05:15 PM
Dark Reading
Dark Reading
Products and Releases

DomainTools Launches Predictive Domain Risk Scoring Model

Domain Risk Score is intended to identify dangerous domains and enables proactive network defense

SEATTLE, Feb. 21, 2018 -- DomainTools®, the leader in domain name and DNS-based cyber threat intelligence, today announced its Domain Risk Score, a new method of predicting the level of danger or risk associated with internet domains. Providing unparalleled accuracy and breadth over newly registered domains, this model is the first to enable proactive evaluation and risk scoring of a domain based purely on the domain's intrinsic characteristics. Leveraging machine learning and predictive insights, DomainTools' Risk Score identifies factors inherent in high-risk domains from their inception, even if they have not been previously observed in malicious activity. It also predicts which type of threat the domain is most likely to represent, whether phishing, malware, or spam.

While the case for identifying and blocking dangerous domains is universally understood, a recent report from Enterprise Management Associates revealed that 79 percent of security teams are overwhelmed by the volume of alerts triggered on their network. This illustrates the need for accurate, automated identification of dangerous infrastructure. Risk Score was developed to increase efficiency among these resource-strapped security teams, many of which are looking for ways to reduce the number of false-positive notifications they receive. Machine learning and predictive analysis can intelligently automate and streamline certain security functions, and are inherently optimal for enabling risk scoring.

DomainTools has scored all of the more than 310 million currently-registered domains and continues to score tens of thousands of newly registered domains every day. Using the most complete current and historical records in the industry, DomainTools data scientists developed machine learning classifiers to identify domains that have a likelihood of being used for phishing, malware, or spam. The "F Score" data (a means of evaluating detection and false positive rates) for multiple test runs confirm that the classifiers render the correct verdicts over 99 percent of the time. Risk Score can be leveraged to:

  • Surface domains that pose a significant risk to a specific organization or environment;
  • Compare high-risk domains to others in the DomainTools database to identify related sites that may also pose a risk;
  • Search for domains with high-risk scores in archived logs to determine if an attacker has gained entry into the network;
  • Establish DomainTools monitors for alerts on future domains that are registered to the same threat actor or campaign as other known blacklisted sites.

"Our goal is to help security professionals detect, investigate, and prevent malicious activity online. Domain Risk Score further enables us to deliver on that commitment," said Tim Chen, CEO, DomainTools. "Applying the expertise of our data science team to DomainTools' detailed data sets on nearly every active domain on the internet has delivered a unique predictive model that truly helps security teams stay ahead of emerging threat infrastructure."

Domain Risk Score can be utilized by a variety of security professionals, from network defenders who block the domains that are part of phishing, malware, or spam campaigns, to incident responders and threat hunters who determine the level and type of risk associated with various domains. With Risk Score, these teams can streamline their processes from the outset, starting with a point of relevance based on domains observed touching their network. This reduces false positives and allows security teams to focus their efforts.

Domain Risk Score is available as an optional add-on to DomainTools Iris, an enterprise-grade threat investigation platform, and the scores are also available as API queries. Learn more about Iris and how DomainTools is turning threat data into threat intelligence, or to request a demo of Domain Risk Score.

Comment  | 
Print  | 
More Insights
Newest First  |  Oldest First  |  Threaded View
Who Does What in Cybersecurity at the C-Level
Steve Zurier, Freelance Writer,  3/16/2018
Microsoft Report Details Different Forms of Cryptominers
Kelly Sheridan, Staff Editor, Dark Reading,  3/13/2018
New 'Mac-A-Mal' Tool Automates Mac Malware Hunting & Analysis
Kelly Jackson Higgins, Executive Editor at Dark Reading,  3/14/2018
Register for Dark Reading Newsletters
White Papers
Current Issue
How to Cope with the IT Security Skills Shortage
Most enterprises don't have all the in-house skills they need to meet the rising threat from online attackers. Here are some tips on ways to beat the shortage.
Flash Poll
[Strategic Security Report] Navigating the Threat Intelligence Maze
[Strategic Security Report] Navigating the Threat Intelligence Maze
Most enterprises are using threat intel services, but many are still figuring out how to use the data they're collecting. In this Dark Reading survey we give you a look at what they're doing today - and where they hope to go.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
Published: 2017-05-09
NScript in mpengine in Microsoft Malware Protection Engine with Engine Version before 1.1.13704.0, as used in Windows Defender and other products, allows remote attackers to execute arbitrary code or cause a denial of service (type confusion and application crash) via crafted JavaScript code within ...

Published: 2017-05-08
unixsocket.c in lxterminal through 0.3.0 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (preventing terminal launch), or possibly have other impact (bypassing terminal access control).

Published: 2017-05-08
A privilege escalation vulnerability in Brocade Fibre Channel SAN products running Brocade Fabric OS (FOS) releases earlier than v7.4.1d and v8.0.1b could allow an authenticated attacker to elevate the privileges of user accounts accessing the system via command line interface. With affected version...

Published: 2017-05-08
Improper checks for unusual or exceptional conditions in Brocade NetIron 05.8.00 and later releases up to and including 06.1.00, when the Management Module is continuously scanned on port 22, may allow attackers to cause a denial of service (crash and reload) of the management module.

Published: 2017-05-08
Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search module. To be exploitable a user has to write or paste malicious content into the search dialogue.