recursively
 Static content will utilize 1/10 DNS query traffic
 User generated, dynamic and rich content will
utilize more, 1/3 DNS query traffic – most of it,
request to the same domain address (recurrent)
 Cache resolver will reduce at least 30% of DNS
query, significantly improve traffic efficiency
 Localize root servers – including .id root and
by hosting all .id secondary NS (authoritative)
will also benefit in reducing international
access
Improve Traffic Efficiency
REQUEST
www.xyz.any
ISP DNS
Resolver
Id-NS
Resolver
ROOT .id
L-F-I-ROOT
AUTHORITATIVE
www.xyz.any
DNS Recursive Request
Localize
Localize
Secure
Request
VPN to Id-NS
ISP NS Resolver
IP authentication
and DNS Security
TSIG Secure Key
.id cache transfer
VPN to Id-NS
.id Root, Secondary
IP authentication
TSIG Secure Key
.id zone transfer
IP Geo Location
VPN to Id-NS
F and I (L) Root
*IP authentication
*TSIG Secure Key
*Retain Cache NS
*others requirement
NS Resolver Architecture
* by ISC, NETNOD, ICANN permission
 Retaining daily TOP 100 requested domain
 Retaining monthly TOP 1000 requested domain
 Retaining others static most requested domain
 All .id record transferred from ns1.id (PANDI)
 Free robust secondary DNS for all .id domains
 DNS White List feed from partners i.e. Trust +
 Others White List feed from others i.e. users
 Peering with others Id-NS members (locals)
NS Cache Peering
IIX/Core
Id-NS
NIX’s
Locals IX
Local
Id-NS
Local
Id-NS
ISP’s
Institution
Internal
DNS
Distributed Topology
 Provide free – not yet mandatory – fully .id
domains authoritative secondary NS service
 To protect primary NS service – staging design
 To improve .id domains query latency for local
(Indonesia) users and to leverage security
.id Secondary Services
NS1
•Authoritative
•Registered
•Published
NS2
•Authoritative
•Registered
•Published
NS3
•Authoritative
•Registered
•Published
NS Authoritative Staging
.any.id domain
NS0 Primary
Not Registered
(Hidden Host)
Id-
NS
Id-SIRTII
Core System
Coordination
PANDI
Root .id
L-root
APJII
IIX Peer
F and I root
BP3TI
National IX
Infrastructure
AIR PUTIH
Design and
Operation
NAWALA
Content
Filtering
Multi Stakeholder Project
 Stage 1 Q3 2014 – Proposal, Technical FGD and
limited prototyping as Proof of Concept
 Stage 2 Q1 2015 – Limited alpha test with ISP’s
and voluntary institution. Will be fully engaged
with .id-root F-root I-root and L-root. Employ
core features DNSSEC, TSIG, HSM, Content
Filter DNS IP RBL, Black/White Listing
 Stage 3 Q2 2015 – public beta test with ISP’s
and employ all features .id secondary service,
Anti SPAM, Anti Phishing, National Honey Net
 Stage 4 Q3 2015 – public release
Development Stages
 Core DNS System (resolver/cache) and Filtering
 Fine tuning core DNSSEC, TSIG, DNS IP RBL –
synchronized to stratum 1 ID-NTP services
 Engage to .id-root (complete), F-root I-root and
L-root (waiting for approval) .id-root secondary
 Developing web management, dashboard, VPN
and AAA services, NMS and user interface (UI)
 Performance test and security assessment with
participating ISP’s and voluntary institution
 Limited operation at IIX APJII data centers
Implementation Progress
 Roughly statistic as per end of December 2014
 Participated users experiencing better latency
for .id query and reducing 10% international
domains DNS traffic query – in average
 Common DNS Hijacking, Amplification, Cache
Poisoning attack tools did not succeed
 Problems with NS cache database indexing
and query expiration (flush) and renewing
process
Results and Findings
Id-SIRTII/CC
Ravindo Tower 17th Floor
KEBON SIRIH RAYA, KAV. 75
Central Jakarta, 10340
Phone +62 21 3192 5551
Fax +62 21 3193 5556
info@idsirtii.or.id ; www.idsirtii.or.id
Thank You

More Related Content

What's hot

IANA Transition Update, August 2016
IANA Transition Update, August 2016IANA Transition Update, August 2016
IANA Transition Update, August 2016APNIC
 
Measuring the end user
Measuring the end userMeasuring the end user
Measuring the end userAPNIC
 
CommuniCast 2014: APNIC Services Update
CommuniCast 2014: APNIC Services Update CommuniCast 2014: APNIC Services Update
CommuniCast 2014: APNIC Services Update APNIC
 
Introduction to RPKI - MyNOG
Introduction to RPKI - MyNOGIntroduction to RPKI - MyNOG
Introduction to RPKI - MyNOGSiena Perry
 
ITU-APNIC collaboration on the transition from IPv4 to IPv6
ITU-APNIC collaboration on the transition from IPv4 to IPv6ITU-APNIC collaboration on the transition from IPv4 to IPv6
ITU-APNIC collaboration on the transition from IPv4 to IPv6APNIC
 
Internet infrastructure in the South East Asia region
Internet infrastructure in the South East Asia regionInternet infrastructure in the South East Asia region
Internet infrastructure in the South East Asia regionAPNIC
 
IANA Transition: What does it all mean? @ SAMNOG 27
IANA Transition: What does it all mean? @ SAMNOG 27IANA Transition: What does it all mean? @ SAMNOG 27
IANA Transition: What does it all mean? @ SAMNOG 27APNIC
 
WHOIS Database for Incident Response & Handling
WHOIS Database for Incident Response & HandlingWHOIS Database for Incident Response & Handling
WHOIS Database for Incident Response & HandlingAPNIC
 
IANA: Who, What, Why?
IANA: Who, What, Why?IANA: Who, What, Why?
IANA: Who, What, Why?APNIC
 
Asia Pacific Internet Leadership Program
Asia Pacific Internet Leadership ProgramAsia Pacific Internet Leadership Program
Asia Pacific Internet Leadership ProgramAPNIC
 
IDNOG 2: AS interconnection in indonesia
IDNOG 2: AS interconnection in indonesiaIDNOG 2: AS interconnection in indonesia
IDNOG 2: AS interconnection in indonesiaAPNIC
 
APNIC Update, NPNOG 0.5
APNIC Update, NPNOG 0.5APNIC Update, NPNOG 0.5
APNIC Update, NPNOG 0.5APNIC
 
CNNIC Update, by Jessica Shen [APNIC 38 / NIR SIG]
CNNIC Update, by Jessica Shen [APNIC 38 / NIR SIG]CNNIC Update, by Jessica Shen [APNIC 38 / NIR SIG]
CNNIC Update, by Jessica Shen [APNIC 38 / NIR SIG]APNIC
 
npNOG 2: APNIC activity report
npNOG 2: APNIC activity reportnpNOG 2: APNIC activity report
npNOG 2: APNIC activity reportAPNIC
 
Universal Acceptance: APNIC system readiness
Universal Acceptance: APNIC system readinessUniversal Acceptance: APNIC system readiness
Universal Acceptance: APNIC system readinessAPNIC
 
APNIC Updates by Zen Chuan Ng
APNIC Updates by Zen Chuan NgAPNIC Updates by Zen Chuan Ng
APNIC Updates by Zen Chuan NgMyNOG
 
Universal Acceptance of Internationalized Domain Names (IDN), Email Addresses...
Universal Acceptance of Internationalized Domain Names (IDN), Email Addresses...Universal Acceptance of Internationalized Domain Names (IDN), Email Addresses...
Universal Acceptance of Internationalized Domain Names (IDN), Email Addresses...APNIC
 
Apnic Update - SANOG 30
Apnic Update - SANOG 30Apnic Update - SANOG 30
Apnic Update - SANOG 30APNIC
 
Identifier Systems Security, Stability and Resiliency by Champika Wijayatunga
Identifier Systems Security, Stability and Resiliency by Champika WijayatungaIdentifier Systems Security, Stability and Resiliency by Champika Wijayatunga
Identifier Systems Security, Stability and Resiliency by Champika WijayatungaMyNOG
 
APNIC Update for ARIN 35
APNIC Update for ARIN 35APNIC Update for ARIN 35
APNIC Update for ARIN 35APNIC
 

What's hot (20)

IANA Transition Update, August 2016
IANA Transition Update, August 2016IANA Transition Update, August 2016
IANA Transition Update, August 2016
 
Measuring the end user
Measuring the end userMeasuring the end user
Measuring the end user
 
CommuniCast 2014: APNIC Services Update
CommuniCast 2014: APNIC Services Update CommuniCast 2014: APNIC Services Update
CommuniCast 2014: APNIC Services Update
 
Introduction to RPKI - MyNOG
Introduction to RPKI - MyNOGIntroduction to RPKI - MyNOG
Introduction to RPKI - MyNOG
 
ITU-APNIC collaboration on the transition from IPv4 to IPv6
ITU-APNIC collaboration on the transition from IPv4 to IPv6ITU-APNIC collaboration on the transition from IPv4 to IPv6
ITU-APNIC collaboration on the transition from IPv4 to IPv6
 
Internet infrastructure in the South East Asia region
Internet infrastructure in the South East Asia regionInternet infrastructure in the South East Asia region
Internet infrastructure in the South East Asia region
 
IANA Transition: What does it all mean? @ SAMNOG 27
IANA Transition: What does it all mean? @ SAMNOG 27IANA Transition: What does it all mean? @ SAMNOG 27
IANA Transition: What does it all mean? @ SAMNOG 27
 
WHOIS Database for Incident Response & Handling
WHOIS Database for Incident Response & HandlingWHOIS Database for Incident Response & Handling
WHOIS Database for Incident Response & Handling
 
IANA: Who, What, Why?
IANA: Who, What, Why?IANA: Who, What, Why?
IANA: Who, What, Why?
 
Asia Pacific Internet Leadership Program
Asia Pacific Internet Leadership ProgramAsia Pacific Internet Leadership Program
Asia Pacific Internet Leadership Program
 
IDNOG 2: AS interconnection in indonesia
IDNOG 2: AS interconnection in indonesiaIDNOG 2: AS interconnection in indonesia
IDNOG 2: AS interconnection in indonesia
 
APNIC Update, NPNOG 0.5
APNIC Update, NPNOG 0.5APNIC Update, NPNOG 0.5
APNIC Update, NPNOG 0.5
 
CNNIC Update, by Jessica Shen [APNIC 38 / NIR SIG]
CNNIC Update, by Jessica Shen [APNIC 38 / NIR SIG]CNNIC Update, by Jessica Shen [APNIC 38 / NIR SIG]
CNNIC Update, by Jessica Shen [APNIC 38 / NIR SIG]
 
npNOG 2: APNIC activity report
npNOG 2: APNIC activity reportnpNOG 2: APNIC activity report
npNOG 2: APNIC activity report
 
Universal Acceptance: APNIC system readiness
Universal Acceptance: APNIC system readinessUniversal Acceptance: APNIC system readiness
Universal Acceptance: APNIC system readiness
 
APNIC Updates by Zen Chuan Ng
APNIC Updates by Zen Chuan NgAPNIC Updates by Zen Chuan Ng
APNIC Updates by Zen Chuan Ng
 
Universal Acceptance of Internationalized Domain Names (IDN), Email Addresses...
Universal Acceptance of Internationalized Domain Names (IDN), Email Addresses...Universal Acceptance of Internationalized Domain Names (IDN), Email Addresses...
Universal Acceptance of Internationalized Domain Names (IDN), Email Addresses...
 
Apnic Update - SANOG 30
Apnic Update - SANOG 30Apnic Update - SANOG 30
Apnic Update - SANOG 30
 
Identifier Systems Security, Stability and Resiliency by Champika Wijayatunga
Identifier Systems Security, Stability and Resiliency by Champika WijayatungaIdentifier Systems Security, Stability and Resiliency by Champika Wijayatunga
Identifier Systems Security, Stability and Resiliency by Champika Wijayatunga
 
APNIC Update for ARIN 35
APNIC Update for ARIN 35APNIC Update for ARIN 35
APNIC Update for ARIN 35
 

Viewers also liked

Best Practices for Monitoring DNS
Best Practices for Monitoring DNSBest Practices for Monitoring DNS
Best Practices for Monitoring DNSThousandEyes
 
Army Network Centric Operations
Army Network Centric OperationsArmy Network Centric Operations
Army Network Centric OperationsBonds Tim
 
glosario de terminos stefydaya
glosario de terminos stefydayaglosario de terminos stefydaya
glosario de terminos stefydayastefydaya
 
Socialnomics o Socialnomia
Socialnomics o SocialnomiaSocialnomics o Socialnomia
Socialnomics o SocialnomiaSilvia Sifuentes
 
Introduccción estudio business intelligence como aliado de la dirección comer...
Introduccción estudio business intelligence como aliado de la dirección comer...Introduccción estudio business intelligence como aliado de la dirección comer...
Introduccción estudio business intelligence como aliado de la dirección comer...Germán Piñeiro Vázquez
 
3.jornal seixal notícia
3.jornal seixal notícia3.jornal seixal notícia
3.jornal seixal notíciacomeniusebvm
 
Politische morde und faelle,bei denen ein politischer mord nicht auszuschlies...
Politische morde und faelle,bei denen ein politischer mord nicht auszuschlies...Politische morde und faelle,bei denen ein politischer mord nicht auszuschlies...
Politische morde und faelle,bei denen ein politischer mord nicht auszuschlies...Chemtrails Spoter
 
Hult MBA Brochure 2010
Hult MBA Brochure 2010Hult MBA Brochure 2010
Hult MBA Brochure 2010crogerson
 
Habbo[1][1]
Habbo[1][1]Habbo[1][1]
Habbo[1][1]evachip
 
Malla civil Mecánica UTFSM energía - producción.
Malla civil Mecánica UTFSM energía - producción.Malla civil Mecánica UTFSM energía - producción.
Malla civil Mecánica UTFSM energía - producción.caamec
 
EMC Testing brochure
EMC Testing brochureEMC Testing brochure
EMC Testing brochureIntertek CE
 
Seguridad en dispositivos móviles
Seguridad en dispositivos móvilesSeguridad en dispositivos móviles
Seguridad en dispositivos móvilespmendi
 
Pastoral social folleto 2 (1)
Pastoral social folleto 2 (1)Pastoral social folleto 2 (1)
Pastoral social folleto 2 (1)Enred Aprende
 
Día de la Paz 2015. Find a light. Encuentra la luz.
Día de la Paz 2015. Find a light. Encuentra la luz.Día de la Paz 2015. Find a light. Encuentra la luz.
Día de la Paz 2015. Find a light. Encuentra la luz.profesdelCarmen
 

Viewers also liked (20)

Best Practices for Monitoring DNS
Best Practices for Monitoring DNSBest Practices for Monitoring DNS
Best Practices for Monitoring DNS
 
Army Network Centric Operations
Army Network Centric OperationsArmy Network Centric Operations
Army Network Centric Operations
 
glosario de terminos stefydaya
glosario de terminos stefydayaglosario de terminos stefydaya
glosario de terminos stefydaya
 
ICE_Informe Marruecos Oscar Aguer 2010
ICE_Informe Marruecos Oscar Aguer 2010ICE_Informe Marruecos Oscar Aguer 2010
ICE_Informe Marruecos Oscar Aguer 2010
 
Socialnomics o Socialnomia
Socialnomics o SocialnomiaSocialnomics o Socialnomia
Socialnomics o Socialnomia
 
Introduccción estudio business intelligence como aliado de la dirección comer...
Introduccción estudio business intelligence como aliado de la dirección comer...Introduccción estudio business intelligence como aliado de la dirección comer...
Introduccción estudio business intelligence como aliado de la dirección comer...
 
3.jornal seixal notícia
3.jornal seixal notícia3.jornal seixal notícia
3.jornal seixal notícia
 
Politische morde und faelle,bei denen ein politischer mord nicht auszuschlies...
Politische morde und faelle,bei denen ein politischer mord nicht auszuschlies...Politische morde und faelle,bei denen ein politischer mord nicht auszuschlies...
Politische morde und faelle,bei denen ein politischer mord nicht auszuschlies...
 
Hult MBA Brochure 2010
Hult MBA Brochure 2010Hult MBA Brochure 2010
Hult MBA Brochure 2010
 
Das E-Commerce Menu
Das E-Commerce MenuDas E-Commerce Menu
Das E-Commerce Menu
 
Get started with angular js
Get started with angular jsGet started with angular js
Get started with angular js
 
Foda Inmobiliario 360
Foda Inmobiliario 360Foda Inmobiliario 360
Foda Inmobiliario 360
 
Habbo[1][1]
Habbo[1][1]Habbo[1][1]
Habbo[1][1]
 
Malla civil Mecánica UTFSM energía - producción.
Malla civil Mecánica UTFSM energía - producción.Malla civil Mecánica UTFSM energía - producción.
Malla civil Mecánica UTFSM energía - producción.
 
Unidad de oct y noviembre
Unidad de oct y noviembreUnidad de oct y noviembre
Unidad de oct y noviembre
 
Nidal suleiman pendulo simple
Nidal suleiman pendulo simpleNidal suleiman pendulo simple
Nidal suleiman pendulo simple
 
EMC Testing brochure
EMC Testing brochureEMC Testing brochure
EMC Testing brochure
 
Seguridad en dispositivos móviles
Seguridad en dispositivos móvilesSeguridad en dispositivos móviles
Seguridad en dispositivos móviles
 
Pastoral social folleto 2 (1)
Pastoral social folleto 2 (1)Pastoral social folleto 2 (1)
Pastoral social folleto 2 (1)
 
Día de la Paz 2015. Find a light. Encuentra la luz.
Día de la Paz 2015. Find a light. Encuentra la luz.Día de la Paz 2015. Find a light. Encuentra la luz.
Día de la Paz 2015. Find a light. Encuentra la luz.
 

Similar to Strengthen DNS Through Infrastructure Design

Denial of Service - Service Provider Overview
Denial of Service - Service Provider OverviewDenial of Service - Service Provider Overview
Denial of Service - Service Provider OverviewMarketingArrowECS_CZ
 
20070605 Radware
20070605 Radware20070605 Radware
20070605 RadwareINFOTIME
 
Ultra Dns Overview Presentation
Ultra Dns Overview PresentationUltra Dns Overview Presentation
Ultra Dns Overview Presentationgueste95639
 
DNS Made Easy Sales Brochure
DNS Made Easy Sales BrochureDNS Made Easy Sales Brochure
DNS Made Easy Sales BrochureDNS Made Easy
 
Indigo Product And Technology Overivew 2005
Indigo Product And Technology Overivew 2005 Indigo Product And Technology Overivew 2005
Indigo Product And Technology Overivew 2005 ir. Carmelo Zaccone
 
Detecting dns-tunneling-34152
Detecting dns-tunneling-34152Detecting dns-tunneling-34152
Detecting dns-tunneling-34152huynhvanphuc
 
F5 DNS Solution for CSPs
F5 DNS Solution for CSPsF5 DNS Solution for CSPs
F5 DNS Solution for CSPsF5 Networks
 
DNS and Infrastracture DDoS Protection
DNS and Infrastracture DDoS ProtectionDNS and Infrastracture DDoS Protection
DNS and Infrastracture DDoS ProtectionImperva Incapsula
 
Information Security
Information SecurityInformation Security
Information SecurityMohit8780
 
EfficientIP webinar mitigate dns zero day vulnerability
EfficientIP webinar mitigate dns zero day vulnerabilityEfficientIP webinar mitigate dns zero day vulnerability
EfficientIP webinar mitigate dns zero day vulnerabilityEfficientIP
 
EfficientIP presentation used during the SWITCHPOINT NV/SA Quarterly Experien...
EfficientIP presentation used during the SWITCHPOINT NV/SA Quarterly Experien...EfficientIP presentation used during the SWITCHPOINT NV/SA Quarterly Experien...
EfficientIP presentation used during the SWITCHPOINT NV/SA Quarterly Experien...SWITCHPOINT NV/SA
 
Cloudshield-DNS_Defender-Data-Sheet
Cloudshield-DNS_Defender-Data-SheetCloudshield-DNS_Defender-Data-Sheet
Cloudshield-DNS_Defender-Data-SheetChad Krantz
 
GateWall DNS Filter for ISP
GateWall DNS Filter for ISPGateWall DNS Filter for ISP
GateWall DNS Filter for ISPentensys
 
The DNS of Things
The DNS of ThingsThe DNS of Things
The DNS of ThingsPeter Silva
 
Infrastructure Tracking with Passive Monitoring and Active Probing: ShmooCon ...
Infrastructure Tracking with Passive Monitoring and Active Probing: ShmooCon ...Infrastructure Tracking with Passive Monitoring and Active Probing: ShmooCon ...
Infrastructure Tracking with Passive Monitoring and Active Probing: ShmooCon ...OpenDNS
 
Infoblox - turning DNS from security target to security tool
Infoblox - turning DNS from security target to security toolInfoblox - turning DNS from security target to security tool
Infoblox - turning DNS from security target to security toolJisc
 

Similar to Strengthen DNS Through Infrastructure Design (20)

Denial of Service - Service Provider Overview
Denial of Service - Service Provider OverviewDenial of Service - Service Provider Overview
Denial of Service - Service Provider Overview
 
20070605 Radware
20070605 Radware20070605 Radware
20070605 Radware
 
Ultra Dns Overview Presentation
Ultra Dns Overview PresentationUltra Dns Overview Presentation
Ultra Dns Overview Presentation
 
DNS Made Easy Sales Brochure
DNS Made Easy Sales BrochureDNS Made Easy Sales Brochure
DNS Made Easy Sales Brochure
 
Nuestar UltraDDI
Nuestar UltraDDINuestar UltraDDI
Nuestar UltraDDI
 
Indigo Product And Technology Overivew 2005
Indigo Product And Technology Overivew 2005 Indigo Product And Technology Overivew 2005
Indigo Product And Technology Overivew 2005
 
Detecting dns-tunneling-34152
Detecting dns-tunneling-34152Detecting dns-tunneling-34152
Detecting dns-tunneling-34152
 
F5 DNS Solution for CSPs
F5 DNS Solution for CSPsF5 DNS Solution for CSPs
F5 DNS Solution for CSPs
 
DNS and Infrastracture DDoS Protection
DNS and Infrastracture DDoS ProtectionDNS and Infrastracture DDoS Protection
DNS and Infrastracture DDoS Protection
 
Information Security
Information SecurityInformation Security
Information Security
 
EfficientIP webinar mitigate dns zero day vulnerability
EfficientIP webinar mitigate dns zero day vulnerabilityEfficientIP webinar mitigate dns zero day vulnerability
EfficientIP webinar mitigate dns zero day vulnerability
 
EfficientIP presentation used during the SWITCHPOINT NV/SA Quarterly Experien...
EfficientIP presentation used during the SWITCHPOINT NV/SA Quarterly Experien...EfficientIP presentation used during the SWITCHPOINT NV/SA Quarterly Experien...
EfficientIP presentation used during the SWITCHPOINT NV/SA Quarterly Experien...
 
Cloudshield-DNS_Defender-Data-Sheet
Cloudshield-DNS_Defender-Data-SheetCloudshield-DNS_Defender-Data-Sheet
Cloudshield-DNS_Defender-Data-Sheet
 
GateWall DNS Filter for ISP
GateWall DNS Filter for ISPGateWall DNS Filter for ISP
GateWall DNS Filter for ISP
 
The DNS of Things
The DNS of ThingsThe DNS of Things
The DNS of Things
 
ION Hangzhou - Why Deploy DNSSEC?
ION Hangzhou - Why Deploy DNSSEC?ION Hangzhou - Why Deploy DNSSEC?
ION Hangzhou - Why Deploy DNSSEC?
 
Infrastructure Tracking with Passive Monitoring and Active Probing: ShmooCon ...
Infrastructure Tracking with Passive Monitoring and Active Probing: ShmooCon ...Infrastructure Tracking with Passive Monitoring and Active Probing: ShmooCon ...
Infrastructure Tracking with Passive Monitoring and Active Probing: ShmooCon ...
 
Infoblox Secure DNS Solution
Infoblox Secure DNS SolutionInfoblox Secure DNS Solution
Infoblox Secure DNS Solution
 
Infoblox - turning DNS from security target to security tool
Infoblox - turning DNS from security target to security toolInfoblox - turning DNS from security target to security tool
Infoblox - turning DNS from security target to security tool
 
Is DNS a Part of Your Cyber Security Strategy?
Is DNS a Part of Your Cyber Security Strategy? Is DNS a Part of Your Cyber Security Strategy?
Is DNS a Part of Your Cyber Security Strategy?
 

More from APNIC

APNIC Updates presented by Paul Wilson at ARIN 53
APNIC Updates presented by Paul Wilson at ARIN 53APNIC Updates presented by Paul Wilson at ARIN 53
APNIC Updates presented by Paul Wilson at ARIN 53APNIC
 
DDoS In Oceania and the Pacific, presented by Dave Phelan at NZNOG 2024
DDoS In Oceania and the Pacific, presented by Dave Phelan at NZNOG 2024DDoS In Oceania and the Pacific, presented by Dave Phelan at NZNOG 2024
DDoS In Oceania and the Pacific, presented by Dave Phelan at NZNOG 2024APNIC
 
'Future Evolution of the Internet' delivered by Geoff Huston at Everything Op...
'Future Evolution of the Internet' delivered by Geoff Huston at Everything Op...'Future Evolution of the Internet' delivered by Geoff Huston at Everything Op...
'Future Evolution of the Internet' delivered by Geoff Huston at Everything Op...APNIC
 
On Starlink, presented by Geoff Huston at NZNOG 2024
On Starlink, presented by Geoff Huston at NZNOG 2024On Starlink, presented by Geoff Huston at NZNOG 2024
On Starlink, presented by Geoff Huston at NZNOG 2024APNIC
 
Networking in the Penumbra presented by Geoff Huston at NZNOG
Networking in the Penumbra presented by Geoff Huston at NZNOGNetworking in the Penumbra presented by Geoff Huston at NZNOG
Networking in the Penumbra presented by Geoff Huston at NZNOGAPNIC
 
IP addressing and IPv6, presented by Paul Wilson at IETF 119
IP addressing and IPv6, presented by Paul Wilson at IETF 119IP addressing and IPv6, presented by Paul Wilson at IETF 119
IP addressing and IPv6, presented by Paul Wilson at IETF 119APNIC
 
draft-harrison-sidrops-manifest-number-01, presented at IETF 119
draft-harrison-sidrops-manifest-number-01, presented at IETF 119draft-harrison-sidrops-manifest-number-01, presented at IETF 119
draft-harrison-sidrops-manifest-number-01, presented at IETF 119APNIC
 
Making an RFC in Today's IETF, presented by Geoff Huston at IETF 119
Making an RFC in Today's IETF, presented by Geoff Huston at IETF 119Making an RFC in Today's IETF, presented by Geoff Huston at IETF 119
Making an RFC in Today's IETF, presented by Geoff Huston at IETF 119APNIC
 
IPv6 Operational Issues (with DNS), presented by Geoff Huston at IETF 119
IPv6 Operational Issues (with DNS), presented by Geoff Huston at IETF 119IPv6 Operational Issues (with DNS), presented by Geoff Huston at IETF 119
IPv6 Operational Issues (with DNS), presented by Geoff Huston at IETF 119APNIC
 
Is DNS ready for IPv6, presented by Geoff Huston at IETF 119
Is DNS ready for IPv6, presented by Geoff Huston at IETF 119Is DNS ready for IPv6, presented by Geoff Huston at IETF 119
Is DNS ready for IPv6, presented by Geoff Huston at IETF 119APNIC
 
Benefits of doing Internet peering and running an Internet Exchange (IX) pres...
Benefits of doing Internet peering and running an Internet Exchange (IX) pres...Benefits of doing Internet peering and running an Internet Exchange (IX) pres...
Benefits of doing Internet peering and running an Internet Exchange (IX) pres...APNIC
 
APNIC Update and RIR Policies for ccTLDs, presented at APTLD 85
APNIC Update and RIR Policies for ccTLDs, presented at APTLD 85APNIC Update and RIR Policies for ccTLDs, presented at APTLD 85
APNIC Update and RIR Policies for ccTLDs, presented at APTLD 85APNIC
 
NANOG 90: 'BGP in 2023' presented by Geoff Huston
NANOG 90: 'BGP in 2023' presented by Geoff HustonNANOG 90: 'BGP in 2023' presented by Geoff Huston
NANOG 90: 'BGP in 2023' presented by Geoff HustonAPNIC
 
DNS-OARC 42: Is the DNS ready for IPv6? presentation by Geoff Huston
DNS-OARC 42: Is the DNS ready for IPv6? presentation by Geoff HustonDNS-OARC 42: Is the DNS ready for IPv6? presentation by Geoff Huston
DNS-OARC 42: Is the DNS ready for IPv6? presentation by Geoff HustonAPNIC
 
APAN 57: APNIC Report at APAN 57, Bangkok, Thailand
APAN 57: APNIC Report at APAN 57, Bangkok, ThailandAPAN 57: APNIC Report at APAN 57, Bangkok, Thailand
APAN 57: APNIC Report at APAN 57, Bangkok, ThailandAPNIC
 
Lao Digital Week 2024: It's time to deploy IPv6
Lao Digital Week 2024: It's time to deploy IPv6Lao Digital Week 2024: It's time to deploy IPv6
Lao Digital Week 2024: It's time to deploy IPv6APNIC
 
AINTEC 2023: Networking in the Penumbra!
AINTEC 2023: Networking in the Penumbra!AINTEC 2023: Networking in the Penumbra!
AINTEC 2023: Networking in the Penumbra!APNIC
 
CNIRC 2023: Global and Regional IPv6 Deployment 2023
CNIRC 2023: Global and Regional IPv6 Deployment 2023CNIRC 2023: Global and Regional IPv6 Deployment 2023
CNIRC 2023: Global and Regional IPv6 Deployment 2023APNIC
 
AFSIG 2023: APNIC Foundation and support for Internet development
AFSIG 2023: APNIC Foundation and support for Internet developmentAFSIG 2023: APNIC Foundation and support for Internet development
AFSIG 2023: APNIC Foundation and support for Internet developmentAPNIC
 
AFNOG 1: Afghanistan IP Deployment Status
AFNOG 1: Afghanistan IP Deployment StatusAFNOG 1: Afghanistan IP Deployment Status
AFNOG 1: Afghanistan IP Deployment StatusAPNIC
 

More from APNIC (20)

APNIC Updates presented by Paul Wilson at ARIN 53
APNIC Updates presented by Paul Wilson at ARIN 53APNIC Updates presented by Paul Wilson at ARIN 53
APNIC Updates presented by Paul Wilson at ARIN 53
 
DDoS In Oceania and the Pacific, presented by Dave Phelan at NZNOG 2024
DDoS In Oceania and the Pacific, presented by Dave Phelan at NZNOG 2024DDoS In Oceania and the Pacific, presented by Dave Phelan at NZNOG 2024
DDoS In Oceania and the Pacific, presented by Dave Phelan at NZNOG 2024
 
'Future Evolution of the Internet' delivered by Geoff Huston at Everything Op...
'Future Evolution of the Internet' delivered by Geoff Huston at Everything Op...'Future Evolution of the Internet' delivered by Geoff Huston at Everything Op...
'Future Evolution of the Internet' delivered by Geoff Huston at Everything Op...
 
On Starlink, presented by Geoff Huston at NZNOG 2024
On Starlink, presented by Geoff Huston at NZNOG 2024On Starlink, presented by Geoff Huston at NZNOG 2024
On Starlink, presented by Geoff Huston at NZNOG 2024
 
Networking in the Penumbra presented by Geoff Huston at NZNOG
Networking in the Penumbra presented by Geoff Huston at NZNOGNetworking in the Penumbra presented by Geoff Huston at NZNOG
Networking in the Penumbra presented by Geoff Huston at NZNOG
 
IP addressing and IPv6, presented by Paul Wilson at IETF 119
IP addressing and IPv6, presented by Paul Wilson at IETF 119IP addressing and IPv6, presented by Paul Wilson at IETF 119
IP addressing and IPv6, presented by Paul Wilson at IETF 119
 
draft-harrison-sidrops-manifest-number-01, presented at IETF 119
draft-harrison-sidrops-manifest-number-01, presented at IETF 119draft-harrison-sidrops-manifest-number-01, presented at IETF 119
draft-harrison-sidrops-manifest-number-01, presented at IETF 119
 
Making an RFC in Today's IETF, presented by Geoff Huston at IETF 119
Making an RFC in Today's IETF, presented by Geoff Huston at IETF 119Making an RFC in Today's IETF, presented by Geoff Huston at IETF 119
Making an RFC in Today's IETF, presented by Geoff Huston at IETF 119
 
IPv6 Operational Issues (with DNS), presented by Geoff Huston at IETF 119
IPv6 Operational Issues (with DNS), presented by Geoff Huston at IETF 119IPv6 Operational Issues (with DNS), presented by Geoff Huston at IETF 119
IPv6 Operational Issues (with DNS), presented by Geoff Huston at IETF 119
 
Is DNS ready for IPv6, presented by Geoff Huston at IETF 119
Is DNS ready for IPv6, presented by Geoff Huston at IETF 119Is DNS ready for IPv6, presented by Geoff Huston at IETF 119
Is DNS ready for IPv6, presented by Geoff Huston at IETF 119
 
Benefits of doing Internet peering and running an Internet Exchange (IX) pres...
Benefits of doing Internet peering and running an Internet Exchange (IX) pres...Benefits of doing Internet peering and running an Internet Exchange (IX) pres...
Benefits of doing Internet peering and running an Internet Exchange (IX) pres...
 
APNIC Update and RIR Policies for ccTLDs, presented at APTLD 85
APNIC Update and RIR Policies for ccTLDs, presented at APTLD 85APNIC Update and RIR Policies for ccTLDs, presented at APTLD 85
APNIC Update and RIR Policies for ccTLDs, presented at APTLD 85
 
NANOG 90: 'BGP in 2023' presented by Geoff Huston
NANOG 90: 'BGP in 2023' presented by Geoff HustonNANOG 90: 'BGP in 2023' presented by Geoff Huston
NANOG 90: 'BGP in 2023' presented by Geoff Huston
 
DNS-OARC 42: Is the DNS ready for IPv6? presentation by Geoff Huston
DNS-OARC 42: Is the DNS ready for IPv6? presentation by Geoff HustonDNS-OARC 42: Is the DNS ready for IPv6? presentation by Geoff Huston
DNS-OARC 42: Is the DNS ready for IPv6? presentation by Geoff Huston
 
APAN 57: APNIC Report at APAN 57, Bangkok, Thailand
APAN 57: APNIC Report at APAN 57, Bangkok, ThailandAPAN 57: APNIC Report at APAN 57, Bangkok, Thailand
APAN 57: APNIC Report at APAN 57, Bangkok, Thailand
 
Lao Digital Week 2024: It's time to deploy IPv6
Lao Digital Week 2024: It's time to deploy IPv6Lao Digital Week 2024: It's time to deploy IPv6
Lao Digital Week 2024: It's time to deploy IPv6
 
AINTEC 2023: Networking in the Penumbra!
AINTEC 2023: Networking in the Penumbra!AINTEC 2023: Networking in the Penumbra!
AINTEC 2023: Networking in the Penumbra!
 
CNIRC 2023: Global and Regional IPv6 Deployment 2023
CNIRC 2023: Global and Regional IPv6 Deployment 2023CNIRC 2023: Global and Regional IPv6 Deployment 2023
CNIRC 2023: Global and Regional IPv6 Deployment 2023
 
AFSIG 2023: APNIC Foundation and support for Internet development
AFSIG 2023: APNIC Foundation and support for Internet developmentAFSIG 2023: APNIC Foundation and support for Internet development
AFSIG 2023: APNIC Foundation and support for Internet development
 
AFNOG 1: Afghanistan IP Deployment Status
AFNOG 1: Afghanistan IP Deployment StatusAFNOG 1: Afghanistan IP Deployment Status
AFNOG 1: Afghanistan IP Deployment Status
 

Recently uploaded

Call Girls In Ashram Chowk Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Ashram Chowk Delhi 💯Call Us 🔝8264348440🔝Call Girls In Ashram Chowk Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Ashram Chowk Delhi 💯Call Us 🔝8264348440🔝soniya singh
 
Russian Call girl in Ajman +971563133746 Ajman Call girl Service
Russian Call girl in Ajman +971563133746 Ajman Call girl ServiceRussian Call girl in Ajman +971563133746 Ajman Call girl Service
Russian Call girl in Ajman +971563133746 Ajman Call girl Servicegwenoracqe6
 
Real Men Wear Diapers T Shirts sweatshirt
Real Men Wear Diapers T Shirts sweatshirtReal Men Wear Diapers T Shirts sweatshirt
Real Men Wear Diapers T Shirts sweatshirtrahman018755
 
(+971568250507 ))# Young Call Girls in Ajman By Pakistani Call Girls in ...
(+971568250507  ))#  Young Call Girls  in Ajman  By Pakistani Call Girls  in ...(+971568250507  ))#  Young Call Girls  in Ajman  By Pakistani Call Girls  in ...
(+971568250507 ))# Young Call Girls in Ajman By Pakistani Call Girls in ...Escorts Call Girls
 
AWS Community DAY Albertini-Ellan Cloud Security (1).pptx
AWS Community DAY Albertini-Ellan Cloud Security (1).pptxAWS Community DAY Albertini-Ellan Cloud Security (1).pptx
AWS Community DAY Albertini-Ellan Cloud Security (1).pptxellan12
 
Hot Service (+9316020077 ) Goa Call Girls Real Photos and Genuine Service
Hot Service (+9316020077 ) Goa  Call Girls Real Photos and Genuine ServiceHot Service (+9316020077 ) Goa  Call Girls Real Photos and Genuine Service
Hot Service (+9316020077 ) Goa Call Girls Real Photos and Genuine Servicesexy call girls service in goa
 
Dubai=Desi Dubai Call Girls O525547819 Outdoor Call Girls Dubai
Dubai=Desi Dubai Call Girls O525547819 Outdoor Call Girls DubaiDubai=Desi Dubai Call Girls O525547819 Outdoor Call Girls Dubai
Dubai=Desi Dubai Call Girls O525547819 Outdoor Call Girls Dubaikojalkojal131
 
Call Girls Service Chandigarh Lucky ❤️ 7710465962 Independent Call Girls In C...
Call Girls Service Chandigarh Lucky ❤️ 7710465962 Independent Call Girls In C...Call Girls Service Chandigarh Lucky ❤️ 7710465962 Independent Call Girls In C...
Call Girls Service Chandigarh Lucky ❤️ 7710465962 Independent Call Girls In C...Sheetaleventcompany
 
Russian Call Girls Pune (Adult Only) 8005736733 Escort Service 24x7 Cash Pay...
Russian Call Girls Pune  (Adult Only) 8005736733 Escort Service 24x7 Cash Pay...Russian Call Girls Pune  (Adult Only) 8005736733 Escort Service 24x7 Cash Pay...
Russian Call Girls Pune (Adult Only) 8005736733 Escort Service 24x7 Cash Pay...SUHANI PANDEY
 
Call Now ☎ 8264348440 !! Call Girls in Rani Bagh Escort Service Delhi N.C.R.
Call Now ☎ 8264348440 !! Call Girls in Rani Bagh Escort Service Delhi N.C.R.Call Now ☎ 8264348440 !! Call Girls in Rani Bagh Escort Service Delhi N.C.R.
Call Now ☎ 8264348440 !! Call Girls in Rani Bagh Escort Service Delhi N.C.R.soniya singh
 
Busty Desi⚡Call Girls in Vasundhara Ghaziabad >༒8448380779 Escort Service
Busty Desi⚡Call Girls in Vasundhara Ghaziabad >༒8448380779 Escort ServiceBusty Desi⚡Call Girls in Vasundhara Ghaziabad >༒8448380779 Escort Service
Busty Desi⚡Call Girls in Vasundhara Ghaziabad >༒8448380779 Escort ServiceDelhi Call girls
 
Call Now ☎ 8264348440 !! Call Girls in Shahpur Jat Escort Service Delhi N.C.R.
Call Now ☎ 8264348440 !! Call Girls in Shahpur Jat Escort Service Delhi N.C.R.Call Now ☎ 8264348440 !! Call Girls in Shahpur Jat Escort Service Delhi N.C.R.
Call Now ☎ 8264348440 !! Call Girls in Shahpur Jat Escort Service Delhi N.C.R.soniya singh
 
Call Now ☎ 8264348440 !! Call Girls in Green Park Escort Service Delhi N.C.R.
Call Now ☎ 8264348440 !! Call Girls in Green Park Escort Service Delhi N.C.R.Call Now ☎ 8264348440 !! Call Girls in Green Park Escort Service Delhi N.C.R.
Call Now ☎ 8264348440 !! Call Girls in Green Park Escort Service Delhi N.C.R.soniya singh
 
Hot Call Girls |Delhi |Hauz Khas ☎ 9711199171 Book Your One night Stand
Hot Call Girls |Delhi |Hauz Khas ☎ 9711199171 Book Your One night StandHot Call Girls |Delhi |Hauz Khas ☎ 9711199171 Book Your One night Stand
Hot Call Girls |Delhi |Hauz Khas ☎ 9711199171 Book Your One night Standkumarajju5765
 
VIP Model Call Girls Hadapsar ( Pune ) Call ON 9905417584 Starting High Prof...
VIP Model Call Girls Hadapsar ( Pune ) Call ON 9905417584 Starting  High Prof...VIP Model Call Girls Hadapsar ( Pune ) Call ON 9905417584 Starting  High Prof...
VIP Model Call Girls Hadapsar ( Pune ) Call ON 9905417584 Starting High Prof...singhpriety023
 

Recently uploaded (20)

Call Girls In Ashram Chowk Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Ashram Chowk Delhi 💯Call Us 🔝8264348440🔝Call Girls In Ashram Chowk Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Ashram Chowk Delhi 💯Call Us 🔝8264348440🔝
 
6.High Profile Call Girls In Punjab +919053900678 Punjab Call GirlHigh Profil...
6.High Profile Call Girls In Punjab +919053900678 Punjab Call GirlHigh Profil...6.High Profile Call Girls In Punjab +919053900678 Punjab Call GirlHigh Profil...
6.High Profile Call Girls In Punjab +919053900678 Punjab Call GirlHigh Profil...
 
Russian Call girl in Ajman +971563133746 Ajman Call girl Service
Russian Call girl in Ajman +971563133746 Ajman Call girl ServiceRussian Call girl in Ajman +971563133746 Ajman Call girl Service
Russian Call girl in Ajman +971563133746 Ajman Call girl Service
 
Real Men Wear Diapers T Shirts sweatshirt
Real Men Wear Diapers T Shirts sweatshirtReal Men Wear Diapers T Shirts sweatshirt
Real Men Wear Diapers T Shirts sweatshirt
 
(+971568250507 ))# Young Call Girls in Ajman By Pakistani Call Girls in ...
(+971568250507  ))#  Young Call Girls  in Ajman  By Pakistani Call Girls  in ...(+971568250507  ))#  Young Call Girls  in Ajman  By Pakistani Call Girls  in ...
(+971568250507 ))# Young Call Girls in Ajman By Pakistani Call Girls in ...
 
Call Girls in Prashant Vihar, Delhi 💯 Call Us 🔝9953056974 🔝 Escort Service
Call Girls in Prashant Vihar, Delhi 💯 Call Us 🔝9953056974 🔝 Escort ServiceCall Girls in Prashant Vihar, Delhi 💯 Call Us 🔝9953056974 🔝 Escort Service
Call Girls in Prashant Vihar, Delhi 💯 Call Us 🔝9953056974 🔝 Escort Service
 
AWS Community DAY Albertini-Ellan Cloud Security (1).pptx
AWS Community DAY Albertini-Ellan Cloud Security (1).pptxAWS Community DAY Albertini-Ellan Cloud Security (1).pptx
AWS Community DAY Albertini-Ellan Cloud Security (1).pptx
 
Hot Service (+9316020077 ) Goa Call Girls Real Photos and Genuine Service
Hot Service (+9316020077 ) Goa  Call Girls Real Photos and Genuine ServiceHot Service (+9316020077 ) Goa  Call Girls Real Photos and Genuine Service
Hot Service (+9316020077 ) Goa Call Girls Real Photos and Genuine Service
 
valsad Escorts Service ☎️ 6378878445 ( Sakshi Sinha ) High Profile Call Girls...
valsad Escorts Service ☎️ 6378878445 ( Sakshi Sinha ) High Profile Call Girls...valsad Escorts Service ☎️ 6378878445 ( Sakshi Sinha ) High Profile Call Girls...
valsad Escorts Service ☎️ 6378878445 ( Sakshi Sinha ) High Profile Call Girls...
 
Dubai=Desi Dubai Call Girls O525547819 Outdoor Call Girls Dubai
Dubai=Desi Dubai Call Girls O525547819 Outdoor Call Girls DubaiDubai=Desi Dubai Call Girls O525547819 Outdoor Call Girls Dubai
Dubai=Desi Dubai Call Girls O525547819 Outdoor Call Girls Dubai
 
Call Girls Service Chandigarh Lucky ❤️ 7710465962 Independent Call Girls In C...
Call Girls Service Chandigarh Lucky ❤️ 7710465962 Independent Call Girls In C...Call Girls Service Chandigarh Lucky ❤️ 7710465962 Independent Call Girls In C...
Call Girls Service Chandigarh Lucky ❤️ 7710465962 Independent Call Girls In C...
 
Russian Call Girls Pune (Adult Only) 8005736733 Escort Service 24x7 Cash Pay...
Russian Call Girls Pune  (Adult Only) 8005736733 Escort Service 24x7 Cash Pay...Russian Call Girls Pune  (Adult Only) 8005736733 Escort Service 24x7 Cash Pay...
Russian Call Girls Pune (Adult Only) 8005736733 Escort Service 24x7 Cash Pay...
 
Call Now ☎ 8264348440 !! Call Girls in Rani Bagh Escort Service Delhi N.C.R.
Call Now ☎ 8264348440 !! Call Girls in Rani Bagh Escort Service Delhi N.C.R.Call Now ☎ 8264348440 !! Call Girls in Rani Bagh Escort Service Delhi N.C.R.
Call Now ☎ 8264348440 !! Call Girls in Rani Bagh Escort Service Delhi N.C.R.
 
Busty Desi⚡Call Girls in Vasundhara Ghaziabad >༒8448380779 Escort Service
Busty Desi⚡Call Girls in Vasundhara Ghaziabad >༒8448380779 Escort ServiceBusty Desi⚡Call Girls in Vasundhara Ghaziabad >༒8448380779 Escort Service
Busty Desi⚡Call Girls in Vasundhara Ghaziabad >༒8448380779 Escort Service
 
(INDIRA) Call Girl Pune Call Now 8250077686 Pune Escorts 24x7
(INDIRA) Call Girl Pune Call Now 8250077686 Pune Escorts 24x7(INDIRA) Call Girl Pune Call Now 8250077686 Pune Escorts 24x7
(INDIRA) Call Girl Pune Call Now 8250077686 Pune Escorts 24x7
 
Low Sexy Call Girls In Mohali 9053900678 🥵Have Save And Good Place 🥵
Low Sexy Call Girls In Mohali 9053900678 🥵Have Save And Good Place 🥵Low Sexy Call Girls In Mohali 9053900678 🥵Have Save And Good Place 🥵
Low Sexy Call Girls In Mohali 9053900678 🥵Have Save And Good Place 🥵
 
Call Now ☎ 8264348440 !! Call Girls in Shahpur Jat Escort Service Delhi N.C.R.
Call Now ☎ 8264348440 !! Call Girls in Shahpur Jat Escort Service Delhi N.C.R.Call Now ☎ 8264348440 !! Call Girls in Shahpur Jat Escort Service Delhi N.C.R.
Call Now ☎ 8264348440 !! Call Girls in Shahpur Jat Escort Service Delhi N.C.R.
 
Call Now ☎ 8264348440 !! Call Girls in Green Park Escort Service Delhi N.C.R.
Call Now ☎ 8264348440 !! Call Girls in Green Park Escort Service Delhi N.C.R.Call Now ☎ 8264348440 !! Call Girls in Green Park Escort Service Delhi N.C.R.
Call Now ☎ 8264348440 !! Call Girls in Green Park Escort Service Delhi N.C.R.
 
Hot Call Girls |Delhi |Hauz Khas ☎ 9711199171 Book Your One night Stand
Hot Call Girls |Delhi |Hauz Khas ☎ 9711199171 Book Your One night StandHot Call Girls |Delhi |Hauz Khas ☎ 9711199171 Book Your One night Stand
Hot Call Girls |Delhi |Hauz Khas ☎ 9711199171 Book Your One night Stand
 
VIP Model Call Girls Hadapsar ( Pune ) Call ON 9905417584 Starting High Prof...
VIP Model Call Girls Hadapsar ( Pune ) Call ON 9905417584 Starting  High Prof...VIP Model Call Girls Hadapsar ( Pune ) Call ON 9905417584 Starting  High Prof...
VIP Model Call Girls Hadapsar ( Pune ) Call ON 9905417584 Starting High Prof...
 

Strengthen DNS Through Infrastructure Design

  • 1. { Strengthen DNS Through Infrastructure Design Id-NS Project – The National Secure DNS Initiatives Muhammad Salahuddien – Deputy of Operation and Network Security
  • 2.  Growth, 90+ M users, 45+ M students, 200+ Gb/s traffic (transit, IX, CDN), 200% rising local content  Mobile: 155+ M data users, 30+ M internet banking, 99%+ district coverage, 60+ M gadget/year  Price War, $5 unlimited/monthly, $200 smartphone price, $300- tablet/netbook (bundled internet ready)  Always On, 60+ M social media (4th largest), 15+ M online media visitors daily, 10+ M online gamers, 500+ M e-commerce transaction yearly  400% rising reported DNS related incident: malware domain, phishing sites, SPAM host, DDOS Recent Profiles
  • 3.  More than 30+ Network Access Provider (NAP) with multiple fiber optic links in conjunction to VSAT and wireless terrestrial distribution  More than 300+ nation wide licensed Internet Service Provider (ISP) and 15 cellular operators  5 major internet local exchange (IX) operate by internet community and Internet Association  33 Province IX operate by government agency (not yet operation due to political reason) Existing Providers
  • 4.  Recent DNS exploitation attack are increasing  Rare but the impact of actual event are serious  i.e. DNS amplification and DDOS during the national election last year, malware domains are also increasing more than 400% last year  DNS protection features is not a mandatory standard, it is difficult to leverage security to prevent common vulnerabilities  This project will employ and to combine most available security features and protection measures and impose it as single robust infrastructure to assure DNS security at every level Background
  • 5.  Provide secure managed DNS shared service  To improve national DNS traffic efficiency  To utilize and maximized existing DNS service  To improve and leverage national internet core infrastructure, security, robustness, availability  Integration of all national DNS resources to simplified management and maintenance Project Objectives
  • 6.  DNS Hijacking  DNS Amplification  DNS Cache Poisoning  Man in The Middle Attack  Distributed Denial of Services  Malware domain, SPAM host, phishing sites To Prevent Threat/Attack
  • 7.  Distributed Secure DNS Peering  DNS Security Extension service  Secure DNS Cache Resolver service  Secure DNS Secondary free service  DNS Based Content Filtering service  DNS Based Anti SPAM Filtering service  DNS Based Anti Phishing Filtering service  DNS BL malware/malicious/bot site detection Managed Shared Services
  • 8. DNSSEC TSIG, HSM Content Filter DNS IP RBL Dashboard Interface ROOT .id F, I and L .id Secondary Authoritative Cache Resolver Anti SPAM Anti Phishing National Honey Net Core System Component
  • 9.  DNS content filtering, mirror from NAWALA  DNS and Open Relay blacklist (updated)  Exploits and Malware blacklist (updated)  RBL, SBL, PBL, Phishing blacklist (updated)  Malicious sites feed from National Honey Net  IP’s/domains black list, feed from Id-SPAM  Public’s reported suspected IP’s/domains  Optional (upon request) DNS White List  Optional (upon request) DNS Geo Location Content/IP Filter
  • 10.  Mandated by Law or Court Order i.e. any kind of pornography, gambling, fraud, defamation, threat/extortion, hatred, racism and bigotry  Any others content violating Indonesian laws and or forbidden by the authority i.e. illegal foods and drugs product, investment scheme  Any others harmful material causing system and or data interference i.e. malware, SPAM  Content are beyond Indonesia jurisdiction and not negotiable to take down suspected host Content Policy (Filtering)
  • 11.  A leading content filtering initiatives since 2009  DNS based filter, open to public and free to use  ANYCAST IP 180.131.144.144 , 180.131.145.145  Multi host: Singapore, Indonesia at 3 different sites BATAM, JAKARTA, SURABAYA and co- hosted by APJII and many others organization  Widely used by 120+ countries, Asia, Africa and middle east. More than 4 billion query per day  NAWALA is an NGO, not for profit foundation NAWALA in Brief
  • 12.  Provide Transaction Signature (TSIG) service  Provide Hardware Security Module (HSM) key  Provide DNS Security (DNSSEC) Extension  Provide (optional) DNS Curve tunnel service  Provide secure client AAA and VPN access  Only connected within pre registered IP’s  Reference RFC 2845 (TSIG), RFC 3833 (threat) Security Features
  • 13.  Integrated logs analysis, SIEM’s and NMS  Interface for DNS Statistics Analysis (web)  Interface for DNS Managed Services (web)  Interface for DNS Management System (web)  Interface for Public Interaction (web portal)  Others interfaces needed (SSH, console etc.) Dashboard and NMS
  • 14.  Normally, a DNS request resolved recursively  Static content will utilize 1/10 DNS query traffic  User generated, dynamic and rich content will utilize more, 1/3 DNS query traffic – most of it, request to the same domain address (recurrent)  Cache resolver will reduce at least 30% of DNS query, significantly improve traffic efficiency  Localize root servers – including .id root and by hosting all .id secondary NS (authoritative) will also benefit in reducing international access Improve Traffic Efficiency
  • 16. VPN to Id-NS ISP NS Resolver IP authentication and DNS Security TSIG Secure Key .id cache transfer VPN to Id-NS .id Root, Secondary IP authentication TSIG Secure Key .id zone transfer IP Geo Location VPN to Id-NS F and I (L) Root *IP authentication *TSIG Secure Key *Retain Cache NS *others requirement NS Resolver Architecture * by ISC, NETNOD, ICANN permission
  • 17.  Retaining daily TOP 100 requested domain  Retaining monthly TOP 1000 requested domain  Retaining others static most requested domain  All .id record transferred from ns1.id (PANDI)  Free robust secondary DNS for all .id domains  DNS White List feed from partners i.e. Trust +  Others White List feed from others i.e. users  Peering with others Id-NS members (locals) NS Cache Peering
  • 19.  Provide free – not yet mandatory – fully .id domains authoritative secondary NS service  To protect primary NS service – staging design  To improve .id domains query latency for local (Indonesia) users and to leverage security .id Secondary Services
  • 21. Id- NS Id-SIRTII Core System Coordination PANDI Root .id L-root APJII IIX Peer F and I root BP3TI National IX Infrastructure AIR PUTIH Design and Operation NAWALA Content Filtering Multi Stakeholder Project
  • 22.  Stage 1 Q3 2014 – Proposal, Technical FGD and limited prototyping as Proof of Concept  Stage 2 Q1 2015 – Limited alpha test with ISP’s and voluntary institution. Will be fully engaged with .id-root F-root I-root and L-root. Employ core features DNSSEC, TSIG, HSM, Content Filter DNS IP RBL, Black/White Listing  Stage 3 Q2 2015 – public beta test with ISP’s and employ all features .id secondary service, Anti SPAM, Anti Phishing, National Honey Net  Stage 4 Q3 2015 – public release Development Stages
  • 23.  Core DNS System (resolver/cache) and Filtering  Fine tuning core DNSSEC, TSIG, DNS IP RBL – synchronized to stratum 1 ID-NTP services  Engage to .id-root (complete), F-root I-root and L-root (waiting for approval) .id-root secondary  Developing web management, dashboard, VPN and AAA services, NMS and user interface (UI)  Performance test and security assessment with participating ISP’s and voluntary institution  Limited operation at IIX APJII data centers Implementation Progress
  • 24.  Roughly statistic as per end of December 2014  Participated users experiencing better latency for .id query and reducing 10% international domains DNS traffic query – in average  Common DNS Hijacking, Amplification, Cache Poisoning attack tools did not succeed  Problems with NS cache database indexing and query expiration (flush) and renewing process Results and Findings
  • 25. Id-SIRTII/CC Ravindo Tower 17th Floor KEBON SIRIH RAYA, KAV. 75 Central Jakarta, 10340 Phone +62 21 3192 5551 Fax +62 21 3193 5556 info@idsirtii.or.id ; www.idsirtii.or.id Thank You