论文标题

用被动DNS和SPF的垃圾邮件域的早期检测

Early Detection of Spam Domains with Passive DNS and SPF

论文作者

Fernandez, Simon, Korczyński, Maciej, Duda, Andrzej

论文摘要

垃圾邮件域是未经请求的邮件的来源,也是欺诈和恶意活动的主要工具之一,例如网络钓鱼活动或恶意软件分发。垃圾邮件域检测是一场比赛:一旦发送垃圾邮件邮件,将垃圾邮件降低或黑名单是相对使用的,因为垃圾邮件发送者必须为他们的下一个广告系列注册一个新的域。为了防止恶意演员发送邮件,我们需要尽快检测到它们,理想情况下,甚至在启动活动之前。在本文中,使用来自Farsight Security的近实时被动DNS数据,我们监视新注册域的DNS流量及其TXT记录的内容,尤其是发件人策略框架的配置,这是针对域名的反欺骗协议,以及针对破坏性业务电子邮件的第一线国防范围。由于垃圾邮件发送者和良性域具有不同的SPF规则和不同的流量配置文件,因此我们使用从无源DNS流量收集的功能构建了一种新方法来检测垃圾邮件域。使用SPF配置和域的TXT记录的流量,我们准确地检测到误差较低的垃圾邮件域的大量垃圾邮件域证明了其在现实世界中的潜力。我们的分类方案可以在发送任何邮件之前检测到垃圾邮件域,仅使用单个DNS查询,然后在后面,它可以通过监视到域名的更多流量来完善其分类。

Spam domains are sources of unsolicited mails and one of the primary vehicles for fraud and malicious activities such as phishing campaigns or malware distribution. Spam domain detection is a race: as soon as the spam mails are sent, taking down the domain or blacklisting it is of relative use, as spammers have to register a new domain for their next campaign. To prevent malicious actors from sending mails, we need to detect them as fast as possible and, ideally, even before the campaign is launched. In this paper, using near-real-time passive DNS data from Farsight Security, we monitor the DNS traffic of newly registered domains and the contents of their TXT records, in particular, the configuration of the Sender Policy Framework, an anti-spoofing protocol for domain names and the first line of defense against devastating Business Email Compromise scams. Because spammers and benign domains have different SPF rules and different traffic profiles, we build a new method to detect spam domains using features collected from passive DNS traffic. Using the SPF configuration and the traffic to the TXT records of a domain, we accurately detect a significant proportion of spam domains with a low false positives rate demonstrating its potential in real-world deployments. Our classification scheme can detect spam domains before they send any mail, using only a single DNS query and later on, it can refine its classification by monitoring more traffic to the domain name.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源