Assessing the Effectiveness of Domain Blacklisting Against Malicious DNS Registrations

2019 IEEE Security and Privacy Workshops (SPW)(2019)

引用 6|浏览33
暂无评分
摘要
Domain blacklists are widely-used in security research. However, given their proprietary nature, there is little insight into how they operate and how effective they are. In this paper, we analyze a unique combination of DNS traffic measurements with domain registration and blacklisting data. We focus in particular on large-scale malicious campaigns that register thousands of domain names used in orchestrated attacks. This allows us to gain insights into how blacklists and cybercriminals interact with each other. Furthermore, it enables us to pinpoint scenarios where blacklist operators struggle to detect campaign registrations.
更多
查看译文
关键词
Domain blacklists,passive DNS analysis
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要