Passive and Active Measurement by Anna Sperotto & Alberto Dainotti & Burkhard Stiller

Passive and Active Measurement by Anna Sperotto & Alberto Dainotti & Burkhard Stiller

Author:Anna Sperotto & Alberto Dainotti & Burkhard Stiller
Language: eng
Format: epub
ISBN: 9783030440817
Publisher: Springer International Publishing


Fig. 4.Top 10 ASes (countries) hosting suspicious domains.

Similar But Yet Different Website Templates: We analyzed the home pages of some of these webshops and found out that they are different, but seem to be using a few content-management systems (CMS). The webshops do not support HTTPS, and have a single image in the page footer that contains icons of most credit card companies with no link or a broken link. Such designs also suggest use of automated tools to create such websites. Wang et al. [38] describe many doorway pages, which are non-shopping sites that are specifically designed to improve SEO results and redirect users to the real websites. In our work we do not see such pages since we do not rely on search engine results—we see the actual automatically generated pages listing the counterfeit goods, always with large discounts.

Most Domains were Drop-Catch: 15242 shops are hosted on domains that expired and were re-registered by the counterfeiters (80.4%). The majority of these domains are immediately registered when they became available (Fig. 5), a practice known as “drop-catch” [7]. By registering freshly expired domains to host counterfeit webshops, counterfeiters can benefit from their previously built reputation [14]. This timely precision in registering domains—and the fact that they seem indifferent to the name of the domain itself, as many were previously used by small businesses such as bakeries, beauty parlors—supports the idea of automation in the registration process.

Fig. 5.Suspicious domains: days in between domain expiration and re-registration.



Download



Copyright Disclaimer:
This site does not store any files on its server. We only index and link to content provided by other sites. Please contact the content providers to delete copyright contents if any and email us, we'll remove relevant links or contents immediately.