Panning for gold.com: Understanding the Dynamics of Domain Dropcatching

Panning for gold.com: Understanding the Dynamics of Domain Dropcatching
复制标题

淘金金网:了解域名丢弃的动态

DOI:
10.1145/3178876.3186092
复制
发表时间:
2018
期刊:
Proceedings of the 2018 World Wide Web Conference
影响因子:
--
通讯作者:
Nick Nikiforakis
Nick Nikiforakis
中科院分区:
--
文献类型:
--
作者:
N. Miramirkhani;Timothy Barron;M. Ferdman;Nick Nikiforakis

文献摘要

参考文献

被引文献

相似文献

一个事件,是很少考虑的技术用户和外行一样,是一个域名过期。域名注册的大规模增长与大量的域名重新注册相匹配,之后域名再次可供注册。虽然绝大多数即将到期的域名都没有价值,但在数十万个每日更新的域名中,存在着明显有价值的域名,要么是因为它们的词汇组成,要么是因为它们的剩余信任。在本文中,我们调查的动态域dropcatching公司,代表用户,竞争注册最理想的域名,一旦他们提供,然后拍卖给出价最高的人。使用数据驱动的方法,我们在九个月内监控2800万个域名的到期情况,收集域名特征,WHOIS记录,并定期抓取注册域名,以发现它们重新注册(捕获)的目的。除此之外,我们发现,平均而言,只有10%的过期(丢弃)域名被捕获,绝大多数重新注册发生在它们发布的当天。我们调查的功能,使一些域更容易被抓住比其他人,并发现一个域是恶意的,在其到期时是两倍的可能性比平均域被抓住。此外,以前的恶意域比以前的良性域更有可能被重新用于恶意目的。我们确定了三种有兴趣购买放弃域名的用户类型,从购买一两个域名的自由职业者到仅在三个月内投资超过11.5万美元购买放弃域名的专业人士。最后,我们观察到只有不到11%的域名被用于托管网络内容,其余域名要么被投机者使用,要么被恶意行为者使用。
An event that is rarely considered by technical users and laymen alike is that of a domain name expiration. The massive growth in the registration of domain names is matched by massive numbers of domain expirations, after which domains are made available for registration again. While the vast majority of expiring domains are of no value, among the hundreds of thousands of daily expirations, there exist domains that are clearly valuable, either because of their lexical composition, or because of their residual trust. In this paper, we investigate the dynamics of domain dropcatching where companies, on behalf of users, compete to register the most desirable domains as soon as they are made available and then auction them off to the highest bidder. Using a data-driven approach, we monitor the expiration of 28 million domains over the period of nine months, collecting domain features, WHOIS records, and crawling the registered domains on a regular basis to uncover the purpose for which they were re-registered (caught). Among others, we find that on average, only 10% of the expired (dropped) domains are caught with the vast majority of the re-registrations happening on the day they are released. We investigate the features that make some domains more likely to be caught than others and discover that a domain that was malicious at the time of its expiration is twice as likely to be caught than the average domain. Moreover, previously-malicious domains are significantly more likely to be reused for malicious purposes than previously benign domains. We identify three types of users who are interested in purchasing dropped domains, ranging from freelancers who purchase one or two domains to professionals who invest more than $115K purchasing dropped domains in only three months. Finally, we observe that less than 11% were used to host web content with the remaining domains used either by speculators, or by malicious actors.
DOI: 10.1145/3133956.3133988
发表时间: 2017-10
期刊: Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security
影响因子: --
作者:
T. Vissers;Timothy Barron;Tom van Goethem;W. Joosen;Nick Nikiforakis
通讯作者: T. Vissers;Timothy Barron;Tom van Goethem;W. Joosen;Nick Nikiforakis