↓Skip to main content
Internships

RDAP: Frontier between protocol specification and implementation

DNS stands for Domain Name System, and domain names are what our research is about. They are an integral part of our daily lives. You’ve already come across domain names such as “google.com”, “univ-grenoble-alpes.fr”, or “amazon.com”. But what about “support-tech-apple.com”, “bank-of-america-help.com” or even “paypall.com”? All of these are malicious domain names, built to mislead users into a phishing site.

By studying domain names, we can improve Internet security. One of our team’s earlier projects, COMAR, distinguishes compromised domain names from malicious ones. For example, if the domain name “univ-grenoble-alpes.fr” hosts malicious content, should it be taken down? And what about paypall.com? COMAR separates the compromised domain — here univ-grenoble-alpes.fr — whose administrator should be notified, from paypall.com, where the right response is to act against the domain name itself.

Internship description #

This internship is a first taste of research. It aims to explore the RDAP protocol and its specification in depth. The RDAP protocol, designed to replace WHOIS, has become a major standard for accessing domain name registration information. The aim of this internship is to develop an in-depth understanding of how the RDAP protocol works and its usefulness in today’s Internet context, in order to propose a more “human-friendly” tool.

Missions #

  • Create an open-source Python tool for retrieving RDAP data.
  • Create a tool to check RDAP/RFC 7483 conformance.
  • Check that RDAP services follow the specifications.

Who we are looking for #

Student in the final year of Master 2 in Computer Science (MOSIG, CYBERSEC, …), with a strong interest in research and a desire to continue in the academic world. The candidate must show real curiosity: a desire to understand, to discover and to question. The position is also open to highly motivated M1 students.

How to apply #

Interested candidates are invited to send their application, including a CV, a covering letter and anything else they think is relevant, to Maciej KORCZYNSKI (maciej.korczynski at univ-grenoble-alpes.fr) and Olivier HUREAU (olivier.hureau at univ-grenoble-alpes.fr)

References #

  • RFC 7482: Registration Data Access Protocol (RDAP) Query Format (https://datatracker.ietf.org/doc/html/rfc7482)
  • RFC 7483: JSON Responses for the Registration Data Access Protocol (RDAP) (https://datatracker.ietf.org/doc/html/rfc7483)
  • [1] Aruna Prem Bianzino, Davide Pezzuolo, and Gianluca Mazzini. 2014. Who Is Whois? An Analysis of Results Consistence.
  • [2] Suqi Liu, Ian Foster, Stefan Savage, Geoffrey M. Voelker, and Lawrence K. Saul. 2015. Who Is .Com?: Learning to Parse WHOIS - Records.
  • [3] Chaoyi Lu, Baojun Liu, Yiming Zhang, Zhou Li, Fenglu Zhang, Haixin Duan, Ying Liu, Joann Qiongna Chen, Jinjin Liang, Zaifeng Zhang, Shuang Hao, and Min Yang. 2021. From WHOIS to WHOWAS: A Large-Scale Measurement Study of Domain Registration Privacy under the GDPR.