The Domain Name System and DNS Blocking Malcolm Hutty Head of Public Affairs, LINX February 2011.

Slides:



Advertisements
Similar presentations
Internet Applications INTERNET APPLICATIONS. Internet Applications Domain Name Service Proxy Service Mail Service Web Service.
Advertisements

Internet Basics The Internet Is… – a network of networks – a community of people, businesses, schools and organizations – , web pages, databases,
IPv6 deployment metrics using.JP domain APNIC February 2004 Kenichi Kanayama Intec NetCore, Inc.
Managing IP addresses for your private clouds 2013 ASEAN CAS Summit Bangkok, Thailand 7 February 2013 George Kuo Member Services Manager.
The Internet Useful Definitions and Concepts About the Internet.
1 Web Content Delivery Reading: Section and COS 461: Computer Networks Spring 2007 (MW 1:30-2:50 in Friend 004) Ioannis Avramopoulos Instructor:
Vocabulary URL = uniform resource locator: web address protocol –set of rules that networked computers follow in order to share data and coordinate communications.
 Proxy Servers are software that act as intermediaries between client and servers on the Internet.  They help users on private networks get information.
Installing and Maintaining ISA Server. Planning an ISA Server Deployment Understand the current network infrastructure Review company security policies.
Internet Basics.
TCP/IP Addressing Design. Objectives Choose an appropriate IP addressing scheme based on business and technical requirements Identify IP addressing problems.
Boris Tshibangu. What is a proxy server? A proxy server is a server (a computer system or an application) that acts as an intermediary for requests from.
Firewalls Marin Stamov. Introduction Technological barrier designed to prevent unauthorized or unwanted communications between computer networks or hosts.
The internet and the WWW
Norman SecureSurf Protect your users when surfing the Internet.
1 Content Distribution Networks. 2 Replication Issues Request distribution: how to transparently distribute requests for content among replication servers.
1 ISA Server 2004 Installation & Configuration Overview By Nicholas Quinn.
Human-Computer Interface Course 5. ISPs and Internet connection.
URL AND DNS A SHORT INTRODUCTION Rachel White7/11/2014.
Web Mastering Module Internet Fundamentals. What is the Internet? –Global network of networks –Communicating using same set of rules (protocols/languages)
© British Telecommunications plc Network Filtering.
HOW ACCESS TO WWW Student Name : Hussein Alkhaldi.
Lectures and Practicals Mon 8-10 SC1222 TUE SC1222 Office: SC Website: mis.csit.sci.tsu.ac.th/kanida.
1 Chapter 6: Proxy Server in Internet and Intranet Designs Designs That Include Proxy Server Essential Proxy Server Design Concepts Data Protection in.
Introduction to Computers Section 8A. home How the Internet Works Anyone with access to the Internet can exchange text, data files, and programs with.
Network Operating Systems versus Operating Systems Computer Networks.
IT Introduction to Information Technology. The Internet & World Wide Web Began in 1969 with the ARPANET (Advanced Research Project Agency Network)
Vulnerabilities in peer to peer communications Web Security Sravan Kunnuri.
Introduction to Internet terms. Topics to Study What is Internet HTTP URL SMS MMS Wi-Fi Video Conferencing Social Webisites.
OWL Jan How Websites Work. “The Internet” vs. “The Web”?
IP BROS Presentation by: Amen Ahmed. Mario and Luigi are here to help us find our way through the internet. Mario will act as our browser and Luigi will.
1 Windows 2008 Configuring Server Roles and Services.
Networking Network Classification, by there: 3 The Rules they use to exchange data: Protocols.
Copyright © 2006 Pearson Addison-Wesley. All rights reserved. 3-1.
DNS Antidote Abhishek Madav( ) Suhas Tikoo( ) Urjit Khadilkar( )
McLean HIGHER COMPUTER NETWORKING Lesson 14 Firewalls & Filtering Comparison of Internet content filtering methods: firewalls, Internet filtering.
The Intranet.
Internet Architecture and Governance
How the Web Works Building a Website – Lesson 1. How People Access the Web Browsers People access websites using software called a web browser. To view.
Microsoft Windows 2008 Features and Functionality Guy Wilkin.
DNS Antidote Abhishek Madav( ) Suhas Tikoo( ) Urjit Khadilkar( )
COMPUTER INTERNET, INTRANET & EXTRANET. INTERNET 1) It is a worldwide system which has the following characteristics: 2) Internet is a world-wide / global.
1 The Internet Registry System Mirjam Kühne RIPE NCC EC-POP Brussels 5 July 1999.
1. Internet hosts:  IP address (32 bit) - used for addressing datagrams  “name”, e.g., ww.yahoo.com - used by humans DNS: provides translation between.
The Internet What is the Internet? The Internet is a lot of computers over the whole world connected together so that they can share information. It.
Keith Mitchellhttp:// RIPE ncc IP Address Space Governance Keith Mitchell Executive Board Chairman, RIPE NCC (Chief Executive, LINX) European.
Uniform Resource Locator URL protocol URL host Path to file Every single website on the Internet has its own unique.
Domain Name System (DNS) The Technology Context – B101 Coursework 2 The Technology Context – B101.
Introduction to HTML 4.0 Getting Started – Basic Terminology Teacher: Mr. Ho.
DNS Domain Name System. Lots of people use the internet for different reasons. DNS Plays a big role in the internet. The DNS translates domain names into.
DOMAIN NAME SYSTEM By Gazain Naeem. Domain Name System is the hierarchical computer system which is connected to the internet. It works like a telephone.
Blocking Access to Websites. Normal operations We type the URL (e.g., to the browser. So many things happen.
E-Business Infrastructure PRESENTED BY IKA NOVITA DEWI, MCS.
Fundamentals of Information Systems, Sixth Edition
Module 3: Enabling Access to Internet Resources
The Intranet.
Technologies and Applications
Internet and Intranet.
“Size of DNS” Size of the DNS can be describe from the time before it was created all the computer on a network used to receive a host file named HOST.TXT,
Practical Censorship Evasion Leveraging Content Delivery Networks
E-commerce | WWW World Wide Web - Concepts
E-commerce | WWW World Wide Web - Concepts
Some Common Terms The Internet is a network of computers spanning the globe. It is also called the World Wide Web. World Wide Web It is a collection of.
Providing Network Services
Internet and Intranet.
Internet and Intranet.
AbbottLink™ - IP Address Overview
DoH! Peter Van Roste GAC/ccNSO meeting - ICANN 64
Your computer is the client
Internet and Intranet.
Presentation transcript:

The Domain Name System and DNS Blocking Malcolm Hutty Head of Public Affairs, LINX February 2011

About LINX A membership association for network operators Based in London, UK One of the largest Internet Exchanges in the world – 400 member networks from over 50 countries – Over 1.2Tb/s peak traffic – Over 70% global Internet routes Public policy role in EU through

The voice of Internet Services Providers in Europe Represents over 1800 ISPs Umbrella structure: – National associations are EuroISPA members – Governed by a Board with one member per association Supported by an advisory forum of large multi-national network and service providers

1. User types domain name into browser

2. Browser asks Access Provider for IP address of What’s the IP address for Access Provider DNS Resolver

3. DNS Resolver asks Root Name Server for IP of a DNS server for.eu Root Name Server Where’s the.eu registry DNS server? Access Provider DNS Resolver

3. DNS Resolver asks Root Name Server for IP of a DNS server for.eu Root Name Server It’s at IP address: It’s at IP address: Access Provider DNS Resolver

4. DNS Resolver asks.eu DNS server for IP of the DNS server for example.eu.eu Registry DNS server Where’s the DNS server for example.eu? Access Provider DNS Resolver

4. DNS Resolver asks.eu DNS server for IP of the DNS server for example.eu.eu Registry DNS server It’s at IP address: It’s at IP address: Access Provider DNS Resolver

5. DNS Resolver asks for the IP address for … DNS example.eu What’s the IP address for Access Provider DNS Resolver

5. DNS Resolver asks for the IP address for … DNS example.eu It’s at IP address: It’s at IP address: Access Provider DNS Resolver

6. … and passes the IP address back to the browser The IP address for is: Access Provider DNS Resolver

7. … which contacts the website host using the IP address Contacting

8. HTTP traffic begins Access Provider DNS Resolver

How DNS blocking works What’s the IP address for Access Provider DNS Resolver

How DNS blocking works No such domain. Access Provider DNS Resolver

How DNS blocking works Or…

How DNS blocking works What’s the IP address for Access Provider DNS Resolver

How DNS blocking works Access Provider DNS Resolver It’s at (cough) IP: (cough) It’s at (cough) IP: (cough)

How DNS blocking works Police controlled server Access Provider DNS Resolver

Technical flaws in DNS blocking

Technical flaws: multiple / changing domain names What’s the IP address for Access Provider DNS Resolver

Technical flaws: multiple / changing domain names Access Provider DNS Resolver No such domain.

Technical flaws: multiple / changing domain names Access Provider DNS Resolver Ok, can I have IP address for

Technical flaws: multiple / changing domain names Root Name Server Access Provider DNS Resolver

Technical flaws: multiple / changing domain names Access Provider DNS Resolver.eu Registry DNS server

Technical flaws: multiple / changing domain names Access Provider DNS Resolver DNS ejemplo.eu

Technical flaws: multiple / changing domain names Access Provider DNS Resolver The IP address for is:

Technical flaws: multiple / changing domain names Access Provider DNS Resolver

Technical flaws: user can bypass DNS by typing IP address directly into browser

Technical flaws: user can bypass DNS by typing IP directly into browser Access Provider DNS Resolver

Technical flaws: many companies run their own DNS resolver Jones & Jones Ltd DNS Resolver Access Provider DNS Resolver What’s the IP address for

Technical flaws: many companies run their own DNS resolver Jones & Jones Ltd Access Provider DNS Resolver Root Name Server DNS Resolver

Technical flaws: many companies run their own DNS resolver Jones & Jones Ltd Access Provider DNS Resolver.eu Registry DNS server DNS Resolver

Technical flaws: many companies run their own DNS resolver Jones & Jones Ltd DNS Resolver Access Provider DNS Resolver DNS example.eu

Technical flaws: many companies run their own DNS resolver Jones & Jones Ltd DNS Resolver Access Provider DNS Resolver The IP address for is:

Technical flaws: many companies run their own DNS resolver Jones & Jones Ltd DNS Resolver Access Provider DNS Resolver

Technical flaws: client can use a third-party DNS resolver Access Provider DNS Resolver

Technical flaws: client can use a third-party DNS resolver

Access Provider DNS Resolver Technical flaws: client can use a third-party DNS resolver 3 rd party DNS Resolver

Access Provider DNS Resolver Technical flaws: client can use a third-party DNS resolver What’s the IP address for 3 rd party DNS Resolver

Technical flaws: client can use a third-party DNS resolver 3 rd party DNS Resolver Root Name Server Access Provider DNS Resolver

Technical flaws: client can use a third-party DNS resolver 3 rd party DNS Resolver.eu Registry DNS server Access Provider DNS Resolver

Technical flaws: client can use a third-party DNS resolver 3 rd party DNS Resolver DNS example.eu Access Provider DNS Resolver

Access Provider DNS Resolver Technical flaws: client can use a third-party DNS resolver 3 rd party DNS Resolver

Technical flaws: client can use a third-party DNS resolver Access Provider DNS Resolver

Technical flaws: web proxies What’s the IP address for ? Access Provider DNS Resolver

Technical flaws: web proxies Root Name Server Access Provider DNS Resolver

Technical flaws: web proxies.example Registry DNS server Access Provider DNS Resolver

Technical flaws: web proxies DNS proxy.example Access Provider DNS Resolver

Technical flaws: web proxies The IP address for is Access Provider DNS Resolver

Technical flaws: web proxies Access Provider DNS Resolver DNS Resolver

Technical flaws: web proxies Enter the URL you wish to access:

Technical flaws: web proxies Access Provider DNS Resolver DNS Resolver Where is www. example.eu ? Where is www. example.eu ?

Technical flaws: web proxies Access Provider DNS Resolver DNS Resolver Root Name Server

Technical flaws: web proxies Access Provider DNS Resolver DNS Resolver.eu Registry DNS server

Technical flaws: web proxies Access Provider DNS Resolver DNS Resolver DNS example.eu

Technical flaws: web proxies Access Provider DNS Resolver DNS Resolver

Technical flaws: web proxies Enter the URL you wish to access:

Other tools use the proxy principle

Conclusions “DNS blocking” is a technical term – It describes a technical procedure, not an outcome – It is not synonymous with “preventing access using DNS” – It is unlikely to prevent users from reaching content they are actively seeking There is a big difference between seeking to protect users from content they wish to avoid, and seeking to obstruct users from reaching content they seek – In the first case, you can enlist the support of users and the software and services they use – In the latter, there is always a way around any impediment, and these ways can and will be made easy for anyone to use