Feeds

DNS Rootservers go international

Anycast anywhere

  • alert
  • submit to reddit

Security for virtualized datacentres

For the first time in Internet history there are more DNS rootservers outside the United States than within, following this week's launch in Frankfurt of an anycast "instance" of RIPE NCC-managed K root server.

The K-root DNS server is one of the 13 official DNS rootservers which answer lookups for domain names all over the world. It is operated by RIPE NCC, the organization in charge of IP adress allocation throughout Europe, the Middle East and parts of Africa, and is sitting at the London Internet Exchange.

Of the original 13 rootservers only three
were outside the US, which fuelled criticism of US centrism in Internet management.

"The launch of the K anycast instance will make the German Internet Community more independent and the DNS in general more reliable," said Denic CEO Sabine Dolderer. The registry for .de-adresses co-sponsered
the new server together with the German ISP association ECO.

According to Axel Pawlik, CEO of RIPE NCC, the anycast system will for example help to mitigate DDoS-attacks on the thirteen root servers. RIPE NCC technicians were among the pioneers of the anycast concept for the root servers. So far they brought instances of the K server that sits at the London Internet Exchange (LINX) to their headquarters in Amsterdam and to Frankfurt. Until the end of the year there will be up to ten identical servers in all of Europe.

The anycast systems makes the central zone files of the original root server available under the same IP adress on different machines in different locations. The spreading of the servers across the net make it more difficult to attack them and lower the response times for local communities.

"We talk about milliseconds," says Dolderer. Most users would not notice the change, and only traceroutes would show that request are now answered by the Frankfurt server. But tests at the anycast instance of the F root server in Dubai resulted in a drop from 130 to 30 milliseconds.

The operators of F, the Internet Software Consortium, so far have spread most rapidly over the globe. F root servers already have been installed in Ottawa, Madrid, Hong Kong, Rome, Auckland, Sao Paulo, Beijing, Seoul, Moscow, Taipei, Dubai, Paris and Singapore.

"It happens that our offers for a K instance were answered by 'oh, we already have F'," says Pawlik. But there was no race between root server operators. Up to now, five of them already joined the anycast effort and more will join, said Pawlik. "The more instances of the root servers the better", he says.

Some-well connected places house the slaves of several root servers. London for example has the K root and also hosts instances of I and J.

Now with the K instance at the Frankfurt German Internet Exchange (DeCIX) there are 24 root server locations outside, compared to 23 in the US. Not counted in are instances of root servers organized by local communities like the N-IX Internet Exchange at Nuremberg, Germany. The N-IX is anycasting root
servers of ICANN, the NASA and WIDE in Japan.

"Technically this changes the concentration," says Dolderer. "But the political problem is still there."

What information is fed into the system has to be decided by the Internet Corporation for Assigned Names and Numbers ICANN) and be propagated through the master, the A root server in Dulles. Everyone of the other 12 root servers are the so-called slaves and so are their new "children". And master A is under the oversight of the US Department of Commerce. ®

Reducing the cost and complexity of web vulnerability management

More from The Register

next story
Phones 4u slips into administration after EE cuts ties with Brit mobe retailer
More than 5,500 jobs could be axed if rescue mission fails
JINGS! Microsoft Bing called Scots indyref RIGHT!
Redmond sporran metrics get one in the ten ring
Driving with an Apple Watch could land you with a £100 FINE
Bad news for tech-addicted fanbois behind the wheel
Murdoch to Europe: Inflict MORE PAIN on Google, please
'Platform for piracy' must be punished, or it'll kill us in FIVE YEARS
Phones 4u website DIES as wounded mobe retailer struggles to stay above water
Founder blames 'ruthless network partners' for implosion
Found inside ISIS terror chap's laptop: CELINE DION tunes
REPORT: Stash of terrorist material found in Syria Dell box
Sony says year's losses will be FOUR TIMES DEEPER than thought
Losses of more than $2 BILLION loom over troubled Japanese corp
prev story

Whitepapers

Providing a secure and efficient Helpdesk
A single remote control platform for user support is be key to providing an efficient helpdesk. Retain full control over the way in which screen and keystroke data is transmitted.
WIN a very cool portable ZX Spectrum
Win a one-off portable Spectrum built by legendary hardware hacker Ben Heck
Saudi Petroleum chooses Tegile storage solution
A storage solution that addresses company growth and performance for business-critical applications of caseware archive and search along with other key operational systems.
Protecting users from Firesheep and other Sidejacking attacks with SSL
Discussing the vulnerabilities inherent in Wi-Fi networks, and how using TLS/SSL for your entire site will assure security.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.