Domain Name Abuse Detection via Character Replacement Rules
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current spam and phish detection techniques fail to recognize domain name abuse when look-alike characters are used, allowing fraudulent websites to mimic legitimate ones and steal user information.
Innovation Solution
A method and system that processes domain names by applying rules to replace or modify characters that resemble legitimate domain names, using homographic, punctuation, foreign language, and character insertion rules to identify and block fraudulent domain names.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If current spam and phish detection techniques are used, then detection of obvious fraudulent domain names is achieved, but detection of domain names using look-alike characters fails
Solution Approach 1:
The system performs preliminary processing of domain names by applying multiple replacement rules (homographic, punctuation, foreign language, character insertion) to generate variant forms of the domain name before detection. This preliminary action transforms the detection problem from recognizing subtle visual differences to matching against known legitimate domain names, thereby resolving the contradiction between detection accuracy and adaptability to homographic abuse
2Reliability
If domain names are processed with multiple replacement rules, then detection of spoofed domain names improves, but processing complexity increases
Solution Approach 1:
The processing system is segmented into distinct modular components, each responsible for a specific type of character replacement rule (homographic, punctuation, foreign language, character insertion). Each module independently processes the domain name and generates variants, which are then collectively evaluated. This segmentation maintains high detection reliability through comprehensive rule application while managing system complexity through modular design and clear separation of concerns
Data Source
AI summary
A method and apparatus for identifying domain name abuse in web-based content is described. In one embodiment, the method for identifying domain name abuse in web-based content to secure a computer comprising processing a first domain name and modifying the first domain name using a at least one rule for replacing characters. The modified first domain name indicates an imitation of a second domain name by the first domain name.


