Hi all,According to the comments, i have made an adjustment to the text
accordingly.
Summary of changes from v1
This version responds to feedback received on the sig-policy mailing list
following the initial posting of prop-172-v001. In particular:
● "Unlawful" has been removed entirely from the operative definition
(Jonathan Brewer, Terry Sweetser). The definition no longer depends on the
legal status of conduct in any jurisdiction.
● The opening clause has been revised to the wording proposed by Jonathan
Brewer, extending the definition to attempted harm and material risk of harm,
not only completed harm.
● A new category has been added covering unauthorised or malicious
scanning, probing, intrusion, and exploitation (Jonathan Brewer).
● The "Note for further discussion" section has been expanded to address
various related issues, but not within the direct scope of this proposal.
● The good-faith safe harbor is now explicit that it operates only within
APNIC policy and does not override or replace any liability or protection that
exists under national law.
● Supporting technical references (RFC 4084, RFC 4732, RFC 4778, RFC 4948)
suggested by Jonathan Brewer and Terry Sweetser, and the Manila Principles
referenced in list discussion, have been added to the References section.
The core, unresolved questions raised by Aftab Siddiqui and by the Japan Open
Policy Forum -- particularly how APNIC's accountability role can be assessed
without an indirect determination on the underlying conduct, and the risk that
a formal definition could narrow attention away from abuse that falls outside
it -- are acknowledged in this version rather than resolved. They remain open
items for the proposed community working group and, where relevant, future PDPs.
4. Proposed policy solution
The following definition is proposed for adoption into the relevant APNIC
policy document. The specific document and section would be confirmed through
community discussion; the IRT object provisions in the APNIC Whois Database
documentation are one likely location.
"Internet Abuse through IP Addresses" means the use of an IP address, or set of
IP addresses, registered to or held by an APNIC account holder, to conduct or
facilitate activity that causes, attempts to cause, or creates a material risk
of technical harm to the security, stability, or trust of the Internet, that
the resource holder has the practical and operational ability to address. This
includes, but is not limited to:
● distributing or hosting malware, including botnet command-and-control
infrastructure;
● originating, amplifying, or reflecting Distributed Denial of Service
(DDoS) traffic;
● conducting or facilitating unauthorised or malicious scanning, probing,
intrusion, exploitation, or attempted exploitation of networks, systems,
services, or applications, including vulnerability scanning, credential
attacks, and attempts to gain unauthorised access or execute unauthorised
commands;
● deliberate or grossly negligent routing-layer abuse, including BGP
hijacking, and the use of unallocated, reserved, or squatted address space;
● fraudulently acquiring, transferring, or sub-allocating IP address
resources to facilitate the above;
● hosting infrastructure used for phishing, fraud, scam, or the
impersonation of a legitimate entity for deceptive purposes
Good-faith operational errors that are identified and promptly corrected —
including inadvertent routing misconfigurations — do not constitute abuse under
this definition. Nor does it constitute abuse for conduct described above to
occur on a resource holder's network at the hands of a third party — such as a
customer, user, or employee — where the resource holder addresses that conduct
promptly on being notified of it, consistent with this definition.
Adjudication of whether reported conduct constitutes abuse rests, in the first
instance, with the resource holder. This applies where the resource holder has
been notified by a party with a legitimate basis to report it, and has the
practical ability to act. An isolated instance of delayed or imperfect response
does not, on its own, constitute abuse under this definition; this definition
is directed at conduct and patterns of non-response, not individual lapses.
Acting in good faith to address reported conduct of this kind — including
reasonable reliance on a substantiated notice — does not itself constitute
abuse, even where the resource holder and a complainant ultimately disagree
about the conduct in question. It also does not, on its own, create a broader
monitoring obligation, or amount to an admission of liability beyond what this
definition establishes. Resource holders are encouraged, but not required, to
retain a record of any notice received and the action taken in response, so
that good-faith reliance under this section can be demonstrated if later
disputed. This protection operates only within APNIC policy; it does not
override, replace, or otherwise affect any liability or protection that may
exist for the resource holder under national law.
For the avoidance of doubt, APNIC does not have the power to adjudicate abuse.
As steward of Internet number resources, APNIC's role is limited to ensuring
resource holders do not neglect their stewardship responsibility — for example,
by ignoring legitimate abuse reports in bad faith — not to determining whether
any particular case is or is not abuse.
Note for further discussion (not operative policy text):
This proposal does not aim to resolve all issues related to abuse, but rather
to come up with an agreeable definition as a foundation for further discussion.
Giving this existing duty a defined trigger, rather than creating a new duty,
will still have real operational consequences for how resource holders and
APNIC experience it in practice. While it is out of scope, it is important
that we also outline possible next steps as reference so that the community has
a clear vision of whether this policy would create unintended outcomes, and how
further discussion could be conducted to resolve remaining issues.Issues that
best addressed by “Best practice guidelines” through a “working group/SIG”
- Specific terminology – such as hosting, phishing, fraud, scam – as with
other Internet policies, this term is commonly left undefined at the policy
level. As these definition may change according to local understanding and new
types of attacks, therefore, it is best the policy uses commonly understood,
broad term, and in APNIC best practice guidelines, to address the specific
definition.
- Responsibility and types of resource holders - Responsibility for the
conduct above may reasonably differ depending on a resource holder's registered
or predominant use of its IP addresses (e.g., access/transit network,
hosting/content provider, enterprise/internal-use network) — consistent with
existing cross-industry practice, such as M3AAWG's separate best-practice
guidance for hosting providers versus network operators. This proposal does not
resolve how, or whether, such differentiation should be built into policy;
- Cross-jurisdiction issues – for example, illegal gambling, which may be
lawful in one country and unlawful in another. The proposal put the decision
making power squarely on the shoulder of the resource holder, but to resolve
practical harm, the community may want to consider a best practice guideline to
assist the resource holder from making such decision.
- Narrowing effect – observe whether the definition creates any
“narrowing effect” or “scope creep”. This is an ongoing concern rather than
something a single agreed definition can resolve; the community should
establish a way to observe this trend over time as usage and threats evolve.
- Other cooperations to enhance abuse mitigation without putting policy
compliance burden on the community — This policy does not seek to create a
concrete adjudication and APNIC policy enforcement framework. This differs from
the binding “adequate response” question below, which concerns APNIC’s own
enforcement trigger; this item is about voluntary, non-binding cooperation
models the community may choose to draw on. Within other community, there are
other concepts and cooperation being built and APNIC can draw on models used
elsewhere in Internet governance for bottom-up, distributed adjudication — for
example, the ICANN community's trusted notifier concept, the EU's Trusted
Flagger concept, and the Global Cyber Alliance's Domain Trust project.
Issues requires future Policy Development Process:
- The definition of “adequate response” and APNIC enforcement power and
process — including, specifically: disagreement between a complainant and a
resource holder about the underlying conduct; the distinction between
acknowledging or investigating a complaint and being required to stop the
underlying activity; and what exactly APNIC would assess if a complaint is
escalated.
_______________________________________________
SIG-policy - https://mailman.apnic.net/[email protected]/
To unsubscribe send an email to [email protected]