Skip to main content
QUICK REVIEW

[Paper Review] Hiding in Plain Sight: A Longitudinal Study of Combosquatting Abuse

Panagiotis Kintis, Najmeh Miramirkhani|Research Open (London South Bank University)|Aug 28, 2017
Spam and Phishing Detection35 references66 citations
TL;DR

This paper conducts the first large-scale, longitudinal empirical study of combosquatting, analyzing 468 billion DNS records to reveal prevalence, lifetimes, lexical properties, and real-world abuse of combosquatting domains.

ABSTRACT

Domain squatting is a common adversarial practice where attackers register domain names that are purposefully similar to popular domains. In this work, we study a specific type of domain squatting called "combosquatting," in which attackers register domains that combine a popular trademark with one or more phrases (e.g., betterfacebook[.]com, youtube-live[.]com). We perform the first large-scale, empirical study of combosquatting by analyzing more than 468 billion DNS records---collected from passive and active DNS data sources over almost six years. We find that almost 60% of abusive combosquatting domains live for more than 1,000 days, and even worse, we observe increased activity associated with combosquatting year over year. Moreover, we show that combosquatting is used to perform a spectrum of different types of abuse including phishing, social engineering, affiliate abuse, trademark abuse, and even advanced persistent threats. Our results suggest that combosquatting is a real problem that requires increased scrutiny by the security community.

Motivation & Objective

  • Motivate the study by defining combosquatting and its distinction from other DNS squatting types.
  • Quantify the scale of combosquatting across trademarks and datasets over six years.
  • Characterize lexical and temporal properties of combosquatting domains.
  • Identify real-world abuses including phishing, malware, affiliate and trademark abuse, and APT use.
  • Assess gaps in detection and remediation compared to other squatting phenomena.

Proposed method

  • Combine 468 billion DNS records from passive and active DNS sources over almost six years.
  • Define a seed set of 246 US-brand trademarks from top Alexa domains (later 22 business categories).
  • Construct and analyze Combosquatting Passive (CP) and Combosquatting Active (CA) datasets containing domains with trademarks.
  • Link datasets with Public Blacklists (PBL), APT reports, Spamtrap, Malware feeds, Alexa whitelisting, and Certificate Transparency to study abuse sets (C_pbl, C_apt, C_spa, C_mal, C_ale).
  • Compare combosquatting with typosquatting using Wang et al.’s five typosquatting models to quantify prevalence and attack models.
  • Analyze lexical construction, domain length, tokenization into words/segments, and common abusing words across categories.

Experimental results

Research questions

  • RQ1How prevalent is combosquatting relative to typosquatting and other squatting forms across large DNS datasets?
  • RQ2What lexical and structural properties characterize combosquatting domains?
  • RQ3What is the temporal behavior and lifetimes of combosquatting domains, and how quickly are they remediated or blacklisted?
  • RQ4What real-world abuses are facilitated by combosquatting (phishing, malware, SEO, trademark abuse, APTs)?
  • RQ5What hosting/infrastructure characteristics are associated with combosquatting domains and their abuse?

Key findings

  • Combosquatting domains are about 100 times more prevalent than typosquatting domains targeting the same trademarks.
  • Almost 60% of abusive combosquatting domains persist for more than 1,000 days.
  • About 20% of abusive combosquatting domains appear on public blacklists roughly 100 days after first resolution in DNS data (30% for malware feeds).
  • Between 2011 and 2016, the number of combosquatting queries grows year over year, unlike typosquatting.
  • 50% of combosquatting domains add at most eight characters to the trademark, and 40% are formed by adding a single token; domains tend to include words related to the trademark’s business category.
  • 691,182 TLS certificates were issued to 107,572 fully-qualified combosquatting domains since 2013, with 41.5% issued by Let’s Encrypt, while typosquatting domains had only 3,011 certificates.
  • Combosquatting domains support a wide range of abuses including phishing, social engineering, affiliate abuse, trademark abuse, malware C2, and APT-related use.

Better researchstarts right now

From reading papers to final review, dramatically reduce your research time.

No credit card · Free plan available

This review was created by AI and reviewed by human editors.