首页> 外文会议>IEEE Conference on Communications and Network Security >It's Not what It Looks Like: Measuring Attacks and Defensive Registrations of Homograph Domains
【24h】

It's Not what It Looks Like: Measuring Attacks and Defensive Registrations of Homograph Domains

机译:这不是它看起来的:测量同类域的攻击和防御性注册

获取原文

摘要

International Domain Names (IDNs)may contain Unicode in addition to ASCII characters. This enables attackers to replace one or even more characters of a well-known domain with visually similar Unicode characters to create new, look-alike domains. These so-called homograph domains are attractive for malicious activities such as phishing or scams because they may appear legitimate to potential victims. In this paper, we propose two measurement setups to detect homograph domains and monitor their activity. Throughout eight months, we detected almost 3,000 homograph domains, targeting technology companies as well as financial institutions. To understand this phenomenon in more detail, we monitored the activity of these domains daily for more than five months and identified multiple instances of scamming and phishing, with some campaigns being active for several months. We also detected previously undiscovered domains used for a widespread scam in which attackers promise free shoes and other goods. In many cases, these domains were not detected by classical detection approaches such as VirusTotal or Google Safe Browsing, or reported only with a delay of several days or weeks compared to our approach. While we did observe defensive registrations of homograph domains by domain owners, we found that they were very limited in scope and did not cover all possible look-alike character replacements. To that end, we conclude our paper with recommendations for domain owners.
机译:除了ASCII字符之外,国际域名(IDN)可能包含Unicode。这使攻击者能够用视觉上类似的Unicode字符替换众所周知的域的一个甚至更多字符,以创建新的外观相似的域。这些所谓的同形域对恶意活动有吸引力,例如网络钓鱼或骗局,因为它们可能会对潜在的受害者显得合法。在本文中,我们提出了两种测量设置来检测同学域并监控其活动。在整个八个月内,我们发现了几乎有3,000个同类域,定位技术公司以及金融机构。为了更详细地了解这种现象,我们每天监测这些域的活动超过五个月,并确定了多个诈骗和网络钓鱼的情况,一些活动有几个月的活动。我们还检测到以前的未被发现的域,用于广泛的骗局,其中攻击者承诺自由鞋和其他商品。在许多情况下,这些域未通过经典检测方法(如Virustotal或Google Safe Branessing)检测到,或者仅与我们的方法相比,仅报告了几天或几周的延迟。虽然我们确实观察了域名所有者的定性域的防御性注册,但我们发现它们的范围非常有限,并且没有涵盖所有可能的外观相似的替代品。为此,我们向域名的建议结束了我们的论文。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号