Re: [weirds] I-D Action: draft-hollenbeck-dnrd-ap-query-00.txt

Eric Brunner-Williams <ebw@abenaki.wabanaki.net> Mon, 30 April 2012 21:21 UTC

Return-Path: <ebw@abenaki.wabanaki.net>
X-Original-To: weirds@ietfa.amsl.com
Delivered-To: weirds@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 838D311E8087 for <weirds@ietfa.amsl.com>; Mon, 30 Apr 2012 14:21:51 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.599
X-Spam-Level:
X-Spam-Status: No, score=-2.599 tagged_above=-999 required=5 tests=[BAYES_00=-2.599]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ZdEpUGvSB7Pd for <weirds@ietfa.amsl.com>; Mon, 30 Apr 2012 14:21:50 -0700 (PDT)
Received: from nic-naa.net (nic-naa.net [65.99.1.132]) by ietfa.amsl.com (Postfix) with ESMTP id C814611E8072 for <weirds@ietf.org>; Mon, 30 Apr 2012 14:21:48 -0700 (PDT)
Received: from limpet.local (cpe-67-255-2-48.twcny.res.rr.com [67.255.2.48]) by nic-naa.net (8.14.4/8.14.4) with ESMTP id q3UIOZtb030409 for <weirds@ietf.org>; Mon, 30 Apr 2012 14:24:36 -0400 (EDT) (envelope-from ebw@abenaki.wabanaki.net)
Message-ID: <4F9F0266.1050202@abenaki.wabanaki.net>
Date: Mon, 30 Apr 2012 17:21:42 -0400
From: Eric Brunner-Williams <ebw@abenaki.wabanaki.net>
Organization: wampumpeag
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.5; rv:11.0) Gecko/20120327 Thunderbird/11.0.1
MIME-Version: 1.0
To: weirds@ietf.org
References: <831693C2CDA2E849A7D7A712B24E257F0D5F47A3@BRN1WNEXMBX01.vcorp.ad.vrsn.com> <831693C2CDA2E849A7D7A712B24E257F0D5F4898@BRN1WNEXMBX01.vcorp.ad.vrsn.com> <82189D85-608F-4FC0-8DF4-51D343CF51C6@icann.org>
In-Reply-To: <82189D85-608F-4FC0-8DF4-51D343CF51C6@icann.org>
Content-Type: text/plain; charset="ISO-8859-1"
Content-Transfer-Encoding: 7bit
Subject: Re: [weirds] I-D Action: draft-hollenbeck-dnrd-ap-query-00.txt
X-BeenThere: weirds@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
Reply-To: ebw@abenaki.wabanaki.net
List-Id: "WHOIS-based Extensible Internet Registration Data Service \(WEIRDS\)" <weirds.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/weirds>, <mailto:weirds-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/weirds>
List-Post: <mailto:weirds@ietf.org>
List-Help: <mailto:weirds-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/weirds>, <mailto:weirds-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 30 Apr 2012 21:21:55 -0000

On 4/30/12 12:01 PM, Dave Piscitello wrote:
> These would be interesting in a number of malicious registration/forensics scenarios. For example, think about DGAs that generate names across multiple registries (like Conficker). Now think about trying to pattern match to see if there is a common registrar being used or exploited. 

i made, or thought i made, the point during the .C response that the
.C author's attempt to generate an inventory of rendezvous points had
more utility demonstrating the aggregate complexity and cost the
author was willing to incur, imposed by both registry and registrar,
and if memory serves, ignoring the conjectured, but undiscovered
complexity/cost boundary the .C author was unwilling to cross, my
analysis of the registrar-to-rendezvous-points showed no significant
correlation to com/net/org/biz/info registrars other than market share.

the similarity of string sets has been a known feature of ip
exploiting registrations for almost all of the current iana contract
period, though iterative uni-quiry into arbitrary points into the
adjacent string space seems to be the state of the query art.

> Since many information flows identify IP addresses initially and either resolve to names later or not at all, I suspect that this, too, would be valuable for any investigator.
> 
> These would also be extremely valuable if consensus policy were to consider and add reseller objects to the data model. This is my personal opinion and speculative as well. My company and members of the broader community may think differently.

your company? that would be the rhs of "dave.piscitello@icann.org"?

-e