Understanding the effectiveness of typosquatting techniques

Jeffrey Spaulding, Daehun Nyang, Aziz Mohaisen
{"title":"Understanding the effectiveness of typosquatting techniques","authors":"Jeffrey Spaulding, Daehun Nyang, Aziz Mohaisen","doi":"10.1145/3132465.3132467","DOIUrl":null,"url":null,"abstract":"The nefarious practice of Typosquatting involves deliberately registering Internet domain names containing typographical errors that primarily target popular domain names, in an effort to redirect users to unintended destinations or stealing traffic for monetary gain. Typosquatting has existed for well over two decades and continues to be a credible threat to this day. As recently shown in the online magazine Slate.com [19], cybercriminals have attempted to distribute malware through Netflix.om, a typosquatted variant of the popular streaming site Netflix.com that uses the country code top-level domain (ccTLD) for Oman (.om). While much of the prior work has examined various typosquatting techniques and how they change over time, none have considered how effective they are in deceiving users. In this paper, we attempt to fill in this gap by conducting a user study that exposes subjects to several uniform resource locators (URLs) in an attempt to determine the effectiveness of several typosquatting techniques that are prevalent in the wild. We also attempt to determine if the security education and awareness of cybercrimes such as typosquatting will affect the behavior of Internet users. Ultimately, we found that subjects tend to correctly identify typosquatting which adds characters to the domain names, while the most effective techniques to deceive users involves permutations and substitutions of characters. We also found that subjects generally performed better and faster at identifying typosquatted domain names after being thoroughly educated about them, and that certain attributes such as Age and Education affect their behavior when exposed to them.","PeriodicalId":411240,"journal":{"name":"Proceedings of the fifth ACM/IEEE Workshop on Hot Topics in Web Systems and Technologies","volume":"51 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2017-10-14","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"16","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Proceedings of the fifth ACM/IEEE Workshop on Hot Topics in Web Systems and Technologies","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1145/3132465.3132467","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 16

Abstract

The nefarious practice of Typosquatting involves deliberately registering Internet domain names containing typographical errors that primarily target popular domain names, in an effort to redirect users to unintended destinations or stealing traffic for monetary gain. Typosquatting has existed for well over two decades and continues to be a credible threat to this day. As recently shown in the online magazine Slate.com [19], cybercriminals have attempted to distribute malware through Netflix.om, a typosquatted variant of the popular streaming site Netflix.com that uses the country code top-level domain (ccTLD) for Oman (.om). While much of the prior work has examined various typosquatting techniques and how they change over time, none have considered how effective they are in deceiving users. In this paper, we attempt to fill in this gap by conducting a user study that exposes subjects to several uniform resource locators (URLs) in an attempt to determine the effectiveness of several typosquatting techniques that are prevalent in the wild. We also attempt to determine if the security education and awareness of cybercrimes such as typosquatting will affect the behavior of Internet users. Ultimately, we found that subjects tend to correctly identify typosquatting which adds characters to the domain names, while the most effective techniques to deceive users involves permutations and substitutions of characters. We also found that subjects generally performed better and faster at identifying typosquatted domain names after being thoroughly educated about them, and that certain attributes such as Age and Education affect their behavior when exposed to them.
了解排字技术的有效性
Typosquatting的不法行为包括故意注册包含拼写错误的互联网域名,这些域名主要针对流行域名,目的是将用户重定向到意想不到的目的地或窃取流量以获取金钱利益。误注已经存在了二十多年,直到今天仍然是一个可信的威胁。正如在线杂志Slate.com最近所显示的那样[19],网络犯罪分子试图通过Netflix传播恶意软件。om是流行流媒体网站Netflix.com的后缀,使用国家代码顶级域名(ccTLD)表示阿曼(.om)。虽然之前的许多工作都研究了各种打字技术以及它们如何随着时间的推移而变化,但没有人考虑到它们在欺骗用户方面有多有效。在本文中,我们试图通过进行一项用户研究来填补这一空白,该研究将受试者暴露给几个统一资源定位器(url),试图确定在野外流行的几种类型定位技术的有效性。我们还试图确定安全教育和网络犯罪的意识,如输入是否会影响互联网用户的行为。最终,我们发现受试者倾向于正确识别在域名中添加字符的排字,而欺骗用户的最有效技术包括字符的排列和替换。我们还发现,在对域名进行了全面的教育之后,研究对象通常在识别键入的域名方面表现得更好更快,而且年龄和教育程度等特定属性会影响他们在接触这些域名时的行为。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信