Please use this identifier to cite or link to this item: http://hdl.handle.net/20.500.11960/4808
Full metadata record
DC FieldValueLanguage
dc.contributor.authorSales, Anderson-
dc.contributor.authorTorres, Nuno-
dc.contributor.authorPinto, Pedro-
dc.date.accessioned2026-03-30T08:52:13Z-
dc.date.available2026-03-30T08:52:13Z-
dc.date.issued2024-
dc.identifier.citationAnderson, S., Torres, N., & Pinto, P. (2024). An overview of threats exploring the confusion between top-level domains and file type extensions. In CODASPY 2024: Proceedings of the 14th ACM Conference on Data and Application Security and Privacy, June 19-21, 2024, Portugal (pp. 167-169). ACM. https://doi.org/10.1145/3626232.3658641pt_PT
dc.identifier.isbn979-840070421-5-
dc.identifier.urihttp://hdl.handle.net/20.500.11960/4808-
dc.description.abstractCyberattacks exploit deceptions involving the Domain Name Service (DNS) to direct users to fake websites, such as typosquatting attacks, which exploit natural typographical errors, and homograph attacks, where different Unicode characters resemble the legitimate ones. The deception attacks may also exploit the confusion between DNS domain names, specifically Top-Level Domains (TLDs), and file extensions. Recently, two new TLDs were added, “zip” and “mov”, sharing names with certain file types. This overlapping can be explored by malicious actors in a range of threat scenarios to compromise user security. This paper provides an overview of threats originating from the confusion between specific TLDs and file extensions, such as the recent “zip” and “mov”. The threats are grouped into 6 threat scenarios that are described and discussed. This research can be part of a more comprehensive strategy that includes addressing the risks associated with these threats and designing future strategies to address the threats associated with exploiting this ambiguity.pt_PT
dc.language.isoporpt_PT
dc.publisherACMpt_PT
dc.rightsopenAccesspt_PT
dc.subjectTop-level domainspt_PT
dc.subjectFile extensionspt_PT
dc.subjectSecurity threatspt_PT
dc.subjectCyber securitypt_PT
dc.subjectCyber attackpt_PT
dc.titleAn overview of threats exploring the confusion between top-level domains and file type extensionspt_PT
dc.typeconferenceObjectpt_PT
dc.peerreviewedyespt_PT
degois.publication.firstPage167pt_PT
degois.publication.lastPage169pt_PT
degois.publication.titleCODASPY 2024: Proceedings of the 14th ACM Conference on Data and Application Security and Privacypt_PT
degois.publication.locationPorto, Portugalpt_PT
dc.identifier.doi10.1145/3626232.3658641-
Appears in Collections:ESTG - Publicações indexadas à WoS/Scopus

Files in This Item:
File Description SizeFormat 
3626232.3658641.pdf918.12 kBAdobe PDFView/Open


Items in DSpace are protected by copyright, with all rights reserved, unless otherwise indicated.