Detecting Subdomain TakeOver Threats and Real-Time Alerting for Rapid Response
Mrityunjoy Biswas, Sondip Poul Singh, Shajib Kumar Shaha · 2023
In today’s cyber landscape, the expansion of online services and applications has introduced a critical concern cyber security threats, such as subdomain takeovers. These vulnerabilities can pose significant security risks to organizations, demanding proactive detection and rapid response in the realm of cyber security. Organizations often use cloud services but neglects to update its DNS records for abandoned subdomains. Consequently, these subdomains continue to point to resources that no longer exist or are not under the organization’s control. An attacker exploits this vulnerability by registering the subdomains on the respective cloud services, often with the intent of misusing them for malicious purposes. The primary objective of this research is to develop a robust methodology for analyzing vulnerability reasons and identifying subdomain takeover threats. We proposed an efficient system that could detect these threats in real time and promptly alert organizational authorities. Our model evaluates CNAME records HTTP responses, triggering immediate alerts through webhook integration with communication platforms such as Slack, Discord, and Telegram, enabling organizational authorities to take immediate action on DNS entry.