Criminals are registering millions of malware-spreading domains every month

>

Every month, cyber criminals register about 13 million domains to host and distribute malware (opens in new tab)in phishing campaigns or otherwise malicious activity.

This is according to cybersecurity researchers at Akamai, which claims to have flagged some 79 million brand new, malicious domains in the first half of 2022 alone.

Not only are that some 13 million domains per month, but a fifth (20%) of all successful new domain resolutions appear to be malicious.

Analyzing the data

Outlining his research, Akamai said it looked first and foremost at a dataset of domains that were first queried, over the past 60 days. In this dataset, the company explains, “you will find freshly registered domain names, typos and domains that are only very rarely requested on a global scale.”

Given the size of new domains and the speed at which new ones are generated, it would be impossible for Akamai to manually analyze each domain. Instead, it took multiple approaches, including cross-checking new domains with a list of known domain-generating algorithms that Akamai (along with the cybersecurity community) built over a 30-year predictive list.

In addition, Akamai used “more than 190 NOD-specific detection rules” and attributes most of its detections to these rules. Reportedly, the false positive rate for the 79 million domains analyzed was 0.00042%.

“We also found that of the names we could find, more than 99.9 percent had a ‘reputation’ of 0, meaning they had not yet been tagged as benign or malignant,” Akamai said.

Finally, the company said a multifaceted approach is needed, as one method will not be able to accurately determine malicious domains.

“This shows the need for a multi-faceted approach so that we get the best out of both systems,” said Akamai’s Stijn Tilborghs and Gregorio Ferreira. “The NOD dataset offers a lot of additional value because there is only a very small overlap between the output and other important threat intelligence.”

  • These are the best ways to protect against ransomware (opens in new tab) Today

Through: The register (opens in new tab)

Related Post