The Ghosts of Banking Past: Empirical Analysis of Closed Bank Websites

The Ghosts of Banking Past: Empirical Analysis of Closed Bank Websites
复制标题

银行业过去的幽灵:对已关闭银行网站的实证分析

DOI:
10.1007/978-3-662-45472-5_3
复制
发表时间:
2014
期刊:
Comput. Secur.
影响因子:
--
通讯作者:
R. Clayton
R. Clayton
中科院分区:
--
文献类型:
--
作者:
T. Moore;R. Clayton

文献摘要

被引文献

相似文献

我们研究了当美国银行关闭或与另一家机构合并时,银行用于面向客户的网站的域名会发生什么。联邦存款保险公司(FDIC)公布了数千家美国银行的详细统计数据,包括它们的网站网址。我们提取了自2003年以来关闭的3181家银行的详细信息,并确定了已知它们使用过的2302个域名的命运。我们发现,47%的域名仍然由银行机构拥有,但33%的域名已经落入那些通过托管广告、分发恶意软件或进行搜索引擎优化(SEO)活动来利用域名剩余良好声誉的人手中。我们绘制了域名使用的生命周期后,原来的机构不再需要它作为他们的主要客户接触点-并解释我们的研究结果从经济的角度。我们提出了逻辑回归,有助于解释为什么封闭的银行域被放弃的一些原因,以及为什么其他人选择重新利用它们。例如,我们发现规模较小且陷入困境的银行更有可能失去对其域名的控制,而较大银行的域名更有可能被其他银行重新利用。我们提请注意最好远离公开市场的其他类别的域,以免旧的僵尸网络复活或其他形式的犯罪复活。最后,我们将探讨哪些公共政策选项可以保护我们所有人免受原始注册人不再照顾的幽灵域名的影响。
We study what happens to the domains used by US banks for their customer-facing websites when the bank is shut down or merges with another institution. The Federal Deposit Insurance Corporation (FDIC) publishes detailed statistical data about the many thousands of US banks, including their website URLs. We extracted details of the 3 181 banks that have closed their doors since 2003 and determined the fate of 2 302 domain names they are known to have used. We found that 47 % are still owned by a banking institution but that 33 % have passed into the hands of people who are exploiting the residual good reputation attached to the domain by hosting adverts, distributing malware or carrying out search engine optimization (SEO) activities. We map out the lifecycle of domain usage after the original institution no longer requires it as their main customer contact point – and explain our findings from an economic perspective. We present logistic regressions that help explain some of reasons why closed bank domains are let go, as well as why others choose to repurpose them. For instance, we find that smaller and troubled banks are more likely to lose control of their domains, and that the domains from bigger banks are more likely to be repurposed by others. We draw attention to other classes of domain that are best kept off the open market lest old botnets be revivified or other forms of criminality be resurrected. We end by exploring what the public policy options might be that would protect us all from ghost domains that are no longer being looked after by their original registrants.