Exploring The Ecosystem Of Malicious Domain Registrations In The .Eu Tld

RESEARCH IN ATTACKS, INTRUSIONS, AND DEFENSES (RAID 2017)(2017)

引用 30|浏览163
暂无评分
摘要
This study extensively scrutinizes 14 months of registration data to identify large-scale malicious campaigns present in the .eu TLD. We explore the ecosystem and modus operandi of elaborate cybercriminal entities that recurrently register large amounts of domains for one-shot, malicious use. Although these malicious domains are short-lived, by incorporating registrant information, we establish that at least 80.04% of them can be framed in to 20 larger campaigns with varying duration and intensity. We further report on insights in the operational aspects of this business and observe, amongst other findings, that their processes are only partially automated. Finally, we apply a post-factum clustering process to validate the campaign identification process and to automate the ecosystem analysis of malicious registrations in a TLD zone.
更多
查看译文
关键词
Malicious domain names, Campaigns, DNS security
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要