Vulnerabilities / Threats
10/28/2016
05:30 PM
Connect Directly
Twitter
LinkedIn
RSS
E-Mail
100%
0%

And Now A PREDATOR To Fight DNS Domain Abuse

Researchers at Princeton and elsewhere demo a new tool for spotting people registering domains for malicious purposes.

Security researchers at Princeton University, Google, and three other organizations have developed a software tool designed to let domain name registration companies detect and block people attempting to register domains intended for malicious purposes.

The researchers provided details of the new Proactive Recognition and Elimination of Domain Abuse at Time-Of-Registration (PREDATOR) in a technical paper presented at the ACM Conference on Computer and Communications Security this week.

They described the tool as an evolution of existing domain reputation systems that work by first observing domain use and then assigning a reputation score to it based on type of content hosted and other factors.

The goal with PREDATOR is to equip security professional and domain registrars with the ability to do such reputation scoring before the actual domain registration takes place by observing and evaluating so-called time-of-registration features.

"The intuition has always been that the way that malicious actors use online resources somehow differs fundamentally from the way legitimate actors use them," Nick Feamster, acting director of Princeton’s Center for Information Technology Policy said in a statement announcing PREDATOR.

"We were looking for those signals: what is it about a domain name that makes it automatically identifiable as a bad domain name?"

Early evaluations of the tool using registration logs of .com and .net domains over a five-month period showed it to achieve a 70% detection rate and a false-positive rate of 0.35%, the researchers claimed in the paper. The results suggest the tool offers an effective and early first line of defense against DNS domain misuse, they noted. “It predicts malicious domains when they are registered, which is typically days or weeks earlier than existing DNS blacklists.”

Researchers from the University of California, Santa Barbara, the University of California, Berkeley, Google, the International Computer Science Institute and Princeton University contributed to PREDATOR.

The work on PREDATOR builds on previous research focused on evaluating DNS preregistration data to predict future DNS traffic, says Feamster in comments to Dark Reading. He pointed to a patent that Verisign filed in 2012 as one example of previous work in this area.

The idea is to make it harder for threat actors to register websites for sending spam, for launching phishing and denial-of-service campaigns and other malicious activities. Cybercriminals routinely register thousands of domains on a daily basis for such purposes.

The Anti-Phishing Work Group for instance counted nearly 630,500 sites being used for phishing alone between Q1 and Q3 last year, with the US hosting the most number of such sites.

Others have worked to fight domain name abuse in different ways. Recently, researchers at Georgia Tech for instance demonstrated a method for spotting attackers hiding behind reputable domains or hijacking domains previously associated with malicious uses. Last year, internet pioneer Paul Vixie proposed introducing a short waiting period between when a domain is registered and when it goes live, to deter abuse.

Current blacklisting tools only allow for after-the-fact action. So criminals are able to launch new domains to support their activities almost as quickly as old ones are taken down. “If we can identify in advance that a DNS domain name is going to be used for malicious purposes we could prevent it from being registered,” Feamster says.

People registering domain names with malicious intent often exhibit certain behaviors, he says. For example, someone planning on using domain names in an attack campaign might register hundreds and even thousands of domains over a very small window of time. Similarly, it is not unusual for such domains to have names that are not necessarily human readable or names that are minor variations of a single name, he says.

By detecting such patterns and blocking automatic domain registration until vetting takes place, registrars can make it much harder for malicious actors to abuse DNS domains, Feamster says.

The hope is to be able to make the technology commercially available eventually, he adds.

Related stories:

 

 

Jai Vijayan is a seasoned technology reporter with over 20 years of experience in IT trade journalism. He was most recently a Senior Editor at Computerworld, where he covered information security and data privacy issues for the publication. Over the course of his 20-year ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
juliazz
50%
50%
juliazz,
User Rank: Apprentice
3/26/2017 | 7:06:34 AM
here
I get a DNs abuse and its not funny at all... Thx for the post
Benefiter
50%
50%
Benefiter,
User Rank: Apprentice
11/2/2016 | 4:55:52 PM
Re: here I got the tips!
It's actually a cool and useful piece of information. I am glad that you shared this helpful information with us. Please keep us informed like this. Thank you for sharing.
tomysong
50%
50%
tomysong,
User Rank: Apprentice
11/2/2016 | 2:16:43 PM
here
I don't even know how I stopped up right here, but I believed this submit used to be good. I do not recognize who you might be however certainly you're going to a famous blogger in the event you aren't already. Cheers!
amiee
50%
50%
amiee,
User Rank: Apprentice
11/1/2016 | 6:45:21 PM
here I got the tips!
Its like you learn my mind! You seem to understand a lot about this, like you wrote the e-book in it or something. I believe that you could do with some percent to pressure the message house a bit, but instead of that, this is great blog. A fantastic read. I'll certainly be back.
kasstri
100%
0%
kasstri,
User Rank: Moderator
11/1/2016 | 5:04:39 PM
thanks
I have learn several good stuff here. Definitely value bookmarking for revisiting. I surprise how much attempt you set to create this sort of magnificent informative site.
jalair105
50%
50%
jalair105,
User Rank: Apprentice
10/31/2016 | 9:31:47 AM
Food for thought
Interesting name for this process. Have any safeguards been thought of before a "Government or Political NGO" decides that the "malicious actors" with an alternative viewpoint should not be on the web.
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Security Operations and IT Operations: Finding the Path to Collaboration
A wide gulf has emerged between SOC and NOC teams that's keeping both of them from assuring the confidentiality, integrity, and availability of IT systems. Here's how experts think it should be bridged.
Flash Poll
New Best Practices for Secure App Development
New Best Practices for Secure App Development
The transition from DevOps to SecDevOps is combining with the move toward cloud computing to create new challenges - and new opportunities - for the information security team. Download this report, to learn about the new best practices for secure application development.
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-7445
Published: 2015-10-15
The Direct Rendering Manager (DRM) subsystem in the Linux kernel through 4.x mishandles requests for Graphics Execution Manager (GEM) objects, which allows context-dependent attackers to cause a denial of service (memory consumption) via an application that processes graphics data, as demonstrated b...

CVE-2015-4948
Published: 2015-10-15
netstat in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.2.x, when a fibre channel adapter is used, allows local users to gain privileges via unspecified vectors.

CVE-2015-5660
Published: 2015-10-15
Cross-site request forgery (CSRF) vulnerability in eXtplorer before 2.1.8 allows remote attackers to hijack the authentication of arbitrary users for requests that execute PHP code.

CVE-2015-6003
Published: 2015-10-15
Directory traversal vulnerability in QNAP QTS before 4.1.4 build 0910 and 4.2.x before 4.2.0 RC2 build 0910, when AFP is enabled, allows remote attackers to read or write to arbitrary files by leveraging access to an OS X (1) user or (2) guest account.

CVE-2015-6333
Published: 2015-10-15
Cisco Application Policy Infrastructure Controller (APIC) 1.1j allows local users to gain privileges via vectors involving addition of an SSH key, aka Bug ID CSCuw46076.

Dark Reading Radio
Archived Dark Reading Radio
In past years, security researchers have discovered ways to hack cars, medical devices, automated teller machines, and many other targets. Dark Reading Executive Editor Kelly Jackson Higgins hosts researcher Samy Kamkar and Levi Gundert, vice president of threat intelligence at Recorded Future, to discuss some of 2016's most unusual and creative hacks by white hats, and what these new vulnerabilities might mean for the coming year.