On the potential of proactive domain blacklisting
Márk Félegyházi, Christian Kreibich, Vern Paxson
Abstract
Márk Félegyházi, Christian Kreibich, Vern Paxson
Abstract
In this paper we explore the potential of leveraging properties inherent to domain registrations and their appearance in DNS zone files to predict the malicious use of domains proactively, using only minimal observation of known-bad domains to drive our inference. Our analysis demonstrates that our inference procedure derives on average 3.5 to 15 new domains from a given known-bad domain. 93 % of these inferred domains subsequently appear suspect (based on third-party assessments), and nearly 73 % eventually appear on blacklists themselves. For these latter, proactively blocking based on our predictions provides a median headstart of about 2 days versus using a reactive blacklist, though this gain varies widely for different domains. 1
OpenAlex reports 138 citations for this work. Citation counts describe recorded attention and do not establish research quality.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
In this paper we explore the potential of leveraging properties inherent to domain registrations and their appearance in DNS zone files to predict the malicious use of domains proactively, using only minimal observation of known-bad domains to drive our inference. Our analysis demonstrates that our inference procedure derives on average 3.5 to 15 new domains from a given known-bad domain. 93 % of these inferred domains subsequently appear suspect (based on third-party assessments), and nearly 73 % eventually appear on blacklists themselves. For these latter, proactively blocking based on our predictions provides a median headstart of about 2 days versus using a reactive blacklist, though this gain varies widely for different domains. 1
Key concepts: Blacklisting, Blacklist, Inference, Domain (mathematical analysis), Computer science, Suspect, Blocking (statistics), Computer security