A group of scientists at the Hamad Bin Khalifa University’s Qatar Computing Research Institute (QCRI) has invented a new tool to identify unknown malicious domains by using a real-life “guilt by association” principle.
The researchers, led by Issa Khalil and Ting Yu, have developed a prototype that can detect malicious domains by analysing the movements and previous associations of a domain address.
Malicious domains are involved in many cyber security attacks including Distributed Denial of Service (DDoS) attacks, in which web servers are attacked and become unusable. They are also a source of phishing, whereby criminals dupe e-mail users to disclose information by posing as reputable entities; and are used to control botnets, when armies of infected machines without their owners’ knowledge can propagate malware and send spam messages.
Khalil said the tool, dubbed Guilt by Association Inference of Malicious Domains, used data from public Domain Name Service (DNS) records and other interested parties to provide high-quality intelligence of potentially
malicious domains.
“One would consider an unknown person suspicious if he mostly hangs around with known criminals and trustworthy if he hangs around
with known good people,” Khalil said.
“Similarly, in the context of malicious domains, hanging around can be interpreted in different ways including moving from one web-hosting provider to another in flocks, being hosted on similar IPs, accessed by similar set of clients, or having similar registration records, among other behaviour.”
An example used by the researchers in developing the tool was a tendency by owners of malicious domains to “run”, changing the hosting of their domains from one service provider to another to avoid being detected and blocked.
The research findings are to appear in the ACM AsiaCCS conference to be held in June.
There are no comments.
Saying goodbye is never easy, especially when you are saying farewell to those that have left a positive impression. That was the case earlier this month when Canada hosted Mexico in a friendly at BC Place stadium in Vancouver.
Some 60mn primary-school-age children have no access to formal education
Lekhwiya’s El Arabi scores the equaliser after Tresor is sent off; Tabata, al-Harazi score for QSL champions
The Yemeni Minister of Tourism, Dr Mohamed Abdul Majid Qubati, yesterday expressed hope that the 48-hour ceasefire in Yemen declared by the Command of Coalition Forces on Saturday will be maintained in order to lift the siege imposed on Taz City and ease the entry of humanitarian aid to the besieged
Some 200 teachers from schools across the country attended Qatar Museum’s (QM) first ever Teachers Council at the Museum of Islamic Art (MIA) yesterday.
The Supreme Judiciary Council (SJC) of Qatar and the Indonesian Supreme Court (SCI) have signed a Memorandum of Understanding (MoU) on judicial co-operation, it was announced yesterday.
Sri Lanka is keen on importing liquefied natural gas (LNG) from Qatar as part of government policy to shift to clean energy, Minister of City Planning and Water Supply Rauff Hakeem has said.