Skip to main content

Research Repository

Advanced Search

Hiding in Plain Sight: A Longitudinal Study of Combosquatting Abuse

Kintis, Panagiotis; Miramirkhani, Najmeh; Lever, Charles; Chen, Yizheng; Romero-G�mez, Rosa; Pitropakis, Nikolaos; Nikiforakis, Nick; Antonakakis, Manos

Authors

Panagiotis Kintis

Najmeh Miramirkhani

Charles Lever

Yizheng Chen

Rosa Romero-G�mez

Nick Nikiforakis

Manos Antonakakis



Abstract

Domain squatting is a common adversarial practice where attackers register domain names that are purposefully similar to popular domains. In this work, we study a specific type of domain squatting called "combosquatting," in which attackers register domains that combine a popular trademark with one or more phrases (e.g., betterfacebook[.]com, youtube-live[.]com). We perform the first large-scale, empirical study of combosquatting by analyzing more than 468 billion DNS records - collected from passive and active DNS data sources over almost six years. We find that almost 60% of abusive combosquatting domains live for more than 1,000 days, and even worse, we observe increased activity associated with combosquatting year over year. Moreover, we show that combosquatting is used to perform a spectrum of different types of abuse including phishing, social engineering, affiliate abuse, trademark abuse, and even advanced persistent threats. Our results suggest that combosquatting is a real problem that requires increased scrutiny by the security community.

Presentation Conference Type Conference Paper (Published)
Conference Name 2017 ACM SIGSAC Conference on Computer and Communications Security
Start Date Oct 30, 2017
End Date Nov 3, 2017
Acceptance Date Oct 30, 2017
Publication Date Oct 30, 2017
Deposit Date Sep 21, 2018
Publicly Available Date Sep 27, 2018
Publisher Association for Computing Machinery (ACM)
Book Title CCS '17 Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security
ISBN 9781450349468
DOI https://doi.org/10.1145/3133956.3134002
Keywords Domain squatting, Combosquatting, network security, domain name system,
Public URL http://researchrepository.napier.ac.uk/Output/1303999
Contract Date Sep 27, 2018

Files

Hiding in Plain Sight: A Longitudinal Study of Combosquatting Abuse (1.6 Mb)
PDF

Copyright Statement
Permission to make digital or hard copies of all or part of this work for personal or classroom use is granted without fee provided that copies are not made or distributed for profit or commercial advantage and that copies bear this notice and the full citation on the first page. Copyrights for components of this work owned by others than ACM
must be honored. Abstracting with credit is permitted. To copy otherwise, or republish, to post on servers or to redistribute to lists, requires prior specific permission and/or a fee. Request permissions from permissions@acm.org.
CCS ’17, October 30-November 3, 2017, Dallas, TX, USA
© 2017 Association for Computing Machinery.
ACM ISBN 978-1-4503-4946-8/17/10. . . $15.00
https://doi.org/10.1145/3133956.3134002






You might also like



Downloadable Citations