Top Banner
Sweeping the .nz name space (zone and web scan) .nz Registrar Conference Auckland November 2014
24

Sweeping(the(.nz(name(space( (zone(and(web(scan)(...Agenda • Zone(scan(– Methodology(– A(year(worth(of(results(– DNSSEC(adopJon(– IPv6(adopJon(– Mail(services(marketshare(•

Jul 17, 2020

Download

Documents

dariahiddleston
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: Sweeping(the(.nz(name(space( (zone(and(web(scan)(...Agenda • Zone(scan(– Methodology(– A(year(worth(of(results(– DNSSEC(adopJon(– IPv6(adopJon(– Mail(services(marketshare(•

Sweeping  the  .nz  name  space  (zone  and  web  scan)  

.nz  Registrar  Conference  Auckland  -­‐  November  2014  

Page 2: Sweeping(the(.nz(name(space( (zone(and(web(scan)(...Agenda • Zone(scan(– Methodology(– A(year(worth(of(results(– DNSSEC(adopJon(– IPv6(adopJon(– Mail(services(marketshare(•

Agenda  •  Zone  scan  – Methodology  – A  year  worth  of  results  – DNSSEC  adopJon  –  IPv6  adopJon  – Mail  services  market  share  

•  Web  scan  – Methodology  –  Some  early  results  

Page 3: Sweeping(the(.nz(name(space( (zone(and(web(scan)(...Agenda • Zone(scan(– Methodology(– A(year(worth(of(results(– DNSSEC(adopJon(– IPv6(adopJon(– Mail(services(marketshare(•

Zone  scan  •  Started  on  Aug  2013  •  Governed  by  policy  hQps://nzrs.net.nz/dns/zone-­‐and-­‐host-­‐scanning  

•  Takes  a  few  days  to  run  –  Not  opJmized  for  speed  

•  Several  tests  for  correctness  +  data  gathering  •  Originated  from  zonescan.nzrs.net.nz  •  Uses  dnscheck  from  .SE,  plus  local  modificaJons  – Will  be  obsoleted  by  Zonemaster  

•  Stored  in  the  Hadoop  cluster:  120Gb  

Page 4: Sweeping(the(.nz(name(space( (zone(and(web(scan)(...Agenda • Zone(scan(– Methodology(– A(year(worth(of(results(– DNSSEC(adopJon(– IPv6(adopJon(– Mail(services(marketshare(•

Zone  scan  –  General  Status  

Page 5: Sweeping(the(.nz(name(space( (zone(and(web(scan)(...Agenda • Zone(scan(– Methodology(– A(year(worth(of(results(– DNSSEC(adopJon(– IPv6(adopJon(– Mail(services(marketshare(•

Zone  scan  –  DNSSEC  adopJon  

Page 6: Sweeping(the(.nz(name(space( (zone(and(web(scan)(...Agenda • Zone(scan(– Methodology(– A(year(worth(of(results(– DNSSEC(adopJon(– IPv6(adopJon(– Mail(services(marketshare(•

Zone  scan  –  v4  status  

Page 7: Sweeping(the(.nz(name(space( (zone(and(web(scan)(...Agenda • Zone(scan(– Methodology(– A(year(worth(of(results(– DNSSEC(adopJon(– IPv6(adopJon(– Mail(services(marketshare(•

Zone  scan  –  v6  status  

Page 8: Sweeping(the(.nz(name(space( (zone(and(web(scan)(...Agenda • Zone(scan(– Methodology(– A(year(worth(of(results(– DNSSEC(adopJon(– IPv6(adopJon(– Mail(services(marketshare(•

Zone  scan  -­‐  TTLs  

Page 9: Sweeping(the(.nz(name(space( (zone(and(web(scan)(...Agenda • Zone(scan(– Methodology(– A(year(worth(of(results(– DNSSEC(adopJon(– IPv6(adopJon(– Mail(services(marketshare(•

Zone  scan  –  Maps!  

Page 10: Sweeping(the(.nz(name(space( (zone(and(web(scan)(...Agenda • Zone(scan(– Methodology(– A(year(worth(of(results(– DNSSEC(adopJon(– IPv6(adopJon(– Mail(services(marketshare(•

Zone  scan  –  Maps!  

Page 11: Sweeping(the(.nz(name(space( (zone(and(web(scan)(...Agenda • Zone(scan(– Methodology(– A(year(worth(of(results(– DNSSEC(adopJon(– IPv6(adopJon(– Mail(services(marketshare(•

Zone  scan  –  web  servers  

Page 12: Sweeping(the(.nz(name(space( (zone(and(web(scan)(...Agenda • Zone(scan(– Methodology(– A(year(worth(of(results(– DNSSEC(adopJon(– IPv6(adopJon(– Mail(services(marketshare(•

Zone  scan  –  mail  services  market  share  

Page 13: Sweeping(the(.nz(name(space( (zone(and(web(scan)(...Agenda • Zone(scan(– Methodology(– A(year(worth(of(results(– DNSSEC(adopJon(– IPv6(adopJon(– Mail(services(marketshare(•

Zone  scan  -­‐  future  

•  Keep  the  gathering,  make  some  of  the  data  publicly  available  

•  Fetch  more  interesJng  stuff,  like  DANE  adopJon  

•  Analysis  of  Geo-­‐locaJon  of  services  

Page 14: Sweeping(the(.nz(name(space( (zone(and(web(scan)(...Agenda • Zone(scan(– Methodology(– A(year(worth(of(results(– DNSSEC(adopJon(– IPv6(adopJon(– Mail(services(marketshare(•

Web  scan  -­‐  IntroducJon  

•  For  all  .nz  domains,  tries  to  fetch  the  main  page  (www.$domain)  

•  Implemented  internally  in  Python  •  First  test  run  using  random  10%  sample  of  domains  in  September  2014  

•  ObjecJve:  Understand  more  about  what  domains  are  used  for  

Page 15: Sweeping(the(.nz(name(space( (zone(and(web(scan)(...Agenda • Zone(scan(– Methodology(– A(year(worth(of(results(– DNSSEC(adopJon(– IPv6(adopJon(– Mail(services(marketshare(•

Web  scan  –  Result  overview  

Page 16: Sweeping(the(.nz(name(space( (zone(and(web(scan)(...Agenda • Zone(scan(– Methodology(– A(year(worth(of(results(– DNSSEC(adopJon(– IPv6(adopJon(– Mail(services(marketshare(•

Web  scan  –  Status  vs.  age  

Page 17: Sweeping(the(.nz(name(space( (zone(and(web(scan)(...Agenda • Zone(scan(– Methodology(– A(year(worth(of(results(– DNSSEC(adopJon(– IPv6(adopJon(– Mail(services(marketshare(•

Webscan  –  Status  vs.  registrar  

Page 18: Sweeping(the(.nz(name(space( (zone(and(web(scan)(...Agenda • Zone(scan(– Methodology(– A(year(worth(of(results(– DNSSEC(adopJon(– IPv6(adopJon(– Mail(services(marketshare(•

Webscan  –  CMS  detecJon  

Page 19: Sweeping(the(.nz(name(space( (zone(and(web(scan)(...Agenda • Zone(scan(– Methodology(– A(year(worth(of(results(– DNSSEC(adopJon(– IPv6(adopJon(– Mail(services(marketshare(•

Web  scan  –  CMS  vs  Age  

Page 20: Sweeping(the(.nz(name(space( (zone(and(web(scan)(...Agenda • Zone(scan(– Methodology(– A(year(worth(of(results(– DNSSEC(adopJon(– IPv6(adopJon(– Mail(services(marketshare(•

Web  scan  –  Social  Media  

Page 21: Sweeping(the(.nz(name(space( (zone(and(web(scan)(...Agenda • Zone(scan(– Methodology(– A(year(worth(of(results(– DNSSEC(adopJon(– IPv6(adopJon(– Mail(services(marketshare(•

Web  scan  -­‐  RedirecJon  

Page 22: Sweeping(the(.nz(name(space( (zone(and(web(scan)(...Agenda • Zone(scan(– Methodology(– A(year(worth(of(results(– DNSSEC(adopJon(– IPv6(adopJon(– Mail(services(marketshare(•

Web  scan  –  Page  latency  

401  domains  with  latency  >  10s  Slowest:  848  (s)  

Page 23: Sweeping(the(.nz(name(space( (zone(and(web(scan)(...Agenda • Zone(scan(– Methodology(– A(year(worth(of(results(– DNSSEC(adopJon(– IPv6(adopJon(– Mail(services(marketshare(•

Web  scan  –  Number  of  links  

•  788  domains  with  more  than  200  links  

•  rockonvidtrade.co.nz  3740  •  postshoplocator.co.nz  4481    

Page 24: Sweeping(the(.nz(name(space( (zone(and(web(scan)(...Agenda • Zone(scan(– Methodology(– A(year(worth(of(results(– DNSSEC(adopJon(– IPv6(adopJon(– Mail(services(marketshare(•

Web  scan  -­‐  future  

•  Run  with  the  full  list  of  domains  •  Technical  improvements  – Split  latency  by  DNS  +  HTTP  – Follow  iframes  – Understand  more  of  domains  by  text  analysis  – VisualizaJon  of  page  interlinking  

•  Focus  in  the  deep  web  scan