System and method for detecting phishing-domains in a set of Domain Name System (DNS) records
This document describes a system and method for detecting phishing-domains, which are used by cyber-attackers to carry out phishing attacks, in a set of Domain Name System (DNS) records, the system comprising a homoglyph phishing domain detection module, a typo-squatting phishing domain detection mo...
Gespeichert in:
Hauptverfasser: | , , , , |
---|---|
Format: | Patent |
Sprache: | eng |
Schlagworte: | |
Online-Zugang: | Volltext bestellen |
Tags: |
Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
|
Zusammenfassung: | This document describes a system and method for detecting phishing-domains, which are used by cyber-attackers to carry out phishing attacks, in a set of Domain Name System (DNS) records, the system comprising a homoglyph phishing domain detection module, a typo-squatting phishing domain detection module, a general phishing domain detection module and an alert module. These modules are configured to collaboratively detect and identify phishing-domains from the set of DNS records using a combination of homoglyph, typo-squatting and general phishing domain techniques. Subsequently, an alert module may be used to correlate the alerts from the various phishing detection modules to discover phishing campaigns occurring in DNS network data. |
---|