Abstract
The Domain Name System (DNS) is a critical component of the Internet, and as such it is widely relied upon by a large part of the world. Consequently, it can be abused for multiple purposes, with financial gain being perhaps the most obvious, and important. An important countermeasure to such criminal and malicious activity is to identify involved domains, in order to blacklist or otherwise disable them. In this paper we provide the results of studying existing work on detecting malicious domains and analyse the findings. We identify an approach which is promising but has received surprisingly little attention; Pre-registration detection. We identify the following gaps between the problem of domain abuse, and the described state-of-The-Art: Existing work on Pre-registration is strictly focused on a single form of abuse, spam, hence it must be explored if Pre-registration detection can be applied to other forms of abuse as well. Existing work, on both Pre-and Post-registration detection, is focused on a few Top-Level domains (TLDs) and Registries, prompting for studies with other TLDs and Registries. There is relevant information, including Registrant-based features, that has not yet been used for Pre-registration detection-which also calls for investigation. Finally, a study of a real-world deployment of Pre-registration detection at a Registry has not yet been presented, despite the potential of the approach. We contribute with an analysis of existing work, by identifying the state-of-The-Art, and by identifying important areas of future work.
Original language | English |
---|---|
Title of host publication | Proceedings - 2018 1st International Conference on Data Intelligence and Security, ICDIS 2018 |
Number of pages | 8 |
Publisher | IEEE |
Publication date | 2018 |
Pages | 49-56 |
ISBN (Print) | 978-1-5386-5763-8 |
ISBN (Electronic) | 978-1-5386-5762-1 |
DOIs | |
Publication status | Published - 2018 |
Event | The 1st International Conference on Data Intelligence and Security - South Padre Island, United States Duration: 8 Apr 2018 → 10 Apr 2018 https://www.icdis.org |
Conference
Conference | The 1st International Conference on Data Intelligence and Security |
---|---|
Location | South Padre Island |
Country/Territory | United States |
Period | 08/04/2018 → 10/04/2018 |
Internet address |
Keywords
- Abuse
- DNS
- Detection
- Domain
- Domain name
- Maliciousness
- Malware
- Phishing
- Pre registration
- Registration
- Registry
- Spam
- Time of registration