首页> 外文会议>Annual IEEE/IFIP International Conference on Dependable Systems and Networks >A Reexamination of Internationalized Domain Names: The Good, the Bad and the Ugly
【24h】

A Reexamination of Internationalized Domain Names: The Good, the Bad and the Ugly

机译:重新审视国际化域名:好的,坏的和丑陋的

获取原文

摘要

Internationalized Domain Names (IDNs) are domain names containing non-ASCII characters. Despite its installation in DNS for more than 15 years, little has been done to understand how this initiative was developed and its security implications. In this work, we aim to fill this gap by studying the IDN ecosystem and cyber-attacks abusing IDN. In particular, we performed by far the most comprehensive measurement study using IDNs discovered from 56 TLD zone files. Through correlating data from auxiliary sources like WHOIS, passive DNS and URL blacklists, we gained many insights. Our discoveries are multi-faceted. On one hand, 1.4 million IDNs were actively registered under over 700 registrars, and regions within east Asia have seen prominent development in IDN registration. On the other hand, most of the registrations were opportunistic: they are currently not associated with meaningful websites and they have severe configuration issues (e.g., shared SSL certificates). What is more concerning is the rising trend of IDN abuse. So far, more than 6K IDNs were determined as malicious by URL blacklists and we also identified 1,516 and 1,497 IDNs showing high visual and semantic similarity to reputable brand domains (e.g., apple.com). Meanwhile, brand owners have only registered a few of these domains. Our study suggests the development of IDN needs to be re-examined. New solutions and proposals are needed to address issues like its inadequate usage and new attack surfaces.
机译:国际化域名(IDN)是包含非ASCII字符的域名。尽管将其安装在DNS中已有15年以上,但对于了解该计划的开发方式及其安全隐患却丝毫没有做过。在这项工作中,我们旨在通过研究IDN生态系统和滥用IDN的网络攻击来填补这一空白。特别是,我们使用从56个TLD区域文件中发现的IDN进行了迄今为止最全面的测量研究。通过关联来自辅助来源(如WHOIS,被动DNS和URL黑名单)的数据,我们获得了许多见解。我们的发现是多方面的。一方面,在700多个注册服务商的积极注册下,有140万个IDN,而在东亚地区,IDN注册的发展显着。另一方面,大多数注册是机会性的:它们目前与有意义的网站不相关,并且存在严重的配置问题(例如,共享的SSL证书)。更令人担忧的是IDN滥用的上升趋势。到目前为止,URL黑名单将超过6K个IDN确定为恶意IDN,我们还确定了1,516个和1,497个IDN与知名品牌域名(例如apple.com)具有高度的视觉和语义相似性。同时,品牌所有者仅注册了其中一些域名。我们的研究表明,IDN的发展需要重新审查。需要新的解决方案和建议来解决诸如使用不当和新的攻击面之类的问题。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号