Enhancing Domain Name Security: Proposal for Fraudulent Domain Detection #163
Replies: 2 comments 1 reply
-
One solution to this issue is the addition of a PhishTank database. The creators provide a downloadable database in the following format:
To import this new database into the IYP, we need to create a new node/relationship. P.S. While we can download the database without an API key, the providers recommend having one. Without an API key, they may limit our access. However, they have temporarily stopped the creation of new accounts, so we may need to contact them to request access. More information on this link: https://phishtank.org/developer_info.php @InternetHealthReport/iij members, what’s your view about this approach? |
Beta Was this translation helpful? Give feedback.
-
As per the new workflow this should've been a discussion instead :P But apart from that looking at the data I think we can only link the data to the announcing network. I don't see how we can link to organizations in our graph, since the So from a use-case perspective I guess you could find which network hosts the most phishing websites according to this dataset. |
Beta Was this translation helpful? Give feedback.
-
Is your feature request related to a problem? Please describe.
There are multiple ways to write a domain name due to the use of different languages. For example, the domain name
iij.ad.jp
can be mistakenly written asiij.әd.jp
, where the English lettera
is replaced with the Cyrillic letterә
. Although these letters look similar, this substitution can lead users to click on a link that directs them to a phishing website.Describe the solution you'd like
I propose adding a comprehensive list of fraudulent domains that do not correspond to verified organizations. By "verified," I mean organizations whose true domain names are known. This could involve of adding a new dataset.
Describe alternatives you've considered
One alternative is to develop a validator (such as a browser plugin or website or a new page in IHR website) that uses the IYP (Internet Yellow Pages) to verify whether a domain name is valid. The IYP contains the true domain names of various entities, including organizations and companies.
Beta Was this translation helpful? Give feedback.
All reactions