NDSS 2025 – Studying the Defensive Registration Practices of the Fortune 500
嗯,用户让我帮忙总结一篇文章的内容,控制在100字以内,而且不需要特定的开头。首先,我需要仔细阅读文章内容,抓住主要信息。 文章是关于Fortune 500公司防御性注册域名的研究。他们使用了多种模型来分析这些公司的防御策略。研究发现这些公司注册了很多类似域名,尤其是TLD抢注。这些公司主要依赖在线品牌保护服务提供商,但这些服务的效果有限。研究还提到很多高流量域名价格低廉,建议OBPs主动注册这些域名以防止滥用。 接下来,我需要将这些信息浓缩到100字以内。要确保涵盖研究对象、方法、发现和建议。同时,语言要简洁明了,避免复杂术语。 可能的结构是:研究对象+方法+主要发现+建议。这样既全面又简洁。 最后,检查字数是否符合要求,并确保没有使用任何不必要的词汇。 </think> 研究分析了 Fortune 500 公司的防御性域名注册实践,发现它们通过在线品牌保护服务提供商注册大量类似域名(如 TLD 抢注),但策略效果有限。研究建议 OBP 提供商利用被动 DNS 数据主动注册高流量低价域名以防止滥用。 2026-1-20 20:0:0 Author: securityboulevard.com(查看原文) 阅读量:0 收藏

Session 9C: Phishing & Fraud 2

Authors, Creators & Presenters: Boladji Vinny Adjibi (Georgia Tech), Athanasios Avgetidis (Georgia Tech), Manos Antonakakis (Georgia Tech), Michael Bailey (Georgia Tech), Fabian Monrose (Georgia Tech)
PAPER
The Guardians of Name Street: Studying the Defensive Registration Practices of the Fortune 500
Using orthographic, phonetic, and semantic models, we study the prevalence of defensive registrations related to a wide spectrum of transformations of the base domain names of Fortune 500 companies. As part of a large-scale evaluation, we explore several questions aimed at (a) understanding whether there are explainable factors (e.g., the size of the company’s security team or its domain name’s popularity rank) that correlate with a company’s level of engagement regarding defensive registrations; (b) identifying the main actors in the defensive registration ecosystem that Fortune 500 companies rely upon; (c) uncovering the strategies used by these actors, and d) assessing the efficacy of those strategies from the perspective of queries emanating from a large Internet Service Provider (ISP). Overall, we identified 19,523 domain names defensively registered by 447 Fortune 500 companies. These companies engage in defensive registrations sparingly, with almost 200 companies having fewer than ten defensive registrations. By analyzing the registrations, we found many similarities between the types of domain names the companies registered. For instance, they all registered many TLD-squatting domain names. As it turns out, those similarities are due to the companies’ reliance on online brand protection (OBP) service providers to protect their brands. Our analysis of the efficacy of the strategies of those OBPs showed that they register domain names that receive most of the potential squatting traffic. Using regression models, we learned from those strategies to provide recommendations for future defensive registrants. Our measurement also revealed many domain names that received high proportions of traffic over long periods of time and could be registered for only 15 USD. To prevent the abusive use of such domain names, we recommend that OBP providers proactively leverage passive DNS data to identify and preemptively register highly queried available domain names.
ABOUT NDSS
The Network and Distributed System Security Symposium (NDSS) fosters information exchange among researchers and practitioners of network and distributed system security. The target audience includes those interested in practical aspects of network and distributed system security, with a focus on actual system design and implementation. A major goal is to encourage and enable the Internet community to apply, deploy, and advance the state of available security technologies.

Our thanks to the Network and Distributed System Security (NDSS) Symposium for publishing their Creators, Authors and Presenter’s superb NDSS Symposium 2025 Conference content on the Organizations’ YouTube Channel.

Permalink

*** This is a Security Bloggers Network syndicated blog from Infosecurity.US authored by Marc Handelman. Read the original post at: https://www.youtube-nocookie.com/embed/o701sNRfvbM?si=eUmnbtILfkR5VJaQ


文章来源: https://securityboulevard.com/2026/01/ndss-2025-studying-the-defensive-registration-practices-of-the-fortune-500/
如有侵权请联系:admin#unsafe.sh