Measuring the prevalence and security implications of abandoned resources on the internet
Tobias Lauinger · 2018
Resources on the Internet are not guaranteed to be available or maintained in perpetuity. Rather, resources may start to be neglected, and eventually be abandoned, by their previous owners. This can affect other Internet services that rely on these resources. When web developers place a link to an external site, for example, they typically do not expect ownership and nature of that site to change. However, around 1.7% of all registered .com domains are deleted every month, and many of them are re-registered by a new owner. Similarly, many websites include JavaScript libraries that are not maintained any more, or they fail to update included libraries when vulnerabilities in these libraries are patched. Abandoned or neglected resources can result in violation of security assumptions, and enable attacks with severe consequences. Therefore, it is critical to quantify how often these scenarios occur in order to understand the extent of the threat. Furthermore, visibility into the underlying reasons can help devise more effective and efficient countermeasures. This thesis proposes novel measurement techniques tailored to two application areas in order to quantify the prevalence and security implications of abandoned or neglected Internet resources. First, we show that expired Internet domain names are frequently re-registered and "recycled" by a new owner. Internet domain names must be renewed regularly in order to remain active. As a result, many domains expire and can ultimately be re-registered by any interested party on a first-come, first-served basis. Many security mechanisms use domain names to identify zones of trust, assuming perpetual domain ownership. When ownership changes, the new owner can abuse the residual trust that is still being placed in the domain. Ownership changes often occur in a highly competitive environment, and are predominantly part of speculative or ad revenue-based schemes. Second, we show that many websites include outdated or known vulnerable JavaScript libraries. Websites frequently use third-party JavaScript libraries and components such as advertisements or social media widgets. This code is executed with the same privileges as the remainder of the site. When web developers include a vulnerable version of a library, their websites may inherit the vulnerability. Furthermore, libraries are often included indirectly and perhaps unknowingly, such as by advertisement or social media widget components. In both areas, instead of focussing on a single, specific type of attack, we measure at a higher level of abstraction that captures the consequences of abandoned or neglected resources in a more general way. Our results indicate that such measurements can help better understand what drives these issues, and ultimately inform more targeted remediation efforts.