Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - “Sometimes There Is A Crystal Ball”
Articles

“Sometimes There Is A Crystal Ball”

Tim HelmingBy Tim HelmingApril 17, 2018Updated:December 30, 20214 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

The ability to predict—and defend against—malicious activity is something of a holy grail in the realm of security. There are many technologies that seek to do it, and some of them have made inroads. When it comes to blacklisting domains involved in activities like phishing, malware, and spam, however, most of the blacklists and intel feeds in existence rely on reports or observation of evil on the domains. Only after someone has been affected does the malicious infrastructure appear on the feeds. What’s more, if an attack is targeted at an individual organization and that organization doesn’t report the attack to blacklist providers, the rest of the world may never have a chance to learn about infrastructure that could be aimed at others.

No one wants to get hurt or for it to happen to others. But how does one go about accurately predicting that a domain will be malicious? Some take the approach of blocking all young domains on the theory that most newly-registered domains are malicious. There is merit to this idea, but it also has some drawbacks: it will yield some false positives, since there are certainly plenty of innocent domains registered every day. Perhaps more concerning from a security standpoint, threat actors know about this approach, and may start “seasoning” domains–registering them and leaving them dormant until they’re not so young. Any threat actor who takes the long-term view can do this.

At the same time, anyone who has examined malicious domains as part of a threat hunting or forensic response exercise can often get a good sense of whether a domain is dangerous just by looking at certain characteristics. Does its name make sense, or is it a keyboard-smash of characters? Does the registrant information in the domain’s Whois record look rational? Does the IP address for the domain appear on blacklists because other domains hosted there have proved bad? A domain has many attributes that help paint a picture of its propensity for good or evil.

If human analysts could magically apply this kind of scrutiny to every new domain that comes into being, they could create high-fidelity blacklists that could block ahead of time. Magic, however, is in short supply. But here’s the good news: technologies such as machine learning are doing some fairly magical things, and the classification of dangerous domains a priori is one of those things.

In the world of machine learning, things like those attributes of domains (name composition, age, etc.) are called features. A machine learning classifier looks at sets of features in order to determine whether a given entity fits into a particular category. Data scientists “train” machine learning classifiers on various combinations and permutations of features and run the models to see how good the machine is at placing unknown entities into the right classification “buckets.” Some features have more predictive value than others; ultimately, developing a good classifier depends on selecting the best sets of features, and having a data set with a large enough sample size to enable a fine-grained analysis of the entities.

Predicting whether a newly-registered domain is likely to be used for phishing, spam, malware, or neutral purposes is the kind of exercise that lends itself well to machine learning, provided that the data scientists have access to a sufficient pool of domains (including a training set that are known to have been involved with malware/spam/phishing) and that they can identify enough unique features in a given domain to give the machine classifiers something to work with. Data science, combined with a healthy proportion of the world’s approximately 330 million existing domains, holds the promise of giving beleaguered security teams a useful crystal ball. Teams dealing with network defense or with incident response and forensics could make meaningful progress in their battle against malicious infrastructure if armed with the kinds of blacklists that don’t require someone to get hurt before identifying the danger spots.

Literal crystal balls are the stuff of fantasy, of course. We don’t have, nor will we ever have, perfect vision into the future. But there are areas of the everyday security battle in which predictive technologies can make an important difference. Threat actors never rest; the good news is that science never rests, either.

[su_box title=”About Tim Helming” style=”noise” box_color=”#336588″][short_info id=’84617′ desc=”true” all=”false”][/su_box]

Tim Helming

Security Advocate

    The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

    Share. Facebook Twitter LinkedIn Email Copy Link

    Related Posts

    Exploited Faster, Patched Slower: Verizon DBIR 2026 Shows Security Teams Losing Ground

    May 20, 20265 Mins Read

    Security’s Blind Spot: The Threats Hiding in “Low-Severity” Alerts

    May 6, 20265 Mins Read

    Why OSINT deserves the same status as other intelligence disciplines

    March 17, 20266 Mins Read
    ISB-Bora-Side-Bar

    No se ha podido establecer conexión. Error 429

     
    ISB-Bora-Side-Bar
    Black ISB Logo

    Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

    X (Twitter) LinkedIn Facebook RSS

    Working With Us

    • About Us
    • Advertise With Us
    • Contact Us

    Write For Us

    • How To Contribute

    The Pages

    • Privacy Policy
    • Cookie Policy
    • AI Policy
    • Terms & Conditions
    • Copyright Notice

    Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

    Type above and press Enter to search. Press Esc to cancel.

    Manage Consent
    To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
    Functional Always active
    The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
    Preferences
    The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
    Statistics
    The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
    Marketing
    The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
    • Manage options
    • Manage services
    • Manage {vendor_count} vendors
    • Read more about these purposes
    View preferences
    • {title}
    • {title}
    • {title}