Tehničko veleučilište u Zagrebu · Zagreb

Special Characters in Domain’s Name as Possible Indication of Compromitation Status

izvorni znanstveni rad

izvorni znanstveni rad

Special Characters in Domain’s Name as Possible Indication of Compromitation Status

Vrsta prilog sa skupa (u zborniku)
Tip izvorni znanstveni rad
Godina 2023
Nadređena publikacija XXII međunarodni simpozijum Infoteh-Jahorina 2023 : zbornik radova
Stranice str. 1-6
DOI 10.1109/INFOTEH60418.2024.10495994
Status objavljeno

Sažetak

Today, networks of compromised computers, known as botnets, pose a major threat to computer security. These networks serve websites that are used for communication between bots and for further expansion of the network, where they fraudulently collect information or carry out their scams. Fraud is carried out by imitating existing websites, i.e. by referring to a known business transaction of the user, e.g. the websites of the Tax Administration or the Ministry of the Interior. Blocking such domains can significantly limit the spread of botnets. There are known features that can be used to detect such domains. Many of these known features are based on forensic linguistic methods. In this paper, we will focus on one of the known features of using numbers in domain names. By analyzing available detected compromised domains as well as known valid domains, we determine the applicability of such a feature.

Ključne riječi

Botnet detection, forensic linguistic