Compromised or Attacker-Owned: A Large Scale Classification and Study of Hosting Domains of Malicious URLs
Ravindu De Silva, Mohamed Nabeel, Charith Elvitigala, Issa Khalil, Ting Yu, Chamath Keppitiyagama
摘要
The mitigation action against a malicious website may differ greatly depending on how that site is hosted. If it is hosted under a private apex domain, where all its subdomains and pages are under the apex domain owner's direct control, we could block at the apex domain level. If it is hosted under a public apex domain though (e.g., a web hosting service provider), it would be more appropriate to block at the subdomain level. Further, for the former case, the private apex domain may be legitimate but compromised, or may be attackergenerated, which, again, would warrant different mitigation actions: attacker-owned apex domains could be blocked permanently, while only temporarily for compromised ones. In this paper, we study over eight hundred million Virus-Total (VT) URL scans from Aug. 1, 2019 to Nov. 18, 2019 and build the first content agnostic machine learning models to distinguish between the above mentioned different types of apex domains hosting malicious websites. Specifically, we first build a highly accurate model to distinguish between public and private apex domains. Then we build additional models to further distinguish compromised domains from attacker-owned ones. Utilizing our trained models, we conduct a large-scale study of the host domains of malicious websites . We observe that even though public apex domains are less than 1% of the apexes hosting malicious websites, they amount to a whopping 46.5% malicious web pages seen in VT URL feeds during our study period. 19.5% of these public malicious websites are compromised. Out of the remaining websites (53.5%), which are hosted on private apexes, we observe that attackers mostly compromise benign websites (65.6%) to launch their attacks, whereas only 34.4% of malicious websites are hosted on domains registered by attackers. Overall, we observe the concerning trend that the majority (81.7%) of malicious websites are hosted under apex domains that attackers do not own.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper14
- Phishing URL Detection: A Network-based Approach Robust to EvasionTaeri Kim, Noseong Park, Jiwon Hong, Sang-Wook KimCCS 2022 · 被引用 21 次
- "Get in Researchers; We're Measuring Reproducibility": A Reproducibility Study of Machine Learning Papers in Tier 1 Security ConferencesDaniel Olszewski, Allison Lu, Carson Stillman, Kevin Warren 等CCS 2023 · 被引用 19 次
- Practical Attacks Against DNS Reputation SystemsTillson Galloway, Kleanthis Karakolios, Zane Ma, Roberto Perdisci 等S&P 2024 · 被引用 13 次
- SIRAJ: A Unified Framework for Aggregation of Malicious Entity DetectorsSaravanan Thirumuruganathan, Mohamed Nabeel, Euijin Choo, Issa Khalil 等S&P 2022 · 被引用 13 次
- Characterizing and Mitigating Phishing Attacks at ccTLD ScaleGiovane C. M. Moura, Thomas Daniels, Maarten Bosteels, Sebastian Castro 等CCS 2024 · 被引用 7 次
它引用的顶会 Paper8
- Hiding in Plain Sight: A Longitudinal Study of Combosquatting AbusePanagiotis Kintis, Najmeh Miramirkhani, Charles Lever, Yizheng Chen 等CCS 2017 · 被引用 166 次
- PREDATOR: Proactive Recognition and Elimination of Domain Abuse at Time-Of-RegistrationShuang Hao, Alex Kantchelian, Brad Miller, Vern Paxson 等CCS 2016 · 被引用 133 次
- Measurement and Analysis of Private Key Sharing in the HTTPS EcosystemFrank Cangialosi, Taejoong Chung, David R. Choffnes, Dave Levin 等CCS 2016 · 被引用 89 次
- Domain-Z: 28 Registrations Later Measuring the Exploitation of Residual Trust in DomainsChaz Lever, Robert J. Walls, Yacin Nadji, David Dagon 等S&P 2016 · 被引用 76 次
- Predicting Impending Exposure to Malicious Content from User BehaviorMahmood Sharif, Jumpei Urakawa, Nicolas Christin, Ayumu Kubota 等CCS 2018 · 被引用 71 次
相关 Paper
- Don't Let One Rotten Apple Spoil the Whole Barrel: Towards Automated Detection of Shadowed DomainsDaiping Liu, Zhou Li, Kun Du, Haining Wang 等CCS 2017 · 被引用 60 次
- MANTIS: Detection of Zero-Day Malicious Domains Leveraging Low Reputed Hosting InfrastructureFatih Deniz, Mohamed Nabeel, Ting Yu, Issa KhalilS&P 2025
- Zombie Awakening: Stealthy Hijacking of Active Domains through DNS Hosting ReferralEihal Alowaisheq, Siyuan Tang, Zhihao Wang, Fatemah Alharbi 等CCS 2020 · 被引用 19 次
- Exposing the Roots of DNS Abuse: A Data-Driven Analysis of Key Factors Behind Phishing Domain RegistrationsYevheniya Nosyk, Maciej Korczynski, Carlos Gañán, Sourena Maroofi 等CCS 2025 · 被引用 1 次
- Indicator of Benignity: An Industry View of False Positive in Malicious Domain Detection and its MitigationDaiping Liu, Danyu Sun, Zhenhua Chen, Shu Wang 等NDSS 2026
