Who cares about abuse? Rodney Tillotson, JANET-CERT APNIC, August 2001 United Kingdom Education & Research Networking Association
Three points UBE is like other abuse Only global consensus will stop it We would like to talk with AP
RIPE Réseaux IP Européens Anti-spam Working Group WG chair
RIPE view Originate no spam Persuade originators to stop Block and filter
Originate no spam Contracts with customers Penalties available Act on reports of abuse RIPE-206
Problems Free accounts Cybercafé use Competitive advantage
Block and filter Local choice MAPS Other blacklists Outbound blocks
Filtering Content-based Subjective, always changing Can help with other abuse –Viruses, porn
DNS blacklists Test IP addresses Hooks in most mailers –(but not Exchange) Getting on/off the list –Who decides?
Other public blacklists ORBS not now operating Several others –A variety of behaviours
MAPS Paul Vixie, Dave Rand Highly respected Thorough, not fast –Will let through some spam Pressure on originators
MAPS update Subscription only from 1 Aug 2001 Costs –DNS operation –List management –Legal
UBE What is spam? –Usenet Unsolicited Bulk
Pressure on originators RBL –Realtime Blackhole List Focus for consensus and conflict –Advice on good practice
Other abuse The issues are the same Consensus is better Compliance is about the same
Who said this? I dont want to report spam to the spammers ISP. I want to report it to my own ISP, or if I am an ISP then I want to report it to my own peers. They ought to verify my identity and the complaint format and then pitch it on to their peers or upstreams or customers or whatever and so on …
Who said this? … until it finally gets to the owner of the the address space which is being abused. If that owner wont act, then they ought to lose peering or be dropped as a customer or whatever, because the standard contracts among Internet peers and between customers and their ISPs ought to require proper response.
Who said this? Paul Vixie –To a private list, June 2001 –(quoted with permission)
UBE issues with AP US is the major source Many relays in AP –Increased early 2000 Little response from
Code Red Many sources in AP –Fewer in US (still too many) Unclear where to report it Lots in JANET, too!
JANET-CERT Coordinate security responses Contacts at customer sites Network blocks if needed Contacts with other CSIRTs
Other CSIRTs FIRST TERENA Trusted Introducer
AP CSIRTs Useful responses from AP CSIRTs –AUS-CERT, JP-CERT, KR-CERT etc Whois data usually available –Not easy to find abuse contact
My guess Fast-growing networks and user communities –Support lags behind –Many small companies Expectations are different Guidance is in (bad) English
Those points again UBE is like other abuse Only global consensus will stop it We would like to talk with AP
My questions How should we make contact? What problems do you have with the RIPE region? Do we need a new forum? How can we help? Who cares about abuse?
Your questions?
Thank you! Rodney Tillotson senior JANET-CERT member