Matches in SemOpenAlex for { <https://semopenalex.org/work/W10100871> ?p ?o ?g. }
Showing items 1 to 95 of
95
with 100 items per page.
- W10100871 abstract "Internet users are threatened daily by spam, phishing, and malware. These attacks are often launched using armies of compromised machines, complicating identification of the miscreants behind the attacks. Unfortunately, most current approaches to fight these problems are reactive in nature, allowing significant damage before security measures are adapted to new attacks. For example, blacklisting prevents communications with known malicious hosts, but many users may fall victim to an attack before blacklists are updated. In this dissertation we argue for a proactive approach to fighting cybercrime. Our approach relies on the observation that to avoid attribution and to stay up amidst take-down attempts, miscreants must provision their infrastructure differently than legitimate web sites. Thus, we propose to proactively identify malicious activity using unique characteristics of malicious web site provisioning. Specifically, using near real-time feeds of malicious web hosts, we investigate the extent to which miscreants use five specific provisioning practices. The first three are based on the Domain Name System (DNS), which translates host names to IP addresses. We first examine fast-flux, a practice where the association between name and address changes much more frequently than usual. We then investigate the use of DNS wildcards, which point many host names to a single address. Next, we examine the use of orphan DNS servers, which are DNS servers in non-existent domains. Then, we study the concentration of malicious activity in certain networks. Finally, we examine web redirects, which may appear to be links to legitimate web sites but in reality trick users into visiting malicious sites. We find that although good web sites sometimes make use of some of these techniques, malicious web sites are more likely to use them. Consequently, their presence can be used for proactive identification of malicious web sites." @default.
- W10100871 created "2016-06-24" @default.
- W10100871 creator A5041804593 @default.
- W10100871 creator A5061510260 @default.
- W10100871 date "2010-01-01" @default.
- W10100871 modified "2023-09-24" @default.
- W10100871 title "Proactive cyberfraud detection through infrastructure analysis" @default.
- W10100871 cites W1479710165 @default.
- W10100871 cites W148814131 @default.
- W10100871 cites W1516506771 @default.
- W10100871 cites W1590936031 @default.
- W10100871 cites W1592133747 @default.
- W10100871 cites W1604437383 @default.
- W10100871 cites W1674877186 @default.
- W10100871 cites W1775772884 @default.
- W10100871 cites W178883471 @default.
- W10100871 cites W1828150029 @default.
- W10100871 cites W1854214752 @default.
- W10100871 cites W191098608 @default.
- W10100871 cites W192036632 @default.
- W10100871 cites W1971784203 @default.
- W10100871 cites W1985920648 @default.
- W10100871 cites W1997564913 @default.
- W10100871 cites W2003590000 @default.
- W10100871 cites W2053774863 @default.
- W10100871 cites W2098301119 @default.
- W10100871 cites W2108214308 @default.
- W10100871 cites W2113167642 @default.
- W10100871 cites W2113344319 @default.
- W10100871 cites W2134750673 @default.
- W10100871 cites W2139565456 @default.
- W10100871 cites W2146729596 @default.
- W10100871 cites W2151972741 @default.
- W10100871 cites W2157798513 @default.
- W10100871 cites W2166731089 @default.
- W10100871 cites W2240246332 @default.
- W10100871 cites W2292342911 @default.
- W10100871 cites W2404789011 @default.
- W10100871 cites W2150995021 @default.
- W10100871 hasPublicationYear "2010" @default.
- W10100871 type Work @default.
- W10100871 sameAs 10100871 @default.
- W10100871 citedByCount "0" @default.
- W10100871 crossrefType "journal-article" @default.
- W10100871 hasAuthorship W10100871A5041804593 @default.
- W10100871 hasAuthorship W10100871A5061510260 @default.
- W10100871 hasConcept C108827166 @default.
- W10100871 hasConcept C110875604 @default.
- W10100871 hasConcept C11392498 @default.
- W10100871 hasConcept C116834253 @default.
- W10100871 hasConcept C136764020 @default.
- W10100871 hasConcept C172191483 @default.
- W10100871 hasConcept C22735295 @default.
- W10100871 hasConcept C2779797433 @default.
- W10100871 hasConcept C2781345505 @default.
- W10100871 hasConcept C31258907 @default.
- W10100871 hasConcept C35026560 @default.
- W10100871 hasConcept C38652104 @default.
- W10100871 hasConcept C41008148 @default.
- W10100871 hasConcept C541664917 @default.
- W10100871 hasConcept C59822182 @default.
- W10100871 hasConcept C83860907 @default.
- W10100871 hasConcept C86803240 @default.
- W10100871 hasConcept C93996380 @default.
- W10100871 hasConceptScore W10100871C108827166 @default.
- W10100871 hasConceptScore W10100871C110875604 @default.
- W10100871 hasConceptScore W10100871C11392498 @default.
- W10100871 hasConceptScore W10100871C116834253 @default.
- W10100871 hasConceptScore W10100871C136764020 @default.
- W10100871 hasConceptScore W10100871C172191483 @default.
- W10100871 hasConceptScore W10100871C22735295 @default.
- W10100871 hasConceptScore W10100871C2779797433 @default.
- W10100871 hasConceptScore W10100871C2781345505 @default.
- W10100871 hasConceptScore W10100871C31258907 @default.
- W10100871 hasConceptScore W10100871C35026560 @default.
- W10100871 hasConceptScore W10100871C38652104 @default.
- W10100871 hasConceptScore W10100871C41008148 @default.
- W10100871 hasConceptScore W10100871C541664917 @default.
- W10100871 hasConceptScore W10100871C59822182 @default.
- W10100871 hasConceptScore W10100871C83860907 @default.
- W10100871 hasConceptScore W10100871C86803240 @default.
- W10100871 hasConceptScore W10100871C93996380 @default.
- W10100871 hasLocation W101008711 @default.
- W10100871 hasOpenAccess W10100871 @default.
- W10100871 hasPrimaryLocation W101008711 @default.
- W10100871 hasRelatedWork W1533000870 @default.
- W10100871 hasRelatedWork W2052496023 @default.
- W10100871 hasRelatedWork W2525706884 @default.
- W10100871 hasRelatedWork W2612247514 @default.
- W10100871 hasRelatedWork W2911670768 @default.
- W10100871 hasRelatedWork W2915028980 @default.
- W10100871 isParatext "false" @default.
- W10100871 isRetracted "false" @default.
- W10100871 magId "10100871" @default.
- W10100871 workType "article" @default.