학술논문

Ten years of attacks on companies using visual impersonation of domain names
Document Type
Conference
Source
2020 APWG Symposium on Electronic Crime Research (eCrime) Electronic Crime Research (eCrime), 2020 APWG Symposium on. :1-12 Nov, 2020
Subject
Communication, Networking and Broadcast Technologies
Computing and Processing
Visualization
Companies
Explosions
Timing
Registers
Time factors
Servers
Language
ISSN
2159-1245
Abstract
We identify over a quarter of a million domains used by medium and large companies within the .com registry. We find that for around 7% of these companies very similar domain names have been registered with character changes that are intended to be indistinguishable at a casual glance. These domains would be suitable for use in Business Email Compromise frauds. Using historical registration and name server data we identify the timing, rate, and movement of these look-alike domains over a ten year period. This allows us to identify clusters of registrations which are quite clearly malicious and show how the criminals have moved their activity over time in response to countermeasures. Although the malicious activity peaked in 2016, there is still sufficient ongoing activity to cause concern.