Please use this identifier to cite or link to this item: http://hdl.handle.net/20.500.11960/4808
Title: An overview of threats exploring the confusion between top-level domains and file type extensions
Authors: Sales, Anderson
Torres, Nuno
Pinto, Pedro
Keywords: Top-level domains
File extensions
Security threats
Cyber security
Cyber attack
Issue Date: 2024
Publisher: ACM
Citation: Anderson, S., Torres, N., & Pinto, P. (2024). An overview of threats exploring the confusion between top-level domains and file type extensions. In CODASPY 2024: Proceedings of the 14th ACM Conference on Data and Application Security and Privacy, June 19-21, 2024, Portugal (pp. 167-169). ACM. https://doi.org/10.1145/3626232.3658641
Abstract: Cyberattacks exploit deceptions involving the Domain Name Service (DNS) to direct users to fake websites, such as typosquatting attacks, which exploit natural typographical errors, and homograph attacks, where different Unicode characters resemble the legitimate ones. The deception attacks may also exploit the confusion between DNS domain names, specifically Top-Level Domains (TLDs), and file extensions. Recently, two new TLDs were added, “zip” and “mov”, sharing names with certain file types. This overlapping can be explored by malicious actors in a range of threat scenarios to compromise user security. This paper provides an overview of threats originating from the confusion between specific TLDs and file extensions, such as the recent “zip” and “mov”. The threats are grouped into 6 threat scenarios that are described and discussed. This research can be part of a more comprehensive strategy that includes addressing the risks associated with these threats and designing future strategies to address the threats associated with exploiting this ambiguity.
URI: http://hdl.handle.net/20.500.11960/4808
ISBN: 979-840070421-5
Appears in Collections:ESTG - Publicações indexadas à WoS/Scopus

Files in This Item:
File Description SizeFormat 
3626232.3658641.pdf918.12 kBAdobe PDFView/Open


Items in DSpace are protected by copyright, with all rights reserved, unless otherwise indicated.