Analytics
6/23/2014
01:50 PM
Connect Directly
Google+
Twitter
RSS
E-Mail
50%
50%

DNS Pioneer Founds New Security Startup

Paul Vixie launches Farsight Security, aimed at catching domain abuse early in the lifecycle.

Farsight Security today came out of stealth mode with a service that spots potentially malicious new domain names as a way to fight spam and cybercrime activity.

At the helm is DNS pioneer Paul Vixie, the principal author of the pervasive BIND DNS server software and creator of several DNS standards. This is Vixie's first commercial gig after nearly 20 years as founder, chairman, and president of the nonprofit Internet Systems Consortium.

Farsight Security's first offering, also announced today, is Newly Observed Domains (NOD), which provides real-time contextual intelligence about newly created domain names for reputation and threat feeds such as indicators of compromise, whitelists, and blacklists.

"There's no tool on the market for that," Vixie says. The goal of NOD and Farsight's strategy is to make threat intelligence more useful and actionable, according to Vixie.

Tens of thousands of domains are born daily, many of which are for spamming or cyber criminals' infrastructure. According to Farsight, 10% of spam uses domains that are less than 10 minutes old, and the bad guys are regularly registering new domain names to keep their operations up and running and out of reach by law enforcement.

"60% of spammers used domain names that are less than 24 hours old," Vixie says.

"Too many [vendors] are selling threat intelligence feeds... and they are not working," he says. "We’re trying to change the game... We sell context so people can make their own determinations and make [decisions] reliably. We have eyeballs on the ground: this is what we saw, this is what we know."

"I spent most of the 1980s and 1990s making the Internet bigger and easier to use, but unfortunately, the criminals came along for the ride," Vixie says. "We're looking at a day we can tear down criminal infrastructure as fast or faster than it's built."

Kelly Jackson Higgins is Executive Editor at DarkReading.com. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Christian Bryant
50%
50%
Christian Bryant,
User Rank: Ninja
6/23/2014 | 7:14:17 PM
Re: Great Thinking
@Robert McDougal

While I love the idea of Paul being an uber-lord of the Internet, I wonder how much whois information is actually available to private, non-government parties? Now, I've seen scripts that comb whois records, and for those that are private, tries matches through Google searches of like info (users with emails matching the info@ or admin@ of the domain), etc. Essentially a hack to pull as much information together with what is already out there as possible toward identifying the registrar and populating a database.  Hard to imagine a private party can get much more detailed information legally, unless Mr. Vixie is tied into PRISM... :-)
Robert McDougal
50%
50%
Robert McDougal,
User Rank: Ninja
6/23/2014 | 6:57:53 PM
Re: Great Thinking
This is awesome!  I imagine Mr. Vixie is leveraging his contacts within the domain registrars to pull this off.  I'm not sure if an average startup company could have provided this service.  Maybe I am wrong but to be able to access that information so quickly I would assume he would need access to information only available to the domain registrars.
Kelly Jackson Higgins
100%
0%
Kelly Jackson Higgins,
User Rank: Strategist
6/23/2014 | 4:16:45 PM
Re: Great Thinking
What's interesting here is focusing on newly created domains and trying to stop them from getting established by the bad guys so quickly. And it's cool that DNS mavens Vixie and Mockapetris are behind this venture.
Marilyn Cohodas
100%
0%
Marilyn Cohodas,
User Rank: Strategist
6/23/2014 | 3:54:34 PM
"Criminals came along for the rid"
Great quote: "I spent most of the 1980s and 1990s making the Internet bigger and easier to use, but unfortunately, the criminals came along for the ride," 
Christian Bryant
50%
50%
Christian Bryant,
User Rank: Ninja
6/23/2014 | 3:31:12 PM
Great Thinking
Kudos, Mr. Vixie. "We're looking at a day we can tear down criminal infrastructure as fast or faster than it's built." This is a great way of thinking and hopefully one we can propagate across organizations.  Creating a database from this activity will help law enforcement and others in the cyber security industry work more efficiently with access to historic criminal domain activity.  Of course, as soon as this gets underway, the "dark side" will respond, but I assume Farsight processes and technology are designed to be as malleable as the cyber criminals are... 
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
DNS Threats: What Every Enterprise Should Know
Domain Name System exploits could put your data at risk. Here's some advice on how to avoid them.
Flash Poll
Threat Intel Today
Threat Intel Today
The 397 respondents to our new survey buy into using intel to stay ahead of attackers: 85% say threat intelligence plays some role in their IT security strategies, and many of them subscribe to two or more third-party feeds; 10% leverage five or more.
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-7445
Published: 2015-10-15
The Direct Rendering Manager (DRM) subsystem in the Linux kernel through 4.x mishandles requests for Graphics Execution Manager (GEM) objects, which allows context-dependent attackers to cause a denial of service (memory consumption) via an application that processes graphics data, as demonstrated b...

CVE-2015-4948
Published: 2015-10-15
netstat in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.2.x, when a fibre channel adapter is used, allows local users to gain privileges via unspecified vectors.

CVE-2015-5660
Published: 2015-10-15
Cross-site request forgery (CSRF) vulnerability in eXtplorer before 2.1.8 allows remote attackers to hijack the authentication of arbitrary users for requests that execute PHP code.

CVE-2015-6003
Published: 2015-10-15
Directory traversal vulnerability in QNAP QTS before 4.1.4 build 0910 and 4.2.x before 4.2.0 RC2 build 0910, when AFP is enabled, allows remote attackers to read or write to arbitrary files by leveraging access to an OS X (1) user or (2) guest account.

CVE-2015-6333
Published: 2015-10-15
Cisco Application Policy Infrastructure Controller (APIC) 1.1j allows local users to gain privileges via vectors involving addition of an SSH key, aka Bug ID CSCuw46076.

Dark Reading Radio
Archived Dark Reading Radio

The cybersecurity profession struggles to retain women (figures range from 10 to 20 percent). It's particularly worrisome for an industry with a rapidly growing number of vacant positions.

So why does the shortage of women continue to be worse in security than in other IT sectors? How can men in infosec be better allies for women; and how can women be better allies for one another? What is the industry doing to fix the problem -- what's working, and what isn't?

Is this really a problem at all? Are the low numbers simply an indication that women do not want to be in cybersecurity, and is it possible that more women will never want to be in cybersecurity? How many women would we need to see in the industry to declare success?

Join Dark Reading senior editor Sara Peters and guests Angela Knox of Cloudmark, Barrett Sellers of Arbor Networks, Regina Wallace-Jones of Facebook, Steve Christey Coley of MITRE, and Chris Roosenraad of M3AAWG on Wednesday, July 13 at 1 p.m. Eastern Time to discuss all this and more.