HomeSecurityOpenDNS: Detecting malicious websites

OpenDNS: Detecting malicious websites

OpenDNSThe security team at OpenDNS is developing a new method to help automatically identify malware using a prototype tool called NLPRank, according to a post on the company's blog.

"Using natural language processing (NLP), the predictive model identifies potentially malicious typos and targeted phishing domains. Malicious groups often use spear-phishing techniques and spoofing legitimate domains as an obfuscation technique to conduct their criminal activities with the aim of distributing malware."

The NLPRank tool is designed to detect these domains that distribute malware that often act as C2 regions for targeted attacks. The system uses heuristics, such as NLP and ASN mappings . Weighting is performed, and matching with WHOIS data, as well as analysis of HTML tags to classify these domains as attack entities.»

The language processing techniques (natural language processing) are common in bioinformatics and data mining. The company reports that "so far it appears that this technique offers a new way of categorizing websites used for Advanced Persistent Threat (APT) attacks and cyber-space espionage, as well as a mechanism to discover links that exist between hacker groups.

We should note that NLP (natural language processing) is a field of computer science that focuses on the interaction between computer language and humans. It has nothing to do with neuro-linguistic programming, a term that often also uses the abbreviation NLP.

You can see more information about the new technique on the official OpenDNS Security Labs.

Source: secnews.gr

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS