Owned, Pwned or Rented: Whose Domain Is It?

Mina Erfan, Paula Branco, Guy-Vincent Jourdan · 2024

Phishing attacks continue to be a persistent threat, leading researchers to develop various detection approaches that leverage data sources like Certificate Transparency (CT) logs and Domain Name System (DNS) records. These techniques aim to identify newly registered domains associated with phishing campaigns. However, the extent to which these methods can effectively cover the diverse landscape of phishing activities remains unclear. This paper seeks to quantify the proportion of phishing attacks that utilize dedicated, attacker-owned domains - the primary target of techniques based on CT logs and domain registration data. By developing a taxonomy of phishing website ownership types, this study analyzes the percentage of phishing attacks that involve domains directly controlled by the attackers, versus those hosted on compromised or third-party platforms. This analysis provides valuable insights into the diverse phishing domain ownership patterns. The findings can guide the security community in developing more comprehensive solutions to mitigate this persistent threat.

Read the paper · More papers on PaperTik