Security Group
About:
ICANN has a small team of security experts who are responsible for day-to-day planning and execution of operational ICANN efforts related to security as directed by the ICANN Board and CEO in fulfillment of the ICANN strategic and operational plans. The team coordinates across the range of ICANN efforts to ensure effective engagement in topics relating to security, including cyber security and other forums related to security, stability and resiliency.
Who are we:
The current work plan for the group and ICANN as a whole is documented as the Plan for Enhanced Internet Security, Stability and Resiliency.
Situation Awareness Bulletins:
ICANN-SA-2009-0001: Potential attack against ccTLD Registration Systems (Published 13 July 2009)
ICANN-SA-2009-0002: High volume criminal phishing attack known as Avalanche the delivery method for the Zeus botnet infector (Published 6 October 2009)
Documents:
Plan for Enhanced Internet Security, Stability and Resiliency
Final Report from Global DNS Security, Stability and Resiliency Symposium
Upcoming Events:
These are events where staff will be participating. Please feel free to come talk to us.
2009
| Date | Host Organisation | Location | Program |
| Nov 22 | PACNOG | Fiji | SSR, collaborative response brief Possible ACRP or IROC |
2010
| Date | Host Organisation | Location | Program |
| Jan 18 | TF-CSIRT & FIRST TC | Hamburg, Germany | SSR, collaborative response brief |
| Feb 1-2 | DNS SSR Metrics Symposiumy | Kyoto, Japan | DNS SSR Metrics |
| Mar 2 | APCERT | Thailand | New gTLD, IDN security |
Contact:
ICANN Security Group Point of Contact (security-ops@icann.org)
Reports sent to security-ops@icann.org will be forwarded to ICANN security team staff.
ICANN's security team is interested in hearing about events and incidents where the DNS or registration services are exploited and/or misdirected on a large scale, attacks where the name service or domain registration services are used to facilitate those attacks, or where the DNS infrastructure or registrations services are the targets of malicious activity.