SlideShare a Scribd company logo
Submit Search
Upload
TLD Anycast DNS servers to ISPs
Report
Share
APNIC
APNIC
Follow
•
1 like
•
1,510 views
1
of
38
TLD Anycast DNS servers to ISPs
•
1 like
•
1,510 views
Report
Share
Internet
Presentation by Shoji Noguchi at APRICOT 2017 on Tuesday, 28 February 2017.
Read more
APNIC
APNIC
Follow
Recommended
Running a Local Copy of the DNS Root Zone by
Running a Local Copy of the DNS Root Zone
APNIC
522 views
•
19 slides
Minimum Viable FIB by
Minimum Viable FIB
APNIC
502 views
•
19 slides
LF_OVS_17_OVS-DPDK Installation and Gotchas by
LF_OVS_17_OVS-DPDK Installation and Gotchas
LF_OpenvSwitch
703 views
•
11 slides
LISP + GETVPN as alternative to DMVPN+OSPF+GETVPN by
LISP + GETVPN as alternative to DMVPN+OSPF+GETVPN
JobSnijders
6.6K views
•
32 slides
LF_OVS_17_Red Hat's perspective on OVS HW Offload Status by
LF_OVS_17_Red Hat's perspective on OVS HW Offload Status
LF_OpenvSwitch
1.7K views
•
19 slides
redGuardian DP100 large scale DDoS mitigation solution by
redGuardian DP100 large scale DDoS mitigation solution
Redge Technologies
1.6K views
•
19 slides
More Related Content
What's hot
DPDK in Containers Hands-on Lab by
DPDK in Containers Hands-on Lab
Michelle Holley
10.3K views
•
35 slides
Make Internet Safer with DNS Firewall - Implementation Case Study at a Major ISP by
Make Internet Safer with DNS Firewall - Implementation Case Study at a Major ISP
APNIC
1.8K views
•
48 slides
BPF & Cilium - Turning Linux into a Microservices-aware Operating System by
BPF & Cilium - Turning Linux into a Microservices-aware Operating System
Thomas Graf
2.9K views
•
27 slides
Implementing BGP Flowspec at IP transit network by
Implementing BGP Flowspec at IP transit network
Pavel Odintsov
2K views
•
24 slides
OVS Hardware Offload with TC Flower by
OVS Hardware Offload with TC Flower
Netronome
3.6K views
•
28 slides
Spy hard, challenges of 100G deep packet inspection on x86 platform by
Spy hard, challenges of 100G deep packet inspection on x86 platform
Redge Technologies
4.3K views
•
35 slides
What's hot
(20)
DPDK in Containers Hands-on Lab by Michelle Holley
DPDK in Containers Hands-on Lab
Michelle Holley
•
10.3K views
Make Internet Safer with DNS Firewall - Implementation Case Study at a Major ISP by APNIC
Make Internet Safer with DNS Firewall - Implementation Case Study at a Major ISP
APNIC
•
1.8K views
BPF & Cilium - Turning Linux into a Microservices-aware Operating System by Thomas Graf
BPF & Cilium - Turning Linux into a Microservices-aware Operating System
Thomas Graf
•
2.9K views
Implementing BGP Flowspec at IP transit network by Pavel Odintsov
Implementing BGP Flowspec at IP transit network
Pavel Odintsov
•
2K views
OVS Hardware Offload with TC Flower by Netronome
OVS Hardware Offload with TC Flower
Netronome
•
3.6K views
Spy hard, challenges of 100G deep packet inspection on x86 platform by Redge Technologies
Spy hard, challenges of 100G deep packet inspection on x86 platform
Redge Technologies
•
4.3K views
Ipv6 by Yan Drugalya
Ipv6
Yan Drugalya
•
553 views
Neutron qos overview by Sławomir Kapłoński
Neutron qos overview
Sławomir Kapłoński
•
214 views
DNS-SD by netvis
DNS-SD
netvis
•
3.4K views
Future services on Janet by Jisc
Future services on Janet
Jisc
•
542 views
BIND’s New Security Feature: DNSRPZ - the "DNS Firewall" by Barry Greene
BIND’s New Security Feature: DNSRPZ - the "DNS Firewall"
Barry Greene
•
12K views
Make the internet safe with DNS Firewall by Bangladesh Network Operators Group
Make the internet safe with DNS Firewall
Bangladesh Network Operators Group
•
484 views
Building and operating a global DNS content delivery anycast network by APNIC
Building and operating a global DNS content delivery anycast network
APNIC
•
315 views
An Introduction to BGP Flow Spec by ShortestPathFirst
An Introduction to BGP Flow Spec
ShortestPathFirst
•
57K views
The new Janet access infrastructure by Jisc
The new Janet access infrastructure
Jisc
•
557 views
NFD9 - Dinesh Dutt, Data Center Architectures by Cumulus Networks
NFD9 - Dinesh Dutt, Data Center Architectures
Cumulus Networks
•
1.3K views
Puppet Camp Boston 2014: Network Automation with Puppet and Arista (Beginner) by Puppet
Puppet Camp Boston 2014: Network Automation with Puppet and Arista (Beginner)
Puppet
•
2.4K views
Flowspec @ Bay Area Juniper User Group (BAJUG) by Juniper Networks
Flowspec @ Bay Area Juniper User Group (BAJUG)
Juniper Networks
•
3K views
TC Flower Offload by Netronome
TC Flower Offload
Netronome
•
4.1K views
DPDK Support for New HW Offloads by Netronome
DPDK Support for New HW Offloads
Netronome
•
843 views
Viewers also liked
The Age of Data-Driven Network Operations by
The Age of Data-Driven Network Operations
APNIC
800 views
•
49 slides
Root DNS Anycast in South Asia by
Root DNS Anycast in South Asia
APNIC
1K views
•
37 slides
Cryptography - RSA and ECDSA by
Cryptography - RSA and ECDSA
APNIC
2.9K views
•
48 slides
The Death of Transit and Beyond by
The Death of Transit and Beyond
APNIC
356 views
•
28 slides
Rhinolith by
Rhinolith
Anwaaar
6.9K views
•
28 slides
Service Redundancy and Traffic Balancing Using Anycast by
Service Redundancy and Traffic Balancing Using Anycast
Sean Jain Ellis
5K views
•
17 slides
Viewers also liked
(20)
The Age of Data-Driven Network Operations by APNIC
The Age of Data-Driven Network Operations
APNIC
•
800 views
Root DNS Anycast in South Asia by APNIC
Root DNS Anycast in South Asia
APNIC
•
1K views
Cryptography - RSA and ECDSA by APNIC
Cryptography - RSA and ECDSA
APNIC
•
2.9K views
The Death of Transit and Beyond by APNIC
The Death of Transit and Beyond
APNIC
•
356 views
Rhinolith by Anwaaar
Rhinolith
Anwaaar
•
6.9K views
Service Redundancy and Traffic Balancing Using Anycast by Sean Jain Ellis
Service Redundancy and Traffic Balancing Using Anycast
Sean Jain Ellis
•
5K views
Using ~300 Billion DNS Queries to Analyse the TLD Name Collision Problem by APNIC
Using ~300 Billion DNS Queries to Analyse the TLD Name Collision Problem
APNIC
•
316 views
Routing for an Anycast CDN by Tom Paseka
Routing for an Anycast CDN
Tom Paseka
•
4.5K views
Umbrella Fabric/IXP SDN OpenFlow: The TouiX to TouSIX Experience by APNIC
Umbrella Fabric/IXP SDN OpenFlow: The TouiX to TouSIX Experience
APNIC
•
306 views
Journey to IPv6 - A Real-World deployment for Mobiles by APNIC
Journey to IPv6 - A Real-World deployment for Mobiles
APNIC
•
572 views
Network Automation with Salt and NAPALM: a self-resilient network by APNIC
Network Automation with Salt and NAPALM: a self-resilient network
APNIC
•
814 views
DNSSEC/DANE/TLS Testing in Go6Lab by APNIC
DNSSEC/DANE/TLS Testing in Go6Lab
APNIC
•
582 views
Community Networks: An Alternative Paradigm for Developing Network Infrastruc... by APNIC
Community Networks: An Alternative Paradigm for Developing Network Infrastruc...
APNIC
•
751 views
Korea IPv6 Measurement by APNIC
Korea IPv6 Measurement
APNIC
•
524 views
Case Studies: TakNet by APNIC
Case Studies: TakNet
APNIC
•
440 views
Technical and Business Considerations for DNSSEC Deployment by APNIC
Technical and Business Considerations for DNSSEC Deployment
APNIC
•
369 views
Japan IPv6 Measurement by APNIC
Japan IPv6 Measurement
APNIC
•
339 views
Juvenile nasal angiofibroma by Dr. Muhammad Bin Zulfiqar
Juvenile nasal angiofibroma
Dr. Muhammad Bin Zulfiqar
•
4.4K views
APNIC Update - MMNOG 2017 by APNIC
APNIC Update - MMNOG 2017
APNIC
•
682 views
APIX Update by APNIC
APIX Update
APNIC
•
376 views
Similar to TLD Anycast DNS servers to ISPs
Experience of IPv6 Introduction in Japan by
Experience of IPv6 Introduction in Japan
Koji Yasukagawa
138 views
•
46 slides
Run Simulations and Then Become An Inventor (Best Paper Award in CDNLive Taiw... by
Run Simulations and Then Become An Inventor (Best Paper Award in CDNLive Taiw...
Nansen Chen
148 views
•
25 slides
2018-04-17_GA-booth__3gppNR_compressed.ppt by
2018-04-17_GA-booth__3gppNR_compressed.ppt
ssuser38e5dc1
13 views
•
62 slides
PLNOG 22 - Aleksandra Chećko, Robert Cieloch - 5G: wydatek czy oszczędność? by
PLNOG 22 - Aleksandra Chećko, Robert Cieloch - 5G: wydatek czy oszczędność?
PROIDEA
47 views
•
31 slides
Software Stacks to enable SDN and NFV by
Software Stacks to enable SDN and NFV
Yoshihiro Nakajima
1.3K views
•
129 slides
PIT Overload Analysis in Content Centric Networks - Slides ICN '13 by
PIT Overload Analysis in Content Centric Networks - Slides ICN '13
Matteo Virgilio
502 views
•
16 slides
Similar to TLD Anycast DNS servers to ISPs
(20)
Experience of IPv6 Introduction in Japan by Koji Yasukagawa
Experience of IPv6 Introduction in Japan
Koji Yasukagawa
•
138 views
Run Simulations and Then Become An Inventor (Best Paper Award in CDNLive Taiw... by Nansen Chen
Run Simulations and Then Become An Inventor (Best Paper Award in CDNLive Taiw...
Nansen Chen
•
148 views
2018-04-17_GA-booth__3gppNR_compressed.ppt by ssuser38e5dc1
2018-04-17_GA-booth__3gppNR_compressed.ppt
ssuser38e5dc1
•
13 views
PLNOG 22 - Aleksandra Chećko, Robert Cieloch - 5G: wydatek czy oszczędność? by PROIDEA
PLNOG 22 - Aleksandra Chećko, Robert Cieloch - 5G: wydatek czy oszczędność?
PROIDEA
•
47 views
Software Stacks to enable SDN and NFV by Yoshihiro Nakajima
Software Stacks to enable SDN and NFV
Yoshihiro Nakajima
•
1.3K views
PIT Overload Analysis in Content Centric Networks - Slides ICN '13 by Matteo Virgilio
PIT Overload Analysis in Content Centric Networks - Slides ICN '13
Matteo Virgilio
•
502 views
Lte key technologies by Abdulqader Al-kaboudei
Lte key technologies
Abdulqader Al-kaboudei
•
97 views
01 FO_BT1101_C01_1 LTE FDD Principles and Key Technologies.pptx by SudheeraIndrajith
01 FO_BT1101_C01_1 LTE FDD Principles and Key Technologies.pptx
SudheeraIndrajith
•
14 views
Webinar: Desenvolvimento NB-IoT de baixíssimo consumo by Embarcados
Webinar: Desenvolvimento NB-IoT de baixíssimo consumo
Embarcados
•
207 views
LTEcloudSecurityIssuesTakeaways-GP by Dr. Galina Diker Pildush
LTEcloudSecurityIssuesTakeaways-GP
Dr. Galina Diker Pildush
•
489 views
onos-day-dkim-20150914-lkin by Dongkyun Kim
onos-day-dkim-20150914-lkin
Dongkyun Kim
•
244 views
DPDK summit 2015: It's kind of fun to do the impossible with DPDK by Lagopus SDN/OpenFlow switch
DPDK summit 2015: It's kind of fun to do the impossible with DPDK
Lagopus SDN/OpenFlow switch
•
4.7K views
DPDK Summit 2015 - NTT - Yoshihiro Nakajima by Jim St. Leger
DPDK Summit 2015 - NTT - Yoshihiro Nakajima
Jim St. Leger
•
1.3K views
Fast RTPS: Programming with the Default Middleware for Robotics Adopted in ROS2 by Jaime Martin Losa
Fast RTPS: Programming with the Default Middleware for Robotics Adopted in ROS2
Jaime Martin Losa
•
1.1K views
IRJET- Performance Analysis of IP Over Optical CDMA System based on RD Code by IRJET Journal
IRJET- Performance Analysis of IP Over Optical CDMA System based on RD Code
IRJET Journal
•
7 views
DOME 64-bit μDataCenter by inside-BigData.com
DOME 64-bit μDataCenter
inside-BigData.com
•
1.1K views
PLNOG 7: Emil Gągała, Sławomir Janukowicz - carrier grade NAT by PROIDEA
PLNOG 7: Emil Gągała, Sławomir Janukowicz - carrier grade NAT
PROIDEA
•
82 views
CTIA 2010 Corporate Overview by Continuous Computing
CTIA 2010 Corporate Overview
Continuous Computing
•
339 views
A Platform for Data Intensive Services Enabled by Next Generation Dynamic Opt... by Tal Lavian Ph.D.
A Platform for Data Intensive Services Enabled by Next Generation Dynamic Opt...
Tal Lavian Ph.D.
•
660 views
6 intelligent-placement-of-datacenters by zafargilani
6 intelligent-placement-of-datacenters
zafargilani
•
352 views
More from APNIC
IETF 118: Starlink Protocol Performance by
IETF 118: Starlink Protocol Performance
APNIC
186 views
•
22 slides
HKNOG 12.0: RPKI Actions Required by HK Networks by
HKNOG 12.0: RPKI Actions Required by HK Networks
APNIC
459 views
•
26 slides
KHNOG 5: RPKI Status Update by
KHNOG 5: RPKI Status Update
APNIC
401 views
•
25 slides
KHNOG 5: APNIC Services by
KHNOG 5: APNIC Services
APNIC
414 views
•
15 slides
PITA Strategy Forum 2023: Internet resilience by
PITA Strategy Forum 2023: Internet resilience
APNIC
438 views
•
7 slides
SANOG 40: DDoS in South Asia by
SANOG 40: DDoS in South Asia
APNIC
350 views
•
52 slides
More from APNIC
(20)
IETF 118: Starlink Protocol Performance by APNIC
IETF 118: Starlink Protocol Performance
APNIC
•
186 views
HKNOG 12.0: RPKI Actions Required by HK Networks by APNIC
HKNOG 12.0: RPKI Actions Required by HK Networks
APNIC
•
459 views
KHNOG 5: RPKI Status Update by APNIC
KHNOG 5: RPKI Status Update
APNIC
•
401 views
KHNOG 5: APNIC Services by APNIC
KHNOG 5: APNIC Services
APNIC
•
414 views
PITA Strategy Forum 2023: Internet resilience by APNIC
PITA Strategy Forum 2023: Internet resilience
APNIC
•
438 views
SANOG 40: DDoS in South Asia by APNIC
SANOG 40: DDoS in South Asia
APNIC
•
350 views
SANOG 40: RPKI in South Asia by APNIC
SANOG 40: RPKI in South Asia
APNIC
•
351 views
RenasCON 2023: Learning from honeypots by APNIC
RenasCON 2023: Learning from honeypots
APNIC
•
426 views
IGF 2023: DNS Privacy by APNIC
IGF 2023: DNS Privacy
APNIC
•
428 views
MNSEC Conference 2023: Mining Bots by APNIC
MNSEC Conference 2023: Mining Bots
APNIC
•
421 views
VNIX-NOG 2023: IPv6 Deployment in government networks by APNIC
VNIX-NOG 2023: IPv6 Deployment in government networks
APNIC
•
427 views
VNIX-NOG 2023: State of RPKI in APAC - Cleaning up invalids by APNIC
VNIX-NOG 2023: State of RPKI in APAC - Cleaning up invalids
APNIC
•
422 views
SGNOG 10: IPv6 Insights in South East Asia by APNIC
SGNOG 10: IPv6 Insights in South East Asia
APNIC
•
416 views
mnNOG 5: Open source SD-WAN by APNIC
mnNOG 5: Open source SD-WAN
APNIC
•
482 views
mnNOG 2023: State of IPv6 in Mongolia by APNIC
mnNOG 2023: State of IPv6 in Mongolia
APNIC
•
933 views
mnNOG 2023: On GEOs, LEOs and Starlink by APNIC
mnNOG 2023: On GEOs, LEOs and Starlink
APNIC
•
495 views
AusNOG 2023: RPKI and whois updates by APNIC
AusNOG 2023: RPKI and whois updates
APNIC
•
566 views
AusNOG 2023: A quick look at QUIC by APNIC
AusNOG 2023: A quick look at QUIC
APNIC
•
583 views
APrIGF 2023: Sustainability of Complementary Connectivity Initiatives by APNIC
APrIGF 2023: Sustainability of Complementary Connectivity Initiatives
APNIC
•
607 views
APAN 56: APNIC Report by APNIC
APAN 56: APNIC Report
APNIC
•
293 views
Recently uploaded
Opportunities for Youth in IG - Alena Muravska RIPE NCC.pdf by
Opportunities for Youth in IG - Alena Muravska RIPE NCC.pdf
RIPE NCC
9 views
•
12 slides
WEB 2.O TOOLS: Empowering education.pptx by
WEB 2.O TOOLS: Empowering education.pptx
narmadhamanohar21
16 views
•
16 slides
We see everywhere that many people are talking about technology.docx by
We see everywhere that many people are talking about technology.docx
ssuserc5935b
6 views
•
2 slides
childcare.pdf by
childcare.pdf
fatma alnaqbi
14 views
•
4 slides
Building trust in our information ecosystem: who do we trust in an emergency by
Building trust in our information ecosystem: who do we trust in an emergency
Tina Purnat
92 views
•
18 slides
information by
information
khelgishekhar
8 views
•
4 slides
Recently uploaded
(20)
Opportunities for Youth in IG - Alena Muravska RIPE NCC.pdf by RIPE NCC
Opportunities for Youth in IG - Alena Muravska RIPE NCC.pdf
RIPE NCC
•
9 views
WEB 2.O TOOLS: Empowering education.pptx by narmadhamanohar21
WEB 2.O TOOLS: Empowering education.pptx
narmadhamanohar21
•
16 views
We see everywhere that many people are talking about technology.docx by ssuserc5935b
We see everywhere that many people are talking about technology.docx
ssuserc5935b
•
6 views
childcare.pdf by fatma alnaqbi
childcare.pdf
fatma alnaqbi
•
14 views
Building trust in our information ecosystem: who do we trust in an emergency by Tina Purnat
Building trust in our information ecosystem: who do we trust in an emergency
Tina Purnat
•
92 views
information by khelgishekhar
information
khelgishekhar
•
8 views
zotabet.pdf by zotabetcasino
zotabet.pdf
zotabetcasino
•
6 views
PORTFOLIO 1 (Bret Michael Pepito).pdf by brejess0410
PORTFOLIO 1 (Bret Michael Pepito).pdf
brejess0410
•
7 views
Existing documentaries (1).docx by MollyBrown86
Existing documentaries (1).docx
MollyBrown86
•
13 views
Sustainable Marketing by Theo van der Zee
Sustainable Marketing
Theo van der Zee
•
10 views
UiPath Document Understanding_Day 3.pptx by UiPathCommunity
UiPath Document Understanding_Day 3.pptx
UiPathCommunity
•
101 views
𝐒𝐨𝐥𝐚𝐫𝐖𝐢𝐧𝐝𝐬 𝐂𝐚𝐬𝐞 𝐒𝐭𝐮𝐝𝐲 by Infosec train
𝐒𝐨𝐥𝐚𝐫𝐖𝐢𝐧𝐝𝐬 𝐂𝐚𝐬𝐞 𝐒𝐭𝐮𝐝𝐲
Infosec train
•
9 views
informing ideas.docx by MollyBrown86
informing ideas.docx
MollyBrown86
•
12 views
DU Series - Day 4.pptx by UiPathCommunity
DU Series - Day 4.pptx
UiPathCommunity
•
100 views
UiPath Document Understanding_Day 2.pptx by RohitRadhakrishnan8
UiPath Document Understanding_Day 2.pptx
RohitRadhakrishnan8
•
292 views
Audience profile.pptx by MollyBrown86
Audience profile.pptx
MollyBrown86
•
12 views
IGF UA - Dialog with I_ organisations - Alena Muavska RIPE NCC.pdf by RIPE NCC
IGF UA - Dialog with I_ organisations - Alena Muavska RIPE NCC.pdf
RIPE NCC
•
15 views
Is Entireweb better than Google by sebastianthomasbejan
Is Entireweb better than Google
sebastianthomasbejan
•
12 views
Serverless cloud architecture patterns by Jimmy Dahlqvist
Serverless cloud architecture patterns
Jimmy Dahlqvist
•
17 views
google forms survey (1).pptx by MollyBrown86
google forms survey (1).pptx
MollyBrown86
•
14 views
TLD Anycast DNS servers to ISPs
1.
APRICOT 2017 Shoji Noguchi
(JPRS), Yoshibumi Suematsu (QTNet) TLD Anycast DNS servers to ISPs - to Create a More Resilient DNS Environment - 1Copyright © 2017 Japan Registry Services Co., Ltd., and Kyushu Telecommunication Network Co., Inc.
2.
Agenda 1. Concept of
“.jprs” 2. Background of Joint Research 3. Overview of Joint Research 4. Joint Research Report by JPRS 5. Joint Research Report by QTNet Copyright © 2017 Japan Registry Services Co., Ltd. 2
3.
1. Concept of
“.jprs” Copyright © 2017 Japan Registry Services Co., Ltd. 3
4.
“.jprs” R&D Platform Concept
of “.jprs” In order for the Internet to keep growing, as a registry operator, we will need an environment in which to create innovations … .jprs TLD can provide experimental environment for domain names and DNS. For demonstration of experiments – For innovative technologies and productions – Difficult to implement in a production environment For collaborative R&D with research and business partners – Autonomous research pertaining to the Internet Copyright © 2017 Japan Registry Services Co., Ltd. 4
5.
2. Background of
Joint Research Copyright © 2017 Japan Registry Services Co., Ltd. 5
6.
Japan is a
Disaster-prone Country Natural disasters in/around Japan Earthquake, tsunami, typhoon, and volcanic eruption… Copyright © 2017 Japan Registry Services Co., Ltd. 6 The importance of being prepared for natural disasters Collapsed highway The Great Hanshin/Awaji Earthquake on Jan 17, 1995 [*1] [*1] http://sciencewindow.jst.go.jp/html/sw23/sp-003 [*2] http://www.bousai.go.jp/kohou/kouhoubousai/h23/63/special_01.html Tsunami Surging to town The Great East Japan Earthquake on Mar 11, 2011 [*2]
7.
Physical Geography of
Japan Characteristics of national land Japan is an unexpectedly large land. Copyright © 2017 Japan Registry Services Co., Ltd. 7 From <http://thetruesize.com/#/aboutModal?borders=1~!MTE3ODk5MzY.NzQyNzMzNw*MzMzOTgyNDc(MjQ5NjA3NDc~!JP*Mzg5NTA4MA.NDc5NjA5Mw(MTQw)OQ> * Geographical latitude of Japan is not same as that of Southeast Asia. Approx. 3,000 km Geographical features do not always pose potential danger to all regions of Japan but specific regions in many cases.
8.
Logical Structure of
Internet in Japan Characteristic of Internet structure Internet resources are concentrated in Tokyo and Osaka. Internet Exchanges (IXs), Transit connections, Data Centers, and so on Copyright © 2017 Japan Registry Services Co., Ltd. 8 Tokyo Osaka Approx. 400km Natural disasters that occur in/around Tokyo/Osaka can intensely affect Internet connectivity.
9.
Goal - Enhancing
the DNS Resiliency By locations of DNS servers Install DNS servers in several regions other than Tokyo and Osaka. Mitigation/distribution of DNS traffic concentration Stabilization/reduction of RTT Continuous provision of DNS/Internet services In case of an outage of the DNS servers in a particular region Copyright © 2017 Japan Registry Services Co., Ltd. 9
10.
3. Overview of
Joint Research Copyright © 2017 Japan Registry Services Co., Ltd. 10
11.
.jprs DNS servers Installation
sites of .jprs DNS servers The above locations resemble those of .jp DNS. .jprs DNS operations .jprs DNS servers in Tokyo/Osaka are operated by JPRS. Copyright © 2017 Japan Registry Services Co., Ltd. 11 Hostname Location Remarks tld1.nic.jprs Tokyo tld2.nic.jprs Osaka tld3.nic.jprs Worldwide tld4.nic.jprs Tokyo For R&D tld5.nic.jprs Worldwide tld2 Osaka Tokyo tld1 tld4
12.
Approach Joint research effort
with 8 domestic ISPs Each of their service area covers designated geographical areas without overlapping. How to direct DNS query to Local Node Install tld4.nic.jprs DNS servers into their networks as Local Node. A) Routing configuration BGP B) Full resolver configuration “static-stub” zone type for BIND – Specifying DNS servers’ IP addresses Copyright © 2017 Japan Registry Services Co., Ltd. 12 Global Node (JPRS) Local Node (ISP)
13.
Measurement Environment Model Copyright
© 2017 Japan Registry Services Co., Ltd. 13 AS18149 AS2914 AS12041 AS131905 tld1.nic.jprs tld2.nic.jprs tld3.nic.jprs tld4.nic.jprs Collecting Data Source Destination Tools Interval [min.] Continuous ISP’s Internet service Stub Resolver 2LD App server – Web wget 1 Continuous Name Resolution Stub Resolver 2LD App server – DNS dig 1 Reachability of .jprs DNS servers Full Resolver tld[1-5].nic.jp (JPRS) + tld4.nic.jprs (ISP) ping 1 traceroute 1 tcpdump without a pause tld5.nic.jprs Internet ISP 1 - AS XXX1 .jprs DNS - Global Nodes AS131905 tld4.nic.jprs Full Resolver Stub Resolver 2LD App server - Web & DNS ISP network www.example.jprs ISP 8 – AS XXX8 Local Node
14.
ISPs’ Measurement Environment ISPs
used routing/full resolver configuration and DNS software. Copyright © 2017 Japan Registry Services Co., Ltd. 14 ISP Configuration (A) Routing (B) Full resolver DNS Software (BIND) version Full Resolver Local Node HOTnet (A) BGP 9.9.7 9.9.8-P4 TOHKnet (A) BGP 9.9.4-RedHat-9.9.4-29.el7_2.3 HTNet (B) “static-stub” 9.8.2rc1-RedHat-9.8.2-0.37.rc1.el6_7.6 K-OPT (A) BGP 9.9.4-RedHat-9.9.4-29.el7_2.2 Enecom (B) “static-stub” 9.9.8-P4 STNet (B) “static-stub” 9.8.2rc1-RedHat-9.8.2-0.37.rc1.el6_7.6 QTNet (A) BGP 9.9.8-P4 OTNet (A) BGP N/A (Non-disclosure for business use)
15.
Evaluation Methods Continuous
Internet service availability and reachability of .jprs DNS Compare traffic behavior with/without Local Node. Copyright © 2017 Japan Registry Services Co., Ltd. 15 .jprs DNS are located only outside ISP network. .jprs DNS are located inside/outside ISP network. < Without Local Node > < With Local Node > Global Nodes Global Nodes Local Nodes
16.
Evaluation Methods Continuous
Internet service availability and reachability of .jprs DNS Compare traffic behavior by turning on/off Internet connection (hereinafter called Normal/Disaster). Copyright © 2017 Japan Registry Services Co., Ltd. 16 All .jprs DNS are unreachable from inside ISP network. Only Local Node inside ISP is reachable from inside ISP network. < Without Local Node > < With Local Node > Global Nodes Global Nodes Local Nodes
17.
4. Joint Research
Report by JPRS Copyright © 2017 Japan Registry Services Co., Ltd. 17
18.
Enhancing the DNS
Resiliency Reachability of .jprs DNS confirmed at full resolvers Destination of .jprs DNS queries from full resolver had inclined toward Local Node on their ISP network. Copyright © 2017 Japan Registry Services Co., Ltd. 18 Queries/ hour Measured using tcpdump command at ISPs’ full resolvers. Full resolver .jprs DNS servers Execute on a minute-by-minute basis at stub resolver (dig command) Number of DNS queries to each .jprs DNS (IPv4+IPv6) * GN: Global Node, LN: Local Node 0 40 80 120 6/26 13:00 6/26 19:00 6/27 1:00 6/27 7:00 6/27 13:00 6/27 19:00 6/28 1:00 6/28 7:00 GN (tld1) GN (tld2) GN (tld3) LN (tld4) GN (tld5) Local Node W/O With Normal - Disaster - <Normal> <Disaster> by K-OPT
19.
Findings at Full
Resolver - Normal & W/O Local Node Geographic distribution of DNS traffic Over concentration of DNS query to Tokyo and Osaka Copyright © 2017 Japan Registry Services Co., Ltd. Tokyo Osaka ISP Global Node (Tokyo, Osaka) 828km 401km 486km 292km 281km DNS query by Destination and ISP at ISPs’ full resolvers Dest. ISP Tokyo tld[14] Osaka tld2 Worldwide tld[35] Total HOTnet @Sapporo 3,646 (72.7) 170 (3.4) 1,200 (23.9) 5,016 (100.0) HTNet @Kanazawa 1,476 (79.6) 154 (8.3) 224 (12.1) 1,854 (100.0) K-OPT @Osaka 222 (10.8) 1,488 (72.4) 346 (16.8) 2,056 (100.0) Enecom @Hiroshima 812 (44.9) 678 (37.5) 319 (17.6) 1,809 (100.0) QTNet @Fukuoka 2,242 (27.9) 3,286 (40.9) 2,514 (31.3) 8,042 (100.0) Total 8,398 (44.7) 5,776 (30.8) 4,603 (24.5) 18,777 (100.0) [queries (ratio)] Measurement period: 2016/6/23 13:00 ~ 6/24 13:00 (JST) 19 Local Node W/O With Normal - - Disaster - - Worldwide 24.5% Tokyo 44.7% Osaka 30.8%
20.
Findings at Full
Resolver - Disaster & With Local Node De-concentration of DNS query to Tokyo and Osaka DNS query addressed to other than Local Node ≠ Zero Affected by NS selection algorithm in BIND Copyright © 2017 Japan Registry Services Co., Ltd. DNS query by Destination and ISP at ISPs’ full resolvers [queries (ratio)] Measurement period: 2016/6/23 13:00 ~ 6/24 13:00 (JST) 20 Local Node W/O With Normal - - Disaster - - Dest. ISP Tokyo tld[14] Osaka tld2 World tld[35] Local Node Total HOTnet 102* (2.2) 96* (1.3) 162* (2.4) 5,108 (94.1) 5,468 (100.0) HTNet 36* (6.0) 34* (1.0) 80* (5.2) 2,066 (87.8) 2,216 (100.0) K-OPT 112* (4.5) 96* (3.9) 158* (6.4) 2,102 (85.2) 2,468 (100.0) Enecom - - - 1,638 1,638 QTNet - - - 8,236 8,236 Total 250* 226* 400* 19,150 20,026 *: packet loss Tokyo Osaka ISP Global Node (Tokyo, Osaka) 828km 401km 486km 292km 281km Worldwide 3.9%*Tokyo 2.5%* Osaka 2.2%* Local Node 91.4%
21.
Findings at Stub
Resolver Changes in RTT: Normal Disaster Compared between “(A) BGP” and “(B) static-stub.” Case “(A) BGP” - 5 ISPs selected S.D. of RTT affected by loss was 4~10 times larger. Setting initial timeout to 800ms from BIND 9.6.0a1. Copyright © 2017 Japan Registry Services Co., Ltd. 21 Measurement period: 2016/6/26 13:00 ~ 6/28 13:00 (JST) 20 40 60 80 Local Node W/O With Normal - Disaster - RTT of DNS query Avg. + S.D. [ms] HOTnet @Sapporo 0.7 + 6.7 1.9 + 31.2 K-OPT @Osaka 7.2 + 5.4 8.2 + 54.8 QTNet @Fukuoka 3.7 + 17.6 8.9 + 69.0
22.
Findings at Stub
Resolver Case “(B) static-stub” - 3 ISPs selected This function is provided by BIND 9.8.0 or above. Forcing DNS queries for a zone to go to specified IP addresses S.D. of RTT affected by loss was ~2 times larger. S.D. of RTT(B) was 2~8 times smaller than that of (A). Copyright © 2017 Japan Registry Services Co., Ltd. 22 Measurement period: 2016/6/26 13:00 ~ 6/28 13:00 (JST) 20 40 60 80 Local Node W/O With Normal - Disaster - RTT of DNS query Avg. + S.D. [ms] HTNet @Kanazawa 2.5 + 11.3 2.6 + 14.8 Enecom @Hiroshima 2.5 + 3.4 2.6 + 7.7 HOTnet : 31.2 K-OPT : 54.8 QTNet : 69.0 In a particular (B), DNS query inclines toward a destination with a shorter RTT. It depends on how we use either or both of (A) and (B).
23.
RTT of Enecom
was shorter than that of HTNet. Confirmed the trend of DNS queries. Enecom - BIND 9.9.8 – Sent one DNS query to all .jprs DNS servers only once a day at 0:00 AM, and sent all the other DNS queries to Local Node. HTNet - BIND 9.8.2 – Sent DNS queries to all .jprs DNS servers approximately every 6 hours, and sent all the other DNS queries to Local Node. Secondary Findings - Behavior of “static-stub” 23 Assumed that the difference is a load balancing algorithm. 5 10 15 20 Local Node W/O With Normal - Disaster - - Copyright © 2017 Japan Registry Services Co., Ltd. Full Resolver DNS Software RTT of DNS query [ms] Avg. + S.D. Enecom BIND 9.9.8-P4 0.9 + 0.8 HTNet BIND 9.8.2rc1 5.1 + 4.6
24.
Continuity of Internet
services Effect of installing Local Node into ISP network All 8 ISPs were able to continue offering their Internet service inside their own network. Copyright © 2017 Japan Registry Services Co., Ltd. 24 Measured using wget command at ISPs’ stub resolvers. Stub resolver .jprs 2LD Web server Execute on a minute-by-minute basis All 8 ISPs could continue receiving the results of success! Number of Success to access .jprs 2LD Web Server by K-OPTSuccesses/ hour 0 10 20 30 40 50 60 6/26 13:00 6/26 19:00 6/27 01:00 6/27 07:00 6/27 13:00 6/27 19:00 6/28 01:00 6/28 07:00 6/28 13:00 <Normal> <Disaster> 100%! Local Node W/O With Normal - Disaster -
25.
Future Works Relating to
this activity Sharing ISPs’ .jprs DNS servers, or Local Nodes, among themselves Evaluation of geographical dispersal of DNS Root, TLD, and 2nd level domain DNS servers Vertical integration Full resolver and authoritative DNS Horizontal integration Copyright © 2017 Japan Registry Services Co., Ltd. 25
26.
Copyright © 2017
Kyushu Telecommunication Network Co., Inc. All rights reserved. 5. Joint Research Report by QTNet 26
27.
Copyright © 2017
Kyushu Telecommunication Network Co., Inc. All rights reserved. Kyushu Telecommunication Network 27 Company Name Kyushu Telecommunication Network Co., Inc. (QTNet) Telecommunications carrier in Kyushu , Japan Services Wide-Area Ethernet FTTH Internet Accsess, VoIP, and TV AS7679 Our coverage area: Area: 36.750km2 (10% of Japan) Population: 13.2Mil. (10% of Japan) Kyushu is one of the 8 regions of Japan
28.
Copyright © 2017
Kyushu Telecommunication Network Co., Inc. All rights reserved. Internet connectivity in Japan concentrates in Tokyo and Osaka. →The network of Kyushu depends on these areas. What are problems? If the large disasters simultaneously hit in/around Tokyo and Osaka Isolated from other regions of Japan Cannot provide our Internet services in Kyushu IX Full Resolver(QTNet) Internet in Kyushu 28 Approx. 486km Approx. 401km
29.
Copyright © 2017
Kyushu Telecommunication Network Co., Inc. All rights reserved. The task of immediate importance Earthquake in Kyusyu (Kumamoto) Felt earthquakes have been approximately 4000 times since Oct. 10, 2016 04/15 06:00 04/15 08:20 04/15 10:40 04/15 13:00 04/15 15:20 04/15 17:40 04/15 20:00 04/15 22:20 04/16 00:40 04/16 03:00 04/16 05:20 DNS Query received at Full Resolver requests received Recent Natural Disasters in Kyushu 29 In any situation, we must provide our customers with our Internet services! Date & Time(JST) Magnitude 14 April 21:26 6.5 14 April 22:07 5.8 15 April 00:03 6.4 16 April 01:25 7.3 16 April 01:45 5.9 16 April 03:55 5.8 16 April 09:48 5.4 [qps] M7.3 M5.8
30.
Copyright © 2017
Kyushu Telecommunication Network Co., Inc. All rights reserved. Damage by Earthquake Kumamoto Earthquakes in Apr. 14, 2016 30 https://ja-jp.facebook.com/kyuden.jp/posts/940170829434491
31.
Copyright © 2017
Kyushu Telecommunication Network Co., Inc. All rights reserved. Background 31 com jp net arpa org other TLD ranking of request for DNS query jp com net The advantage of using “.jprs” ".jprs" registry operator is same as ".jp," which is ccTLD for Japan Ratio of DNS queries by TLD in our FTTH service: “.jp” is 2nd place. There are many DNS queries for .jp. Many important customers have used .jp.
32.
Copyright © 2017
Kyushu Telecommunication Network Co., Inc. All rights reserved. Simulating the isolation of Kyushu. TLD Anycast DNS servers to QTNet 32 0 20 40 60 80 01/08 13:00 01/09 03:00 01/09 17:00 01/10 07:00 01/10 21:00 01/11 11:00 01/12 01:00 01/12 15:00 01/13 05:00 01/13 19:00 01/14 09:00 01/14 23:00 01/15 13:00 01/16 03:00 01/16 17:00 01/17 07:00 01/17 21:00 Number of DNS queries to each .jprs DNS GN(tld1) GN(tld2) GN(tld3) GN/LN(tld4) GN(tld5) Process #1 #2 #3 #4 #5 [Queries/Hour] (Full resolver .jprs DNS servers) LN GN 1 GN 2 GN 3 GN 4 GN 5 #1 #2 #3 #4 #5 Disconnect DNS service could be provided even under the condition that Kyushu had been isolated.
33.
Copyright © 2017
Kyushu Telecommunication Network Co., Inc. All rights reserved. Other results Other interesting results by setting local node to ISP. 33 0.0 5.0 10.0 15.0 20.0 25.0 30.0 0.0 5.0 10.0 15.0 20.0 25.0 30.0 35.0 04/25 05:00 04/25 07:00 04/25 09:00 04/25 11:00 04/25 13:00 04/25 15:00 04/25 17:00 04/25 19:00 04/25 21:00 Number of RTT & hop to each .jprs DNS tld1(RTT) tld2(RTT) tld3(RTT) tld4(RTT) tld5(RTT) tld1(hop) tld2(hop) tld3(hop) tld4(hop) tld5(hop) 0 10 20 30 40 50 60 70 04/25 05:00 04/25 07:00 04/25 09:00 04/25 11:00 04/25 13:00 04/25 15:00 04/25 17:00 04/25 19:00 04/25 21:00 Number of DNS queries to each .jprs DNS tld1v4 tld2v4 tld3v4 tld4v4 tld5v4 The full resolver(BIND) preferentially selects .jprs DNS with shorter RTT. [ms] [hop] [Queries /Hour] <Normal> <Disaster> Collecting Data Source Destination Tools Interval [min.] RTT & hop Stub Resolver .jprs DNS traceroute 1 DNS query Stub Resolver .jprs DNS dig 1 <Normal> <Disaster>
34.
Copyright © 2017
Kyushu Telecommunication Network Co., Inc. All rights reserved. Conclusion Installing TLD Anycast DNS server in QTNet. Providing DNS service could be continued under the conditions such as Kyushu is isolated. Reducing RTT by installing .jprs local node. Installing local node is effective both in normal times and in large-scale disasters. Future work To install .jp local node in Kyushu! :-) 34
35.
Contact Us Email: dotjprstestbed-sec@jprs.co.jp URI:
https://nic.jprs/ Copyright © 2017 Japan Registry Services Co., Ltd. 35
36.
APPENDICES Copyright © 2017
Japan Registry Services Co., Ltd. 36
37.
Sample of “static-stub”
zone type named.conf for BIND Copyright © 2017 Japan Registry Services Co., Ltd. 37 % cat /etc/named-without-localnode.conf (snip) zone "jprs." { type static-stub; server-addresses { // Global Nodes (JPRS) 103.47.2.1; // tld1.nic.jprs 2001:dda::1; // tld1.nic.jprs 117.104.133.16; // tld2.nic.jprs 2001:218:3001::1; // tld2.nic.jprs 65.22.40.1; // tld3.nic.jprs 2a01:8840:1ba::1; // tld3.nic.jprs 103.198.210.1; // tld4.nic.jprs 2403:2880::1; // tld4.nic.jprs 65.22.40.129; // tld5.nic.jprs 2a01:8840:1ba::129; // tld5.nic.jprs }; }; (snip) % cat /etc/named-with-localnode.conf (snip) zone "jprs." { type static-stub; server-addresses { // Global Nodes (JPRS) 103.47.2.1; // tld1.nic.jprs 2001:dda::1; // tld1.nic.jprs 117.104.133.16; // tld2.nic.jprs 2001:218:3001::1; // tld2.nic.jprs 65.22.40.1; // tld3.nic.jprs 2a01:8840:1ba::1; // tld3.nic.jprs // 103.198.210.1; // tld4.nic.jprs // 2403:2880::1; // tld4.nic.jprs 65.22.40.129; // tld5.nic.jprs 2a01:8840:1ba::129; // tld5.nic.jprs // Local Nodes (ISP) 192.0.2.53; // tld4.nic.jprs 2001:db8::53; // tld4.nic.jprs }; }; (snip) Add Rem
38.
Available to Local
Node Mitigation of DNS traffic De-concentration of DNS query to Tokyo and Osaka Copyright © 2017 Japan Registry Services Co., Ltd. DNS query by Destination and ISPs at ISPs’ full resolvers Measurement period: 2016/6/24 13:00 ~ 6/25 13:00 (JST) 38 Local Node W/O With Normal - - Disaster - - Dest. ISP Tokyo tld[14] Osaka tld2 World tld[35] Local Node Total HOTnet 114 (2.2) 70 (1.3) 128 (2.4) 4,954 (94.1) 5,266 (100.0) HTNet 128 (6.0) 22 (1.0) 112 (5.2) 1,880 (87.8) 2,142 (100.0) K-OPT 122 (5.5) 176 (8.0) 224 (10.2) 1,678 (76.3) 2,200 (100.0) Enecom 18 (1.1) 11 (0.7) 13 (0.8) 1,592 (97.4) 1,634 (100.0) QTNet 972 (16.4) 890 (15.1) 1,854 (31.4) 2,988 (50.6) 5,894 (100.0) Total 1,696 (7.5) 2,067 (6.5) 3,071 (13.0) 13,484 (73.0) 20,318 (100.0) Tokyo Osaka ISP Global Node (Tokyo, Osaka) 828km 401km 486km 292km 281km [queries (ratio)] Worldwide 13.0% Tokyo 7.5% Osaka 6.5% Local Node 73.0%