<html><body><font face="Tahoma" size="2"><div><font size="3">Excuse me if this is too far off base. It does serve as a quick primer on the kinds of threats that the DNS system is up against on a daily basis. </font><br></div><div><br></div><div>As we work within the ICANN remit it might be useful to on occasion look out there at the ongoing daily threats to the security and stability of the DNS system. We are keenly aware of when various actors "turn off" the Internet but most of us are less aware of the other forms of attack on DNS security and stability. Here is a link to, and a few words from, the U.S. Department of Homeland Security on recent attacks on the DNS system. <br></div><div><br></div><div><font size="3"><a href="https://cyber.dhs.gov/ed/19-01/">https://cyber.dhs.gov/ed/19-01/</a><br></font></div><div><font size="3"><br></font></div><div><br><font size="3">This page contains a web-friendly version of the Cybersecurity and Infrastructure Security Agency’s <a href="https://cyber.dhs.gov/assets/report/ed-19-01.pdf">Emergency Directive 19-01</a>, “<em>Mitigate DNS Infrastructure Tampering</em>”.</font></div><div><font size="3"><br></font></div><div class="rss_title" style="font-weight: bold; font-size: 120%; margin: 0 0 0.3em; padding: 0;"><i><b><font size="3">Excerpts: </font></b></i><a href="https://www.us-cert.gov/ncas/current-activity/2019/01/22/CISA-Emergency-Directive-DNS-Infrastructure-Tampering">CISA Emergency Directive on DNS Infrastructure Tampering</a></div><div>
<div class="rss_pub_date" style="font-size: 90%; font-style: italic; color: #666666; margin: 0 0 0.3em; padding: 0;">01/22/2019 06:48 PM EST</div>
<br>
Original release date: January 22, 2019<br>
<p>The U.S. Department of Homeland Security (DHS) Cybersecurity and
Infrastructure Security Agency (CISA) issued an emergency directive to
address ongoing incidents associated with global Domain Name System
(DNS) infrastructure tampering. CISA is aware of multiple executive
branch agency domains that were impacted by the tampering campaign and
has notified the agencies that maintain them. The directive requires
Federal agencies to take specific steps and comply with reporting
procedures to mitigate risks from undiscovered tampering, prevent
illegitimate DNS activity, and detect unauthorized certificates.</p>
<p>Federal agencies should review <a href="https://cyber.dhs.gov/ed/19-01/">Emergency Directive 19-01</a> for required actions and reporting procedures. <br></p><h3 id="background">Background</h3>
<p>In coordination with government and industry partners, the Department
of Homeland Security (DHS) Cybersecurity and Infrastructure Security
Agency (CISA) is tracking a series of incidents<sup id="fnref:1"><a href="https://cyber.dhs.gov/ed/19-01/#fn:1" class="footnote">1</a></sup>
involving Domain Name System (DNS) infrastructure tampering. CISA is
aware of multiple executive branch agency domains that were impacted by
the tampering campaign and has notified the agencies that maintain them.</p>
<p>Using the following techniques, attackers have redirected and
intercepted web and mail traffic, and could do so for other networked
services.</p>
<ol><li>The attacker begins by compromising user credentials, or obtaining
them through alternate means, of an account that can make changes to
DNS records.</li><li>Next, the attacker alters DNS records, like Address (A), Mail
Exchanger (MX), or Name Server (NS) records, replacing the legitimate
address of a service with an address the attacker controls. This enables
them to direct user traffic to their own infrastructure for
manipulation or inspection before passing it on to the legitimate
service, should they choose. This creates a risk that persists beyond
the period of traffic redirection.</li><li>Because the attacker can set DNS record values, they can also
obtain valid encryption certificates for an organization’s domain names.
This allows the redirected traffic to be decrypted, exposing any
user-submitted data. Since the certificate is valid for the domain, end
users receive no error warnings.</li></ol>
<p>To address the significant and imminent risks to agency information
and information systems presented by this activity, this emergency
directive requires the following near-term actions to mitigate risks
from undiscovered tampering, enable agencies to prevent illegitimate DNS
activity for their domains, and detect unauthorized certificates. <br></p><p>See: <a href="https://cyber.dhs.gov/ed/19-01/">Emergency Directive 19-01</a></p><p>Posted by: Sam L. NPOC<br></p><p><br></p></div></font></body></html>