2010Unpublished venueRequires access

On the potential of proactive domain blacklisting

Márk Félegyházi, Christian Kreibich, Vern Paxson

Open publisher page 138 citations

Abstract

In this paper we explore the potential of leveraging properties inherent to domain registrations and their appearance in DNS zone files to predict the malicious use of domains proactively, using only minimal observation of known-bad domains to drive our inference. Our analysis demonstrates that our inference procedure derives on average 3.5 to 15 new domains from a given known-bad domain. 93 % of these inferred domains subsequently appear suspect (based on third-party assessments), and nearly 73 % eventually appear on blacklists themselves. For these latter, proactively blocking based on our predictions provides a median headstart of about 2 days versus using a reactive blacklist, though this gain varies widely for different domains. 1

About this research paper

What this paper is about

In this paper we explore the potential of leveraging properties inherent to domain registrations and their appearance in DNS zone files to predict the malicious use of domains proactively, using only minimal observation of known-bad domains to drive our inference. Our analysis demonstrates that our inference procedure derives on average 3.5 to 15 new domains from a given known-bad domain. 93 % of these inferred domains subsequently appear suspect (based on third-party assessments), and nearly 73 % eventually appear on blacklists themselves. For these latter, proactively blocking based on our predictions provides a median headstart of about 2 days versus using a reactive blacklist, though this gain varies widely for different domains. 1

Why it matters

OpenAlex reports 138 citations for this work. Citation counts describe recorded attention and do not establish research quality.

Key contribution

A contribution statement is not available in the OpenAlex record.

Method / approach

Method details are not available in the OpenAlex metadata.

Main findings

Findings are not separately available in the OpenAlex metadata.

Limitations

Limitations are not available in the OpenAlex metadata.

Applications

Application details are not available in the OpenAlex metadata.

Available abstract

In this paper we explore the potential of leveraging properties inherent to domain registrations and their appearance in DNS zone files to predict the malicious use of domains proactively, using only minimal observation of known-bad domains to drive our inference. Our analysis demonstrates that our inference procedure derives on average 3.5 to 15 new domains from a given known-bad domain. 93 % of these inferred domains subsequently appear suspect (based on third-party assessments), and nearly 73 % eventually appear on blacklists themselves. For these latter, proactively blocking based on our predictions provides a median headstart of about 2 days versus using a reactive blacklist, though this gain varies widely for different domains. 1

Key concepts: Blacklisting, Blacklist, Inference, Domain (mathematical analysis), Computer science, Suspect, Blocking (statistics), Computer security

Related papers

Back to paper searchBrowse research topicsOriginal source
On the potential of proactive domain blacklisting — Research Paper | ScholarLens