The Guardians of Name Street: Studying the Defensive Registration Practices of the Fortune 500

Boladji Vinny Adjibi

Network and Distributed System Security (NDSS) Symposium 2025 · Day 3 · Phishing & Fraud 2 · Phishing & Fraud 2

Overview

In the digital age, domain names serve as crucial interfaces between companies and their customers, facilitating access to services and establishing brand identity. However, this essential asset is constantly under threat from adversaries who exploit human error, hardware glitches, and confusing similarities to redirect users to malicious lookalike domains. While the strategies of these adversaries are well-documented, a significant knowledge gap persists regarding how companies, particularly large enterprises, proactively defend their digital presence through defensive domain name registration. This talk, presented by Boladji Vinny Adjibi at the NDSS Symposium, addresses this critical void by offering a comprehensive analysis of defensive registration practices among Fortune 500 companies.

Watch on YouTube · Slides

Key moments

  1. 0:00 Introduction to defensive domain registration problem
  2. 2:00 Methodology: Fortune 500 and domain transformations
  3. 2:29 Discovery of novel 'stock name squatting' transformation
  4. 4:09 Four-condition methodology for identifying defensive registrations
  5. 6:00 Five key factors correlating with defensive registrations
  6. 7:02 Most common transformations registered by companies
  7. 7:44 Misalignment between company practices and research focus

The Guardians of Name Street: Studying the Defensive Registration Practices of the Fortune 500

Speakers: Boladji Vinny Adjibi

Conference: NDSS Symposium

YouTube: https://www.youtube.com/watch?v=o701sNRfvbM

Overview

In the digital age, domain names serve as crucial interfaces between companies and their customers, facilitating access to services and establishing brand identity. However, this essential asset is constantly under threat from adversaries who exploit human error, hardware glitches, and confusing similarities to redirect users to malicious lookalike domains. While the strategies of these adversaries are well-documented, a significant knowledge gap persists regarding how companies, particularly large enterprises, proactively defend their digital presence through defensive domain name registration. This talk, presented by Boladji Vinny Adjibi at the NDSS Symposium, addresses this critical void by offering a comprehensive analysis of defensive registration practices among Fortune 500 companies.

The research delves into the scale and effectiveness of these defensive efforts, investigating which types of domain name transformations companies prioritize and the efficacy of third-party brand protection services they employ. By analyzing a massive dataset of potential domain name variations and assessing real-world registration patterns, the study uncovers significant discrepancies between perceived and actual protection levels. Ultimately, the talk highlights critical vulnerabilities in current defensive strategies and proposes data-driven recommendations for enhancing brand and customer security in the face of persistent online threats.

Background

▶ Watch: Introduction to defensive domain registration problem (0:00)

The pervasive nature of the internet means that users frequently interact with companies through their domain names. Unfortunately, this interaction is ripe for exploitation by malicious actors. Users can inadvertently navigate to fraudulent websites due to simple typing mistakes (typosquatting), hardware errors leading to unintended keystrokes, or being presented with domain names so similar to legitimate ones that they become indistinguishable (confusing similarity). These deceptive domains are then leveraged for various nefarious activities, including phishing, malware distribution, and brand impersonation, all of which erode customer trust and inflict financial and reputational damage on legitimate businesses.

While the literature provides a robust understanding of adversary tactics and the mechanisms by which users fall prey to these schemes, there has been a notable lack of research into the defensive countermeasures employed by companies. Specifically, how do companies proactively register domain names that are similar to their primary assets to prevent malicious appropriation? This study aimed to bridge this gap by focusing on Fortune 500 companies, selected for their dual characteristics of having ample financial resources to invest in defensive strategies and being prominent enough targets to attract sophisticated adversaries. The research explored various categories of domain name transformations, including direct character or word-level alterations, abbreviation squatting (e.g., using "CapOne" for Capital One), brand name squatting (using the full company name in variations), and a newly identified prevalent category: stock name squatting, which involves using a company's ticker symbol as a domain name. These transformations were applied across 383 generic Top-Level Domains (gTLDs), generating a vast landscape of 147 million potential domain names for analysis.

Key Findings

▶ Watch: Discovery of novel 'stock name squatting' transformation (2:29)

The comprehensive analysis yielded several critical insights into the state of defensive domain name registration among Fortune 500 companies. Out of the 147 million generated domain name transformations, the study identified almost 20,000 domains that were defensively registered. Alarmingly, the research found that 53 of the Fortune 500 companies, despite their significant resources and high-profile status, had no defensive registrations whatsoever according to the robust methodology employed. This highlights a substantial gap in protective measures across a significant portion of the corporate elite.

Further correlation analyses, conducted at a statistically significant probability of 95%, revealed five key features associated with the volume of defensive registrations a company undertakes:

  1. Domain Name Popularity: Companies with more popular primary domain names tended to have a higher number of defensive registrations.
  2. Abuse List Appearance: If a company's domain name transformations frequently appeared on abuse lists (e.g., phishing lists), it correlated with more defensive registrations, suggesting a reactive element to their strategies.
  3. Financial Assets: Companies possessing greater financial assets were observed to engage in more defensive registrations, underscoring the resource-intensive nature of these efforts.
  4. Security Analyst Workforce: A larger number of hired security analysts within a company correlated with increased defensive registration activity, indicating internal security posture influences proactive measures.
  5. Domain Name Length: Intriguingly, companies with shorter primary domain names tended to perform more defensive registrations, which could be attributed to shorter names being easier to manipulate for squatting purposes and thus requiring more comprehensive protection.

Regarding the types of transformations companies prioritize, the study found that over 80% of defensive registrations primarily focused on TLD squatting, followed by typo squatting and other transformations. A notable misalignment was observed between company preferences and academic research interests. While companies were heavily investing in defending against brand name squatting and stock name squatting, research in these specific areas was comparatively scarce, suggesting a disconnect between real-world corporate concerns and academic focus.

The investigation into who facilitates these defensive registrations revealed that a concentrated group of a few registrars accounted for up to 97% of all observed defensive registrations. These registrars typically claim to offer "online brand protection services" to their corporate clients. To assess the effectiveness of these providers, the researchers leveraged three years of passive DNS data from a large US Internet Service Provider (ISP). The study measured effectiveness by assessing how well providers protected their current customers (detailed in the paper) and, more critically, how well they would protect prospective customers. For the latter, the 53 companies with no defensive registrations were treated as hypothetical new clients. Machine learning models (specifically, recommended models) were trained to predict provider registration preferences, achieving an impressive 98.12% accuracy by analyzing only 5% of the available domain name space.

The core finding regarding provider effectiveness was a stark one: when comparing the provider-predicted registration priorities with actual domain name value (based on query volume), the alignment was poor. Using Normalized Discounted Cumulative Gain (NDCG), a metric where a score close to one indicates perfect alignment, the best median score achieved by the six analyzed providers was a mere 0.36. This score unequivocally indicates a significant need for improvement in the strategies employed by these brand protection providers. The research further highlighted this by identifying numerous available domain names that were receiving hundreds of thousands to hundreds of millions of queries over a two-to-three-year period, some of which had even been used maliciously in the past, yet remained unregistered by providers.

Technical Deep Dive

▶ Watch: Four-condition methodology for identifying defensive registrations (4:09)

The methodology for this study was meticulously designed to overcome challenges such as the use of external name servers by large corporations, redacted WHOIS records due to privacy policies like GDPR, and the frequent mergers and acquisitions common among Fortune 500 entities.

To establish a robust ground truth for identifying defensively registered domain names, the researchers combined a wide array of data sources:

  • CCDS Zone Files: Used to identify authoritative name servers for each generated domain name. Each name server was rigorously checked to ensure exclusive use by the target company.
  • WHOIS Records: The registrant organization field was conservatively matched to company names, and the domain name in the registrant email address was also utilized as an indicator of ownership.
  • US Securities and Exchange Commission (SEC) Data and Wikipedia: These sources were leveraged to compile comprehensive lists of alternative company names, subsidiaries, and historical merger/acquisition data, crucial for accurately tracking corporate identities over time.

Based on this aggregated data, a four-condition methodology was developed to classify a domain name as defensively registered:

  1. Name Server Subdomain: All configured name servers are subdomains of the base domain name from which the transformation was generated.
  2. Name Server Ownership: If condition 1 is not met, the name servers are still unequivocally owned by the company.
  3. WHOIS Registrant Organization: If conditions 1 and 2 are not met, the registrant organization field in the WHOIS record explicitly points to the company or its subsidiaries.
  4. WHOIS Email Domain: As a last resort, if the previous three conditions fail, the domain name within the email address listed in the WHOIS record points to a domain name owned by the company.

The generation of potential squatting domains involved applying various transformations across 383 gTLDs. These transformations included:

  • Typo Squatting: Character-level changes (e.g., omissions, insertions, substitutions, transpositions) and word-level changes (e.g., adding common prefixes/suffixes).
  • Abbreviation Squatting: Deriving domain names from common abbreviations of company names.
  • Brand Name Squatting: Using variations of the full brand name.
  • Stock Name Squatting: Utilizing the company's ticker symbol as a domain. This was identified as a prevalent form previously under-researched.

To assess the effectiveness of brand protection providers, the study employed a sophisticated analytical framework. Three years of passive DNS data from a major US ISP were utilized to understand real-world query volumes for various domain names. To evaluate proactive protection for prospective customers, historical records and daily zone files were consulted to identify domain names that were available for registration at a point in the past.

The core of the provider effectiveness assessment relied on machine learning models, specifically "recommended models," to learn and predict the registration preferences of each brand protection provider. While the specific features used for training these models were not detailed in the talk, they would typically include characteristics of the domain name (length, type of transformation, TLD), historical registration patterns of the provider, and possibly metadata about the client. These models demonstrated remarkable predictive power, achieving up to 98.12% accuracy by only exploring 5% of the available domain name space.

The final evaluation metric was Normalized Discounted Cumulative Gain (NDCG). NDCG is a measure of ranking quality, assessing how well a predicted list (provider's likely registrations) aligns with a ground truth list (domains ranked by actual query volume/value). A perfect ranking would yield an NDCG of 1, while lower scores indicate poorer alignment. The observed median NDCG score of 0.36 for the best-case provider scenario clearly demonstrated that current brand protection strategies are significantly suboptimal in prioritizing the registration of truly valuable and queried domain names.

Demo / Proof of Concept

▶ Watch: Most common transformations registered by companies (7:02)

This talk presented a comprehensive research study and analysis of existing defensive registration practices, rather than a live demonstration or proof of concept of a new tool or technique. The methodology involved extensive data collection, analysis, and the application of machine learning models to infer and evaluate current strategies.

Defensive Implications

▶ Watch: Misalignment between company practices and research focus (7:44)

The findings of "The Guardians of Name Street" carry significant implications for both companies and the brand protection services they employ. The low Normalized Discounted Cumulative Gain (NDCG) scores (0.36 at best) clearly indicate that current brand protection strategies are failing to adequately prioritize the registration of high-value, high-traffic domain names that are most likely to be exploited by adversaries. Companies should not solely rely on the "black box" services offered by third-party registrars claiming brand protection. Instead, they must adopt a more proactive and data-driven approach.

For Companies:

  • Independent Verification: Companies should conduct independent audits of their defensive registrations, comparing their protected domains against high-volume queries observed in passive DNS data or other internal telemetry.
  • Data-Driven Prioritization: Leverage their own internal data, such as website traffic logs, brand mentions, and customer feedback, alongside external threat intelligence, to identify and prioritize domain name transformations that pose the highest risk.
  • Expand Protection Scope: Be aware of emerging or under-researched squatting types, such as stock name squatting, which the study found to be a significant focus for companies but less so for academic research.
  • Engage with Providers Critically: Demand transparency from brand protection providers regarding their prioritization methodologies and effectiveness metrics. Question why heavily queried, available domains are not being registered.

For Brand Protection Providers:

  • Improve Prioritization Algorithms: There is an urgent need to enhance the intelligence behind domain registration prioritization. Providers should integrate passive DNS data and other real-time telemetry to identify domain names that are receiving significant query volumes but remain unregistered. These are prime targets for adversaries and represent critical gaps in current protection.
  • Proactive Registration: Shift from a reactive approach (e.g., responding to abuse reports) to a truly proactive one, registering these high-risk, high-query domains before adversaries can claim them.
  • Transparency and Metrics: Offer clients clear metrics on the effectiveness of their services, going beyond simply the number of domains registered, to demonstrate the actual protective value.

For the Security Community:

  • Enhanced Reactive Strategies: While proactive measures are ideal, the community must continue to research and develop more effective reactive strategies for domain takedowns and mitigation when proactive registrations are missed. This includes streamlining legal and technical processes for reclaiming maliciously registered domains.
  • Broaden Research Focus: Academic research should expand to cover areas of defensive registration, like brand name squatting and stock name squatting, where there is a clear corporate need but a current lack of scholarly attention.
  • Rethink Domain Relevance (as raised in Q&A): While the talk focuses on proactive registration, the question of how users actually interact with domain names (via search engines, apps, QR codes, rather than direct typing) is a valid long-term consideration. Future research could explore how this shift impacts the prioritization of defensive registration efforts. However, as long as direct typing or search engine results can lead to malicious lookalikes, defensive registration remains a critical component of a robust security posture.

Key Takeaways

  • A significant portion of Fortune 500 companies (53 in this study) lack any defensive domain name registrations, leaving them vulnerable to various forms of squatting.
  • Factors such as domain popularity, appearance on abuse lists, financial assets, security analyst headcount, and domain name length correlate with the level of defensive registration activity.
  • While companies heavily focus on TLD squatting, brand name squatting, and stock name squatting, there's a notable gap in academic research for the latter two, indicating a disconnect between industry needs and scholarly attention.
  • Brand protection services, responsible for the vast majority of defensive registrations, demonstrate limited effectiveness, with a median Normalized Discounted Cumulative Gain (NDCG) of only 0.36 in prioritizing valuable domains.
  • Many heavily queried and potentially malicious domain names remain unregistered and available, posing a significant ongoing risk to corporate brands and customer security.
  • Companies and brand protection providers must improve their strategies by leveraging passive DNS data and other telemetry to proactively identify and register high-value, high-query domain names before adversaries can exploit them.

About the Speaker(s)

Boladji Vinny Adjibi is the researcher who presented this comprehensive study on the defensive registration practices of Fortune 500 companies at the NDSS Symposium. His work focuses on understanding and improving cybersecurity defenses related to domain name infrastructure and brand protection.

Reviews

Dr. Zero (Offensive Security Researcher) — SOLID

Competent empirical research with a clear contribution — Fortune 500 defensive registration coverage is measurably poor and the brand protection industry is underperforming against a quantifiable metric. The 147M domain corpus, passive DNS grounding, and NDCG framing give this more rigor than the typical domain-abuse think-piece, but the novelty ceiling is low and the findings land where you'd expect them to.

Heather Calloway (CISO) — SOLID

Credible empirical work that surfaces a real and measurable gap in how Fortune 500 companies and their brand protection vendors manage defensive domain registration. The findings are quantifiable and the methodology is sound, but the talk stops at diagnosis — it doesn't translate into governance decisions or organizational accountability, and the actionability ceiling is low for anyone above the DNS operations tier.

→ Top-rated talks at Network and Distributed System Security (NDSS) Symposium 2025

All talks from Network and Distributed System Security (NDSS) Symposium 2025