ICANN SAC105: The DNS and the Internet of Things: Opportunities, Risks, and Challenges
This is a report of the ICANN Security and Stability Advisory Committee (SSAC). The SSAC focuses on matters relating to the security and integrity of the Internet’s naming and address allocation systems. SSAC engages in ongoing threat assessment and risk analysis of the Internet naming and address allocation services to assess where the principal threats to stability and security lie, and advises the ICANN community accordingly.
The number of open resolvers on the Internet is on the order of millions, with [31] estimating 23- 25 million open resolvers in 2014 and Shadowserver reporting over 3 million open resolvers based on their active scanning system (Dec 2018). While open resolvers are a longtime problem [42], they represent an additional risk to the IoT.
A few prototypes of shared systems for exchanging DDoS information across multiple collaborating players are under development and are potential starting points for a shared system for DNS operators. Sources that may enrich the botnet information in the shared database include: Shadowserver’s Open Resolver Scanning Project, which could help to identify resolvers that IoT botnets have used or could use for reflection attacks.