|
The new Global Phishing Survey released by the Anti-Phishing Working Group (APWG) this month reveals that phishing gangs are concentrating their efforts within specific top level domains (TLDs), but also that anti-phishing policies and mitigation programs by domain name registrars and registries can have a significant and positive effect.
For this new study, covering the first half of 2008, Rod Rasmussen of Internet Identity and Greg Aaron of Afilias surveyed 47,324 unique phishing attacks located on 26,678 unique domain names. The number of TLDs abused by phishers for their attacks expanded 7 percent from 145 in H2/2007 to 155 in H1/2008. The proportion of Internet-protocol (IP) number-based phishing sites decreased 35 percent in that same period, declining from 18 percent in the second half of 2007 to 13 percent in the first half of 2008.
The full report is available for download here (press release).
Sponsored byCSC
Sponsored byVerisign
Sponsored byDNIB.com
Sponsored byWhoisXML API
Sponsored byVerisign
Sponsored byRadix
Sponsored byIPv4.Global
Its interesting that of two TLDs - .biz and .us, which are about the same size and run by the same operator, that .us has a higher score (more phishing) than .biz, while one of the only differences between these two TLDs is the .us does not allow proxy services and .biz does. There seems to be an inverse correlation - no proxy allowed gets more phishing - which may deserve more investigation.
biz and us are certainly far lower down on the list of most abused TLDs than com, cn, info ..
They used to have a much more massive problem earlier, mostly with spam sites - but that seems to have been resolved ages back.
Its like running an experiement. Try to keep as many variables constant as you can, so you can see the effect of the single variable you are changing. .biz and .us have many variables in common, except one major variable: .us does not allow proxy whois registrations, and .us does. Thanks to this report we can compare these two TLDs when it comes to phishing. It was said that proxy whois registrations lead to more phishing. Comparing these two very similar TLDs shows that apparently that is not the case.
.us does not allow proxy whois registrations, and .biz (not .us) does.