Skip to main navigation Skip to search Skip to main content

NDEWS: A new domains early warning system for TLDs

Research output: Chapter in Book/Report/Conference proceedingConference contributionAcademicpeer-review

Abstract

We present nDEWS, a Hadoop-based automatic early warning system of malicious domains for domain name registry operators, such as top-level domain (TLD) registries. By monitoring an entire DNS zone, nDEWS is able to single out newly added suspicious domains by analyzing both domain registration and global DNS lookup patterns of a TLD. nDEWS is capable to detect several types of domain abuse, such as malware, phishing, and allegedly fraudulent web shops. To act on this data, we have established a pilot study with two major.nl registrars, and provide them with daily feeds of their respective suspicious domains. Moreover, nDEWS can also be implemented by other TLD operators/registries.

Original languageEnglish
Title of host publicationProceedings of the NOMS 2016 - 2016 IEEE/IFIP Network Operations and Management Symposium
EditorsSema Oktug Badonnel, Mehmet Ulema, Cicek Cavdar, Lisandro Zambenedetti Granville, Carlos Raniery P. dos Santos
PublisherIEEE
Pages1061-1066
Number of pages6
ISBN (Electronic)9781509002238
DOIs
Publication statusPublished - 30 Jun 2016
Externally publishedYes
Event2016 IEEE/IFIP Network Operations and Management Symposium, NOMS 2016: Managing Everything toward a Secure, Smart, and Hyperconnected World - Suleyman Demirel Cultural Center, Istanbul, Turkey
Duration: 25 Apr 201629 Apr 2016
Conference number: 15
https://noms2016.ieee-noms.org/
http://noms2016.ieee-noms.org/

Publication series

NameProceedings of the NOMS 2016 - 2016 IEEE/IFIP Network Operations and Management Symposium

Conference

Conference2016 IEEE/IFIP Network Operations and Management Symposium, NOMS 2016
Abbreviated titleNOMS 2016
Country/TerritoryTurkey
CityIstanbul
Period25/04/1629/04/16
Internet address

Keywords

  • n/a OA procedure

Fingerprint

Dive into the research topics of 'NDEWS: A new domains early warning system for TLDs'. Together they form a unique fingerprint.

Cite this