Early Homograph Threat Detection: A DNS Study of IDNs | WhoisXML API

White Papers

Early Homograph Threat Detection: A DNS Study of IDNs and Native-Language Characters

While businesses gained an advantage by using domains with native-language characters to enter local markets, the utilization of Punycode also gave threat actors more leeway to create look-alike domains.

The WhoisXML API research team analyzed the TLD distribution, IP resolution, and WHOIS registration data of 63,105 unique FQDNs containing native-language characters. We also zoomed in on the FQDN dynamics and took a closer look at some homograph clusters, among other checks.

Our analysis yielded these interesting findings, among others:

  • More than half of the FQDNs used the most used TLDs.
  • The U.S. was the #1 geolocation country of the top 100 FQDN IP addresses.
  • Amazon led the pack of ISPs of the top 100 IP addresses.

Download the white paper now or contact sales to discuss your intelligence needs for threat detection and response or other cybersecurity use cases.

Try our WhoisXML API for free
Get started