whois accuracy
play

WHOIS ACCURACY San Jose, Costa Rica September 29, 2016 Not only - PowerPoint PPT Presentation

WHOIS ACCURACY San Jose, Costa Rica September 29, 2016 Not only RIR community, but public uses of WHOIS : Ensuring IP address holders worldwide are properly registered so individuals, consumers and the public are empowered to resolve


  1. WHOIS ACCURACY San Jose, Costa Rica September 29, 2016

  2. Not only RIR community, but public uses of WHOIS : • Ensuring IP address holders worldwide are properly registered so individuals, consumers and the public are empowered to resolve abusive pracBces that impact safety and security • Assuring the security and reliability of the network • AssisBng businesses, consumer groups, healthcare organizaBons and other organizaBons in combaBng abuse • AssisBng organizaBons responsible for the safety of the general public

  3. • WHOIS searches are one of many tools invesBgators use in addiBon to: § RouBng tables/services § Commercially available tools § Internally developed tools and services • However, WHOIS is the most common star-ng point for most invesBgaBons

  4. • IP Address Chain of Custody Accuracy Issue § Sub-allocaBon informaBon of ISPs many Bmes removed from original delegaBon can be inaccurate and old data § Each RIR tends to have different policies and requirements for what informaBon to retain regarding sub-allocaBons • Problem expanding § IPv6 § IETF MODERN Protocol § IOT • Seeking industry solu-on § Work with LACNIC community to for best soluBon

  5. From a public safety perspecBve, failure to have accurate WHOIS informaBon can present the following challenges: • Ability of public safety agencies to quickly idenBfy resources used in abusive acBviBes • Wasted network operator resources dedicated to responding to potenBally misdirected legal requests • Domain and IP address hijacking resulBng in the potenBal use of those domain names and number resources for criminal acBvity

  6. Case Examples Chief Erick Lewis Hernández Judicial Cyber Investigative Section San Jose, Costa Rica

  7. Goal: Work with all 5 RIRs on WHOIS accuracy to ISP closest to the bad actor Other RIR efforts: ARIN: DEA, FBI and RCMP RIPE NCC: Europol and Spanish Guardia Civil AfriNIC: African Union APNIC: Sri Lanka Police

  8. THANK YOU

  9. Office of Investigative Technology Supervisory Special Agent Thomas Walden Section Chief Technical Support Section

Download Presentation
Download Policy: The content available on the website is offered to you 'AS IS' for your personal information and use only. It cannot be commercialized, licensed, or distributed on other websites without prior consent from the author. To download a presentation, simply click this link. If you encounter any difficulties during the download process, it's possible that the publisher has removed the file from their server.

Recommend


More recommend