A domain name server (hereinafter referred to as a DNS server) receives a specific domain access request from a user terminal and determines whether the particular domain requested to be accessed is a malicious domain If the DNS server determines that the specific domain is a malicious domain, the DNS server transmits the Internet address of the sinkhole server to the user terminal. If the sinkhole server includes the header information of the traffic generated from the user terminal And the sinkhole server tracks abuse points linked to the malicious code based on the previous visit information.
展开▼