|
||
ICANN has released a new method for identifying domains potentially connected to known DNS abuse, finding that 56.4% of maliciously registered generic top-level domains (gTLDs) in its study sample had at least one associated domain. The research could inform proposed requirements for registrars to investigate related registrations when abuse is detected.
Public data reveals registration patterns. The study, Associated Domain Analysis Using Public Data, published October 6 as part of ICANN’s Office of the Chief Technology Officer (OCTO) series, uses publicly available technical registration and DNS infrastructure information rather than private customer records. Researchers examined registrar identifiers, authoritative nameservers, registration timestamps and IP addresses to identify domains potentially registered or operated together.
The methodology combines three detection techniques: identifying domains registered within seconds of one another, examining registrations sharing infrastructure within a broader time window, and detecting domains that begin resolving through common infrastructure around the same time. Additional lexical analysis helps distinguish potentially coordinated registrations from unrelated domains sharing technical services.
Early detection remains limited. Although the study found associations for more than half of reported malicious registrations, its results show that only 4.6% of the sample could have been detected earlier under existing data-processing constraints. ICANN says improved data availability and processing speed could increase that proportion.
The research examined domains reported through security intelligence feeds during September 2025, using a broader observation period to identify related registrations. It also identified previously unreported suspicious domains through association analysis, although these findings do not establish that every associated domain was malicious.
The findings intersect with an active ICANN policy debate. The Generic Names Supporting Organization’s DNS Abuse Mitigation Policy Development Process is considering associated domain checks that would require registrars to investigate other registrations connected to domains implicated in abuse. The proposal has prompted concerns about evidentiary standards and the risk of incorrectly linking legitimate domains to malicious activity.
As CircleID previously reported, participants in the consultation have urged safeguards distinguishing evidence sufficient to trigger an investigation from evidence justifying action against another domain. Shared infrastructure or registration characteristics do not necessarily establish common malicious control.
ICANN describes the new methodology as preliminary and plans further validation, faster processing and distribution of results to relevant stakeholders. The research provides a technical basis for identifying potentially related registrations, but its effectiveness in operational abuse mitigation—and the standards for acting on those associations—remain unresolved.
Sponsored byCSC
Sponsored byDNIB.com
Sponsored byWhoisXML API
Sponsored byRadix
Sponsored byVerisign
Sponsored byIPv4.Global
Sponsored byVerisign