Home / Industry

The State of Phishing

Over the last three years, the Anti-Phishing Working Group's semiannual Global Phishing Survey has become a widely cited source of information about the state of phishing and its place in the Internet landscape. Afilias' Director of Domain Security, Greg Aaron, has been co-authoring these reports with Rod Rasmussen of Internet Identity, with the goal to show the community what phishers are doing and how anti-abuse measures are effective. The newly published edition of the report highlights how criminals have utilized the domain name space, but offers good news about how the domain name community has helped diminish the effects of some very dangerous phishing. It's an encouraging success story.

The new Global Phishing Survey reveals that in the second half of 2009, the Avalanche phishing gang perpetrated two-thirds of all phishing attacks on the Internet! This criminal entity utilizes a botnet comprised of consumer-level computers to host its phishing and malware too. By running its own distributed, illegal hosting, the gang tries to make its phishing "bullet-proof" — resistant to take-down because there's no traditional hosting provider to call. But such phishing can be stopped by suspending the domain names. Fortunately we saw a number of domain name registrars and registries shut down Avalanche phishing in an increasingly effective fashion, often neutralizing the phishers' technical advantage.

In the second half of 2009, we saw Avalanche registered 4,141 domain names in various TLDs, and hosted up to 40 separate attacks on each domain. Avalanche prefers to register domains at registrars that react slowly (or not at all) to abuse reports and/or have weak fraud-detection routines. Similarly, Avalanche prefers TLDs where the registry operators do not have effective anti-abuse policies and procedures to help the registrars and provide swift action when needed. Unfortunately, we saw Avalanche victimize certain registrars and TLDs over and over again.

Avalanche and similar threats have prompted many industry members to adopt best practices to fight phishing and other criminal abuses. Afilias adopted its .INFO Anti-Abuse Policy in 2007, defining what constitutes abusive use, and reiterating the registry's right to take action. Registrars also have terms of service in their registration agreements, and those terms prohibit illegal activities and allow the registrars to suspend domain names at their discretion. In practice, Afilias monitors for phishing and other problems in the .INFO space, and communicates abuse reports and documentation to its registrars. The registrars examine the reports and work on mitigation as they feel appropriate. On occasion Afilias will also suspend domains directly, especially to stop large-scale abuse in a timely fashion. This kind of cooperation and information-sharing is adaptable and effective, allows registrars and registries to install good process, and appropriately manage risk. On a daily basis, it saves thousands of Internet users from becoming victims.

The 2009 data shows that Avalanche phish stayed up for less than half the time as other phish — a great result. How did it happen? First, the entire response community concentrated attention on Avalanche, pushing phishing attack alerts to each other. That response community includes the banks and online services targeted by the phishers, security companies and researchers, registries, and registrars. Second, a number of registrars and registries took quick action, looking for Avalanche domains and killing them through the summer and fall of 2009. Education and data sharing clearly helped. In November 2009, members of the security community shut down Avalanche's infrastructure for a week. After re-establishing its operations, Avalanche kept registering domains, but launched fewer attacks. Avalanche attacks decreased from 26,411 in October 2009 to just 59 in April 2010. We'll continue to monitor Avalanche, but it appears that overall, the domain industry may be more prepared for whatever comes next.

The median up-time for all phishing attacks on the Internet has fallen remarkably over the past two years, from 19 hours 30 minutes in early 2008 to 11 hours 44 minutes in the second half of 2009. The falling times point to improved awareness, responsiveness, and detection across the board. Here at Afilias, our policies and procedures have dissuaded phishers like Avalanche from registering .INFO domains, and non-Avalanche phish in .INFO stayed alive for less than half the industry average.

The results above emphasize the effectiveness of best practices and processes. Domain industry players are becoming increasingly sophisticated about e-crime, and can greatly improve the safety of the Internet for everyone.

To see all the details, please read the new APWG report (PDF).

Written by Ram Mohan, Executive Vice President & CTO, Afilias

About Afilias

Afilias

Afilias is a global provider of Internet infrastructure services that connect people to their data. Afilias' reliable, secure, scalable, and globally available technology supports a wide range of applications including Internet domain registry services and Managed DNS. (Learn More)

Related topics: Cybercrime, Cybersquatting, Domain Names, Registry Services, Malware, Security, Top-Level Domains

WEEKLY WRAP — Get CircleID's Weekly Summary Report by Email:

Comments

To post comments, please login or create an account.

Related Blogs

Related News

Topics

Industry Updates – Sponsored Posts

DotConnectAfrica Trust Responds to ICANN GAC Objection Advice on Its .Africa Application

.IN.NET - New Internet Address for India, Launching June 17th

Afilias Joins Internet Infrastructure Coalition

Radix Registry Passes 4 New gTLD Initial Evaluations

DomainsBot to Help Professionals Find .PRO Internet Addresses More Easily

INTA 2013: Gearing Up for Dallas

Hope is Not a Strategy: Neustar Releases 2012 Annual DDoS Attack and Impact Survey

.PW Crosses 50,000 Domain Registrations in 3 Weeks

DotConnectAfrica Participates at the ICANN 46 International Meeting in Beijing, China

The Ratings Are In: Measuring .ORG's Trust and Success in Numbers

How Neustar Technology Can Help Mitigate DDoS Attacks

dot Brand or dot What? Consumers Unaware of New TLDs, Including .Google, .Microsoft and .Nike

Zodiac Prepares for Chinese New gTLDs, Announces "Chinese Advisory Services" for New gTLD Applicants

DotConnectAfrica Clarified Its .africa Bid at the Innovation Africa Digital Summit in Addis Ababa

.PW General Availability Opens With More Than 4000 Orders in 30 Minutes

CentralNic Powers First New Top-Level Domains Announced by ICANN

Invitation to a Seminar on "A New Beginning - Domain Name Market in China"

LogicBoxes Announces Vertical Integration Solutions for New gTLDs

.PW Registry Extends Landrush Till March 22, 2013

DCA Registry Services Participates in ICANN Africa Strategy Meeting, Addis Ababa

Sponsored Topics

Neustar

DNS

Sponsored by
Neustar
Afilias

DNS Security

Sponsored by
Afilias
Minds + Machines

Top-Level Domains

Sponsored by
Minds + Machines
dotMobi

Mobile

Sponsored by
dotMobi