6–7 Feb 2025
Atlanta Marriott Marquis
America/New_York timezone

Academic Thoughts on Data Needs for Fighting DNS Abuse

7 Feb 2025, 10:40
20m
Imperial Salon B ( Atlanta Marriott Marquis)

Imperial Salon B

Atlanta Marriott Marquis

265 Peachtree Center Ave NE Atlanta GA 30303 United States
In-Person Standard Presentation Main Session OARC 44 Day 2

Speaker

Raffaele Sommese (University of Twente)

Description

Malicious actors exploit the DNS namespace to carry out spam campaigns, phishing attacks, malware distribution, and other harmful activities. Combating these threats demands visibility into domain existence, ownership, and nameservice activity—insights that the DNS protocol itself does not inherently provide.

In this talk, I aim to brainstorm with the operational community about the challenges and possibilities of sharing data beyond daily zone snapshots. We will explore the need for finer-grained visibility into DNS changes, the complexities of sharing business and privacy-sensitive information, and ultimately, how to enable a "follow-the-money" process to trace DNS abusers.

The goal is to spark a discussion on the feasibility of sharing additional data: What are the benefits of such sharing? What types of harm can it help prevent? What are the risks involved, and what mitigation strategies might be possible?

Talk duration 10 Minutes (+5 for Q&A)

Primary author

Raffaele Sommese (University of Twente)

Presentation materials