Statistical Analysis of DNS Abuse in Gtlds Final Report
Statistical Analysis of DNS Abuse in gTLDs Final Report Maciej Korczynski´ ⇤, Maarten Wullink†, Samaneh Tajalizadehkhoob⇤, Giovane C.M. Moura†, Cristian Hesselman† ⇤Delft University of Technology, The Netherlands †SIDN Labs, The Netherlands {Maciej.Korczynski, S.T.Tajalizadehkhoob}@tudelft.nl {Maarten.Wullink, Giovane.Moura, Cristian.Hesselman}@sidn.nl Abstract—Commissioned by the Competition, Consumer Trust, A number of safeguards were built into the Program that and Consumer Choice Review Team with the support of ICANN, were intended to mitigate the rates of abusive, malicious, this study is focused on measuring rates of common forms of and criminal activity in these new gTLDs, such as phishing, abusive activities in the domain name system. We conduct a comprehensive study examining malicious behavior in the global spam, and malware distribution. ICANN is currently engaged DNS and compare abuse rates in new and legacy gTLDs. We in a review of these safeguards and their effects on rates of combine data sets from many sources, including zone files, DNS abuse as an aspect of the Competition, Consumer Trust, domain WHOIS information, data obtained through our active and Consumer Choice Review2. In this paper, we conduct a measurements, and 11 reputable blacklists representing malware, comprehensive study examining rates of malicious and abusive phishing, and spam. We find that the new gTLDs have impacted spam counts of the legacy gTLDs: abused domains in the new behavior in the global DNS and compare abuse rates in gTLDs do not increase the number of total malicious registrations new gTLDs and legacy gTLDs. As the DNS represents a but instead, we observe a decrease in the number of malicious large ecosystem of registries, registrars, privacy/proxy service registrations in legacy gTLDs.
[Show full text]