Public Comment on the Statistical Analysis of DNS Abuse in gTLDs (SADAG) Report
Nick Shorey
lists at NICKSHOREY.COM
Thu Sep 21 18:38:04 EEST 2017
Hi everyone,
My apologies that I have yet to have time to provide an in-depth response
on this issue - unfortunately tackling issues of DNS abuse in the $dayjob
has impeded my spare time today - oh the irony!!
My initial reaction is that we need to consider what we recommend as a
result of this study.
It's clear the report has highlighted issues of concern, areas of
contention, and elements where some further analysis maybe required. As
just one example, when I held discussions with the authors of this study
during Johannesburg, I noted there was a gap in analysis of the
relationship between WHOIS privacy services and DNS abuse, which may
broaden insight.
There also seemed to be a concentration of abuse within the new gTLD space
to particular TLDs - further in-depth analysis probably needed to
understand the root causes - more engagement with cyber security companies
to better understand criminal modus operandi would be useful.
So what questions might we consider regarding next steps? Couple of
thoughts:
- Should a further gTLD round (or continuous registration process) be
opened until further analysis and reviews have been completed?
- Should ICANN continue to gather and publish such data (i.e. through
things like the Domain Abuse Activity Reporting Tools) on this issue, and
how should this feed into Compliance processes?
- How can this and future studies inform the policy making process?
Hope this is helpful!
Best,
Nick
*Nick Shorey*
Phone: +44 (0) 7552 455 988
Email: lists at nickshorey.com
Skype: nick.shorey
Twitter: @nickshorey
LinkedIn: www.linkedin.com/in/nicklinkedin
Web: www.nickshorey.com
On Wed, Sep 20, 2017 at 10:20 PM, Enrique Chaparro <
echaparro at vialibre.org.ar> wrote:
> Let me add that the three hypotheses are logical fallacies. Of course,
> if your starting point is a logical fallacy you can prove anything you
> want, as we clearly see everyday. As always, the old research
> guideline stands: “correlation is not causation”.
> For instance, a new critical bug in bind (which has a tearful history of
> bugs) could cause a surge in DHS hijacking anytime, completely
> out of the hypotheses.
>
> On the other hand, the IP constituency's insistence on measures
> that go in the direction of centralising more and more the Internet's
> critical sttucture shouldn't be a surpise for anyone.
>
> Regards from the Far South,
>
> Enrique
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.ncsg.is/pipermail/ncsg-discuss/attachments/20170921/ceb6bb66/attachment.htm>
More information about the Ncsg-discuss
mailing list