icann s monitoring system api
play

ICANNs Monitoring System API Focus on ccTLDs Francisco Arias Tech - PowerPoint PPT Presentation

ICANNs Monitoring System API Focus on ccTLDs Francisco Arias Tech Day 26 June 2017 | 1 Agenda ICANNs SLAM system Statistics MoSAPI Zone File Access | 2 ICANNs SLA Monitoring (SLAM) system | 3 | 3 What is the SLAM?


  1. ICANN’s Monitoring System API Focus on ccTLDs Francisco Arias Tech Day 26 June 2017 | 1

  2. Agenda ¤ ICANN’s SLAM system ¤ Statistics ¤ MoSAPI ¤ Zone File Access | 2

  3. ICANN’s SLA Monitoring (SLAM) system | 3 | 3

  4. What is the SLAM? • Zabbix monitoring platform with additional custom plugins and code available at: svn://svn.zabbix.com/branches/2.0.rsm/opt/ zabbix • Probe node network of ~40 probe nodes • Designed to avoid false positives • Consolidates data points in a rolling week basis | 4

  5. How it works? | 5

  6. DNS test • One non-recursive DNS query sent every minute from each active probe node: o for A record for QNAME www.zz--icann-monitoring.<TLD> o to every IP-address/NS pair of <TLD> • If DNSSEC is offered: o NSEC/NSEC3 and the signatures are verified o The chain of trust is validated against the root zone KSK | 6

  7. DNS test • Examples of failure criteria o No reply o Invalid reply (e.g., RCODE/SERVFAIL) o Malformed or invalid responses o Broken chain of trust o NSEC and NSEC3 errors | 7

  8. Statistics | 8 | 8

  9. Some data points • 273 ccTLD’s DNS failures have reached 4 hours or more in a rolling week period • 60 of 295 ccTLDs have reached 4 hours of downtime at least one time in a rolling week • 178 of 295 (60%) ccTLDs have had at least one DNS service down event o 34 of 48 (70%) IDNs ccTLDs o 144 of 247 (58%) ASCII ccTLDs • 5 ccTLDs are down most of the time Note: Data from 1 October 2014 to 31 May 2017 | 9

  10. ccTLD’s DNS downtime incidents of 4+ hours | 10

  11. MoSAPI ICANN’s Monitoring System API | 11 | 11

  12. MoSAPI • REST API methods to retrieve data collected by the SLAM in ~real-time • In pilot mode at the moment • A registry can only see their own performance data | 12

  13. MoSAPI - Credentials • Username, Password, List of IP address blocks (IPv4 and/or IPv6) • Current pilot only supports IPv4 transport • Interested ccTLDs can request access through ICANN’s Global Support Center at globalSupport@icann.org • Plan to authenticate requestor relying on the ccTLD contacts in IANA | 13

  14. Zone File Access | 14 | 14

  15. Zone File Access • ICANN is interested in periodic access to ccTLD’s zone files • Interest on statistics like: o DNSSEC penetration, o IDNs penetration, o Active names; and o Input to the DAARS • Interested ccTLDs please contact us at globalSupport@icann.og | 15

  16. Engage with ICANN Thank You and Questions Visit us at icann.org Email: globalSupport@icann.org @icann facebook.com/icannorg youtube.com/icannnews flickr.com/icann linkedin/company/icann slideshare/icannpresentations soundcloud/icann | 16

Download Presentation
Download Policy: The content available on the website is offered to you 'AS IS' for your personal information and use only. It cannot be commercialized, licensed, or distributed on other websites without prior consent from the author. To download a presentation, simply click this link. If you encounter any difficulties during the download process, it's possible that the publisher has removed the file from their server.

Recommend


More recommend