Search RPD Archives
[rpd] [off-topic] Humble feature request for quarantined/cleaned up IP addresses
Sylvain BAYA
baya.sylvain at cmnog.cm
Sat Sep 26 19:41:14 UTC 2026
Le 26 septembre 2026 09:23:43 GMT+01:00, Ben Roberts - AfriNIC via RPD <rpd at afrinic.net> a écrit :
>Logan,
>
Dear Ben,
Thanks for your email ; brother!
>
>It might be wrong to assume that all quarantined and returned space is contaminated. I’m sure that cyber threat blacklist companies have their own methods of determining address space with threats.
>
...i think, it's more related to INRs squatting;
but i would leave it to Logan to better
explain it's context.
>
>I might be wrong to just ask to block all returned space (thus rendering it potentially useless to a future user who has been allocated the space).
>
...again, it might be such a scenario where:
s1. a delegated resource is returned to the RIR;
s2. it's added to the quarantine pool;
s3. it suddently appears on the Internet;
s4. Cybersecurity concerned parties want to know few things;
s5. .
>
>Is there a particular problem that you are trying to solve ?
>
...few questions; then:
q1| where could a Cybersecurity concerned
party go, in order to be able to check
actual status of that resource?
q2| if it's still under quarantine, then how
one could check by itself?
q3| is a resource into the quanrantine pool
also associated to AS0?
q4| .
Also, as said by Nishal, the WhoWas [*] (requested service) could benefit of such
a useful add-on.
__
[*]:
By the way, i think the quarantine pool is
a useful tool; but we need to be able to
also start to automatically create AS0
ROAs to each returned IP resources...if
it's not actually in Staff's procedure...
Thanks to help in pushing for that AS0
ROA policy implementation; still awaited!
Shalom,
--sb.
>
>Kind regards
>Ben
>Sent from my iPhone
>
>> On 26 Sep 2026, at 10:21, Loganaden Velvindron <loganaden at gmail.com> wrote:
>>
>> Hi All,
>>
>> Recently, I was investigating a cyber security incident involving IP addresses.
>>
>> A recurring challenge is that even after these IP ranges are returned
>> to AFRINIC for quarantine and cleanup, there is no quick, centralized
>> way for cybersecurity threat intelligence providers or law enforcement
>> agencies to track this status change. I fully appreciate that the
>> AFRINIC team already handles a significant workload.
>>
>> I would therefore kindly request AFRINIC members to discuss whether
>> putting a dedicated page would be a good idea ? The web page would be
>> for quarantined and cleaned up IP ranges so that Cybersecurity Threat
>> Intelligence Providers and Law enforcement agencies can easily parse
>> those to update their blocklists. CSV format is acceptable but json
>> format would be nice to have especially with the rise of automation.
>>
>> Kind regards,
>> Loganaden Velvindron
>> (Speaking in my own capacity)
>>
>> _______________________________________________
>> RPD mailing list
>> RPD at afrinic.net
>> https://lists.afrinic.net/mailman/listinfo/rpd
>[...]
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.afrinic.net/pipermail/rpd/attachments/20260926/a9997a33/attachment-0001.html>
More information about the RPD
mailing list