Registrars to get more domain takedown powers
ICANN will soon grant its accredited registrars the ability to unilaterally take down domains involved in ongoing security incidents, according to chair Maarten Botterman.
Responding to the news that registries have come up with a voluntary framework for tackling botnets that auto-generate domain registrations for use in command and control activities, Botterman said ICANN will extend a process currently restricted to registries into the registrar community.
That policy is the Expedited Registry Security Request Process, which allows registries to quickly obtain a retroactive waiver of its contractual obligations — such as the obligation to pay ICANN fees — if it has to urgently respond to a major incident.
The process was invoked four times last year, covering six gTLDs and roughly 1,600 domains. ICANN granted all four requests, though it seems to have on average missed its target of responding within three business days.
“As part of ICANN’s efforts to support the mitigation of DNS security threats, ICANN org will soon enable registrars to also request such waivers,” Botterman recently told the Registries Stakeholder Group.
He was responding to the news that several registries have signed up to a voluntary “Framework on Domain Generating Algorithms (DGAs) Associated with Malware and Botnets”.
That framework would allow registries to preemptively register or block domains likely to be auto-generated by botnet code, thereby cutting the head off the snake before it can wreak more havoc.
Recent Comments