Assessing Network Operator Actions to Enhance Digital Sovereignty and Strengthen Network Resilience: A Longitudinal Analysis during the Russia-Ukraine Conflict

Muhammad Yasir Muzayan Haq,Abhishta Abhishta,Raffaele Sommese,Mattijs Jonker,Lambert J.M. Nieuwenhuis
2023-05-28
Abstract:We conduct longitudinal and temporal analyses on active DNS measurement data to investigate how the Russia-Ukraine conflict impacted the network infrastructures supporting domain names under ICANN's CZDS new gTLDs. Our findings revealed changes in the physical locations of network infrastructures, utilization of managed DNS services, infrastructure redundancy, and distribution, which started right after the first reported Russian military movements in February 2022. We also found that domains from different countries had varying location preferences when moving their hosting infrastructure. These observed changes suggest that network operators took proactive measures in anticipation of an armed conflict to promote resilience and protect the sovereignty of their networks in response to the conflict.
Networking and Internet Architecture,Cryptography and Security
What problem does this paper attempt to address?
The problem that this paper attempts to solve is what measures network operators have taken to enhance the resilience of network infrastructure and protect digital sovereignty during the Russia - Ukraine conflict. Specifically, through longitudinal analysis and time - series analysis, the paper studies the impact of the conflict on the network infrastructure of new gTLD domains in CZDS supported by ICANN, especially the changes in these infrastructures in terms of physical location, the use of hosted DNS services, infrastructure redundancy and distribution. The study found that since the first report of Russian military operations in February 2022, network operators have taken active measures to respond to the armed conflict and improve network resilience and protect network sovereignty. ### Main research questions: 1. **Changes in network infrastructure**: The paper explores the changes in the physical location of network infrastructure before and after the conflict, as well as the use of hosted DNS services. 2. **Infrastructure redundancy and distribution**: It studies the redundancy and geographical distribution of network infrastructure, especially the changes inside and outside the conflict area. 3. **Preferences of different countries**: It analyzes the location preferences of domain names of different countries when migrating hosting infrastructure. 4. **Network resilience and digital sovereignty**: It evaluates how the measures taken by network operators in response to the conflict promote network resilience and protect digital sovereignty. ### Research methods: - **Data sources**: Use DNS measurement data provided by the OpenINTEL project and registration country information in WHOIS records. - **Classification method**: Classify domain names into three categories: "completely inside", "partially inside" and "completely outside" according to the geographical location of the infrastructure. - **Longitudinal analysis**: Conduct time - series analysis on data from January 2018 to February 2023 to observe the change trends before and after the conflict. - **Time - comparison analysis**: Compare the data on January 21, 2021 (the first Russian military build - up) and February 24, 2023 (the first anniversary of the conflict) to analyze the changes in network infrastructure. ### Main findings: - **Infrastructure migration**: Since the first Russian military build - up in February 2021, the proportion of domain names relying on infrastructure within the conflict area has been continuously decreasing. - **Use of hosted DNS services**: The market share of third - party DNS service providers such as Cloudflare has increased significantly, while the market share of GoDaddy has decreased. - **Differences in behavior among different countries**: Russian domain names are mainly migrated back to Russia from Ukraine, while Ukrainian domain names are more migrated to other countries to avoid the impact of the conflict. ### Conclusion: The paper reveals the strategies of network operators in improving network resilience and protecting digital sovereignty by migrating infrastructure, increasing redundancy and using more robust services in the face of armed conflict. These measures are not only helpful in dealing with physical attacks, but also protect data and services from interference by hostile regimes.