Security and Stability Advisory Committee (SSAC)

The SSAC is a volunteer group of specialists in the technical security field that provides advice and insight to the ICANN community and the Board.

本内容仅提供以下语言版本

  • English

SAC090 | Executive Summary for SSAC Advisory on the Stability of the Domain Namespace

[PDF, 254.86 KB]

This advisory focuses on the security and stability of the domain namespace amid its complex use in public and private contexts. It addresses risks stemming from ambiguous uses of domain names and the DNS resolution protocol in environments other than the public DNS, such as private networks. Top-level domain names and labels used in private networks—like .home or .corp—can unintentionally overlap with global DNS names, potentially leading to name collisions. These collisions, where private-use domain names are queried in the global DNS, can create security vulnerabilities if they inadvertently resolve to public domains when they shouldn’t.

SAC090 identifies challenges in managing domain namespaces used across diverse networks that interact with the public internet. Given that a unified authority to regulate and prevent overlaps is infeasible due to the decentralized nature of internet technologies, SSAC suggests a coordinated, multi-stakeholder approach that allows different groups—like ICANN and IETF—to work collaboratively to mitigate namespace conflicts. SSAC further advises ICANN to establish clear criteria to designate whether a name could be a top-level domain, to provide stability as new TLDs are introduced.

The advisory also proposes that ICANN consider formalizing the status of “private use” domains like .home and .corp in policy, possibly restricting or formally recognizing their use to avoid future conflicts in the DNS. This approach, SSAC argues, would reduce the risk of unintended interactions and reinforce a stable global DNS environment by minimizing misinterpretations of domain names across networks.

Recommendations

  • Recommendation 1: SSAC recommends that the ICANN Board take appropriate steps to establish definitive and unambiguous criteria for determining whether or not a syntactically valid domain name label could be a top-level domain name in the global DNS.
  • Recommendation 2: SSAC recommends that the scope of the work presented in Recommendation 1 include at least the following issues and questions: 
    • In the gTLD Applicant Guidebook for the most recent round of new generic Top Level Domain (gTLD) applications, ICANN cited or created several lists of strings that could not be applied-for new gTLD names, such as the “reserved names” listed in Section 2.2.1.2.1, the “ineligible strings” listed in Section 2.2.1.2.3, the two-character ISO 3166 codes proscribed by reference in Section 2.2.1.3.2, and the geographic names proscribed by reference in Section 2.2.1.4. More recently, the IETF has placed a small number of potential gTLD strings into a Special-Use Domain Names Registry (RFC 6761). As described in RFC 6761, a string that is placed into this registry is expected to be processed in a defined “special” way that is different from the normal process of DNS resolution.
      Should ICANN formalize in policy the status of the names on these lists? 
      • How should ICANN respond to changes that other parties may make to lists that are recognized by ICANN but are outside the scope of ICANN’s direct influence? 
      • How should ICANN respond to a change in a recognized list that occurs during a round of new gTLD applications?
    • The IETF is an example of a group outside of ICANN that maintains a list of “special use” names. What should ICANN’s response be to groups outside of ICANN that assert standing for their list of special names? 
    • Some names that are not on any formal list are regularly presented to the global DNS for resolution as TLDs. These so-called “private use” names are independently selected by individuals and organizations that intend for them to be resolved only within a defined private context. As such they are harmlessly discarded by the global DNS—until they collide with a delegated use of the same name as a new ICANN-recognized gTLD.
      Should ICANN formalize in policy the status of “private use” names? If so:
      • How should ICANN deal with private use names such as .corp, .home, and .mail that already are known to collide on a large scale with formal applications for the same names as new ICANN-recognized gTLDs?
      • How should ICANN discover and respond to future collisions between private use names and proposed new ICANN-recognized gTLDs?
  • Recommendation 3: Pursuant to its finding that lack of adequate coordination among the activities of different groups contributes to domain namespace instability, the SSAC recommends that the ICANN Board of Directors establish effective means of collaboration on these issues with relevant groups outside of ICANN, including the IETF.
  • Recommendation 4: The SSAC recommends that ICANN complete this work before making any decision to add new TLD names to the global DNS.