How registrars tackle domain name abuse

By Ellen Messmer, Network World |  Security, cybersquatter, domain name Add a new comment

Cybercriminals worldwide are amassing domain names to keep their botnet and phishing operations a step ahead of authorities

America’s 10 most-wanted botnets

To obscure their tracks, the criminals register the domain names using phony information, pay with stolen credit cards and hack into legitimate domain-name accounts. Adding to the problem of domain-name abuse, some rogue registrars often look the other way as the money rolls in. (See related story, “Domain-name abuse proliferates; rogue registrars turn a blind eye”) 

Today’s cosmopolitan criminals might use “a registrar in China and a Web-hosting company in Russia and a registry in Ireland,” says Ram Mohan, CTO at Dublin-based registry services provider Afilias. The target is usually “a consumer in America.”

Accredited by ICANN for the .info generic top-level domain (gTLD), Afilias helped organize the Registry Internet Safety Group to find ways to improve security.

Mohan says Afilias has seen about 250,000 domain names taken down in the past 2.5 years because they were deemed to be maliciously used. At first the registrars Afilias works with were not too happy to see domain names suspended, but many have come around to see the wisdom in taking action to stop perceived criminal activity, he says.

In the past, standard contracts between ICANN and registrars didn’t address domain-name abuse head-on. (Mohan estimates there about 2,000 registrars and retail channels for domain names globally today.) But Afilias successfully lobbied to have the standard contracts amended so that stringent actions against domain-name abuse could be taken, he says.

Registry services provider Neustar (accredited by ICANN for the .biz gTLD) is also a big believer in tackling domain-name abuse, which after all, hurts the bottom line. Three years ago, Neustar hired a legal team to handle domain abuse questions and set up an internal, isolated networking lab to make determinations to a “near certainty” about a domain name being used for objectionable purposes, says Jeff Neuman, vice president of law and policy at Neustar.

Under its contracts with registrars and ICANN, Neustar can proactively say to a registrar, with a full report, “you have 12 hours to take down that domain name or we will do it,” he says. ICANN has a more informal process for trying to curb domain-name abuse, but that may eventually change, Neuman believes.

Many security researchers today are inclined to blame a lot of domain-name abuse on “rogue registrars” around the world that are said to look the other way when dealing with criminals.

For instance, .cn, the country-code domain for the People’s Republic of China, has emerged as a popular choice for domain-name abuse. For country-code top-level domains, each country through a designated organization directly accredits registrars for the ccTLD, though those registrars may also be accredited by ICANN for gTLDs like .com and .info.

Two ICANN-accredited registrars, Beijing-based Xin Net Technology Corp. and Beijing Innovative Linkage, among other registrars based in China, have gained reputations in some circles as rogue registrars because of the large amount of malicious domains being traced to them over the past year.

ICANN says complaints it received related to inaccurate or missing Whois database information and Beijing Innovative -- which initially failed to respond to ICANN inquiries in a timely manner -- led ICANN to issue the Chinese registrar a “notice of breach” decision last September, and a remediation plan.

Mohan says it’s important do the analysis to understand the source of domain-name abuse, but critics should also consider evidence that Chinese registrars are being targeted because there’s a lot of growth in China and “criminals are hiding in that growth.”

Mohan was in Beijing just a month ago discussing cybercrime for three hours with Mao Wei, the director of China Internet Network Information Center, the state-run registry for .cn, which is under the control of the Ministry of Information Industry. Mohan also spent time with Chinese registrars. “The Chinese government is very strongly aware of this problem,” Mohan says.

Just this week, McAfee touched on the China question in a report about e-mail spam that found high-volume, Chinese URL-based “Canadian Pharmacy” spam has started getting blocked amazingly fast, something McAfee never saw happen before.

    Add a comment

    Post a comment using one of these accounts
    Or join now
    At least 6 characters

    Note: Comment will appear soon after you have activated your account.
    Obscene/spam comments will be removed and accounts suspended.
    The information you submit is subject to our Privacy Policy and Terms of Service.

    ITworld LIVE

    SecurityWhite Papers & Webcasts

    White Paper

    Overcome Top 7 Admin Challenges of Active Directory

    As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable, enforceable processes that reduces administrative overhead and enables robust, customizable reporting and auditing capabilities. Brought to you by NetIQ.

    White Paper

    Insiders Can Ruin Your Company. Take Action.

    Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in organizations worldwide. This white paper from NetIQ, discusses key technology solutions that help to prevent and detect insider threats.

    White Paper

    Top Solutions and Tools to Prevent Devastating Malware

    Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring (FIM) tools that provide immediate alerts. This white paper has been brought to you by NetIQ, the leader in solving complex IT challenges.

    White Paper

    Streamline Compliance and Increase ROI

    Streamline, simplify, and automate compliance related activities; especially those that impact multiple business units. This white paper from NetIQ, outlines solutions that will help your business gain the maximum return on investment possible while aligning your compliance programs.

    White Paper

    X-Ray of the PCI Process-4 Proactive Steps

    This white paper from Forrester Research Inc., helps break PCI into understandable components. Security and risk professionals will gain knowledge and insight into creating a compliant and secure IT environment. Follow these four proactive steps now before your next audit. Brought to you by NetIQ.

    See more White Papers | Webcasts

    Ask a question

    Ask a Question