System and method for detecting phishing-domains in a set of Domain Name System (DNS) records
Abstract:
This document describes a system and method for detecting phishing-domains, which are used by cyber-attackers to carry out phishing attacks, in a set of Domain Name System (DNS) records, the system comprising a homoglyph phishing domain detection module, a typo-squatting phishing domain detection module, a general phishing domain detection module and an alert module. These modules are configured to collaboratively detect and identify phishing-domains from the set of DNS records using a combination of homoglyph, typo-squatting and general phishing domain techniques. Subsequently, an alert module may be used to correlate the alerts from the various phishing detection modules to discover phishing campaigns occurring in DNS network data.
Information query
Patent Agency Ranking
0/0