SPIN: A User-centric Security Extension for In-home Networks
Users at the centre
Kies jouw kleur
Veel bezocht
Veelgestelde vragen
Via de Whois kun je de huidige houder van een domeinnaam opzoeken. Om de persoonsgegevens in te zien moet je vanwege de privacygevoelige informatie eerst de gebruikersvoorwaarden van de Whois accepteren. Gegevens van privé personen kunnen ook afgeschermd zijn vanwege de AVG (Algemene verordening gegevensbescherming).
Op de pagina domeinnaam zoeken lees je meer over wat een domeinnaam is, de werking van de Whois en de privacy van persoonsgegevens.
Je wilt je domeinnaam verhuizen naar een andere registrar. Vraag dan je verhuistoken op bij je huidige registrar. Lees de verhuisstappen op de pagina domeinnaam verhuizen.
Neem contact op met je registrar. Jouw registrar kan de contactgegevens bij je domeinnaam voor je aanpassen. Wij raden je aan het resultaat te controleren via de Whois. Lees meer over het aanpassen van je gegevens bij contactgegevens wijzigen.
Wij weten niet wat de reden van de opheffing is. Neem contact op met je registrar. Het voordeel van de quarantaine is dat je altijd de mogelijkheid hebt om een opheffing die je niet had bedoeld te herstellen.
Voorbeeld: In de voorwaarden van je registrar staat dat je elk jaar je abonnement moet verlengen. Dat gebeurt dan niet automatisch. Zo kan het gebeuren dat je domeinnaam wordt opgeheven zonder dat je er om gevraagd hebt.
Wanneer je een klacht hebt over of een geschil met je registrar dan zijn er verschillende mogelijkheden om tot een oplossing te komen. Hierover lees je meer op pagina klacht over registrar. SIDN heeft geen formele klachtenprocedure voor het behandelen van een klacht over jouw registrar.
Wil je zelf direct domeinnamen kunnen registreren bij SIDN voor je klanten of voor je eigen organisatie? Dan kun je .nl-registrar worden. Lees meer over de voorwaarden en de manier waarop je je kunt inschrijven als registrar via de pagina registrar worden.
Users at the centre
The Internet of Things (IoT) will connect billions of devices to the Internet that we normally do not think of as computers, such as fridges, cameras, and light bulbs. At SIDN Labs, we are developing a system called SPIN (Security and Privacy for In-home Networks) that aims to reduce the security risks that these devices pose to core Internet systems, service providers, and end-users. We discuss our ongoing work on the design and implementation of the system in a technical report, which we released today.
While the Internet of Things (IoT) promises to enable many new types of services and applications, IoT devices are often poorly secured and as a result pose a threat to the security and stability of the core systems of the Internet, such as to the Domain Name System (DNS). In October 2016, for example, DNS operator Dyn was hit by a Denial of Service (DoS) attack carried out through millions of IoT devices compromised with the Mirai botnet that allegedly reached an aggregate magnitude of 1.2 Tbps. Other potential targets of such attacks include operators of Top-level Domains (such as .nl, operated by SIDN), hosting providers, and application service providers.
Another consequence of poorly secured IoT devices is that they compromise the security and privacy of end-users, for instance because they allow attackers to send spam from a vulnerable fridge. This jeopardizes users’ trust in het Internet and their home environment, in particular because the average end-user typically finds it hard to distinguish between well and poorly secured IoT devices and in many cases even lack the interest in these characteristics.
These developments motivated us to design and implement the system for Security and Privacy for In-home Networks (SPIN), which provides network-level security functions that monitor and automatically block vulnerable IoT devices. The goal of the SPIN system is to protect (1) DNS infrastructure operators and other service providers on the Internet from DDoS attacks and (2) to protect users’ security and privacy in their homes. SPIN focuses on home networks because they are typically not as well-managed as corporate ones. Our view is that SPIN is an element of a wider integrated approach to IoT security, which for instance also involves setting up a commonly applied security certification mark for IoT devices.
SPIN takes a unique user-centric approach in that it (1) allows users to easily deploy the system through pluggable SPIN devices that automatically monitor and block traffic for groups of IoT devices in the home, (2) protects users’ privacy by keeping all processing and threat handling on the SPIN devices in their home, (3) allows users to configure the system with their security control preferences, for instance in term of the system’s traffic blocking behavior. SPIN is also unique because it enables the security community to provide traces of malicious traffic, thus extending the systems’ threat detection capabilities.
We have developed a working prototype of the SPIN system, which focuses on visualizing and blocking traffic to and from IoT devices for privacy protection purposes. The source code is available in the form of an open source package for OpenWRT devices, but can also be built and run on other Linux-based systems. We bundled it with our Valibox firmware for DNSSEC validation. A screencast of the SPIN dashboard for a SPIN device running in an actual home network is available here.
Our technical report discusses our ongoing work on the design and implementation of the SPIN system, which builds on the work we previously reported on in this blog.
Feedback welcome!
As usual, we welcome feedback on our work. If you would like to share your thoughts with us, then please drop us an email at sidnlabs@sidn.nl or contact us via Twitter @sidnlabs.
You can read the full tech report here.
Artikel door:
Directeur SIDN Labs
Postdoc researcher
at the University of Twente
Deel dit artikel