Analysis of Domain Name Translation

Abstract

This diploma thesis deals with the analysis of domain names and their translation to network addresses for detecting suspicious domains. The theoretical part describes the principles of DNS, selected domain-related attacks, and methods for malicious domain detection. The practical part focuses on the design and implementation of a Google Chrome browser extension using blacklists, heuristic rules, WHOIS, DNS, and ASN information. The proposed solution was tested on 44 domains and achieved a classification accuracy of 90.91%.

Description

Delayed publication

Available after

Subject(s)

DNS, phishing, typosquatting, malicious domain, blacklist, WHOIS, cybersecurity

Citation