Risk and Privacy Evaluation for RDAP System
Andi Budimansyah, Moh. A. Amin Soetomo, Charles Lim · 2021
The Registration Data Access Protocol (RDAP) is a new protocol that will eventually replace the WHOIS to address security and privacy issues and other current conditions. Like WHOIS, RDAP obtains information about a domain name or an Internet Protocol (IP) registration. One of its features is “user differentiated access,” which enables the Public to view restricted info while Authenticated Users may access complete info. This feature needs complete registration of data in the Data Store, which may contain legally protected Registrant Personal Data. Previous researches focused on digital evidence linked to a domain and IP registrations and technical challenges to enhance request analysis mitigation. This research presents a cyber security and privacy risk analysis of the RDAP system based on ISO 27005, LINDDUN, and STRIDE models.