PDA

View Full Version : Verisign registers IDN Homograph Detection Patent


bwhhisc
29th April 2020, 05:58 PM
https://domainnamewire.com/?s=idn

The U.S. Patent and Trademark Office has granted patent number 10,599,836 (pdf) to Verisign (NASDAQ: VRSN) for “Identification of visual international domain name collisions.”

The patent describes a way to detect a “homograph attack”. A homograph attack is when someone creates a mixed-script domain name that is visually similar to another domain name. Many top level domain names allow registrants to register domain names that include more than one script in an internationalized domain name. For example:

…a malicious entity could register the IDN “xn- -oogle-wmc .com” via a registration service. When a web browser displays this IDN, the punycode element “-wmc” would direct the web browser to place a Latin small capital letter “G” in front of the characters “oogle”—resulting in the domain name Googl e.com. Users accessing Google .com would then be directed to the IDN registered by the malicious user rather than to the expected home page of google.com.

To detect homograph attacks, the patent suggests turning the domain name into an image and then using optical character recognition to look for similarities.

bwhhisc
29th April 2020, 06:14 PM
Another article about hackers using IDNs for phishing, this one is from 2019 but a good read.

https://www.pbs.org/newshour/nation/hackers-are-flooding-the-internet-with-more-fake-domain-names-heres-how-you-can-protect-yourself