The research on a rapid verification method for malicious domain names

L. Wang, Qiuming Shang · 2023

The escalation in the scale of online black industries, including pornography, gambling, and fraud, has simultaneously led to increased challenges in monitoring and governance. These industries are intricately linked with network gray production domain names, which facilitate access, intermediate redirection, and promotion services for black production domain names. The access to these domains is highly secretive and cannot be replicated through standard web browsing. Due to the complexities inherent in gathering evidence related to network gray production domain names, a considerable portion of these domains evade effective oversight and regulation owing to inadequate evidentiary chains. This paper proposes a rapid verification method for black and gray production domain names based on domain name pools. The method utilizes technologies such as graph computing, image similarity, and clustering analysis to construct a comprehensive domain name scanning and dynamic analysis model for all network domain names, as well as a dynamic analysis model for the domain name pool. This study introduces a rapid verification method for black-gray production domain names that utilizes a domain name pool as its foundation. The approach incorporates cutting-edge technologies, including graph computing, image similarity analysis, and clustering, to construct a comprehensive model for scanning and dynamically analyzing domain names across the entire network. Additionally, a dedicated dynamic analysis model is created specifically for the domain name pool. It facilitates the swift scanning and forensic analysis of website content. Through the dynamic tracking and classification of indicators related to black-gray production domain names, a real-time compilation of network black-gray production application domain names is generated. The continuous dynamic tracking and in-depth analysis of black and gray production domain name clues in all domain pools enable the acquisition of their behavioral characteristics, dynamic distribution, and patterns of technological advancement. This process facilitates the discovery of additional indicators of malicious domain names, thereby further enhancing governance efficiency and achieving the timely identification and disposal of undesirable domain names.

Read the paper · More papers on PaperTik