<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>experiment, three &#187; security</title>
	<atom:link href="http://experimenthree.wordpress.com/tag/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://experimenthree.wordpress.com</link>
	<description>The blog you couldn't live without</description>
	<lastBuildDate>Thu, 05 Nov 2009 09:16:26 +0000</lastBuildDate>
	<generator>http://wordpress.com/</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<cloud domain='experimenthree.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://www.gravatar.com/blavatar/7dd08251b23684cd89b03d5604fc5953?s=96&#038;d=http://s.wordpress.com/i/buttonw-com.png</url>
		<title>experiment, three &#187; security</title>
		<link>http://experimenthree.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://experimenthree.wordpress.com/osd.xml" title="experiment, three" />
		<item>
		<title>Italian TLD and malicious web sites</title>
		<link>http://experimenthree.wordpress.com/2008/06/12/italian-tld-and-malicious-web-sites/</link>
		<comments>http://experimenthree.wordpress.com/2008/06/12/italian-tld-and-malicious-web-sites/#comments</comments>
		<pubDate>Thu, 12 Jun 2008 04:43:16 +0000</pubDate>
		<dc:creator>alezzandro</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[dns]]></category>
		<category><![CDATA[internet]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[typosquatting]]></category>

		<guid isPermaLink="false">http://experimenthree.wordpress.com/?p=40</guid>
		<description><![CDATA[Mapping the Mal Web, Revisited (McAfee, June 4).
A new security report from McAfee has just been released on the spread of malicious web sites among different TLDs. Very informative and detailed, the report integrates last year report. Some of the key findings:

.ro (Romania) and .ru (Russia) are the most risky European TLDs, i.e., the probability [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=experimenthree.wordpress.com&blog=4535657&post=40&subd=experimenthree&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p><span style="font-family:trebuchet ms;"><a href="http://us.mcafee.com/en-us/local/docs/Mapping_Mal_Web.pdf?cid=45044">Mapping the Mal Web, Revisited</a> (McAfee, June 4)</span>.</p>
<p><span style="font-family:trebuchet ms;">A new security report from McAfee has just been released on the spread of malicious web sites among different TLDs. Very informative and detailed, the report integrates last year report.</span> <span style="font-family:trebuchet ms;">Some of the key findings:</span></p>
<ul>
<li><span style="font-family:trebuchet ms;">.ro (Romania) and .ru (Russia) are the most risky European TLDs, i.e., the probability of finding a malicious web site is higher if surfing one of those TLDs.</span></li>
<li><span style="font-family:trebuchet ms;">Risk related to .biz (business) and .cn (China) is also increasing (if compared to last year)</span></li>
<li><span style="font-family:trebuchet ms;">.it (Italy) has worsened, but is still &#8220;a safe place&#8221;</span></li>
<li><span style="font-family:trebuchet ms;color:#ff0000;">.hk (Hong Kong) is the riskiest TLDs</span></li>
</ul>
<p><span style="font-family:trebuchet ms;">The “Hong Kong” case, in particular, is worth a closer attention:</span><span style="font-family:trebuchet ms;"> </span></p>
<blockquote><p><span style="font-style:italic;font-family:trebuchet ms;">Bonnie Chun, an official [from the .hk] TLD, acknowledged that they had made some decisions that inadvertently encouraged the scammers:</span><br />
<span style="font-style:italic;font-family:trebuchet ms;">1 . “We enhanced our domain registration online process thus making it more user-friendly. Instances include the capability for registering several domains at one time, auto-copying of administrative contact to technical contact and billing contact, etc. Phishers usually registered eight or more domains at one time. </span><br />
<span style="font-style:italic;font-family:trebuchet ms;">2 . We offered great domain registration discounts, such as buy-one, get-two domains.</span><br />
<span style="font-style:italic;font-family:trebuchet ms;">3 . Our overseas service partners promoted .hk domains in overseas markets.”</span></p></blockquote>
<p><span style="font-family:trebuchet ms;">In a <a href="http://esperimentotre.blogspot.com/2008/05/casi-di-phishing-in-aumento-in-uk.html">previous post</a> I talked about the recent <a href="http://blog.nominet.org.uk/tech/2008/05/23/recent-uk-phishing-activity/">increased phishing activity</a> in the .uk registry, which, in that particular case, has taken advantage from Nominet&#8217;s automatic <a href="http://www.nominet.org.uk/registrars/systems/auto/">registration process</a>.<br />
</span><br />
<span style="font-family:trebuchet ms;">Other country, other problem: the <a href="http://www.nic.it/">.it registry</a> will implement automatic registration procedures by the end of the year; and I read, a couple of weeks ago on <a href="http://www.blorigo.net/ricerca-e-business-italians-do-it-better">Swartzy’s blog</a>, that the IIT/CNR is also launching an advertisement campaign for .it domains.</span></p>
<p><span style="font-family:trebuchet ms;">I am curious to see if, in analogy to what happened in Hong Kong, we will see an increase of the malicious activity in the .it TLD.</span></p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/experimenthree.wordpress.com/40/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/experimenthree.wordpress.com/40/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/experimenthree.wordpress.com/40/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/experimenthree.wordpress.com/40/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/experimenthree.wordpress.com/40/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/experimenthree.wordpress.com/40/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/experimenthree.wordpress.com/40/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/experimenthree.wordpress.com/40/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/experimenthree.wordpress.com/40/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/experimenthree.wordpress.com/40/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/experimenthree.wordpress.com/40/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/experimenthree.wordpress.com/40/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=experimenthree.wordpress.com&blog=4535657&post=40&subd=experimenthree&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://experimenthree.wordpress.com/2008/06/12/italian-tld-and-malicious-web-sites/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/8204b303bd6f96dd46394785d131ad2e?s=96&#38;d=http%3A%2F%2F0.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96" medium="image">
			<media:title type="html">alezzandro</media:title>
		</media:content>
	</item>
		<item>
		<title>DNS Ops Workshop</title>
		<link>http://experimenthree.wordpress.com/2008/06/11/dns-ops-workshop/</link>
		<comments>http://experimenthree.wordpress.com/2008/06/11/dns-ops-workshop/#comments</comments>
		<pubDate>Wed, 11 Jun 2008 13:19:00 +0000</pubDate>
		<dc:creator>alezzandro</dc:creator>
				<category><![CDATA[dns]]></category>
		<category><![CDATA[internet]]></category>
		<category><![CDATA[new york]]></category>
		<category><![CDATA[oarc]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[ripe]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[typosquatting]]></category>
		<category><![CDATA[UK]]></category>
		<category><![CDATA[web]]></category>

		<guid isPermaLink="false">http://experimenthree.wordpress.com/2008/06/11/dns-ops-workshop/</guid>
		<description><![CDATA[As promised, I post a report of the DNS Ops workshop I attended last week. The workshop has been very interesting, though a few talks were a bit too technical for me, which I only have a partial knowledge of DNS operations. Following, then, you will find a non-comprehensive list of &#8220;impressions&#8221; rather than a [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=experimenthree.wordpress.com&blog=4535657&post=25&subd=experimenthree&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p><span style="font-family:trebuchet ms;">As <a href="http://esperimentotre.blogspot.com/2008/06/grazie-alle-lancette-che-sono-tornate.html">promised</a>, I post a report of the <a href="http://public.oarci.net/dns-operations/workshop-2008/agenda/">DNS Ops workshop</a> I attended last week. The workshop has been very interesting, though a few talks were a bit too technical for me, which I only have a partial knowledge of DNS operations. Following, then, you will find a non-comprehensive list of &#8220;impressions&#8221; rather than a detailed report.</p>
<p>&#8212;</p>
<p></span><span style="font-family:trebuchet ms;"><span style="font-weight:bold;">A Statistical Approach to Typosquatting</span><br />Of course <img src='http://s.wordpress.com/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' />  I will start from my talk, which reports the preliminary results of the research on typosquatting I have been conducting recently. The slides can be found <a href="http://public.oarci.net/files/dnsops-2008/Linari-Typosquatting.pdf">here</a> (and <a href="https://www.centr.org/main/4326-CTR/version/default/part/AttachmentData/data/Tech18%20-%20Linari%20-%20typosquatting-uk-registry3.pdf">here</a> as well, as I gave the same talk at the <a href="https://www.centr.org/main/meetings/3612-CTR.html">Centr technical meeting</a> in May).</p>
<p>The talk seems to have generated a bit of interest in the audience, though I think it suffered a bit from the fact that these are &#8220;early results&#8221; and much work still needs to be done before we can claim we really understand what typosquatting is (at least from a technical point of view). The talk also raised a bit of questioning about Nominet&#8217;s involvement in typosquatting. Just to be clear, at the moment Nominet is interested in my work only from a research point of view and is not taking any position in favour or against any registrar, registrant or any other party that might think to be the object of my work.</span><span style="font-family:trebuchet ms;"></span><span style="font-family:trebuchet ms;"></p>
<p><span style="font-weight:bold;">DNS monitoring, use and misuse</span><br />According to <a href="http://public.oarci.net/files/dnsops-2008/Castro-Heavy-hitters.pdf">Sebastian Castro</a> (CAIDA), in 2007 only <span style="color:rgb(204, 0, 0);">510 unique IP addresses generated 30% of the traffic at the root servers</span> and 144 of them (called Heavy Hitters) sent more than 10 queries/sec and in 11 cases more than 40 queries/sec.</p>
<p>This are impressive numbers which might tell something about the kind of traffic that daily takes place in the Internet.<br /></span><br /><span style="font-family:trebuchet ms;">Later on, <a href="http://public.oarci.net/files/dnsops-2008/Toyono-OCN-caching.pdf">Shintaro Nakagami</a><span style="font-family:trebuchet ms;"> from NTT</span> Communications, one of the major ISPs in Japan, reported that <span style="color:rgb(204, 0, 0);">only 15% of the queries hitting their name servers were legitimate</span>. This doesn&#8217;t mean that the other are necessarily malicious, for example, many of them are simply malformed queries or are generated by misconfigured web servers, however&#8230;</span></p>
<p><span style="font-family:trebuchet ms;">Finally, <a href="http://public.oarci.net/files/dnsops-2008/NIDA-Monitoring.pdf">Young Sun La</a> (NIDA, Korea) showed an impressive tool that they use at NIDA for monitoring queries to the .kr name servers in real time. It even sends sms&#8217; to sysadmins if an urgent problem arises. Have a look at the slides for an idea of how it works. I might have heard that the software will be released for download, but I might have misunderstood.</span></p>
<p><span style="font-weight:bold;font-family:trebuchet ms;">Heatmaps</span><br /><span style="font-family:trebuchet ms;">How do you conveniently represent the IPv4 space? With a <a href="http://maps.measurement-factory.com/">Hilbert Curve</a>, for example, or, as </span><span style="font-family:trebuchet ms;"><a href="http://public.oarci.net/files/dnsops-2008/Arends-Heatmaps.pdf">Roy Arends</a> (Nominet) </span><span style="font-family:trebuchet ms;">suggests, with a Z-order curve. The resulting graph is more intuitive to read and can easily be extended to work in a 3D space.</p>
<p>Check out his <a href="http://blog.nominet.org.uk/tech/2008/04/01/ipv4-heat-maps/">interactive tool</a> (from Nominet website) and his <a href="http://public.oarci.net/files/dnsops-2008/Arends-Heatmaps.pdf">slides</a>. In particular, go to slide number 9 and watch the heatmap of&#8230; women below 30 and earning more 100000$/year in Manhattan!!</span></p>
<p><span style="font-weight:bold;font-family:trebuchet ms;">Privacy issues in DNS</span><br /><span style="font-family:trebuchet ms;"><a href="http://public.oarci.net/files/dnsops-2008/Nohl-DNS-privacy.pdf">Karsten Nohl</a> (University of Virginia) talked about the privacy issues related to the use of DNS caches. When users query the DNS they leave pieces of information in many caches and they have to trust several entities, ISPs, registries, backbone operators, etcc, that their information will not be released, sold, etc.</span></p>
<p><span style="font-family:trebuchet ms;">DNS operators cache the results of user queries, i.e., the IP corresponding to certain URLs in order to retrieve them more efficiently. This information is anonymous, i.e., they do not register the IP who made the query (in theory), but in practice certain URLs are used only by one (or a small subset of) person(s). At present, it is relatively easy for a malicious party to trace the online behaviour of some user by querying specific DNS servers only and check whether a specific URL is present in their cache.</span></p>
<p><span style="font-family:trebuchet ms;">Such an attack can be used to identify the individuals that access a specific web site: knowing the IP gives the geographic localisation of a user, but knowing his/her online behaviour might disclose much more personal information. Alternatively, it might be possible to track a specific user.</span></p>
<p><span style="font-family:trebuchet ms;">This scenario might become even more critical with the large-scale deployment of RFIDs. RFIDs have unique identifiers but are too small to store information (e.g., product information, price, etc) and they will use the DNS to look up for this data. Then, RFIDs (which have unique identifiers) will be indexed by the DNS and it will be easy to identify single users.</span></p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/experimenthree.wordpress.com/25/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/experimenthree.wordpress.com/25/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/experimenthree.wordpress.com/25/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/experimenthree.wordpress.com/25/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/experimenthree.wordpress.com/25/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/experimenthree.wordpress.com/25/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/experimenthree.wordpress.com/25/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/experimenthree.wordpress.com/25/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/experimenthree.wordpress.com/25/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/experimenthree.wordpress.com/25/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/experimenthree.wordpress.com/25/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/experimenthree.wordpress.com/25/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=experimenthree.wordpress.com&blog=4535657&post=25&subd=experimenthree&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://experimenthree.wordpress.com/2008/06/11/dns-ops-workshop/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/8204b303bd6f96dd46394785d131ad2e?s=96&#38;d=http%3A%2F%2F0.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96" medium="image">
			<media:title type="html">alezzandro</media:title>
		</media:content>
	</item>
	</channel>
</rss>