Measurement study on abnormal changes in authoritative resource records of government and educational domains

Gespeichert in:
Bibliographische Detailangaben
Titel: Measurement study on abnormal changes in authoritative resource records of government and educational domains
Autoren: SUN Junzhe, LU Chaoyi, LIU Baojun, DUAN Haixin, SUN Donghong
Quelle: Tongxin xuebao, Vol 45, Pp 16-26 (2024)
Verlagsinformationen: Editorial Department of Journal on Communications, 2024.
Publikationsjahr: 2024
Bestand: LCC:Telecommunication
Schlagwörter: domain name system, resource records, authoritative service, hijacking attack, Telecommunication, TK5101-6720
Beschreibung: Authoritative-side domain hijacking is characterized by abnormal changes in resource records. To enable timely warnings for authoritative-side domain hijacking incidents, a monitoring system for authoritative-side resource records was established, targeting significant domains in key sectors such as government and education, as well as high-traffic popular domains. The system actively captured and continuously monitored 7.5 million important domains globally. An algorithm was developed to filter abnormal changes in resource records, identifying abnormal changes in 896 significant domains within a one-month analysis period. Manual verification results indicate that the causes included misconfigurations by domain administrators, phishing attacks, and the display of illegal content.
Publikationsart: article
Dateibeschreibung: electronic resource
Sprache: Chinese
ISSN: 1000-436X
Relation: https://doaj.org/toc/1000-436X
DOI: 10.11959/j.issn.1000-436x.2024252
Zugangs-URL: https://doaj.org/article/1e97bfef1c27400c9f8e6ac6b8105728
Dokumentencode: edsdoj.1e97bfef1c27400c9f8e6ac6b8105728
Datenbank: Directory of Open Access Journals
Beschreibung
Abstract:Authoritative-side domain hijacking is characterized by abnormal changes in resource records. To enable timely warnings for authoritative-side domain hijacking incidents, a monitoring system for authoritative-side resource records was established, targeting significant domains in key sectors such as government and education, as well as high-traffic popular domains. The system actively captured and continuously monitored 7.5 million important domains globally. An algorithm was developed to filter abnormal changes in resource records, identifying abnormal changes in 896 significant domains within a one-month analysis period. Manual verification results indicate that the causes included misconfigurations by domain administrators, phishing attacks, and the display of illegal content.
ISSN:1000436X
DOI:10.11959/j.issn.1000-436x.2024252