OWASP BeNeLux Day Exploring the ecosystem of malicious domain registrations in the .eu TLD

09SNSYHw8H0/default.jpg

Abstract
In this talk, we report on an extensive analysis of 14 months of domain registration in the .eu TLD. The purpose is to identify large-scale malicious campaigns. Overall, the dataset of this study contains 824,121 new domain registrations; 2.53% of which have been flagged as malicious by blacklisting services. We explore the ecosystem and modus operandi of elaborate cybercriminal entities that recurrently register large amounts of domains for one-shot, malicious use. Although these malicious domains are short-lived, we establish that at least 80.04% of them can be framed in to 20 larger campaigns with varying duration and intensity. We further report on insights in the operational aspects of this business and observe, amongst other findings, that their processes are only partially automated.

Bio
Lieven Desmet is a Senior Research Manager on Secure Software in the imec-DistriNet Research Group at the Katholieke Universiteit Leuven (Belgium), where he outlines and implements the research strategy, coaches junior researchers in application security, and participates in dissemination, valorisation and spin-off activities. Lieven is also involved in OWASP as a board member of the Belgium OWASP Chapter, and part of the organisation team of the OWASP BeNeLux Day.

-

Managed by the official OWASP Media Project https://www.owasp.org/index.php/OWASP...



09SNSYHw8H0/default.jpg
OWASP BeNeLux Day Exploring the ecosystem of malicious domain registrations in the .eu TLD OWASP BeNeLux Day Exploring the ecosystem of malicious domain registrations in the .eu TLD Reviewed by Anonymous on January 13, 2018 Rating: 5