SlideShare a Scribd company logo
1 of 33
Download to read offline
1
Regional Internet Registries (RIRs)
and Law Enforcement Agencies
UN INCB - Expert Group Meeting on Dangerous Substance Trafficking
through Social Media and other Internet-related Services
1 July 2020
Jamie Gillespie, Security Specialist at APNIC
jamie@apnic.net
whois: Jamie Gillespie
• Jamie Gillespie
– jamie@apnic.net
– Security Specialist @ APNIC
– Community engagement, CERT building, InfoSec training, awareness
• Work history
– 8 years at AusCERT, Australia’s national CERT
– Google
– Macquarie Telecom / Cloud Services
2
5
Internet and IP Basics
Internet Basics
• Every device on the Internet needs an address, to be found by other
devices
– IPv4: 66.220.144.0
– IPv6: 2a03:2880:11:2f83:face:b00c:0:25de
• Humans are not good with numbers. We have domain names that
translate to address: www.facebook.com → 69.171.239.12
6
The Internet is a Series of Networks
• The Network of Networks
7
Names and Numbers
8
The Internet
2001:0C00:8888:: 2001:0400::
www.apnic.net
202.112.0.46
2001:0400::
My Computer www.apnic.net
www.apnic.net
202.112.0.46
2001:0400::
9
Who is Who in the Internet
Acronyms and Initialisms
• Before we go any further, we should probably define what a
bunch of common acronyms and initialisms mean
– IETF - Internet Engineering Task Force
– IANA - Internet Assigned Numbers Authority
– ICANN - Internet Corporate for Assigned Names and Numbers
– TLD - Top Level Domain
– gTLD - Generic Top Level Domain
– ccTLD - Country Code Top Level Domain
– RIR - Regional Internet Registry
10
Where do IP addresses come from?
11
RIRs from a Global Perspective
12
Regional Internet Registries
13
How APNIC and the RIRs Operate
• APNIC is the Regional Internet Registry
(RIR) for the Asia Pacific region
• Membership-based, not-for-profit
• Industry self-regulatory body
– Open
– Consensus-based
– Transparent
• Delegates and manages Internet
number resources
– IPv4 and IPv6 addresses
• Diagram on next slide
– AS numbers
14
APNIC’s Roles and Services
• Delegates and manages Internet resources
– IPv4 & IPv6 addresses, AS Numbers
• Maintains the APNIC Whois Database
• Manages reverse DNS delegations
– But is NOT a domain name registry
• Facilitates IP address policy development
• Provides capacity building through training, workshops,
conferences, fellowships, and grants
– resource management, routing, IPv6 deployment, and security
• Research, measurements, publications
• Supports Internet infrastructure development
– Root server deployment, Internet Exchange Points (IXPs)
15
So who gets IP address and AS numbers?
• National Internet Registry
• Telcos, ISPs, Mobile Operators
• Hosting Company (Amazon/AWS, Azure, GCP, Linode)
• Universities, Government Departments, Banks
16
How APNIC and the RIRs work with LEAs
• APNIC provides LEAs with publicly available registry information
to help them respond to malicious activity on the Internet
• APNIC coordinates with the global technical community to share
information and develop trusted relationships to ensure
coordinated responses to major network security incidents
• APNIC has dedicated legal and network security experts to
support LEA requests
• APNIC’s legal and network security experts provide training to
LEOs, investigators, and the justice sector
(in addition to network operators and CSIRTs)
18
19
https://www.apnic.net/community/security/security-cooperation/#LEAs
Working with INTERPOL/Europol/FBI
Improving Whois data quality and accuracy
20
How LEAs can Participate with RIRs
• Attend RIR and other industry meetings
– Each RIR runs open meeting and conferences each year
– Network Operator Groups (NOGs)
– Trusted community conferences (UE / RISE, FIRST, M3AAWG…)
• Request training sessions with RIRs
• Participate in the Policy Development Process
– Submit policy proposals, discuss other proposals
• Report invalid contacts from whois records
21
25
Whois Databases
Important – About Whois DB
• Number vs Domain Whois
o Two different types of databases
o APNIC and the other RIRs operate the numbers whois DBs
o Top level domains and registrars operate domain whois DBs
• Other Databases
– Reputation
– Data enrichment
• e.g. http://www.team-cymru.com/IP-ASN-mapping.html
26
What are the numbers Whois databases?
• Public network management database
– Operated by Internet Registries (like APNIC!)
• Public data only
– Tracks network resources
• IP Addresses, ASNs, Reverse DNS Delegations, Routing Policies
• Records administrative information
– Contact information (persons/roles)
– Authorization for updating this info
– Network abuse handling (IRT)
27
IP Address Delegation
28
Whois Database Accuracy
• Accurate & Reliable
• Responsiveness
– Stop / Mitigate on going attack
– Reduce impact / exposure of incidents
– Do not have to go through various loops & hoops
• Ideally
– Ability to provide assistance or do something about it
– Escalation
• Features
– Mechanism for reporting invalid contacts
– Trigger other actions
• Other Databases?
– FIRST, APCERT, Trusted Introducer, etc
32
irt: IRT-APNIC-IS-AP
address: South Brisbane, Australia
e-mail: helpdesk@apnic.net
abuse-mailbox: helpdesk@apnic.net
admin-c: AIC1-AP
tech-c: AIC1-AP
auth: # Filtered
remarks: APNIC Infrastructure Services
mnt-by: MAINT-APNIC-IS-AP
changed: hm-changed@apnic.net 20110704
source: APNIC
Which Whois to Use?
• APNIC
– Asia Pacific
– APNIC Whois Database (previous slide)
• AFRINIC
– Africa
– https://www.afrinic.net/whois-web/public
• RIPE NCC
– Europe, Central Asia and the Middle East
– https://apps.db.ripe.net
• ARIN
– Northern America
– http://whois.arin.net
• LACNIC
– Latin America and the Caribbean
– http://lacnic.net/cgi-bin/lacnic/whois
33
Regional Internet Registries (RIRs)
The APNIC Whois Database
• Holds IP address records within the AP region
• Can use this database to track down the source of the
network abuse
– IP addresses, ASNs, Reverse Domains, Routing policies
• Can find contact details of the relevant network
administrators
– not the individual users
– use administrators log files to contact the individual involved
35
Whois Database Access
• APNIC website
– https://www.apnic.net/manage-ip/using-whois/searching
• Whois search tool
– https://wq.apnic.net/whois-search/static/search.html
• Whois client, query tool, or RDAP
– Point the tools at whois.apnic.net
36
What if Whois info is invalid?
• Members (ISPs and Network Operators) are responsible for
reporting changes to APNIC
– Under formal membership agreement
• Anyone can report invalid ISP/NetOp contacts to APNIC
– http://www.apnic.net/invalidcontact
– APNIC will contact member and update registration details
• Each RIR has a similar process for handling invalid contacts
37
Whois Output
38
Whois Output
39
Future of Whois
• RDAP – Registration Data Access Protocol
• RDAP is a newer standard for accessing whois information
– Uses standardised queries and responses (JSON)
– Internationalisation
– Redirection for seamless referrals to other registries
• Working now but still under development for NIR data
– www.apnic.net/about-apnic/whois_search/about/rdap/
– www.openrdap.org (GoLang client)
• APNIC is also developing a Network ToolBox
– https://netox.apnic.net (let me know your feedback & suggestions!)
42
Reverse DNS
• Reverse DNS translates the IP number back to a name
• Reverse DNS answers are optional for network operators
– The internet works without it
dig -x 202.55.92.5
;; ANSWER SECTION:
5.92.55.202.in-addr.arpa. 5 IN PTR fnet5-m92-access.vqbn.com.sg.
• You can now use whois and other tools/techniques to look
up contact details for vqbn.com.sg
57
Current Challenges
• Fraudulent acquisition and transfer of IPv4 addresses
• Route hijacking
• Leasing, buying, and selling of IPv4 addresses outside of
the registry system
• Invalid contact information
58
Questions?
Jamie Gillespie
jamie@apnic.net
59

More Related Content

Similar to UN INCB: RIRs and LEAs

Regional Internet Registry and Whois
Regional Internet Registry and WhoisRegional Internet Registry and Whois
Regional Internet Registry and WhoisAPNIC
 
apnic handling-network-abuse
apnic handling-network-abuseapnic handling-network-abuse
apnic handling-network-abuseAPNIC
 
Whois - Addressing the Asia Pacifc
Whois - Addressing the Asia PacifcWhois - Addressing the Asia Pacifc
Whois - Addressing the Asia PacifcAPNIC
 
ARIN on the Road
ARIN on the RoadARIN on the Road
ARIN on the RoadARIN
 
Internet Operations and the RIRs
Internet Operations and the RIRsInternet Operations and the RIRs
Internet Operations and the RIRsARIN
 
KHNOG 5: APNIC Services
KHNOG 5: APNIC ServicesKHNOG 5: APNIC Services
KHNOG 5: APNIC ServicesAPNIC
 
Law Enforcement engagement capacity building
Law Enforcement engagement capacity buildingLaw Enforcement engagement capacity building
Law Enforcement engagement capacity buildingAPNIC
 
Cybersecurity Opportunities Challenges APNIC
Cybersecurity Opportunities Challenges APNICCybersecurity Opportunities Challenges APNIC
Cybersecurity Opportunities Challenges APNICAPNIC
 
How APNIC can support law enforcement agencies in cybercrime investigtaion
How APNIC can support law enforcement agencies in cybercrime investigtaionHow APNIC can support law enforcement agencies in cybercrime investigtaion
How APNIC can support law enforcement agencies in cybercrime investigtaionAPNIC
 
Internet Resource Management Tutorial at SANOG 24
Internet Resource Management Tutorial at SANOG 24Internet Resource Management Tutorial at SANOG 24
Internet Resource Management Tutorial at SANOG 24APNIC
 
4th ICANN APAC-TWNIC Engagement Forum and 39th TWNIC OPM:APNIC Vulnerability ...
4th ICANN APAC-TWNIC Engagement Forum and 39th TWNIC OPM:APNIC Vulnerability ...4th ICANN APAC-TWNIC Engagement Forum and 39th TWNIC OPM:APNIC Vulnerability ...
4th ICANN APAC-TWNIC Engagement Forum and 39th TWNIC OPM:APNIC Vulnerability ...APNIC
 
PCTA Convention 2023: APNIC Introduction
PCTA Convention 2023: APNIC IntroductionPCTA Convention 2023: APNIC Introduction
PCTA Convention 2023: APNIC IntroductionAPNIC
 
PCTA Convention 2023: APNIC Introduction
PCTA Convention 2023: APNIC IntroductionPCTA Convention 2023: APNIC Introduction
PCTA Convention 2023: APNIC IntroductionAPNIC
 
APNIC Report - APStar retreat
APNIC Report - APStar retreatAPNIC Report - APStar retreat
APNIC Report - APStar retreatAPNIC
 
23rd PITA AGM and Conference: Internet number registry services - the next ge...
23rd PITA AGM and Conference: Internet number registry services - the next ge...23rd PITA AGM and Conference: Internet number registry services - the next ge...
23rd PITA AGM and Conference: Internet number registry services - the next ge...APNIC
 
IPv4 Transfers, Taiwan Internet Forum
IPv4 Transfers, Taiwan Internet ForumIPv4 Transfers, Taiwan Internet Forum
IPv4 Transfers, Taiwan Internet ForumAPNIC
 
Intrusion detection 2001
Intrusion detection 2001Intrusion detection 2001
Intrusion detection 2001eaiti
 
DNS Abuse Handling
DNS Abuse HandlingDNS Abuse Handling
DNS Abuse HandlingAPNIC
 

Similar to UN INCB: RIRs and LEAs (20)

Regional Internet Registry and Whois
Regional Internet Registry and WhoisRegional Internet Registry and Whois
Regional Internet Registry and Whois
 
apnic handling-network-abuse
apnic handling-network-abuseapnic handling-network-abuse
apnic handling-network-abuse
 
Whois - Addressing the Asia Pacifc
Whois - Addressing the Asia PacifcWhois - Addressing the Asia Pacifc
Whois - Addressing the Asia Pacifc
 
ARIN on the Road
ARIN on the RoadARIN on the Road
ARIN on the Road
 
Internet Operations and the RIRs
Internet Operations and the RIRsInternet Operations and the RIRs
Internet Operations and the RIRs
 
KHNOG 5: APNIC Services
KHNOG 5: APNIC ServicesKHNOG 5: APNIC Services
KHNOG 5: APNIC Services
 
Law Enforcement engagement capacity building
Law Enforcement engagement capacity buildingLaw Enforcement engagement capacity building
Law Enforcement engagement capacity building
 
Cybersecurity Opportunities Challenges APNIC
Cybersecurity Opportunities Challenges APNICCybersecurity Opportunities Challenges APNIC
Cybersecurity Opportunities Challenges APNIC
 
How APNIC can support law enforcement agencies in cybercrime investigtaion
How APNIC can support law enforcement agencies in cybercrime investigtaionHow APNIC can support law enforcement agencies in cybercrime investigtaion
How APNIC can support law enforcement agencies in cybercrime investigtaion
 
Internet Resource Management Tutorial at SANOG 24
Internet Resource Management Tutorial at SANOG 24Internet Resource Management Tutorial at SANOG 24
Internet Resource Management Tutorial at SANOG 24
 
4th ICANN APAC-TWNIC Engagement Forum and 39th TWNIC OPM:APNIC Vulnerability ...
4th ICANN APAC-TWNIC Engagement Forum and 39th TWNIC OPM:APNIC Vulnerability ...4th ICANN APAC-TWNIC Engagement Forum and 39th TWNIC OPM:APNIC Vulnerability ...
4th ICANN APAC-TWNIC Engagement Forum and 39th TWNIC OPM:APNIC Vulnerability ...
 
PCTA Convention 2023: APNIC Introduction
PCTA Convention 2023: APNIC IntroductionPCTA Convention 2023: APNIC Introduction
PCTA Convention 2023: APNIC Introduction
 
PCTA Convention 2023: APNIC Introduction
PCTA Convention 2023: APNIC IntroductionPCTA Convention 2023: APNIC Introduction
PCTA Convention 2023: APNIC Introduction
 
ICANN Engagement Update
ICANN Engagement UpdateICANN Engagement Update
ICANN Engagement Update
 
APNIC Report - APStar retreat
APNIC Report - APStar retreatAPNIC Report - APStar retreat
APNIC Report - APStar retreat
 
23rd PITA AGM and Conference: Internet number registry services - the next ge...
23rd PITA AGM and Conference: Internet number registry services - the next ge...23rd PITA AGM and Conference: Internet number registry services - the next ge...
23rd PITA AGM and Conference: Internet number registry services - the next ge...
 
IPv4 Transfers, Taiwan Internet Forum
IPv4 Transfers, Taiwan Internet ForumIPv4 Transfers, Taiwan Internet Forum
IPv4 Transfers, Taiwan Internet Forum
 
09 (IDNOG01) Introduction about APNIC by Wita Laksono
09 (IDNOG01) Introduction about APNIC by Wita Laksono09 (IDNOG01) Introduction about APNIC by Wita Laksono
09 (IDNOG01) Introduction about APNIC by Wita Laksono
 
Intrusion detection 2001
Intrusion detection 2001Intrusion detection 2001
Intrusion detection 2001
 
DNS Abuse Handling
DNS Abuse HandlingDNS Abuse Handling
DNS Abuse Handling
 

More from APNIC

DDoS In Oceania and the Pacific, presented by Dave Phelan at NZNOG 2024
DDoS In Oceania and the Pacific, presented by Dave Phelan at NZNOG 2024DDoS In Oceania and the Pacific, presented by Dave Phelan at NZNOG 2024
DDoS In Oceania and the Pacific, presented by Dave Phelan at NZNOG 2024APNIC
 
On Starlink, presented by Geoff Huston at NZNOG 2024
On Starlink, presented by Geoff Huston at NZNOG 2024On Starlink, presented by Geoff Huston at NZNOG 2024
On Starlink, presented by Geoff Huston at NZNOG 2024APNIC
 
Networking in the Penumbra presented by Geoff Huston at NZNOG
Networking in the Penumbra presented by Geoff Huston at NZNOGNetworking in the Penumbra presented by Geoff Huston at NZNOG
Networking in the Penumbra presented by Geoff Huston at NZNOGAPNIC
 
IP addressing and IPv6, presented by Paul Wilson at IETF 119
IP addressing and IPv6, presented by Paul Wilson at IETF 119IP addressing and IPv6, presented by Paul Wilson at IETF 119
IP addressing and IPv6, presented by Paul Wilson at IETF 119APNIC
 
draft-harrison-sidrops-manifest-number-01, presented at IETF 119
draft-harrison-sidrops-manifest-number-01, presented at IETF 119draft-harrison-sidrops-manifest-number-01, presented at IETF 119
draft-harrison-sidrops-manifest-number-01, presented at IETF 119APNIC
 
Making an RFC in Today's IETF, presented by Geoff Huston at IETF 119
Making an RFC in Today's IETF, presented by Geoff Huston at IETF 119Making an RFC in Today's IETF, presented by Geoff Huston at IETF 119
Making an RFC in Today's IETF, presented by Geoff Huston at IETF 119APNIC
 
IPv6 Operational Issues (with DNS), presented by Geoff Huston at IETF 119
IPv6 Operational Issues (with DNS), presented by Geoff Huston at IETF 119IPv6 Operational Issues (with DNS), presented by Geoff Huston at IETF 119
IPv6 Operational Issues (with DNS), presented by Geoff Huston at IETF 119APNIC
 
Is DNS ready for IPv6, presented by Geoff Huston at IETF 119
Is DNS ready for IPv6, presented by Geoff Huston at IETF 119Is DNS ready for IPv6, presented by Geoff Huston at IETF 119
Is DNS ready for IPv6, presented by Geoff Huston at IETF 119APNIC
 
Benefits of doing Internet peering and running an Internet Exchange (IX) pres...
Benefits of doing Internet peering and running an Internet Exchange (IX) pres...Benefits of doing Internet peering and running an Internet Exchange (IX) pres...
Benefits of doing Internet peering and running an Internet Exchange (IX) pres...APNIC
 
APNIC Update and RIR Policies for ccTLDs, presented at APTLD 85
APNIC Update and RIR Policies for ccTLDs, presented at APTLD 85APNIC Update and RIR Policies for ccTLDs, presented at APTLD 85
APNIC Update and RIR Policies for ccTLDs, presented at APTLD 85APNIC
 
NANOG 90: 'BGP in 2023' presented by Geoff Huston
NANOG 90: 'BGP in 2023' presented by Geoff HustonNANOG 90: 'BGP in 2023' presented by Geoff Huston
NANOG 90: 'BGP in 2023' presented by Geoff HustonAPNIC
 
DNS-OARC 42: Is the DNS ready for IPv6? presentation by Geoff Huston
DNS-OARC 42: Is the DNS ready for IPv6? presentation by Geoff HustonDNS-OARC 42: Is the DNS ready for IPv6? presentation by Geoff Huston
DNS-OARC 42: Is the DNS ready for IPv6? presentation by Geoff HustonAPNIC
 
APAN 57: APNIC Report at APAN 57, Bangkok, Thailand
APAN 57: APNIC Report at APAN 57, Bangkok, ThailandAPAN 57: APNIC Report at APAN 57, Bangkok, Thailand
APAN 57: APNIC Report at APAN 57, Bangkok, ThailandAPNIC
 
Lao Digital Week 2024: It's time to deploy IPv6
Lao Digital Week 2024: It's time to deploy IPv6Lao Digital Week 2024: It's time to deploy IPv6
Lao Digital Week 2024: It's time to deploy IPv6APNIC
 
AINTEC 2023: Networking in the Penumbra!
AINTEC 2023: Networking in the Penumbra!AINTEC 2023: Networking in the Penumbra!
AINTEC 2023: Networking in the Penumbra!APNIC
 
CNIRC 2023: Global and Regional IPv6 Deployment 2023
CNIRC 2023: Global and Regional IPv6 Deployment 2023CNIRC 2023: Global and Regional IPv6 Deployment 2023
CNIRC 2023: Global and Regional IPv6 Deployment 2023APNIC
 
AFSIG 2023: APNIC Foundation and support for Internet development
AFSIG 2023: APNIC Foundation and support for Internet developmentAFSIG 2023: APNIC Foundation and support for Internet development
AFSIG 2023: APNIC Foundation and support for Internet developmentAPNIC
 
AFNOG 1: Afghanistan IP Deployment Status
AFNOG 1: Afghanistan IP Deployment StatusAFNOG 1: Afghanistan IP Deployment Status
AFNOG 1: Afghanistan IP Deployment StatusAPNIC
 
AFSIG 2023: Internet routing and addressing
AFSIG 2023: Internet routing and addressingAFSIG 2023: Internet routing and addressing
AFSIG 2023: Internet routing and addressingAPNIC
 
AFSIG 2023: APNIC - Registry & Development
AFSIG 2023: APNIC - Registry & DevelopmentAFSIG 2023: APNIC - Registry & Development
AFSIG 2023: APNIC - Registry & DevelopmentAPNIC
 

More from APNIC (20)

DDoS In Oceania and the Pacific, presented by Dave Phelan at NZNOG 2024
DDoS In Oceania and the Pacific, presented by Dave Phelan at NZNOG 2024DDoS In Oceania and the Pacific, presented by Dave Phelan at NZNOG 2024
DDoS In Oceania and the Pacific, presented by Dave Phelan at NZNOG 2024
 
On Starlink, presented by Geoff Huston at NZNOG 2024
On Starlink, presented by Geoff Huston at NZNOG 2024On Starlink, presented by Geoff Huston at NZNOG 2024
On Starlink, presented by Geoff Huston at NZNOG 2024
 
Networking in the Penumbra presented by Geoff Huston at NZNOG
Networking in the Penumbra presented by Geoff Huston at NZNOGNetworking in the Penumbra presented by Geoff Huston at NZNOG
Networking in the Penumbra presented by Geoff Huston at NZNOG
 
IP addressing and IPv6, presented by Paul Wilson at IETF 119
IP addressing and IPv6, presented by Paul Wilson at IETF 119IP addressing and IPv6, presented by Paul Wilson at IETF 119
IP addressing and IPv6, presented by Paul Wilson at IETF 119
 
draft-harrison-sidrops-manifest-number-01, presented at IETF 119
draft-harrison-sidrops-manifest-number-01, presented at IETF 119draft-harrison-sidrops-manifest-number-01, presented at IETF 119
draft-harrison-sidrops-manifest-number-01, presented at IETF 119
 
Making an RFC in Today's IETF, presented by Geoff Huston at IETF 119
Making an RFC in Today's IETF, presented by Geoff Huston at IETF 119Making an RFC in Today's IETF, presented by Geoff Huston at IETF 119
Making an RFC in Today's IETF, presented by Geoff Huston at IETF 119
 
IPv6 Operational Issues (with DNS), presented by Geoff Huston at IETF 119
IPv6 Operational Issues (with DNS), presented by Geoff Huston at IETF 119IPv6 Operational Issues (with DNS), presented by Geoff Huston at IETF 119
IPv6 Operational Issues (with DNS), presented by Geoff Huston at IETF 119
 
Is DNS ready for IPv6, presented by Geoff Huston at IETF 119
Is DNS ready for IPv6, presented by Geoff Huston at IETF 119Is DNS ready for IPv6, presented by Geoff Huston at IETF 119
Is DNS ready for IPv6, presented by Geoff Huston at IETF 119
 
Benefits of doing Internet peering and running an Internet Exchange (IX) pres...
Benefits of doing Internet peering and running an Internet Exchange (IX) pres...Benefits of doing Internet peering and running an Internet Exchange (IX) pres...
Benefits of doing Internet peering and running an Internet Exchange (IX) pres...
 
APNIC Update and RIR Policies for ccTLDs, presented at APTLD 85
APNIC Update and RIR Policies for ccTLDs, presented at APTLD 85APNIC Update and RIR Policies for ccTLDs, presented at APTLD 85
APNIC Update and RIR Policies for ccTLDs, presented at APTLD 85
 
NANOG 90: 'BGP in 2023' presented by Geoff Huston
NANOG 90: 'BGP in 2023' presented by Geoff HustonNANOG 90: 'BGP in 2023' presented by Geoff Huston
NANOG 90: 'BGP in 2023' presented by Geoff Huston
 
DNS-OARC 42: Is the DNS ready for IPv6? presentation by Geoff Huston
DNS-OARC 42: Is the DNS ready for IPv6? presentation by Geoff HustonDNS-OARC 42: Is the DNS ready for IPv6? presentation by Geoff Huston
DNS-OARC 42: Is the DNS ready for IPv6? presentation by Geoff Huston
 
APAN 57: APNIC Report at APAN 57, Bangkok, Thailand
APAN 57: APNIC Report at APAN 57, Bangkok, ThailandAPAN 57: APNIC Report at APAN 57, Bangkok, Thailand
APAN 57: APNIC Report at APAN 57, Bangkok, Thailand
 
Lao Digital Week 2024: It's time to deploy IPv6
Lao Digital Week 2024: It's time to deploy IPv6Lao Digital Week 2024: It's time to deploy IPv6
Lao Digital Week 2024: It's time to deploy IPv6
 
AINTEC 2023: Networking in the Penumbra!
AINTEC 2023: Networking in the Penumbra!AINTEC 2023: Networking in the Penumbra!
AINTEC 2023: Networking in the Penumbra!
 
CNIRC 2023: Global and Regional IPv6 Deployment 2023
CNIRC 2023: Global and Regional IPv6 Deployment 2023CNIRC 2023: Global and Regional IPv6 Deployment 2023
CNIRC 2023: Global and Regional IPv6 Deployment 2023
 
AFSIG 2023: APNIC Foundation and support for Internet development
AFSIG 2023: APNIC Foundation and support for Internet developmentAFSIG 2023: APNIC Foundation and support for Internet development
AFSIG 2023: APNIC Foundation and support for Internet development
 
AFNOG 1: Afghanistan IP Deployment Status
AFNOG 1: Afghanistan IP Deployment StatusAFNOG 1: Afghanistan IP Deployment Status
AFNOG 1: Afghanistan IP Deployment Status
 
AFSIG 2023: Internet routing and addressing
AFSIG 2023: Internet routing and addressingAFSIG 2023: Internet routing and addressing
AFSIG 2023: Internet routing and addressing
 
AFSIG 2023: APNIC - Registry & Development
AFSIG 2023: APNIC - Registry & DevelopmentAFSIG 2023: APNIC - Registry & Development
AFSIG 2023: APNIC - Registry & Development
 

Recently uploaded

Call Girls South Delhi Delhi reach out to us at ☎ 9711199012
Call Girls South Delhi Delhi reach out to us at ☎ 9711199012Call Girls South Delhi Delhi reach out to us at ☎ 9711199012
Call Girls South Delhi Delhi reach out to us at ☎ 9711199012rehmti665
 
Magic exist by Marta Loveguard - presentation.pptx
Magic exist by Marta Loveguard - presentation.pptxMagic exist by Marta Loveguard - presentation.pptx
Magic exist by Marta Loveguard - presentation.pptxMartaLoveguard
 
Font Performance - NYC WebPerf Meetup April '24
Font Performance - NYC WebPerf Meetup April '24Font Performance - NYC WebPerf Meetup April '24
Font Performance - NYC WebPerf Meetup April '24Paul Calvano
 
Denver Web Design brochure for public viewing
Denver Web Design brochure for public viewingDenver Web Design brochure for public viewing
Denver Web Design brochure for public viewingbigorange77
 
定制(UAL学位证)英国伦敦艺术大学毕业证成绩单原版一比一
定制(UAL学位证)英国伦敦艺术大学毕业证成绩单原版一比一定制(UAL学位证)英国伦敦艺术大学毕业证成绩单原版一比一
定制(UAL学位证)英国伦敦艺术大学毕业证成绩单原版一比一Fs
 
Russian Call Girls in Kolkata Ishita 🤌 8250192130 🚀 Vip Call Girls Kolkata
Russian Call Girls in Kolkata Ishita 🤌  8250192130 🚀 Vip Call Girls KolkataRussian Call Girls in Kolkata Ishita 🤌  8250192130 🚀 Vip Call Girls Kolkata
Russian Call Girls in Kolkata Ishita 🤌 8250192130 🚀 Vip Call Girls Kolkataanamikaraghav4
 
定制(Lincoln毕业证书)新西兰林肯大学毕业证成绩单原版一比一
定制(Lincoln毕业证书)新西兰林肯大学毕业证成绩单原版一比一定制(Lincoln毕业证书)新西兰林肯大学毕业证成绩单原版一比一
定制(Lincoln毕业证书)新西兰林肯大学毕业证成绩单原版一比一Fs
 
Chennai Call Girls Alwarpet Phone 🍆 8250192130 👅 celebrity escorts service
Chennai Call Girls Alwarpet Phone 🍆 8250192130 👅 celebrity escorts serviceChennai Call Girls Alwarpet Phone 🍆 8250192130 👅 celebrity escorts service
Chennai Call Girls Alwarpet Phone 🍆 8250192130 👅 celebrity escorts servicevipmodelshub1
 
VIP Kolkata Call Girl Salt Lake 👉 8250192130 Available With Room
VIP Kolkata Call Girl Salt Lake 👉 8250192130  Available With RoomVIP Kolkata Call Girl Salt Lake 👉 8250192130  Available With Room
VIP Kolkata Call Girl Salt Lake 👉 8250192130 Available With Roomishabajaj13
 
VIP Kolkata Call Girl Kestopur 👉 8250192130 Available With Room
VIP Kolkata Call Girl Kestopur 👉 8250192130  Available With RoomVIP Kolkata Call Girl Kestopur 👉 8250192130  Available With Room
VIP Kolkata Call Girl Kestopur 👉 8250192130 Available With Roomdivyansh0kumar0
 
Complet Documnetation for Smart Assistant Application for Disabled Person
Complet Documnetation   for Smart Assistant Application for Disabled PersonComplet Documnetation   for Smart Assistant Application for Disabled Person
Complet Documnetation for Smart Assistant Application for Disabled Personfurqan222004
 
定制(CC毕业证书)美国美国社区大学毕业证成绩单原版一比一
定制(CC毕业证书)美国美国社区大学毕业证成绩单原版一比一定制(CC毕业证书)美国美国社区大学毕业证成绩单原版一比一
定制(CC毕业证书)美国美国社区大学毕业证成绩单原版一比一3sw2qly1
 
Packaging the Monolith - PHP Tek 2024 (Breaking it down one bite at a time)
Packaging the Monolith - PHP Tek 2024 (Breaking it down one bite at a time)Packaging the Monolith - PHP Tek 2024 (Breaking it down one bite at a time)
Packaging the Monolith - PHP Tek 2024 (Breaking it down one bite at a time)Dana Luther
 
Sushant Golf City / best call girls in Lucknow | Service-oriented sexy call g...
Sushant Golf City / best call girls in Lucknow | Service-oriented sexy call g...Sushant Golf City / best call girls in Lucknow | Service-oriented sexy call g...
Sushant Golf City / best call girls in Lucknow | Service-oriented sexy call g...akbard9823
 
Russian Call Girls in Kolkata Samaira 🤌 8250192130 🚀 Vip Call Girls Kolkata
Russian Call Girls in Kolkata Samaira 🤌  8250192130 🚀 Vip Call Girls KolkataRussian Call Girls in Kolkata Samaira 🤌  8250192130 🚀 Vip Call Girls Kolkata
Russian Call Girls in Kolkata Samaira 🤌 8250192130 🚀 Vip Call Girls Kolkataanamikaraghav4
 
VIP Call Girls Kolkata Ananya 🤌 8250192130 🚀 Vip Call Girls Kolkata
VIP Call Girls Kolkata Ananya 🤌  8250192130 🚀 Vip Call Girls KolkataVIP Call Girls Kolkata Ananya 🤌  8250192130 🚀 Vip Call Girls Kolkata
VIP Call Girls Kolkata Ananya 🤌 8250192130 🚀 Vip Call Girls Kolkataanamikaraghav4
 
定制(Management毕业证书)新加坡管理大学毕业证成绩单原版一比一
定制(Management毕业证书)新加坡管理大学毕业证成绩单原版一比一定制(Management毕业证书)新加坡管理大学毕业证成绩单原版一比一
定制(Management毕业证书)新加坡管理大学毕业证成绩单原版一比一Fs
 
Git and Github workshop GDSC MLRITM
Git and Github  workshop GDSC MLRITMGit and Github  workshop GDSC MLRITM
Git and Github workshop GDSC MLRITMgdsc13
 

Recently uploaded (20)

Call Girls South Delhi Delhi reach out to us at ☎ 9711199012
Call Girls South Delhi Delhi reach out to us at ☎ 9711199012Call Girls South Delhi Delhi reach out to us at ☎ 9711199012
Call Girls South Delhi Delhi reach out to us at ☎ 9711199012
 
Magic exist by Marta Loveguard - presentation.pptx
Magic exist by Marta Loveguard - presentation.pptxMagic exist by Marta Loveguard - presentation.pptx
Magic exist by Marta Loveguard - presentation.pptx
 
Font Performance - NYC WebPerf Meetup April '24
Font Performance - NYC WebPerf Meetup April '24Font Performance - NYC WebPerf Meetup April '24
Font Performance - NYC WebPerf Meetup April '24
 
Denver Web Design brochure for public viewing
Denver Web Design brochure for public viewingDenver Web Design brochure for public viewing
Denver Web Design brochure for public viewing
 
定制(UAL学位证)英国伦敦艺术大学毕业证成绩单原版一比一
定制(UAL学位证)英国伦敦艺术大学毕业证成绩单原版一比一定制(UAL学位证)英国伦敦艺术大学毕业证成绩单原版一比一
定制(UAL学位证)英国伦敦艺术大学毕业证成绩单原版一比一
 
young call girls in Uttam Nagar🔝 9953056974 🔝 Delhi escort Service
young call girls in Uttam Nagar🔝 9953056974 🔝 Delhi escort Serviceyoung call girls in Uttam Nagar🔝 9953056974 🔝 Delhi escort Service
young call girls in Uttam Nagar🔝 9953056974 🔝 Delhi escort Service
 
Russian Call Girls in Kolkata Ishita 🤌 8250192130 🚀 Vip Call Girls Kolkata
Russian Call Girls in Kolkata Ishita 🤌  8250192130 🚀 Vip Call Girls KolkataRussian Call Girls in Kolkata Ishita 🤌  8250192130 🚀 Vip Call Girls Kolkata
Russian Call Girls in Kolkata Ishita 🤌 8250192130 🚀 Vip Call Girls Kolkata
 
定制(Lincoln毕业证书)新西兰林肯大学毕业证成绩单原版一比一
定制(Lincoln毕业证书)新西兰林肯大学毕业证成绩单原版一比一定制(Lincoln毕业证书)新西兰林肯大学毕业证成绩单原版一比一
定制(Lincoln毕业证书)新西兰林肯大学毕业证成绩单原版一比一
 
Chennai Call Girls Alwarpet Phone 🍆 8250192130 👅 celebrity escorts service
Chennai Call Girls Alwarpet Phone 🍆 8250192130 👅 celebrity escorts serviceChennai Call Girls Alwarpet Phone 🍆 8250192130 👅 celebrity escorts service
Chennai Call Girls Alwarpet Phone 🍆 8250192130 👅 celebrity escorts service
 
VIP Kolkata Call Girl Salt Lake 👉 8250192130 Available With Room
VIP Kolkata Call Girl Salt Lake 👉 8250192130  Available With RoomVIP Kolkata Call Girl Salt Lake 👉 8250192130  Available With Room
VIP Kolkata Call Girl Salt Lake 👉 8250192130 Available With Room
 
VIP Kolkata Call Girl Kestopur 👉 8250192130 Available With Room
VIP Kolkata Call Girl Kestopur 👉 8250192130  Available With RoomVIP Kolkata Call Girl Kestopur 👉 8250192130  Available With Room
VIP Kolkata Call Girl Kestopur 👉 8250192130 Available With Room
 
Complet Documnetation for Smart Assistant Application for Disabled Person
Complet Documnetation   for Smart Assistant Application for Disabled PersonComplet Documnetation   for Smart Assistant Application for Disabled Person
Complet Documnetation for Smart Assistant Application for Disabled Person
 
定制(CC毕业证书)美国美国社区大学毕业证成绩单原版一比一
定制(CC毕业证书)美国美国社区大学毕业证成绩单原版一比一定制(CC毕业证书)美国美国社区大学毕业证成绩单原版一比一
定制(CC毕业证书)美国美国社区大学毕业证成绩单原版一比一
 
Packaging the Monolith - PHP Tek 2024 (Breaking it down one bite at a time)
Packaging the Monolith - PHP Tek 2024 (Breaking it down one bite at a time)Packaging the Monolith - PHP Tek 2024 (Breaking it down one bite at a time)
Packaging the Monolith - PHP Tek 2024 (Breaking it down one bite at a time)
 
Sushant Golf City / best call girls in Lucknow | Service-oriented sexy call g...
Sushant Golf City / best call girls in Lucknow | Service-oriented sexy call g...Sushant Golf City / best call girls in Lucknow | Service-oriented sexy call g...
Sushant Golf City / best call girls in Lucknow | Service-oriented sexy call g...
 
Russian Call Girls in Kolkata Samaira 🤌 8250192130 🚀 Vip Call Girls Kolkata
Russian Call Girls in Kolkata Samaira 🤌  8250192130 🚀 Vip Call Girls KolkataRussian Call Girls in Kolkata Samaira 🤌  8250192130 🚀 Vip Call Girls Kolkata
Russian Call Girls in Kolkata Samaira 🤌 8250192130 🚀 Vip Call Girls Kolkata
 
VIP Call Girls Kolkata Ananya 🤌 8250192130 🚀 Vip Call Girls Kolkata
VIP Call Girls Kolkata Ananya 🤌  8250192130 🚀 Vip Call Girls KolkataVIP Call Girls Kolkata Ananya 🤌  8250192130 🚀 Vip Call Girls Kolkata
VIP Call Girls Kolkata Ananya 🤌 8250192130 🚀 Vip Call Girls Kolkata
 
定制(Management毕业证书)新加坡管理大学毕业证成绩单原版一比一
定制(Management毕业证书)新加坡管理大学毕业证成绩单原版一比一定制(Management毕业证书)新加坡管理大学毕业证成绩单原版一比一
定制(Management毕业证书)新加坡管理大学毕业证成绩单原版一比一
 
Git and Github workshop GDSC MLRITM
Git and Github  workshop GDSC MLRITMGit and Github  workshop GDSC MLRITM
Git and Github workshop GDSC MLRITM
 
Model Call Girl in Jamuna Vihar Delhi reach out to us at 🔝9953056974🔝
Model Call Girl in  Jamuna Vihar Delhi reach out to us at 🔝9953056974🔝Model Call Girl in  Jamuna Vihar Delhi reach out to us at 🔝9953056974🔝
Model Call Girl in Jamuna Vihar Delhi reach out to us at 🔝9953056974🔝
 

UN INCB: RIRs and LEAs

  • 1. 1 Regional Internet Registries (RIRs) and Law Enforcement Agencies UN INCB - Expert Group Meeting on Dangerous Substance Trafficking through Social Media and other Internet-related Services 1 July 2020 Jamie Gillespie, Security Specialist at APNIC jamie@apnic.net
  • 2. whois: Jamie Gillespie • Jamie Gillespie – jamie@apnic.net – Security Specialist @ APNIC – Community engagement, CERT building, InfoSec training, awareness • Work history – 8 years at AusCERT, Australia’s national CERT – Google – Macquarie Telecom / Cloud Services 2
  • 4. Internet Basics • Every device on the Internet needs an address, to be found by other devices – IPv4: 66.220.144.0 – IPv6: 2a03:2880:11:2f83:face:b00c:0:25de • Humans are not good with numbers. We have domain names that translate to address: www.facebook.com → 69.171.239.12 6
  • 5. The Internet is a Series of Networks • The Network of Networks 7
  • 6. Names and Numbers 8 The Internet 2001:0C00:8888:: 2001:0400:: www.apnic.net 202.112.0.46 2001:0400:: My Computer www.apnic.net www.apnic.net 202.112.0.46 2001:0400::
  • 7. 9 Who is Who in the Internet
  • 8. Acronyms and Initialisms • Before we go any further, we should probably define what a bunch of common acronyms and initialisms mean – IETF - Internet Engineering Task Force – IANA - Internet Assigned Numbers Authority – ICANN - Internet Corporate for Assigned Names and Numbers – TLD - Top Level Domain – gTLD - Generic Top Level Domain – ccTLD - Country Code Top Level Domain – RIR - Regional Internet Registry 10
  • 9. Where do IP addresses come from? 11
  • 10. RIRs from a Global Perspective 12
  • 12. How APNIC and the RIRs Operate • APNIC is the Regional Internet Registry (RIR) for the Asia Pacific region • Membership-based, not-for-profit • Industry self-regulatory body – Open – Consensus-based – Transparent • Delegates and manages Internet number resources – IPv4 and IPv6 addresses • Diagram on next slide – AS numbers 14
  • 13. APNIC’s Roles and Services • Delegates and manages Internet resources – IPv4 & IPv6 addresses, AS Numbers • Maintains the APNIC Whois Database • Manages reverse DNS delegations – But is NOT a domain name registry • Facilitates IP address policy development • Provides capacity building through training, workshops, conferences, fellowships, and grants – resource management, routing, IPv6 deployment, and security • Research, measurements, publications • Supports Internet infrastructure development – Root server deployment, Internet Exchange Points (IXPs) 15
  • 14. So who gets IP address and AS numbers? • National Internet Registry • Telcos, ISPs, Mobile Operators • Hosting Company (Amazon/AWS, Azure, GCP, Linode) • Universities, Government Departments, Banks 16
  • 15. How APNIC and the RIRs work with LEAs • APNIC provides LEAs with publicly available registry information to help them respond to malicious activity on the Internet • APNIC coordinates with the global technical community to share information and develop trusted relationships to ensure coordinated responses to major network security incidents • APNIC has dedicated legal and network security experts to support LEA requests • APNIC’s legal and network security experts provide training to LEOs, investigators, and the justice sector (in addition to network operators and CSIRTs) 18
  • 17. Working with INTERPOL/Europol/FBI Improving Whois data quality and accuracy 20
  • 18. How LEAs can Participate with RIRs • Attend RIR and other industry meetings – Each RIR runs open meeting and conferences each year – Network Operator Groups (NOGs) – Trusted community conferences (UE / RISE, FIRST, M3AAWG…) • Request training sessions with RIRs • Participate in the Policy Development Process – Submit policy proposals, discuss other proposals • Report invalid contacts from whois records 21
  • 20. Important – About Whois DB • Number vs Domain Whois o Two different types of databases o APNIC and the other RIRs operate the numbers whois DBs o Top level domains and registrars operate domain whois DBs • Other Databases – Reputation – Data enrichment • e.g. http://www.team-cymru.com/IP-ASN-mapping.html 26
  • 21. What are the numbers Whois databases? • Public network management database – Operated by Internet Registries (like APNIC!) • Public data only – Tracks network resources • IP Addresses, ASNs, Reverse DNS Delegations, Routing Policies • Records administrative information – Contact information (persons/roles) – Authorization for updating this info – Network abuse handling (IRT) 27
  • 23. Whois Database Accuracy • Accurate & Reliable • Responsiveness – Stop / Mitigate on going attack – Reduce impact / exposure of incidents – Do not have to go through various loops & hoops • Ideally – Ability to provide assistance or do something about it – Escalation • Features – Mechanism for reporting invalid contacts – Trigger other actions • Other Databases? – FIRST, APCERT, Trusted Introducer, etc 32 irt: IRT-APNIC-IS-AP address: South Brisbane, Australia e-mail: helpdesk@apnic.net abuse-mailbox: helpdesk@apnic.net admin-c: AIC1-AP tech-c: AIC1-AP auth: # Filtered remarks: APNIC Infrastructure Services mnt-by: MAINT-APNIC-IS-AP changed: hm-changed@apnic.net 20110704 source: APNIC
  • 24. Which Whois to Use? • APNIC – Asia Pacific – APNIC Whois Database (previous slide) • AFRINIC – Africa – https://www.afrinic.net/whois-web/public • RIPE NCC – Europe, Central Asia and the Middle East – https://apps.db.ripe.net • ARIN – Northern America – http://whois.arin.net • LACNIC – Latin America and the Caribbean – http://lacnic.net/cgi-bin/lacnic/whois 33 Regional Internet Registries (RIRs)
  • 25. The APNIC Whois Database • Holds IP address records within the AP region • Can use this database to track down the source of the network abuse – IP addresses, ASNs, Reverse Domains, Routing policies • Can find contact details of the relevant network administrators – not the individual users – use administrators log files to contact the individual involved 35
  • 26. Whois Database Access • APNIC website – https://www.apnic.net/manage-ip/using-whois/searching • Whois search tool – https://wq.apnic.net/whois-search/static/search.html • Whois client, query tool, or RDAP – Point the tools at whois.apnic.net 36
  • 27. What if Whois info is invalid? • Members (ISPs and Network Operators) are responsible for reporting changes to APNIC – Under formal membership agreement • Anyone can report invalid ISP/NetOp contacts to APNIC – http://www.apnic.net/invalidcontact – APNIC will contact member and update registration details • Each RIR has a similar process for handling invalid contacts 37
  • 30. Future of Whois • RDAP – Registration Data Access Protocol • RDAP is a newer standard for accessing whois information – Uses standardised queries and responses (JSON) – Internationalisation – Redirection for seamless referrals to other registries • Working now but still under development for NIR data – www.apnic.net/about-apnic/whois_search/about/rdap/ – www.openrdap.org (GoLang client) • APNIC is also developing a Network ToolBox – https://netox.apnic.net (let me know your feedback & suggestions!) 42
  • 31. Reverse DNS • Reverse DNS translates the IP number back to a name • Reverse DNS answers are optional for network operators – The internet works without it dig -x 202.55.92.5 ;; ANSWER SECTION: 5.92.55.202.in-addr.arpa. 5 IN PTR fnet5-m92-access.vqbn.com.sg. • You can now use whois and other tools/techniques to look up contact details for vqbn.com.sg 57
  • 32. Current Challenges • Fraudulent acquisition and transfer of IPv4 addresses • Route hijacking • Leasing, buying, and selling of IPv4 addresses outside of the registry system • Invalid contact information 58