Short, Brutal Lives: Life Expectancy for Malicious Domains

  /     /     /  
Publicated : 23/11/2024   Category : security


Short, Brutal Lives: Life Expectancy for Malicious Domains


Using a cooling-off period for domain names can help catch those registered by known bad actors.



Domain Name System (DNS) pioneer Paul Vixie for more than three years has been calling for
a cooling off period
for newly created Internet domain names as a way to deter cybercrime and other abuses. Domain names registered and spun up in less than a minute only encourage and breed malicious activity, he argues, and placing them in a holding pattern for a few minutes or hours can help vet them and catch any registered by known spammers and other bad actors.
Vixie — who is founder and CEO of threat intelligence firm Farsight Security — and his team have now taken an up-close look at the life cycle of new Internet domains, and their findings shine new light on the lifespan of malicious and suspicious domains. Most of them die young, and most of them die after living short, brutal lives, he says of newly created domains.
Over a six-month period, Vixie and his team conducted a longitudinal study of 23.8 million domains under 936 top-layer domains from their creation. They found that in the first seven days, 9.3% of new domains died: the median lifespan was four hours and 16 minutes.
The cause of death for 6.7% of those new domains was blacklisting, and most of them were blocked within an hour of their birth. DNS registrars and hosting providers, meanwhile, deleted or revoked malicious domains in three days or more after their creation. Interestingly, new generic top-level domains (gTLDs) suffered three times the rapid deaths than traditional ones such as .com, .net, .org, and .edu, for example.
Vixies team found in the first week of life for new gTLDs there were 12 cases of more of them dying than living past their first week. I was not shocked to see them as poster children of the short-lifetime effect, he says. I dont know if they are more abusable or not, but its possible the registries who snapped them up to sell arent getting as much business as they expected. Theyre under a good deal of financial pressure, he says, so some may be less choosy over to whom they sell their available domains.
The Internets biggest TLD, .com, had just 2% of its new domains blacklisted and 3.6% deleted by registrars.
The new research, which Vixie will present on October 5 at the VirusBulletin International Conference in Montreal, underscores how a secure DNS policy is needed both for registrars that issue domains as well as enterprises that register new domains, he says. Putting new domains on ice for hours, days, or a week, is the best approach to ensure theres no malicious intent or ties. Enterprises, too, get the benefit of ensuring their new domains arent incorrectly blacklisted, for example.
All new domain should go into a penalty box — good or bad — until theyve had a chance to live long enough, he says. Vixies full report will be released on Friday.
Related Content:
DNS a Victim of its Own Success
Domain Abuse Sinks Anchors Of Trust
7 Ways to Keep DNS Safe
10 Threats Lurking on the Dark Web
Black Hat Europe returns to London Dec. 3-6, 2018, with hands-on technical Trainings, cutting-edge Briefings, Arsenal open-source tool demonstrations, top-tier security solutions, and service providers in the Business Hall. Click for information on the
conference
 and
to register.

Last News

▸ Some DLP Products Vulnerable to Security Holes ◂
Discovered: 23/12/2024
Category: security

▸ Scan suggests Heartbleed patches may not have been successful. ◂
Discovered: 23/12/2024
Category: security

▸ IoT Devices on Average Have 25 Vulnerabilities ◂
Discovered: 23/12/2024
Category: security


Cyber Security Categories
Google Dorks Database
Exploits Vulnerability
Exploit Shellcodes

CVE List
Tools/Apps
News/Aarticles

Phishing Database
Deepfake Detection
Trends/Statistics & Live Infos



Tags:
Short, Brutal Lives: Life Expectancy for Malicious Domains