ICANN Remit: Security & Stability of the DNS System
Sam Lanfranco
lanfran at YORKU.CA
Tue Jan 22 20:44:02 EET 2019
Excuse me if this is too far off base. It does serve as a quick primer on
the kinds of threats that the DNS system is up against on a daily basis.
As we work within the ICANN remit it might be useful to on occasion look
out there at the ongoing daily threats to the security and stability of the
DNS system. We are keenly aware of when various actors "turn off" the
Internet but most of us are less aware of the other forms of attack on DNS
security and stability. Here is a link to, and a few words from, the U.S.
Department of Homeland Security on recent attacks on the DNS system.
https://cyber.dhs.gov/ed/19-01/ (https://cyber.dhs.gov/ed/19-01/)
This page contains a web-friendly version of the Cybersecurity and
Infrastructure Security Agency’s Emergency Directive 19-01
(https://cyber.dhs.gov/assets/report/ed-19-01.pdf), “Mitigate DNS
Infrastructure Tampering”.
Excerpts: CISA Emergency Directive on DNS Infrastructure Tampering
(https://www.us-cert.gov/ncas/current-activity/2019/01/22/CISA-Emergency-Directive-DNS-Infrastructure-Tampering)
01/22/2019 06:48 PM EST
Original release date: January 22, 2019
The U.S. Department of Homeland Security (DHS) Cybersecurity and
Infrastructure Security Agency (CISA) issued an emergency directive to
address ongoing incidents associated with global Domain Name System (DNS)
infrastructure tampering. CISA is aware of multiple executive branch agency
domains that were impacted by the tampering campaign and has notified the
agencies that maintain them. The directive requires Federal agencies to
take specific steps and comply with reporting procedures to mitigate risks
from undiscovered tampering, prevent illegitimate DNS activity, and detect
unauthorized certificates.
Federal agencies should review Emergency Directive 19-01
(https://cyber.dhs.gov/ed/19-01/) for required actions and reporting
procedures.
Background
In coordination with government and industry partners, the Department of
Homeland Security (DHS) Cybersecurity and Infrastructure Security Agency
(CISA) is tracking a series of incidents1
(https://cyber.dhs.gov/ed/19-01/#fn:1) involving Domain Name System (DNS)
infrastructure tampering. CISA is aware of multiple executive branch agency
domains that were impacted by the tampering campaign and has notified the
agencies that maintain them.
Using the following techniques, attackers have redirected and intercepted
web and mail traffic, and could do so for other networked services.
* The attacker begins by compromising user credentials, or obtaining them
through alternate means, of an account that can make changes to DNS
records.
* Next, the attacker alters DNS records, like Address (A), Mail Exchanger
(MX), or Name Server (NS) records, replacing the legitimate address of a
service with an address the attacker controls. This enables them to direct
user traffic to their own infrastructure for manipulation or inspection
before passing it on to the legitimate service, should they choose. This
creates a risk that persists beyond the period of traffic redirection.
* Because the attacker can set DNS record values, they can also obtain
valid encryption certificates for an organization’s domain names. This
allows the redirected traffic to be decrypted, exposing any user-submitted
data. Since the certificate is valid for the domain, end users receive no
error warnings.
To address the significant and imminent risks to agency information and
information systems presented by this activity, this emergency directive
requires the following near-term actions to mitigate risks from
undiscovered tampering, enable agencies to prevent illegitimate DNS
activity for their domains, and detect unauthorized certificates.
See: Emergency Directive 19-01 (https://cyber.dhs.gov/ed/19-01/)
Posted by: Sam L. NPOC
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.ncsg.is/pipermail/ncsg-discuss/attachments/20190122/87791969/attachment.htm>
More information about the Ncsg-discuss
mailing list