Posts

BT survey indicates movement on IPv6 deployments

We recently invited network engineers to participate in an online industry survey to characterize opinions and attitudes about IPv6 deployment in their networks. We’ve conducted this survey for five years running now, and we’ve observed a steady climb in the proportion of survey participants who have deployed or were actively deploying IPv6. This year’s survey didn’t disappoint, as we saw continued IPv6 deployment progress with over half of survey participants indicating they had deployed or were in the process of deploying IPv6. This tally represented a fifteen percent higher proportion that in last year’s survey. Deploying IPv6 is necessary for organizations to continue to communicate with all users on the “ total Internet ,” which is slowly evolving from a homogeneous IPv4 Internet to a mixed protocol IPv4-IPv6 Internet. Evidence of such an evolution is visible from various industry measurements, such as the proportion of Google users accessing their sites via IPv6 and vyncke....

IPv6 deployments growing steadily though not exponentially (yet)

Image
The percentage of users of google's websites accessing via IPv6 has reached 8% for the first time last week, essentially doubling up the percentage from only a bit more than a year ago. It was then, a year ago that I had last blogged about predicting future IPv6 adoption trends based on "curve fitting" historical measurements. At that time, the predictions for the end of 2014 indicated 6.2% for the exponential growth model, while the polynomial model predicted 5.6%. The actual measurement was 5.7%. As illustrated in the graph below with curve fits based on the most recent data, the exponential curve, the top (green) curve is certainly the most ambitious as it was last year. It predicts the percentage of IPv6 users accessing google's sites at 11.4% by the end of this year and over 25% by the end of next. Meanwhile the polynomial curve fits are more conservative predicting 8-9% by the end of this year and 12-15% by the end of next. While IPv6 adoption growth has...

Will the IoT be the IPv6 killer app?

The Internet of Things (IoT) refers to the extension of today’s Internet beyond connectivity and interaction among traditional user-operated devices like PCs, tablets, phones and like types of devices into the realm of connectivity and interaction with non-user operated devices such as sensors, monitors and remotely controllable devices. Internet-enabling such “unmanned” devices allows these devices to autonomously report updates, status changes, events, or to perform actions commanded by users or other devices via the Internet. Examples of such “things” commonly in use today range from consumer goods to devices supporting business initiatives such as those in support of the following example applications. Smart initiatives – providing a centralized view of yet unrealized volumes of data for more intelligence resource management and customer service such as: Smart Grid – Dynamic matching of electricity, water, gas, etc. supply with demand, reducing resource waste and saving consu...

DNSSEC Survey Report

BT Diamond IP just published its latest report detailing results of its DNSSEC industry survey, conducted in November, 2014. This year’s survey yielded strong participation from active DNSSEC deployers, meaning those who have already deployed or are deploying DNSSEC. While not likely representative of overall industry deployment status, opinions regarding complexity and business case as obstacles and lack of interest in high security module (HSM) appliances for private key storage prove insightful. Among the key findings of the survey: Nearly all respondents agreed with the statement that DNSSEC can or does provide value to their organization and over 85 percent likewise agreed that DNSSEC technology is mature and can be reliably deployed. Forty-seven percent of respondents agreed that deploying and maintaining DNSSEC is very complex, 12 of the 47 percent strongly. Only 22 percent disagreed. This is rather telling in that DNSSEC is not only considered complex to the uninitiated, bu...

You're invited to participate in our DNSSEC Survey

Signing DNS data with DNSSEC enables an organization to authenticate its web addresses and other published DNS information, i.e., to secure its namespace. DNSSEC also protects against DNS cache poisoning attacks when DNSSEC validation is enabled on DNS recursive server resolvers. As such DNSSEC is a critical component of a comprehensive DNS security strategy which should also include use of functional and port access control lists (ACLs), transaction signature keys to sign updates and transfers among servers, detection of DNS anomalies, and possibly domain name filtering or firewalling to restrict communications among malware-infected devices and corresponding command and control centers. BT Diamond IP is sponsoring a DNSSEC survey to gather input from DNS and network administrators regarding their opinions about the value of DNSSEC, potential obstacles to implementation, and relative priority of deployment. And you are hereby invited to participate! The survey consists of twelve que...

What Exactly is a DNS Firewall?

When you think of an Internet firewall, you likely think of a gateway device which examines IP packets flowing through it and which selectively blocks or redirects those packets meeting certain criteria. Such criteria may include filtering parameters such as IP addresses or ports such that when an IP packet under inspection matches such parameter settings, the packet is blocked or otherwise handled according to policy settings. A DNS firewall performs similar examination and policy handling functions for DNS queries to prevent unwelcome DNS and subsequent data traffic. Another common assumption associated with Internet firewalls is that they are deployed on the perimeter of a network with the intention of protecting the network from attacks originating external to the network. DNS firewalls however protect the network against attacks that originate within the network. Why worry about internal attacks if morale is sky high and IP firewalls are seemingly impervious? With the proliferat...

IPv6 Growth Inflection Point

Image
Now that the percentage of IPv6 users accessing Google's websites has reached 4% , I decided to revisit my prior post projecting IPv6 growth . Assuming that people around the world use google as it sits atop Alexa’s list of top websites, it would seem such a measurement provides data that could be loosely projected to the Internet at large. It took just 140 days for the IPv6 user rate to climb from 2% to 3%, and interestingly only 140 days from 3% to 4%. Is IPv6 growth going linear? Or more likely have just passed an inflection point beyond which growth will accelerate? Reiterating our view that the historical IPv6 user data is comprised of two segments, the first being the nearly linear component of near zero penetration up through 2011, and the second representing the present growth phase, we plot the measured IPv6 penetration since the end of 2011. Applying both exponential and second order polynomial curve fittings as before in Figure 1, we see that our exponential curve, the ...