Skip to main content
Resources

新闻发布:ICANN 的倡议推广互联网安全最佳实践

技术专家社群将通力合作以确保域名系统更安全可靠

本页面还提供其他语种:

洛杉矶 - 2022 年 9 月 6 日 - 互联网名称与数字地址分配机构 (Internet Corporation for Assigned Names and Numbers, ICANN) 正在发起"DNS 和域名安全的知识共享和实例规范 (Knowledge-sharing and Instantiating Norms for DNS and Naming Security, KINDNS)"倡议,以使互联网对所有用户来说更安全、更具弹性。ICANN 通过与一个全球技术专家社群开展合作,正在为域名系统 (Domain Name System, DNS) 的安全制定一套明确的运营最佳实践框架。

KINDNS 只是 ICANN 正在进行的众多努力之一。这些工作旨在促进公共和私人行为者的广泛参与,改善互联网的安全性、可靠性和互用性。

"随着互联网的日益发展,并在我们的日常生活中发挥更大的作用,DNS 的安全从未如此重要,"ICANN 高级副总裁兼首席技术官约翰·克莱恩 (John Crain)指出。"尽管存在各种 DNS 运营的最佳实践,但它们的应用并不一致,有时还导致了影响整个互联网的重大安全漏洞。"

为了缓解这种情况,ICANN 与技术社群展开合作,启动了 KINDNS,将其作为分享最佳实践的一套机制,以更好地保障 DNS 运营的安全。此举构建了一套简单有效的框架,大大小小的 DNS 运营商均可方便且自愿地遵循。例如,通过 KINDNS 分享的一个良好实践,旨在确保域名服务器实现地理上和拓扑上的多样性(即:权威和递归服务器运营商的 KINDNS 实践-5)。另一个例子是鼓励运营商启用域名系统安全扩展 (Domain Name System Security Extensions, DNSSEC),即通过权威服务器进行签名,并使用解析器验证这些签名。DNSSEC 是一项技术,通过帮助防止某些类型的攻击,确保互联网用户抵达他们想要的网上目的地(即:权威和递归服务器运营商的 KINDNS 实践-1)。

互联网服务提供商、企业 IT 经理人、DNS 服务运营商和软件开发商均受邀采纳 KINDNS 在其网站上推广的最佳实践,帮助促进本项目。如需了解更多信息,请访问 KINDNS 的专属网页

ICANN 简介

ICANN 的使命在于确保全球互联网的稳定、安全与统一。要在互联网上访问另一个人的信息,您必须在电脑或其他设备中键入一个地址——可以是一个名称或是一串数字。这个地址必须是独一无二的,只有这样电脑之间才能互相识别。ICANN 负责协调这些分布在世界各地的唯一标识符并提供相应支持。ICANN 是一个非营利性公益机构,成立于 1998 年,其社群的参与者遍布世界各地。

媒体联系人

亚历山大·丹斯 (Alexandra Dans)
美洲地区传播主管
乌拉圭蒙得维的亚
+598 95 831 442
alexandra.dans@icann.org
press@icann.org

Domain Name System
Internationalized Domain Name ,IDN,"IDNs are domain names that include characters used in the local representation of languages that are not written with the twenty-six letters of the basic Latin alphabet ""a-z"". An IDN can contain Latin letters with diacritical marks, as required by many European languages, or may consist of characters from non-Latin scripts such as Arabic or Chinese. Many languages also use other types of digits than the European ""0-9"". The basic Latin alphabet together with the European-Arabic digits are, for the purpose of domain names, termed ""ASCII characters"" (ASCII = American Standard Code for Information Interchange). These are also included in the broader range of ""Unicode characters"" that provides the basis for IDNs. The ""hostname rule"" requires that all domain names of the type under consideration here are stored in the DNS using only the ASCII characters listed above, with the one further addition of the hyphen ""-"". The Unicode form of an IDN therefore requires special encoding before it is entered into the DNS. The following terminology is used when distinguishing between these forms: A domain name consists of a series of ""labels"" (separated by ""dots""). The ASCII form of an IDN label is termed an ""A-label"". All operations defined in the DNS protocol use A-labels exclusively. The Unicode form, which a user expects to be displayed, is termed a ""U-label"". The difference may be illustrated with the Hindi word for ""test"" — परीका — appearing here as a U-label would (in the Devanagari script). A special form of ""ASCII compatible encoding"" (abbreviated ACE) is applied to this to produce the corresponding A-label: xn--11b5bs1di. A domain name that only includes ASCII letters, digits, and hyphens is termed an ""LDH label"". Although the definitions of A-labels and LDH-labels overlap, a name consisting exclusively of LDH labels, such as""icann.org"" is not an IDN."