Baidu expert analysis paralysis event: call attention to the security domain name
HC Communication Network : January 13 morning news, domain name hijacking against Baidu regarding failure 11 hours, CNNIC Lin Qi, assistant director, said today to the SAN, from the CNNIC tracking data, the analysis of DNS outside accident and not related to security, should lead to ponder the domain security issues.
Qi Lin said that from the present data show baidu.com analytical point of view, Baidu failure stems from its domain name NameServer (hereinafter referred to as "NS") is modified, the NS's role is to decide which DNS server on the domain parsing, NS modify DNS records returned to the wrong course, can cause access errors.
The NS record this important, it is the domain name registration service provider maintenance. Information, baidu.com domain name registration service providers in the United States of register.com. Qi Lin that under the current situation analysis, there may be accidents NS tampering baidu.com account at register.com domain name theft, or register.com systems are penetrated.
Some voices condemning Baidu, Qi Lin believes that in the event there is no responsibility on Baidu. "This responsibility is in the United States register.com domain name registration service provider above, because their system is not very good security, protection account for baidu.com not very high security level."
Qi Lin pointed out that this also reflects the domain name registration service provider outside of China's Internet companies taken seriously. "Baidu in China is well-known search engine, if the domain registration business office in China, all ISPs will have a high profile. And foreign registered business does not necessarily aware of the importance of Baidu users in China."
And domain registrar services from the outside, another disadvantage is that because of time differences and geographical segment, up emergency treatment failure is not smooth. Qi Lin also contributed to the Baidu that it takes longer to restore access to one of the reasons.
Talk about the incident, Qi Lin gives three suggestions. First, an important network of domestic companies should make full use of the domestic domain name registration service provider for service providers within the network of domestic important high-level corporate security after qq.com go to China from overseas is a case.
Second, CNNIC Internet companies as much as possible the proposed application. CN domain names. CN domain name registration authorities in Beijing, in an emergency, contact and the relative speed will be faster. And for the protection of the CN domain name to its NS records are the focus of high-frequency monitoring, monitoring of the situation is modified, can greatly reduce the probability of the occurrence Baidu. Even if the occurrence of malicious tampering, CNNIC7 * 24-hour technical support can be restored in a very short period of time.
Third, Taiwan's major Internet companies, should try to enable the other main domain name, the implementation of multi-domain strategy, this can occur after a fault, the risks and losses to a minimum.
I am China Toys Suppliers writer, reports some information about gentian violet solution , gyrostabilizer.