ICANN report proposes method to identify domains linked to DNS abuse

ICANN has published a report describing a transparent method for identifying domain names that may be technically associated with domains involved in DNS Abuse, using publicly available data.

ICANN report proposes method to identify domains linked to DNS abuse

The Internet Corporation for Assigned Names and Numbers (ICANN) has published a new report outlining a method for identifying domain names that may be associated with domains involved in DNS Abuse.

DNS, or the Domain Name System, helps users reach websites and other online services by connecting domain names with the technical addresses used by computers. ICANN uses the term DNS Abuse to refer to botnets, malware, phishing, pharming, and spam when it is used to support these forms of abuse.

The report, Associated Domain Analysis Using Public Data, examines whether publicly available technical data can be used to identify connections between domain names. This could help identify groups of domains that may be linked to the same malicious activity.

The method does not use personal information such as registrant contact details, payment information, or account-holder identifiers. Instead, it looks at publicly available domain registration and DNS infrastructure data. ICANN said the approach is designed to be transparent and reproducible, meaning that others can understand how the analysis was conducted and potentially repeat it using the same type of data.

The study found that 56.4% of the reported maliciously registered generic top-level domains (gTLDs) in its sample had at least one associated domain. A gTLD is a domain ending such as .com or .org.

The research builds on observations that large-scale DNS Abuse campaigns can involve the rapid registration of many domain names. By using several overlapping techniques, the report establishes a baseline method for detecting domain registrations that may be associated with known abusive domains.

ICANN said the methodology could eventually support reporting and help identify domains that may be at higher risk of being used for abuse. The organisation plans further research to validate the results, reduce delays in processing data, and make the findings available to relevant stakeholders.

The work is part of ICANN community discussions on the GNSO-initiated DNS Abuse Mitigation Policy Development Process, which is examining possible approaches to addressing DNS Abuse.

Go to Top