<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>NOMS on TIDE - Threat Identification Using Active DNS Measurements</title>
    <link>https://www.tide-project.nl/tags/noms/</link>
    <description>Recent content in NOMS on TIDE - Threat Identification Using Active DNS Measurements</description>
    <generator>Hugo -- gohugo.io</generator>
    <language>en-us</language>
    <lastBuildDate>Wed, 14 Aug 2019 09:55:56 +0200</lastBuildDate><atom:link href="https://www.tide-project.nl/tags/noms/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Unicode Homoglyphs</title>
      <link>https://www.tide-project.nl/blog/unicode_homoglyphs/</link>
      <pubDate>Wed, 14 Aug 2019 09:55:56 +0200</pubDate>
      
      <guid>https://www.tide-project.nl/blog/unicode_homoglyphs/</guid>
      <description>For the last couple of months Ramin Yazdani has been looking into phishing
domains using Unicode characters to appear like the target domain. In this
process he developed a new &amp;lsquo;confusables&amp;rsquo; table of Unicode characters which can
easily be mistaken for their ASCII counterpart. The table is based on the
&amp;lsquo;Unicode Confusables list&amp;rsquo; and the &amp;lsquo;Unicode Similarity List&amp;rsquo;.
The proposed Unicode Confusables table can be found here.
The dataset is supplied as a &amp;lsquo;csv&amp;rsquo; file where the first column represents the</description>
    </item>
    
    <item>
      <title>Threat Identification Using Active DNS Measurements</title>
      <link>https://www.tide-project.nl/publications/aims2018/</link>
      <pubDate>Mon, 11 Jun 2018 00:00:00 +0200</pubDate>
      
      <guid>https://www.tide-project.nl/publications/aims2018/</guid>
      <description>The third publication for the TIDE project. Details more formally the research
questions of this project.
   The DNS is a core service for the Internet. Most uses of the DNS are benign, but some are malicious. Attackers often use a DNS do- main to enable an attack (e.g. DDoS attacks). Detection of these attacks often happens passively, but this leads to a reactive detection of attacks. However, registering and configuring a domain takes time.</description>
    </item>
    
    <item>
      <title>Melting the Snow: Using Active DNS Measurements to Detect Snowshoe Spam Domains</title>
      <link>https://www.tide-project.nl/publications/noms2018/</link>
      <pubDate>Thu, 03 May 2018 00:00:00 +0200</pubDate>
      
      <guid>https://www.tide-project.nl/publications/noms2018/</guid>
      <description>The second publication for the TIDE project. It has received the Best Paper Award at NOMS 2018.
   Snowshoe spam is a type of spam which is notoriously hard to detect. Differently from regular spam, snowshoe spammers distribute the volume among many hosts, in order to make detection harder. To be successful, however spammers need to appear as legitimate as possible, for example, by adopting email best practice like Sender Policy Framework (SPF).</description>
    </item>
    
    <item>
      <title>Best Paper Award at NOMS 2018</title>
      <link>https://www.tide-project.nl/blog/noms2018_post/</link>
      <pubDate>Tue, 01 May 2018 00:00:00 +0200</pubDate>
      
      <guid>https://www.tide-project.nl/blog/noms2018_post/</guid>
      <description>TIDE was present at the Network Operations and Management Symposium (NOMS 2018) conference in Taipei, Taiwan. Olivier was there to present &amp;ldquo;Melting the Snow: Detecting Snowshoe Spam Domains Using Active DNS Measurements&amp;rdquo;.
NOMS 2018 was held in Taipei, Taiwan, from the 23rd till the 27th of April. NOMS has been held in every even-numbered year since 1988. This was the 30th anniversary of NOMS.
Our work was very well received at the conference.</description>
    </item>
    
  </channel>
</rss>
