Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Threat Intelligence

End of Bibblio RCM includes -->
5/4/2021
06:35 PM
Connect Directly
Twitter
LinkedIn
RSS
E-Mail

Newer Generic Top-Level Domains a Security 'Nuisance'

Ten years of passive DNS data shows classic TLDs such as .com and .net dominate newer TLDs in popularity and use.

A study into the use and popularity of the Internet's top-level domains (TLDs) over a 10-year period shows that many newer TLDs may present more of a security nuisance for organizations than anything else.

That's according to Farsight Security, which this week released a 182-page snapshot of top-level domain traffic associated with each of 1,576 TLDs recognized by the Internet Assigned Numbers Authority (IANA). The company's findings are based on passive DNS data from 2010 to 2019 and do not include DNSSEC-related records.

Related Content:

How Fraudulent Domains 'Hide in Plain Sight'

Special Report: Assessing Cybersecurity Risk in Today's Enterprises

New From The Edge: Planning Our Passwordless Future

The dataset includes traffic associated with generic top-level domains, such as .com, .net, and .org; country-code TLDs, such as .uk, .ca, and .de; new generic TLDs, such as .aarp, .nba, and .abc; and internationalized domain names, or TLDs with non-Latin characters.

One of the main goals of the study was to get a general sense of how broadly popular — or not — various TLDs have become over the past 10 years. While .com is generally perceived as — and actually is — the largest TLD, there's less information on the uptake of other TLDs after IANA began recognizing a lot more of them in recent years, Farsight notes in its report.

"One aspect of this to ask if it was a valuable extension of the namespace or pointless nuisance" to add more TLDs in recent years, says Ben April, chief technology officer at Farsight Security. The data around TLD use suggests that the latter might well be the case, he says.

"Overall, the new TLDs aren't thriving," April says. Many have a user population and some even show signs of growth. Even so, there is no evidence of the broad migration to sector-specific TLDs that many had expected initially. "We don't see entire sectors — for example, banks — dropping .com as a primary TLD and refocusing on .bank."

From a security perspective, one concern with the growth in the number of TLDs over the past few years is that attackers have more opportunities for spoofing domains for phishing, cyber squatting, and other malicious activities. For instance, by registering a popular brand's domain name on a newer generic TLD and sending phishing emails from there, an attacker might have more success in getting victims to part with credentials and other sensitive information. In a 2019 Proofpoint study, nearly 96% of organizations found an exact match of their brand-owned domain on other TLDs.

Concerns over the threat have prompted interest in so-called defensive registrations where organization register their domains, sometimes in varied grammatical formats, on different TLDs just to prevent others from doing it for malicious purposes.

Varying Risks
What Farsight's data provides is a way for organizations to identify TLDs that present the biggest risk to their brand, April says. "When evaluating risks to your brand, the size of your target surface is directly proportional to the number of TLDs relevant to your brand," he says. "You need to evaluate each TLD to determine the level of risk it presents. This report gives you data to compare how much risk each new TLD represents."

April says the data shows that while some TLDs are likely to be worthy of concern for specific organizations, others can be safely ignored.

For example, TLDs such as .aero and .gov that have access limitations present less of a risk as registrants need to prove their identity. "If you were an airline, you don't have to worry about an attacker registering myairline.areo," April notes. Open TLDs present more of a risk, but even here that risk varies with the relevance of the TLD. "For example, if I were a retailer, I would consider TLDs like .bargains, .blackfriday, .boutique, and .shop more of a risk than TLDs like .university, .travel, and .webcam," he says.

Organizations concerned about brand abuse on new TLDs should also do substring matching, April advises. This is where a TLD may contain part of an organization's domain or brand name. "As example, if you have bobsyoga.com, you might also want to evaluate the value of a defensive registration for bobs.yoga," April says.

Another issue that organizations need to consider is whether TLDs have enough of a critical user base to justify accepting email from them. Decisions would need to be made on a case-by-case basis and after a careful evaluation of each TLD. "The decision to reject mail from an entire TLD is not one to be taken lightly," April says. "Organizations with a low risk tolerance and an identifiable customer/vendor base can use the data in this report to eliminate TLDs that add exposure to their security operations without also adding value."

Jai Vijayan is a seasoned technology reporter with over 20 years of experience in IT trade journalism. He was most recently a Senior Editor at Computerworld, where he covered information security and data privacy issues for the publication. Over the course of his 20-year ... View Full Bio

Comment  | 
Print  | 
More Insights
//Comments
Newest First  |  Oldest First  |  Threaded View
Edge-DRsplash-10-edge-articles
I Smell a RAT! New Cybersecurity Threats for the Crypto Industry
David Trepp, Partner, IT Assurance with accounting and advisory firm BPM LLP,  7/9/2021
News
Attacks on Kaseya Servers Led to Ransomware in Less Than 2 Hours
Robert Lemos, Contributing Writer,  7/7/2021
Commentary
It's in the Game (but It Shouldn't Be)
Tal Memran, Cybersecurity Expert, CYE,  7/9/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Everything You Need to Know About DNS Attacks
It's important to understand DNS, potential attacks against it, and the tools and techniques required to defend DNS infrastructure. This report answers all the questions you were afraid to ask. Domain Name Service (DNS) is a critical part of any organization's digital infrastructure, but it's also one of the least understood. DNS is designed to be invisible to business professionals, IT stakeholders, and many security professionals, but DNS's threat surface is large and widely targeted. Attackers are causing a great deal of damage with an array of attacks such as denial of service, DNS cache poisoning, DNS hijackin, DNS tunneling, and DNS dangling. They are using DNS infrastructure to take control of inbound and outbound communications and preventing users from accessing the applications they are looking for. To stop attacks on DNS, security teams need to shore up the organization's security hygiene around DNS infrastructure, implement controls such as DNSSEC, and monitor DNS traffic
Flash Poll
How Enterprises are Developing Secure Applications
How Enterprises are Developing Secure Applications
Recent breaches of third-party apps are driving many organizations to think harder about the security of their off-the-shelf software as they continue to move left in secure software development practices.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2023-33196
PUBLISHED: 2023-05-26
Craft is a CMS for creating custom digital experiences. Cross site scripting (XSS) can be triggered by review volumes. This issue has been fixed in version 4.4.7.
CVE-2023-33185
PUBLISHED: 2023-05-26
Django-SES is a drop-in mail backend for Django. The django_ses library implements a mail backend for Django using AWS Simple Email Service. The library exports the `SESEventWebhookView class` intended to receive signed requests from AWS to handle email bounces, subscriptions, etc. These requests ar...
CVE-2023-33187
PUBLISHED: 2023-05-26
Highlight is an open source, full-stack monitoring platform. Highlight may record passwords on customer deployments when a password html input is switched to `type="text"` via a javascript "Show Password" button. This differs from the expected behavior which always obfuscates `ty...
CVE-2023-33194
PUBLISHED: 2023-05-26
Craft is a CMS for creating custom digital experiences on the web.The platform does not filter input and encode output in Quick Post validation error message, which can deliver an XSS payload. Old CVE fixed the XSS in label HTML but didn’t fix it when clicking save. This issue was...
CVE-2023-2879
PUBLISHED: 2023-05-26
GDSDB infinite loop in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via packet injection or crafted capture file