Hundreds of thousands of malicious domains are created everyday. These malicious domains are hosted on a wide variety of network infrastructures. Traditionally, attackers utilize bullet proof hosting services (e.g. MaxiDed, Cyber Bunker) to take advantage of relatively lenient policies on what content they can host. However, these IP ranges are increasingly being blocked or the services are taken down by law enforcement. Hence, attackers are moving towards utilizing IPs from regular hosting providers while staying under the radar of these hosting providers. There are several practical advantages of accurately knowing the type of IP used to host malicious domains. If the IP is a dedicated IP (i.e. it is leased to a single entity), one may blacklist the IP to block domains hosted on those IPs as welll as use as a way to identify other malicious domains hosted the same IP. If the IP is a shared hosting IP, hosting providers may take measures to clean up such domains and maintain a high reputation for their users.
翻译:这些恶意域每天创建数十万个恶意域名。 这些恶意域名由各种网络基础设施托管。 传统上, 攻击者利用弹证托管服务( 如 MaxiDed 、 Cyber Bunker ) 来利用相对宽松的政策, 了解他们可以托管的内容。 但是, 这些 IP 范围日益受阻, 或被执法部门取消 。 因此, 攻击者正在逐渐利用普通主机提供商的IP, 而同时又处于这些主机提供商的雷达之下 。 准确了解用于托管恶意域名的IP 类型有若干实际好处 。 如果 IP 是专用的 IP ( 租赁给一个单一的实体 ), 人们可能会将 IP 黑名单, 封堵这些 IP 所在域名, 并作为一种方法, 来识别同一 IP 所托管的其他恶意域名。 如果 IP 是共同主机, 托管商可以采取措施清理这类域名并保持用户的高声望 。