?url_ver=Z39.88-2004&rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Adc&rft.title=Correlating+domain+registrations+and+DNS+first+activity+in+general+and+for+malware&rft.creator=Spring%2C+JM&rft.creator=Metcalf%2C+LB&rft.creator=Stoner%2C+E&rft.description=From+the+date+that+a+domain+name+is+registered+with%0D%0Aa+registrar%2C+there+should+be+a+pattern+in+the+amount+of+time+it%0D%0Atakes+for+that+domain+to+be+actively+resolved+on+the+Internet.+We%0D%0Afirst+attempt+to+describe+that+pattern+in+general+terms+by%0D%0Acorrelating+data+from+registries+for+several+top-level+domains+and%0D%0Aa+large+passive+DNS+data+source.+This+pattern+is+then+used+as+a%0D%0Abaseline+for+a+comparison+with+the+pattern+of+activity+in+domains%0D%0Athat+malicious+software+utilizes.+While+our+quantitative+results%0D%0Aare+not+to+be+considered+representative+of+the+patterns+exhibited%0D%0Aby+all+types+of+malware%2C+the+malicious+domains+are+found+to+have%0D%0Aa+significantly+different+pattern+than+the+standard+domains.&rft.subject=measurement+studies%2C+passive+DNS%2C+SIE%2C+malware+and+the+DNS.&rft.publisher=National+Physical+Laboratory&rft.date=2011-04-05&rft.type=Proceedings+paper&rft.publisher=Securing+and+Trusting+Internet+Names&rft.language=eng&rft.source=+++++In%3A++Securing+and+Trusting+Internet+Names%3A+SATIN+2011.++++National+Physical+Laboratory+(2011)+++++&rft.format=text&rft.identifier=https%3A%2F%2Fdiscovery.ucl.ac.uk%2Fid%2Feprint%2F10037792%2F1%2Fmetcalf-et_2011_domain-reg-and-activity-for-malware.pdf&rft.identifier=https%3A%2F%2Fdiscovery.ucl.ac.uk%2Fid%2Feprint%2F10037792%2F&rft.rights=open