------------------------------------------------------- prop-173: Align implementation of Prop-125 in APNIC Policy (APNIC-127) ------------------------------------------------------- Proposer: Alban Kwan alban.kwan@trustednotifier.network 1. Problem statement ------------------------------------------------------- The outcome of prop-125 is reflected in APNIC-127 v015 in Section 5.3.3 ("Registering Contact Persons"), including: - mandatory IRT object per resource; - requirement to monitor IRT contacts and respond to abuse promptly; - 6-monthly validation of IRT contacts; - 15/30-day timelines and MyAPNIC limitation if validation fails. However, several elements of prop-125 that APNIC has implemented in practice are not yet explicitly reflected in APNIC policy. Such elements include: - that the IRT abuse-mailbox must be capable of receiving abuse reports submitted by email, including automated reports, and must be actively monitored; - that APNIC may also validate account holders' other registered contact, e.g., admin-c and/or tech-c; - that APNIC publishes an abuse-c attribute derived from the IRT object in the Whois database; - that persistent failure to maintain valid IRT contacts is a breach of policy, not just an operational inconvenience. 2. Objective of policy change ------------------------------------------------------- - Clarify the obligations on IRT / abuse-mailbox contacts according to the approved Prop-125. - Recognise and spell out the obligations for the abuse-mailbox attribute in the IRT objects. - Acknowledge that persistent failure to maintain a valid IRT contact will constitute a breach of policy. 3. Situation in other regions ------------------------------------------------------- LACNIC implemented LAC-2018-5 in 2020, now codified as Section 12 of its Policy Manual. Resources must include a mandatory abuse-c with at least one valid, monitored abuse-mailbox that accepts manual or automated reports, and must not require the use of a form to report abuse. Validation occurs at least twice a year. RIPE NCC implemented ripe-705 in 2018, making abuse-c mandatory for all inetnum, inet6num, and aut-num objects. The abuse-mailbox attribute is validated at least annually. ARIN validates all Points of Contact annually under NRPM Section 3.6. Each POC has up to sixty days to confirm their WHOIS contact information is correct or to submit corrections. ARIN does not impose requirements on how abuse reports must be received or handled beyond contact reachability. 4. Proposed policy solution ------------------------------------------------------- Proposed replacement 5.3.3 text 5.3.3. Registering Contact Persons Administrative and technical contact persons must be registered. The registered administrative contact ("admin-c") must be someone who is physically located at the site of the network, subject to the following exceptions: - For residential networks or users, the IR's technical contact may be registered as the admin-c. - For networks in exceptional circumstances that make it impractical to maintain an on-site administrative contact, an off-site person may be registered as the admin-c. The technical contact ("tech-c") need not be physically located at the site of the network but must be a person who is responsible for the day-to-day operation of the network. Incident Response contacts a) It is mandatory to register an Incident Response Team (IRT) object for each resource record in the APNIC Whois Database. b) The IRT object must include abuse contact mailbox attribute ("abuse-mailbox"). The abuse-mailbox must: : - be valid and capable of receiving email, including automated reports; and - ensure that reports it receives are subject to appropriate review, triage, or escalation processes, which may include automated processing, provided legitimate reports are not systematically ignored or rejected;; (NOTE: Prop-125 specifically require “manual intervention” in 4.1; however, due to current trend in automation, we propose to soften the language with the proposed text so that some automated process would be accepted, while maintaining the spirit of prop-125 to avoid unreasonable automated rejection of abuse reports) - accept automated reports submitted as plain text, structured abuse-reporting formats such as XARF (eXtended Abuse Reporting Format), or in common attachment formats (e.g., text, CSV, PDF, or standard log-file formats); the abuse-mailbox MAY apply standard anti-spam, anti-malware, message-size, or rate-limiting measures of the kind ordinarily applied to any mail system, provided such measures do not systematically prevent legitimate abuse reports from being received; (NOTE: this is added so that Prop-125 requirement can be operationalised in practice. Basically, this line provides some guideline as to what kind of automated report can be accepted but it is not aimed to be exclusive) c) Web forms MUST NOT be the only mechanism for submitting abuse reports. Where a web form is provided, it MUST supplement, not replace, a working abuse-mailbox. (NOTE: this is a requirement in Prop-125 but not covered in current policy) d) Abuse reports sent to the “abuse-mailbox” MUST be responded to promptly to resolve the complaint. (NOTE: this is exact wording in current policy text, except that we narrowed the scope to abuse-mailbox instead of all IRT objects. The meaning is that if an abuse report were sent to admin-c – which is not specifically used for abuse report, should not trigger any of the report obligations. This is to prevent malicious reporters spamming abuse reports to any IRT objects in hopes for some response.) Validation of IRT and related contacts e) APNIC will validate IRT contacts, including the abuse-mailbox and any other email addresses listed in the IRT object, at least once every six (6) months, and may perform additional validation at its discretion. f) APNIC MAY also validate the email addresses of admin-c and tech-c contacts associated with the same account as part of this process, to ensure that all registration contact information is accurate and valid and functioning. g) Account holders MUST complete any validation checks within fifteen (15) days of receiving a validation request from APNIC. h) If an IRT contact fails validation, APNIC will: - mark the IRT object as "Invalid" in the APNIC Whois Database; and - follow up with the account holder using other registered contacts, consistent with applicable policies and procedures. i) If IRT contacts remain invalid thirty (30) days after failing validation, the account holder's access to MyAPNIC will be limited until valid IRT contact information is provided and successfully validated. j) Persistent failure to maintain valid IRT contacts, or to monitor and respond to abuse reports as required under clause (b), will be treated as a breach of these policies, addressed in the first instance through the escalation steps below and, if unremedied, dealt with under the breach provisions of the Membership Agreement (which may include revocation of delegated resources). APNIC's response under this section shall be proportionate to the nature and duration of the failure, applied in the following order absent circumstances warranting immediate action to prevent ongoing harm: • i) written notice identifying the specific failure and a reasonable period to remedy; • ii) marking the IRT object "Invalid" in the APNIC Whois Database (as under clause h); • iii) limitation of MyAPNIC access (as under clause i); • iv) where the failure is persistent, substantiated, and steps (i)-(iii) have not resulted in remedy within 60 days — or where the resource holder's conduct poses an ongoing and demonstrable risk to the security of the Internet number resource system — referral for further action under the Membership Agreement's breach provisions. 4.2. Proposed new text, inserted immediately after 5.3.3: 5.3.4. Abuse contact publication APNIC shall publish an "abuse-c" attribute for resource records in the APNIC Whois Database, generated automatically from the corresponding IRT object, consistent with the abuse-c convention used by other Regional Internet Registries. 5. Advantages / Disadvantages ------------------------------------------------------- Advantages: - Align APNIC Policy with actual implementation of prop-125. - Clarifies expectations on members: - abuse-mailbox must be usable and monitored, - email must be accepted, - there must be human review. - Consolidates abuse contact obligations into a single authoritative policy document, reducing reliance on implementation notes and help-centre pages that may not carry binding weight. - Makes it explicit that persistent non-compliance with IRT validation is in breach of policy. Disadvantages: - Members whose abuse reporting setup currently relies solely on web forms will need to ensure a working abuse-mailbox is also in place. - The monitoring and human-review obligations introduced by this proposal are difficult to audit proactively and will primarily be enforced on a complaint-driven basis. 6. Impact on resource holders ------------------------------------------------------- - This proposal formalizes obligations already implicit in current APNIC-127 v015 Section 5.3.3 (which already requires IRT contacts to be "regularly monitored" and complaints "responded to promptly to resolve"), and extends that existing standard explicitly to the abuse-mailbox. Resource holders whose current abuse-handling setup does not meet the monitored/respond-to-resolve standard, or that relies solely on a web form, will need to bring their practices into line. - Some might need to review any setups that only provide web forms as abuse contact and make sure the email abuse-mailbox is documented and monitored. 7. References -------------------------------------------------------