Business Services Industry
Registrars Make Strides to Protect Internet from Phishing
Business Wire, Oct 29, 2008
APWG and Registrars Work Together to Harden Internet Infrastructure from Phishing Domains
LOS ALTOS, Calif. & CAMBRIDGE, Mass. -- The Anti-Phishing Working Group (APWG), in consultation with the ICANN Registrar Constituency and several domain name registrars, has published a "best practices" advisory for registrars to help them implement mechanisms to make it more difficult to register and use domains for illicit uses such as phishing, a confidence scheme used to dupe consumers out of personal financial information.
Related Results
Several globally active registrars, including APWG members Go Daddy, the world's largest registrar and Network Solutions, the world's oldest commercial registrar, have already implemented or are planning to implement many of the best practices prescribed by the APWG's Anti-Phishing Best Practices Recommendations for Registrars, released this month.
"It has been great to see registrars take phishing prevention seriously," said Rod Rasmussen, co-chair of the APWG's Internet Policy Committee and President of InternetIdentity of Tacoma, WA. "Since phishing campaigns often start with a domain registration, the domain name registrars are in the perfect position to make phishing more difficult."
The APWG's best practices advisory distills the counter-ecrime techniques of APWG membership, forged from their experiences as well as keystone policies of registrars who have already implemented them as safety measures to protect against the registration and use of domain names for phishing. The APWG worked closely with several registrars through ICANN's Registrar Constituency to ensure that the best practices were practical and applicable.
Anti-Phishing Best Practices Recommendations for Registrars advisory focuses on three principal areas in which house policy at registrars can help neutralize abusive domain registrations. Those include:
* Proactive fraud screening: low user-burden processes that registrars can adopt to limit phishers' ability to complete fraudulent domain registrations on a large scale
* Phishing domain takedown: best practices registrars can use to process the takedown requests in the most optimized fashion and suspend fraudulent domain registrations used in a phishing campaign
* Evidence Preservation for Investigative Purposes: Data retention practices to save key evidence that can be later used by law enforcement to identify and prosecute the phishers.
Registrars, like Go Daddy, the world's largest, and Network Solutions, an Internet pioneer that was the first authorized to register domain names, are welcoming these guidelines to help domain name registrars make the Internet a safer place.
"Based on Network Solutions' experience, the APWG's best practices are effective tools in the fight against phishing, and we hope that more registrars will implement them as well," said Jon Nevett, Vice President of Policy for Network Solutions.
The APWG and its members were moved to develop and publish the advisory to staunch abuse of the Domain Name System (DNS) in phishing attacks and other electronic crimes by means of increasingly sophisticated schemes. Several of the most potent phishing techniques that have recently grown more prevalent require fraudulent domain registrations as their cornerstones.
Examples included so-called "fast-flux" attacks and the infamous "Rock" group's phishing sites, a technique used to hide counterfeit phishing websites by rapidly shifting the Internet Protocol (IP) address hosting the website, vastly complicating their removal as security professionals are forced to chase the sites from one IP address to the next.
"Go Daddy always has and always will work to combat online phishing and identity theft," said GoDaddy.com CEO and Founder Bob Parsons. "Our goal is to make the Internet a safer place for everyone. Not only does Go Daddy follow Best Practice guidelines, we employ a 24/7 Abuse Department to help identify and shutdown offenders. We challenge other registrars to put some teeth into fighting this epidemic, as well."
In addition to duping thousands of people out of their personal financial data and money, these attacks harm domain registrars with excessive credit card charge-backs and floods of complaints to their support desks, and paints registrars with a poor reputation. Protecting their reputation is becoming increasingly important to registrars as ISPs and others look to filter e-mail and web traffic for their customers to effectively combat fraud.
A domain registrar with a poor reputation, for example, is increasingly likely to see their domains blocked from access to large segments of the Internet. Thus there is a bottom-line impact to go along with helping to fight against e-crime, and the APWG is dedicated to helping registrars gain those benefits by implementing best practices.
Going forward, the APWG plans to continue to work with registrars to evolve the Anti-Phishing Best Practices Recommendations for Registrars advisory, keeping it up to date with contemporary phishing attack techniques that coopt the DNS - and to identify ways to implement correlative security measures in the most cost-effective and effective manner.
- 5 Rules for Immediate Annuities
- Death in the Family: 12 Things to Do Now
- Dumbest Things You Do With Your Money
- 6 Online Networking Mistakes to Avoid
- 401(k) Mistakes to Avoid
- 5 Economic Scenarios to Keep You Up at Night
- The Real ‘Best Places to Retire’
- Best Credit Cards for You
- 12 Tough Questions to Ask Your Parents
- The Real ‘Best Colleges’
- Home Buyer Tax Credit: How to Cash In
- Why You Shouldn’t Bash Cash
- 8 Phony 'Bargains' and Better Alternatives
- Danger: 3 Debit Card Scams to Avoid
- 6 Myths About Gas Mileage
- 29 Fees We Hate Most
- Quick and Easy Ways to Boost Returns
- Best Stocks to Buy Now
- Lower Your Taxes: 10 Moves to Make Now
- New Jobs: 8 Lessons from Real-Life Career Switchers
- The New Job Market: Who Wins and Who Loses?
- Health Care Reform's Public Option: Everything You Need to Know
- Volunteer Work When Unemployed: Should You Work for Free?
- Whose Recovery Is This?
- Long-Term-Care Insurance: 4 Biggest Risks to Avoid
Content provided in partnership with
Most Recent Business Articles
- Multiple criteria evaluation and optimization of transportation systems
- Multi-criteria analysis procedure for sustainable mobility evaluation in urban areas
- A two-leveled multi-objective symbiotic evolutionary algorithm for the hub and spoke location problem
- Multi-criteria analysis for evaluating the impacts of intelligent speed adaptation
- The development of Taiwan arterial traffic-adaptive signal control system and its field test: a Taiwan experience
Most Recent Business Publications
Most Popular Business Articles
- 7 tips for effective listening: productive listening does not occur naturally. It requires hard work and practice - Back To Basics - effective listening is a crucial skill for internal auditors
- FAS 109: a primer for non-accountants - Financial Accounting Standards Board's "Statement 109: Accounting for Income Taxes"
- LIFO vs. FIFO: a return to the basics
- Too Young to Rent a Car? - 25-years-old the minimum age for car renting - Brief Article
- Design a commission plan that drives sales - Sales Commissions


