Showing posts with label DNS. Show all posts
Showing posts with label DNS. Show all posts

Friday, April 10, 2015

Sandvine Sold its Holding in Xerocole to Akamai


Sandvine released yesterday its Q1 results (revenues of $32.4M - here). The release also states that "Net income for the quarter includes $2.8 million of other income related to a gain on the disposition of an investment in a private company".

Sandvine's financial report explains that "On February 27, 2015, the Company sold its preferred share investment in a private company for consideration of $3,057. Consequently, the Company has recognized a gain related to the disposition of its preferred share investment of $2,778. Subsequent to February 28, 2015 the Company collected $2,595 with the balance held in escrow and due August 27, 2016" (here).

According to SeekingAlpha's transcript of the earning call (See "Sandvine's (SNVNF) CEO Dave Caputo on Q1 2015 Results - Earnings Call Transcript" - here) - "approximately $2.8 million of current quarter net income resulted from a gain on the sale of a minority investment in Duracool, which related to a spin out of our 2007 acquisition of Simplicita. Duracool was recently acquired by [indiscernible]".

To be more exact, the name of the private company is Xerocole. 

Simplicita built behavioral advertising solutions and was acquired by Sandvine in 2007, Xerocole was spawn-off in 2010 (see "Sandvine Spins-off Simplicita as Xerocole" - here). Its site explains that its mission is to "simply deliver, for service providers, the smartest and most personal DNS platform on the planet We relentlessly pursue DNS technology and service excellence and perfect how users control the right websites and right time for each. We believe that a great Internet experience begins with great DNS technology and services".
On March 2nd, Akamai announced it has acquired Xerocole (see 'Akamai Acquires Xerocole" - here) - explaining that "Xerocole's intelligent recursive DNS technology was designed to provide carriers with security, speed, and the ability to dynamically and flexibly set DNS policy and user preferences".

Wednesday, July 23, 2014

UK: How do ISPs Implement Network Based Parental Control Service?


Ofcom has "published a report for Government outlining measures the UK's largest internet service providers have put in place to help parents protect children from harmful content online. This follows an agreement between the Government and BT, Sky, TalkTalk and Virgin Media, the four largest fixed line internet service providers (ISPs), announced in July 2013 [see "UK to Enforce Opt Out Network Based Web Filtering on All ISPs" - here]. Each ISP committed to offer new customers 'family-friendly network-level filtering' by the end of December 2013 [see "UK ISPs for Safer Internet" - here]" 


"The report finds that the four ISPs now have a network level family friendly filtering service .. There are a number of filtering categories common to all four ISPs. Suicide and self-harm, pornography, file sharing, crime, drugs, violence and hate are covered by each provider's classification systems .. All of the ISPs offer some additional services alongside the network family-friendly 
filters, some including internet security services aimed at protecting the subscriber from issues like viruses or malware. All offer device level filtering or security software for installation on individual computers

All of the ISPs have commissioned third parties to perform the categorisation of 
internet content and services: 

  • BT and Virgin employ Nominum
  • Sky uses Symantec 
  • TalkTalk uses Huawei [see "Huawei's SIG: Policy Enforcement and URL Filtering" - here], although Symantec was also initially involved.
The filtering solutions rely on two basic technologies:
  • Filtering by Uniform Resource Locator (URL) blocking: the filtering of sites or services based on their web address – either addresses covering whole websites (http://www.example.com) or individual sections or pages on those sites (http://www.example.com/adultpictures). This involves the ISP checking some or all of the URLs which an opted-in subscriber requests against the list of sites or pages to be blocked. If there is a match, the subscriber request is not fulfilled – typically a page with the message “this site is blocked because it is classified as…” may be delivered instead.
  • Filtering by Domain Name System (DNS) alteration: the DNS translates domain names (“www.example.com” into IP addresses “192.0.32.10”), to allow a subscriber’s content request to be correctly directed – this is the first stage in requesting a website or service. When used for filtering, the ISP’s DNS server will not provide the IP address for domains on the list; it may instead direct the subscriber request to an information page with “this site is blocked because it is classified as…”.

Each of Virgin Media, BT and TalkTalk has adopted a slightly different version of URL blocking; Sky’s filtering system is exclusively based on its DNS servers. The use of URL blocking allows a more granular classification of online content and services: Sky’s system will always block whole domains, while BT, Virgin Media and TalkTalk can target specific parts of a domain.


See "Ofcom publishes report on internet safety measures" - here.

Monday, December 23, 2013

BT Launches DNS-based Parental Control; Does it Log Traffic?


Following the UK Government decision to enforce opt our parental control on all ISPs (here), BT  announced recently a new, network-based, Parental control service.

Tim Guest, BT's Homepage and marketing manager, explains: "We’ve offered free parental controls to customers for years, but the protection focused on desktop computers and laptops – now the new controls cover any internet-enabled device using home broadband, from PCs, laptops and games consoles to tablets and smartphones. The filter will still be free to all customers. Anyone joining BT can choose whether or not to activate the parental controls when setting up their internet connection for the first time. We’ll also contact all of current customers during 2014 so they can choose whether or not to set up the controls.

See also - "[The Register]: All Major UK ISPs to Implement Network-based Parental Control" - here.

There will be three set filter levels – strict, moderate and light - which can be customised to suit each family’s needs. Additional websites can be added to the list to be permitted or blocked. The filter can be turned off at specific times, and can also be set to an additional level – ‘homework time’ – for extra peace of mind when children are studying.




The Open Rights Group asked BT a number of questions on the new service (see "BT answers our questions about parental controls", by Peter Bradwell, here). BT says that:
  • "BT Parental Controls is a network based solution which means that all devices connected to your BT Broadband will have the same level of protection applied.
  • Our Filtering solution is based on Domain name resolution and can apply to any protocol used for a blocked domain
  • we do not anticipate that BT Parental Controls will have any impact on user’s speeds however we will continue to monitor this
  • BT Parental Controls utilises a trusted specialist 3rd party to categorise content
  • The BT Parental Controls solution does not inspect or log traffic for customers who do NOT opt in to the service"; [q] if so, is it logged in a way that links the traffic to a subscriber? What logging will there be of blocking events? How does this work? - an answer was not available.." 


See "Free filter boosts online safety for families" - here.

Friday, May 10, 2013

How does Netflix Use and Manage DNS to Improve Service?


Continuing my mini-series on "How does Netflix Manage Video Delivery?" (here, here) - and this time: how do they manage their DNS entries to allow dynamic updates?

A blog post by  (pictured) explains: "During 2013 we have been working on the components needed to automate DNS configuration changes. This will let us send customers to more than one region in the cloud, and switch customer traffic between cloud regions. The Denominator project provides a command line tool and a Java library that manages DNS, and can interface to several different DNS vendors"

"..One of the options provided by some DNS vendors is called "directional routing". This looks up the location of a customer, and can automatically send customers on the west coast to a cloud region in Oregon, while sending customers on the east coast to a cloud region in Virginia. Each state can be configured separately. This feature is now supported by Denominator 1.1, which was released a few days ago. Denominator can create the configuration and dynamically switch customers from one coast to the other to balance traffic, or work around maintenance downtime and outages"





See "Denominating Multi-Region Sites" - here.

Friday, February 8, 2013

Vendor Preview: FibroLAN's Small Cell Backhaul w/Cache

 
Earlier this week I mentioned the Saguna-FibroLAN partnership (see "Saguna CEO: 'We have 4 New OEM licensees for our Mobile Caching Technology'" - here) in which FibroLAN licensed Saguna's caching and radio optimization software (CODS) for its second generation Falcon series for LTE mobile backhaul (here).

I asked FibroLAN's CEO, Shamir Stein (pictured) to further explain the new solution, that places popular data as close as possible to the users.

Shamir provided the following details about the new product:

  • FibroLAN's carrier Ethernet backhaul products support indoor and outdoor small cell deployments. Among other features it provides Power over Ethernet (PoE) to the small cells, and centralized synchronization using an integrated GPS.
     
  • Content caching, based Saguna's code, uses SSD storage and handles any kind of content (including video). It promises savings of up to 50% on backhaul bandwidth, while speeding up content delivery. It also supports DNS caching, eliminating the need for round trip delays associated with DNS queries (which could be significant, mainly for web pages with multiple objects).
  • The product aggregates several cells, in a flexible model that combines daisy chaining and star topologies. It also supports a campus configuration - in this case the the caching become even more efficient resulting from the larger number of people using it. 

  • FibroLAN will demonstrate the new product line at MWC 2013, and availability is planned for Q2 
 
   

Wednesday, January 30, 2013

Akamai: Recent DNS Attacks of 23 Gbps; Lists Attacked TCP Ports


Akamai published its State of the Internet report for Q3, 2012. The security section provides some interesting information on the volume of DDoS attacks Akamai saw recently, during "Operation Ababil" and about the distribution of DDoS attacks per TCP ports:

  • 'Denial-of-service attacks associated with “Operation Ababil” are targeting banks and financial institutions. Among those attacks targeting Akamai customers, Akamai observed up to 65 Gbps of total attack traffic, with nearly 23 Gbps of attack traffic targeting DNS servers". 


  • As for other attacks - "As shown in [top] Figure 2 [the second chart shows the Q1 '12/Q4 '11  results] attack traffic concentration among the top 10 ports once again declined during the third quarter of 2012, with these ports responsible for 59% of observed attacks, down from 62% in the second quarter, and 77% in the first quarter. The percentage of attacks targeting Port 445 once again dropped quarter-over-quarter, though not quite as significantly as seen between the first and second quarters. Port 445 remained the most targeted port in eight of the top 10 countries". 


Friday, August 17, 2012

DDoS DNS Attack Disrupted AT&T Data Traffic

 
Martyn Williams (pictured) reported to PC Advisor on Wednesday that "A distributed denial-of-service attack aimed at AT&T's DNS servers has disrupted data traffic for some of the company's customers .. The multi-hour attack began Wednesday morning West Coast time and at the time of this writing, eight hours later, does not appear to have been mitigated .. The attack appears to have affected enterprise customers using AT&T's managed services DNS product".

AT&T said to the press on Thursday that the DNS issues have been resolved.

See also "US ISPs Agreed to Combat Major Cyber Security Threats" - here.

See "AT&T hit by DDoS attack, suffers DNS outage" - here.

Friday, April 27, 2012

TM Wins: US Tier1 Uses Radware to Manage DNS Traffic ($2M Deal)

 
Radware announced a ".. $2 million sale of its Alteon®10000 application delivery controller (ADC) to a leading Tier 1 telecommunications carrier in the United States. The telecom provider will deploy Radware's carrier-grade ADC in its network hubs across the U.S. as part of a major upgrade to its domain name system (DNS) application .. With Radware's Alteon 10000, the carrier has an advanced ADC platform delivering up to 80 Gbps of on-demand capacity for unparalleled application scalability, availability, reliability and performance".
  
See "Radware's Alteon 10000 Delivers the Capacity and Performance Needed to Help a U.S. Tier 1 Carrier Expand Its DNS Application" - here.

Friday, March 23, 2012

US ISPs Agreed to Combat Major Cyber Security Threats


While US ISPs get ready to fight piracy by watching for illegal content downloads (here) they have also agreed to ".. better secure their communications networks and protect consumers and business".
  
An FCC press release announced that ".. an industry advisory group for the Federal Communications Commission (FCC), the Communications, Security, Reliability, and Interoperability Council (CSRIC), unanimously adopted recommendations for voluntary action by Internet service providers (ISPs) to combat three major cyber security threats, including botnets, attacks on the Domain Name System (DNS), and Internet route hijacking .. Chairman Genachowski applauds voluntary commitments by nation’s largest Internet Service Providers, including AT&T, CenturyLink, Comcast, Cox, Sprint, Time Warner Cable, T-Mobile and Verizon".
  • Under the Anti-Bot Code, ISPs agree to educate consumers about the botnet threat, take steps to detect botnet activity on their networks, make consumers aware of botnet infections on their computers, offer assistance to consumers whose computers are infected and collaborate with other service providers that have also adopted the Anti-Bot Code
      
  • DNSSEC is a set of secure protocol extensions that prevent such fraudulent activity
      
  • CSRIC recommended an industry framework to prevent Internet route hijacking, which is the erroneous routing of Internet traffic through potentially untrustworthy networks 
Some examples from other countries: Sri-Lanka, Nigeria, Egypt, India, Korea, Argentina. AT&T also announced several security initiatives (here here and here).    

See "FCC advisory committee adopts recommendations to minimize three major cyber threats, including an anti-bot code of conduct, ip route hijacking industry framework and secure DNS best practices" - here and more details (here).

Saturday, January 28, 2012

Google [Still] Claims there is a Faster TCP

 
Back in June 2010 I reported about Google's work on making the internet protocols (TCP, DNS) work faster (see "Google - [Our] TCP Can Do 12% Better" - here).


A recent post by Yuchung Cheng (pictured), Make The Web Faster Team, to Google's Code blog provides now additional details.

"Our research shows that the key to reducing latency is saving round trips .. [by] [1] Increase TCP initial congestion window to 10 (IW10) [2] Reduce the initial timeout from 3 seconds to 1 second [3] Use TCP Fast Open (TFO) [4] Use Proportional Rate Reduction for TCP (PRR) .. In addition, we are developing algorithms to recover faster on noisy mobile networks, as well as a guaranteed 2-RTT delivery during startup".

See "Let's make TCP faster" - here.

Thursday, January 19, 2012

DNS Blocking to be Removed from the SOPA Proposal

 
US Congressman and House Judiciary Committee Chairman Lamar Smith (pictured) announced a change to the SOPA ( Stop Online Piracy Act, here) proposal:

"After consultation with industry groups across the country, I feel we should remove Domain Name System blocking from the Stop Online Piracy Act so that the Committee can further examine the issues surrounding this provision. We will continue to look for ways to ensure that foreign websites cannot sell and distribute illegal content to U.S. consumers"

The Internet Society said that while they agree with the need to "combat illegal online activities such as child pornography, infringement of intellectual property rights and cybercriminal activities", they find that "policies and regulations that require the interruption of the DNS infrastructure, whether by filtering results or through domain name seizure have serious deficiencies. These techniques do not solve the problem, interfere with cross-border data flows and services, and undermine the Internet as a single, unified, global communications network" (here).

Like always, I will quote Ofcom "All site blocking techniques can be circumvented". This refers to 4 techniques for site blocking: by IP address, DNS response, by URL response alteration or by using Shallow or Deep Packet Inspection (or hybrids of the above). 

See "Smith to Remove DNS Blocking from SOPA" - here.

Wednesday, October 5, 2011

Belgacom and Telenet Ordered to "DNS Block" Pirate Bay - Is this effective?

 
Torrent Freak reports that "A court has overturned a 2010 ruling which said that blocking The Pirate Bay at the ISP level was “disproportionate”. The Antwerp Court of Appeal sided with the Belgian Anti-Piracy Federation in their quest to force two ISPs to block subscriber access to the world’s most famous torrent site. Belgacom and Telenet must now implement a DNS blockade of the site within 14 days or face fines"

Recent experience (see related posts below) shows that trying to black list web sites is problematic, as subscriber have ways to bypass it, or false-positive (over-blocking) errors are made by the ISPs - due to the use of too-simplistic blocking methods.

Related posts:
  • Argentina: ISPs Block 1,000,000 Blogs Instead of One - here
     
  • Ofcom: "All site blocking techniques can be circumvented" - [The Leaked Document] - here.
According to Ofcom's document:
For site operators and end users with a sufficient incentive to engage in circumvention DNS blocking is technically relatively straightforward to bypass: 
  • the blocked site may offer services such as Virtual Private Networking, which is where encryption and other security measures are deployed to ensure that the data cannot be viewed by third parties (DNS name resolution may occur within the VPN providers network thereby bypassing the ISP based DNS site-blocking);
  • the end-user can change their DNS name servers to 3rd party DNS name servers
  • users may use anonymous web proxy or other anonymising services which are not reliant on the ISP DNS servers; or
  • name resolution may be performed locally by adding an entry to a hosts file (IP address resolution information can be obtained from websites running a web-enabled equivalent of “nslookup” command).
See "Belgian ISPs Ordered To Block The Pirate Bay" - here and BAF's press release "BELGACOM EN TELENET VEROORDEELD TOT HET BLOKKEREN VAN ‘THE PIRATE BAY’ - here.
Source: Ofcom

Friday, September 2, 2011

Location Aware DNS Speeds Up Content Access

 
What looks like a trivial enhancement (at least conceptually) to the Internet's DNS protocol promises to help internet users get a faster service.

The "Global Internet Speedup", supported by Google and OpenDNS, implements a small change to DNS queries so users will enjoy the full advantage of CDNs and get the content they ask from the closets server.

Participating CDNs include BitGravity, CDNetworks, Cloudflare, Comodo and EdgeCast.

"When trying to reach a website that exists in 50 locations around the world .. You want to be sent to the closest, fastest or least congested location automatically.  Until now, figuring out which location is closest to you was not possible with DNS alone. Today, if you’re using OpenDNS or Google Public DNS and visiting a website or using a service provided by one of the participating networks or CDNs in the Global Internet Speedup then a truncated version of your IP address will be added into the DNS request. The Internet service or CDN will use this truncated IP address to make a more informed decision in how it responds so that you can be connected to the most optimal server"


See how it works - here and the proposed IETF draft - here and a press release "Global Internet Speedup Initiative Announced; Technology Companies Band Together on Innovation to Make the Internet Faster Around the World" - here.






Monday, August 29, 2011

Salient Federal Solutions: IPv6 Threats can be Eliminated Using DPI

  
Salient Federal Solutions reports "real-world incidents of IPv6 attacks based on the emerging protocol's tunneling capabilities, routing headers, DNS broadcasting and rogue routing announcements. The company asserts that all of these threats can be eliminated with the use of IPv6-enabled deep packet inspection tools, which it (here) and other network vendors sell".

See "IPv6 eyed by torrent users to avoid network throttling" - here.

Jeremy Duncan (pictured), senior director and IPv6 network architect for Salient Federal Systems, said: "IPv6 tunneling gives attackers a green light to penetrate networks .. uTorrent, which is an IPv6-capable freeware client for the BitTorrent peer-to-peer protocol that's used to share large files such as music and movies runs very well over Teredo, and that the BitTorrent community is discovering IPv6 as a way of avoiding network congestion controls that are used by ISPs to manage BitTorrent traffic on IPv4 networks"

The slides below are taken from Jeremy's presentation "IPv6 Is Here. Is Your Network Secure?" at the 7th Annual GFIRST National Conference, held in Nashville earlier this month.

The 2 parts presentation is available here and here.



 

Tuesday, March 8, 2011

NetScout: "Outages at NTT, AT&T and Verizon could have been detected and averted"

 
James Heath interviews Steven Shalita (picture), VP of Marketing, NetScout to B/OSS about "network behavioral analysis (NBA), and why NBA is becoming necessary to provide security and service assurance in IP networks".

See "LTE Monitoring: The Virtue of Combining Service and Security Assurance"  - here.

Some quotes:
  • "For a mobile network the No. 1 location of problem generation is DNS, whether it be DNS flooding or other types of performance issues. So operators typically start in that area, in the authentication or federation layer, which includes DNS, the AAA server and the HLR"
      
  • "Carriers are pretty guarded about sharing information like this and unfortunately all my anecdotes would be too specific and identify a carrier. Yet if you look at the most spectacular telecom outages as example – and I am not saying we detected any of them – these outages at NTT, AT&T and Verizon all started out as little things that could have been detected and averted"
See also:
  • Arbor Networks: Mobile Operators Lack Visibility and Control over Security threats - here
  • Recent Cyber Monday DDoS Attacks "revealed a sophisticated and motivated attacker” - here
  • Yankee Group Prediction: A Denial-of-Service Attack Will Take a 4G Network Down - here