Skip to main navigation Skip to search Skip to main content

Hiding in plain Sight: A longitudinal study of combosquatting abuse

  • Panagiotis Kintis
  • , Najmeh Miramirkhani
  • , Charles Lever
  • , Yizheng Chen
  • , Roza Romero-Gómez
  • , Nikolaos Pitropakis
  • , Nick Nikiforakis
  • , Manos Antonakakis
  • Institute of Technology
  • Stony Brook University
  • London South Bank University

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

145 Scopus citations

Abstract

Domain squatting is a common adversarial practice where attackers register domain names that are purposefully similar to popular domains. In this work, we study a specific type of domain squatting called "combosquatting," in which attackers register domains that combine a popular trademark with one or more phrases (e.g., betterfacebook[.] com, youtube-live[.]com). We perform the first largescale, empirical study of combosquatting by analyzing more than 468 billion DNS records-collected from passive and active DNS data sources over almost six years. We find that almost 60% of abusive combosquatting domains live for more than 1,000 days, and even worse, we observe increased activity associated with combosquatting year over year. Moreover, we show that combosquatting is used to perform a spectrum of different types of abuse including phishing, social engineering, affiliate abuse, trademark abuse, and even advanced persistent threats. Our results suggest that combosquatting is a real problem that requires increased scrutiny by the security community.

Original languageEnglish
Title of host publicationCCS 2017 - Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security
PublisherAssociation for Computing Machinery
Pages569-586
Number of pages18
ISBN (Electronic)9781450349468
DOIs
StatePublished - Oct 30 2017
Event24th ACM SIGSAC Conference on Computer and Communications Security, CCS 2017 - Dallas, United States
Duration: Oct 30 2017Nov 3 2017

Publication series

NameProceedings of the ACM Conference on Computer and Communications Security
ISSN (Print)1543-7221

Conference

Conference24th ACM SIGSAC Conference on Computer and Communications Security, CCS 2017
Country/TerritoryUnited States
CityDallas
Period10/30/1711/3/17

Keywords

  • Combosquatting
  • Domain Name System
  • Domain Squatting
  • Network Security

Fingerprint

Dive into the research topics of 'Hiding in plain Sight: A longitudinal study of combosquatting abuse'. Together they form a unique fingerprint.

Cite this