Fw: [AfrICANN-discuss] US ISPs commit to new cybersecurity measures

FYI Best Alice US ISPs commit to new cybersecurity measures The recommendations from an FCC advisory committee target botnets, domain name fraud and Internet route hijacking <http://www.csoonline.com/article/702666/us-isps-commit-to-new-cybersecurit= y-measures#disqus_thread> By Grant Gross http://www.csoonline.com/article/702666/us-isps-commit-to-new-cybersecurity= -measures March 22, 2012 =97 IDG News Service =97 A group of U.S. Internet service providers, including the four largest, have committed to taking new steps to combat three major cybersecurity threats, based on recommendations from a U.S. Federal Communications Commission advisory committee. The ISPs, including AT&T, Comcast, Time Warner Cable and Verizon Communications, committed Thursday to implement measures to fight botnets, domain name fraud and Internet route hijacking. The FCC's Communications, Security, Reliability, and Interoperability Council (CSRIC) adopted the recommendations for voluntary action by ISPs the same day. Eight wired and wireless ISPs, representing about 80 percent of the broadband subscribers in the U.S., are members of CSRIC<http://transition.fcc.gov/pshs/advisory/csric/members.html>and signed on to the recommendations. "These actions will have a significant positive impact on Internet security," FCC Chairman Julius Genachowski said. "If you own a PC, you'll be significantly better protected against your computer [being] taken over by a bad actor, who could destroy your private files or steal your personal information. If you shop or bank online, you'll be significantly better protected against being directed to an illegitimate website and having your credit card number stolen." The recommendations preserve the open architecture of the Internet and protect Internet users' privacy, Genachowski said. The CSRIC recommendations embraced by the ISPs include an antibot code of conduct. ISPs agreed to educate customers about botnets and to take steps to identify botnet activity on their networks. ISPs will also warn customers about botnet infections on their computers and offer assistance to customers with compromised computers, under the code of conduct. The ISPs also committed to implement a set of best practices to secure the Internet's Domain Name System by implementing DNSSEC, a set of secure protocol extensions designed to prevent DNS spoofing. CSRIC also recommended that the Internet industry develop an Internet Protocol-route highjacking framework, including new technologies and practices to limit the number of times that Internet traffic is misdirected= . T-Mobile USA, one of the ISPs signing on to the recommendations, called cybersecurity an "extremely important issue." The company supports voluntary, industrywide deployment of DNSSEC, T-Mobile said in a statement. ISPs will need help from other Internet companies to implement the security measures, said Bob Quinn, AT&T's senior vice president for federal regulatory affairs. "DNSSEC is predicated upon a chain of trust across the Internet," he wrote in a blog post<http://attpublicpolicy.com/cybersecurity/cybersecurity-and-t= he-fccs-csric-recommendations/>. "[CSRIC] recommends that key industry segments such as banking, healthcare and others sign their respective domains and that software developers, such as web-browser developers, study how and when to incorporate DNSSEC validation functions into their software." The botnet recommendations see a "significant role" for other companies, including security software vendors and operating system developers, he added. "Keeping the Internet safe for consumers to browse, transact business and communicate is an important objective not only for AT&T but any other business that operates online," he wrote. *Grant Gross covers technology and telecom policy in the U.S. government for *The IDG News Service*. Follow Grant on Twitter at GrantGross. Grant's e-mail address is grant_gross@idg.com.* -----Original Message----- From: Anne-Rachel Inné <annerachel@gmail.com> Sender: africann-bounces@afrinic.net Date: Fri, 23 Mar 2012 10:16:05 To: <africann@afrinic.net> Reply-To: africann@afrinic.net Subject: [AfrICANN-discuss] US ISPs commit to new cybersecurity measures _______________________________________________ AfrICANN mailing list AfrICANN@afrinic.net https://lists.afrinic.net/mailman/listinfo.cgi/africann

thnx Alice for the post. the key word/thread in your post is cooperation and voluntary implementation between the US regulator and the ISPs/Telcos in the CyberSecurity space in the US Unfortunately, I am neither an ISP nor a Telco and so am not quite sure how many ISP/Telcos are members of our Kenyan CyberCrime unit at CCK (ofcourse others may argue that for national security reasons they do need to be there?). The moral of my thread is that we can actually have ISPs installing security gadgets (illegal or otherwise) on their networks as long as they feel they are part of the process. The moment they feel left out, they easily hide behind legalese and can make the going pretty rough and expensive for everyone - I already saw Mutoro doing his thing on TV jana and soon Okiki Omutatah might join him ;-) walu. have a cyber-secure weekend. --- On Fri, 3/23/12, alice@apc.org <alice@apc.org> wrote: From: alice@apc.org <alice@apc.org> Subject: [kictanet] Fw: [AfrICANN-discuss] US ISPs commit to new cybersecurity measures To: jwalu@yahoo.com Cc: "KICTAnet ICT Policy Discussions" <kictanet@lists.kictanet.or.ke> Date: Friday, March 23, 2012, 12:32 PM FYI Best AliceUS ISPs commit to new cybersecurity measures The recommendations from an FCC advisory committee target botnets, domain name fraud and Internet route hijacking By Grant Gross http://www.csoonline.com/article/702666/us-isps-commit-to-new-cybersecurity-... March 22, 2012 — IDG News Service — A group of U.S. Internet service providers, including the four largest, have committed to taking new steps to combat three major cybersecurity threats, based on recommendations from a U.S. Federal Communications Commission advisory committee. The ISPs, including AT&T, Comcast, Time Warner Cable and Verizon Communications, committed Thursday to implement measures to fight botnets, domain name fraud and Internet route hijacking. The FCC's Communications, Security, Reliability, and Interoperability Council (CSRIC) adopted the recommendations for voluntary action by ISPs the same day. Eight wired and wireless ISPs, representing about 80 percent of the broadband subscribers in the U.S., are members of CSRIC and signed on to the recommendations. "These actions will have a significant positive impact on Internet security," FCC Chairman Julius Genachowski said. "If you own a PC, you'll be significantly better protected against your computer [being] taken over by a bad actor, who could destroy your private files or steal your personal information. If you shop or bank online, you'll be significantly better protected against being directed to an illegitimate website and having your credit card number stolen." The recommendations preserve the open architecture of the Internet and protect Internet users' privacy, Genachowski said. The CSRIC recommendations embraced by the ISPs include an antibot code of conduct. ISPs agreed to educate customers about botnets and to take steps to identify botnet activity on their networks. ISPs will also warn customers about botnet infections on their computers and offer assistance to customers with compromised computers, under the code of conduct. The ISPs also committed to implement a set of best practices to secure the Internet's Domain Name System by implementing DNSSEC, a set of secure protocol extensions designed to prevent DNS spoofing. CSRIC also recommended that the Internet industry develop an Internet Protocol-route highjacking framework, including new technologies and practices to limit the number of times that Internet traffic is misdirected. T-Mobile USA, one of the ISPs signing on to the recommendations, called cybersecurity an "extremely important issue." The company supports voluntary, industrywide deployment of DNSSEC, T-Mobile said in a statement. ISPs will need help from other Internet companies to implement the security measures, said Bob Quinn, AT&T's senior vice president for federal regulatory affairs. "DNSSEC is predicated upon a chain of trust across the Internet," he wrote in a blog post. "[CSRIC] recommends that key industry segments such as banking, healthcare and others sign their respective domains and that software developers, such as web-browser developers, study how and when to incorporate DNSSEC validation functions into their software."The botnet recommendations see a "significant role" for other companies, including security software vendors and operating system developers, he added. "Keeping the Internet safe for consumers to browse, transact business and communicate is an important objective not only for AT&T but any other business that operates online," he wrote. Grant Gross covers technology and telecom policy in the U.S. government for The IDG News Service. Follow Grant on Twitter at GrantGross. Grant's e-mail address is grant_gross@idg.com. -----Inline Attachment Follows----- _______________________________________________ kictanet mailing list kictanet@lists.kictanet.or.ke http://lists.kictanet.or.ke/mailman/listinfo/kictanet Unsubscribe or change your options at http://lists.kictanet.or.ke/mailman/options/kictanet/jwalu%40yahoo.com The Kenya ICT Action Network (KICTANet) is a multi-stakeholder platform for people and institutions interested and involved in ICT policy and regulation. The network aims to act as a catalyst for reform in the ICT sector in support of the national aim of ICT enabled growth and development. KICTANetiquette : Adhere to the same standards of acceptable behaviors online that you follow in real life: respect people's times and bandwidth, share knowledge, don't flame or abuse or personalize, respect privacy, do not spam, do not market your wares or qualifications.

On 3/23/12, Walubengo J <jwalu@yahoo.com> wrote:
thnx Alice for the post.
the key word/thread in your post is cooperation and voluntary implementation between the US regulator and the ISPs/Telcos in the CyberSecurity space in the US
and I would add that TESPOk already supplies info about botnets and Internet route hijacking, etc to ISPs and government agencies who run infected networks here in Kenya.
Unfortunately, I am neither an ISP nor a Telco and so am not quite sure how many ISP/Telcos are members of our Kenyan CyberCrime unit at CCK (ofcourse others may argue that for national security reasons they do need to be there?).
The moral of my thread is that we can actually have ISPs installing security gadgets (illegal or otherwise) on their networks as long as they feel they are part of the process. The moment they feel left out, they easily hide behind legalese and can make the going pretty rough and expensive for everyone
Expensive is right, a Deep Packet Inspection system for the whole country will cost 10's of Millions of USD to put in place, plus they will need a small army of analysts to make sense of the data.....but really If I am doing something illegal, why would I send unencrypted messages via an operators network? If I really wanted to avoid a DPI setup, I would use a VSAT, which can't be routed to a central inspection point! -- Cheers, McTim "A name indicates what we seek. An address indicates where it is. A route indicates how we get there." Jon Postel

Alice Best, At best, this offers an insight into how such a sensitive measure can be best handled - approached with all sensitivity/transparency observed - laying out clear parameters of what is being targeted and what needs to be achieved. Something akin to a PPP initiative - like Kenic, which has worked so well in our context. We need to adopt a similar 'non-opaque' approach in the development of the current National Firewall. To date all information out in the public domain is quite vague and only serve to feed a lot of fodder to the rumor mill doing rounds and might just throw a spanner into the works of an otherwise good initiative. CCK needs to come out clearly and state:- . Precisely what this National firewall is for and what is meant to do. . How transparently it will implement this and what data will be affected, and at what point. . How it plans to develop partnerships to move this forward, and avoid ultimatums to service providers.. . We are still waiting. Harry From: kictanet-bounces+harry=comtelsys.co.ke@lists.kictanet.or.ke [mailto:kictanet-bounces+harry=comtelsys.co.ke@lists.kictanet.or.ke] On Behalf Of alice@apc.org Sent: Friday, March 23, 2012 12:33 PM To: harry@comtelsys.co.ke Cc: KICTAnet ICT Policy Discussions Subject: [kictanet] Fw: [AfrICANN-discuss] US ISPs commit to new cybersecurity measures US ISPs commit to new cybersecurity measures The recommendations from an FCC advisory committee target botnets, domain name fraud and Internet route hijacking By Grant Gross http://www.csoonline.com/article/702666/us-isps-commit-to-new-cybersecurity- measures March 22, 2012 - IDG News Service - A group of U.S. Internet service providers, including the four largest, have committed to taking new steps to combat three major cybersecurity threats, based on recommendations from a U.S. Federal Communications Commission advisory committee. The ISPs, including AT&T, Comcast, Time Warner Cable and Verizon Communications, committed Thursday to implement measures to fight botnets, domain name fraud and Internet route hijacking. The FCC's Communications, Security, Reliability, and Interoperability Council (CSRIC) adopted the recommendations for voluntary action by ISPs the same day. Eight wired and wireless ISPs, representing about 80 percent of the broadband subscribers in the U.S., are members of CSRIC <http://transition.fcc.gov/pshs/advisory/csric/members.html> and signed on to the recommendations. "These actions will have a significant positive impact on Internet security," FCC Chairman Julius Genachowski said. "If you own a PC, you'll be significantly better protected against your computer [being] taken over by a bad actor, who could destroy your private files or steal your personal information. If you shop or bank online, you'll be significantly better protected against being directed to an illegitimate website and having your credit card number stolen." The recommendations preserve the open architecture of the Internet and protect Internet users' privacy, Genachowski said. The CSRIC recommendations embraced by the ISPs include an antibot code of conduct. ISPs agreed to educate customers about botnets and to take steps to identify botnet activity on their networks. ISPs will also warn customers about botnet infections on their computers and offer assistance to customers with compromised computers, under the code of conduct. The ISPs also committed to implement a set of best practices to secure the Internet's Domain Name System by implementing DNSSEC, a set of secure protocol extensions designed to prevent DNS spoofing. CSRIC also recommended that the Internet industry develop an Internet Protocol-route highjacking framework, including new technologies and practices to limit the number of times that Internet traffic is misdirected. T-Mobile USA, one of the ISPs signing on to the recommendations, called cybersecurity an "extremely important issue." The company supports voluntary, industrywide deployment of DNSSEC, T-Mobile said in a statement. ISPs will need help from other Internet companies to implement the security measures, said Bob Quinn, AT&T's senior vice president for federal regulatory affairs. "DNSSEC is predicated upon a chain of trust across the Internet," he wrote in a blog post <http://attpublicpolicy.com/cybersecurity/cybersecurity-and-the-fccs-csric-r ecommendations/> . "[CSRIC] recommends that key industry segments such as banking, healthcare and others sign their respective domains and that software developers, such as web-browser developers, study how and when to incorporate DNSSEC validation functions into their software." The botnet recommendations see a "significant role" for other companies, including security software vendors and operating system developers, he added. "Keeping the Internet safe for consumers to browse, transact business and communicate is an important objective not only for AT&T but any other business that operates online," he wrote. Grant Gross covers technology and telecom policy in the U.S. government for The IDG News Service. Follow Grant on Twitter at GrantGross. Grant's e-mail address is grant_gross@idg.com.
participants (4)
-
alice@apc.org
-
Harry Delano
-
McTim
-
Walubengo J