Blocking malicious domains: An experimental case study on DNS RPZ mechanism

S Jinu, Kishore V. Krishnan, Pradeep Yadav, M. Reshma Ramanan, A S Revathy · 2024

The Domain Name System (DNS) is a critical component of the internet infrastructure and is frequently targeted by attackers to distribute malware or for conducting phishing attacks. Cybercriminals are using malicious domains for various cyber attacks such as phishing, malware, ransomware, and other forms of cybercrime. The malicious domains are registered using fake identities or stolen identities, which makes it difficult to trace the attackers. The DNS Response Policy Zones (RPZ) mechanism is a security mechanism that allows organizations to block access to known malicious domains by responding to DNS queries with a non-existent IP address. This experimental case study evaluates the effectiveness of the DNS RPZ mechanism in blocking access to known malicious domains and reducing the number of malware infections and phishing attacks on client devices. The study was conducted using a BIND DNS server and a collection of known malware and phishing domains. The results show that the DNS RPZ mechanism was effective in blocking access to known malicious domains and reducing the number of malware infections and phishing attacks on the client devices. However, the study also highlights the need for future research to evaluate the scalability, real-world effectiveness, user behavior, and performance of the DNS RPZ mechanism in comparison with other security mechanisms.

Read the paper · More papers on PaperTik