Verisign Team


Recent posts by Verisign Team:

The “Queen of QVC” Lori Greiner Joins Panel of Judges for the #InternetOfficial Contest

Lori GreinerWe’re honored to announce that star investor, inventor and entrepreneur Lori Greiner is one of our celebrity judges on the #InternetOfficial contest judging panel! She is ready to judge your .com domain name in celebration of 30 years of .com. But, before we get into the details, have you registered your .com domain and entered our #InternetOfficial contest yet?

We can’t wait to hear Lori’s perspective on the entries and .com ideas you submit. Lori truly embodies the spirit of this contest. She was able to cultivate her great business idea—an innovative earring organizer—into what is now a multi-million dollar international brand with hundreds of new products which she sells on QVC, QVC.com and at other retailers. Additionally, Lori has her own show on QVC called Clever & Unique Creations. Her successful journey demonstrates how one idea can create opportunities for you, so make it #InternetOfficial: Register your .com and start your business journey today.

(more…)

Internet Grows to 284 Million Domain Names in the Third Quarter of 2014

Today, we released the latest issue of the Domain Name Industry Brief, which showed that the Internet grew by four million domain names in the third quarter of 2014. The total number of domain names across all top-level domains (TLDs) is now 284 million. This is a 1.6 percent increase over the second quarter of 2014. [1]

Largest TLDs by Zone Size

TLD by Zone Size Q3 2014
Source: Zooknic, Q3 2014; Verisign, Q3 2014; Centralized Zone Data Service, Q3 2014

(more…)

Verisign OpenHybrid™: An Essential New Approach to DDoS Protection

Distributed Denial of Service (DDoS) attacks are a threat to businesses worldwide and the attacks are getting larger and more sophisticated.  The industry’s approach to protecting against DDoS attacks must change, and change fundamentally, to stay ahead of this growing threat.

For too long, the problem has been tackled piecemeal, using isolated devices or services. But protecting against DDoS attacks increasingly requires communication and coordination between many components – from networking equipment, to specialized appliances and cloud-based services.

A shift in security architecture is needed to an open platform where devices and services from different vendors can share and act on information in concert. It must be a hybrid platform, allowing on-premise routers and security appliances to detect and mitigate attacks locally, while automating alerting and switchover to cloud-based services if an attack threatens to swamp the business’ network connection.

(more…)

New from Verisign Labs: What’s in your attack surface?

Recently, Verisign Labs researcher Eric Osterweil and Verisign CSO Danny McPherson, along with Lixia Zhang, a professor of computer science at UCLA, received the Best Paper Award at this year’s IEEE Workshop on Secure Network Protocols (NPSec ‘14) for their paper, “The Shape and Size of Threats: Defining a Networked System’s Attack Surface.” Below is a guest post from one of the authors, Eric Osterweil, principal researcher for Verisign Labs, describing the genesis of the research and future plans.

(more…)

Domain Registrations: Is Bitcoin Going Mainstream?

Earlier this year we used Bitcoin as an example of how domain registrations could be an effective gauge of interest in a particular subject. Our analysis demonstrated a clear rise in the number of registered .com and .net domain names containing the term “Bitcoin” in 2013, as well as a positive correlation between increased registration activity and increases in the dollar value of bitcoin.

In this post, we decided to take a look at the history of Bitcoin-related domain registration activity since 2009 to see if we noticed any other trends.

(more…)

New from Verisign Labs: Measuring the Leakage of Onion at the Root

If you are trying to communicate anonymously on the internet using Tor, this paper may be an important read for you. Anonymity and privacy are at the core of what the Tor project promises its users. Short for The Onion Router, Tor provides individuals with a mechanism to communicate anonymously on the internet. As part of its offerings, Tor provides hidden services, specifically anonymous networking between servers that are configured to receive inbound connections only through Tor. In order to route requests to these hidden services, a namespace is used to identify the resolution requests to such services. Tor uses the .onion namespace under a non-delegated (pseudo) top-level-domain. Although the Tor system was designed to prevent .onion requests from leaking into the global DNS resolution process, numerous requests are still observed in the global DNS, causing concern about the severity of the leakage and the exposure of sensitive private data.

(more…)

New from Verisign Labs – Measuring Privacy Disclosures in URL Query Strings

Have you ever gone to socially share or email a URL and found that it was much longer than you had expected? Take the following contrived URL as an example:

http://www.example.com/path/submit.php?user=userabc&pageid=012345&utm_referrer=rss&localtime=+0500

In your personal experience, as in our example, you might have realized that the URL was as much about you, the client, as it was about the web resource you were trying to access. Indeed, internet addresses may contain a wealth of information about the identities and activities of the users visiting them. URLs often utilize query strings (i.e., key-value pairs appended to the URL path; in our example, everything after the question mark) as a means to pass session parameters and form data. While sometimes benign and necessary to render the web page, query strings often contain tracking mechanisms, user names, email addresses and other information that users may not wish to publicly reveal. In isolation this is not particularly problematic, but the growth of web 2.0 platforms such as social networks and micro-blogging means such URLs are increasingly being publicly broadcast.

(more…)

The Evolving Threat of Amplification DDoS Attacks

If there is one trend in the cybersecurity world over the last 12 to 18 months that cannot be ignored, it is the increasing prevalence and destructive power of amplification-based distributed denial of service (DDoS) attacks.

An amplification attack is a two-part DDoS attack that generally uses the User Datagram Protocol (UDP). An attacker first sends a large number of small requests to unsuspecting third-party servers on the internet. The attacker crafts these requests to result in large responses, but they are otherwise normal except that their source addresses are rewritten (spoofed) so they appear to have come from the victim instead of the attacker. When all the third-party servers send their large responses to the victim, the resulting amount of traffic is much more than the attacker could have generated alone. These attacks often overwhelm the resources of the victim, as attacks in the hundreds of gigabits per second (Gbps) are possible using this method.

(more…)