Warda-DNSDocs v0.6.4

Look-alike names

A name can be made to be mistaken for another: a homograph imitates it with letters of other alphabets (аpple.com with a Cyrillic а, asked in the DNS as xn--pple-43d.com), a typosquatting with a typing mistake (paypa1.com, gooogle.com). Protection → Protections, card Look-alike names (administrators; free, beta, on by default) finds them from the names alone, on the box (internal/lookalike).

  • The names to protect: about 160 names of banks and payment, messages and social networks, big services and shops, and public services of the countries of Warda (lookalike.Protected), and the 500 names the household asked most over 30 days (task lookalike.visited, 10 seconds after the start, then every day). An international name (xn--) is never a name to protect.
  • A homograph is an international name of which the first label of its domain mixes alphabets that are never mixed (UTS #39, highly restrictive: one alphabet, or Latin with those of Japanese, Chinese or Korean; café, münchen, пример.рф are not), or reads as a name to protect once each look-alike character is taken for its letter (NFKC, then the confusable characters of Unicode, confusables.txt, 1315 characters that look like a letter or a digit of ASCII, and a letter with a mark read as the letter: àpple). It is blocked for every device, the domain and every name under it (answer as for a blocked name; reason lookalike, origin lookalike:<name imitated>, shown "Look-alike name (imitates apple.com)", or "mixed alphabets" when it imitates no name known). A label of that kind under another domain (xn--pple-43d.example.net) blocks that name only. A name of ASCII under an international ending (apple.рф) is not a homograph.
  • A typing mistake is a name of ASCII of 5 letters or more that reads as a name to protect once 1, i and | are taken for l, 0 for o, 5 for s, 3 for e, rn for m and vv for w (paypa1, arnazon), or that is one letter added, missing, changed or two swapped away from one of 6 letters or more (gooogle, netfilx), under the same ending or one the typosquatters buy (.com, .net, .xyz, .shop…), and neither the same name under another ending (google.fr) nor a name of the service itself (tiktokv.com, lookalike.Siblings). It is told (a real name can be that close; the alerts can be turned off), and blocked when the domain is young (see below).
  • A known name in front of another domain (paypal.com.login.example: a name to protect as labels under a domain that is not it, nor a content network such as edgekey.net or cloudfront.net, which name the sites they serve that way) is told, and blocked when young.
  • A known name with a word added the way the traps do (login, secure, verify, account, support, colis, facture…: paypal-secure.com, amazonlogin.net; a hyphen alone is not enough, the brands name their own services so: google-analytics.com, youtube-nocookie.com): real names do it too (applesupport.com), so it is only acted on when the domain is young: blocked, and told. Its age is never waited for: asked in the background, it serves the next queries.
  • The second opinion: for these three kinds only, Warda asks the online service of Warda the date the domain was registered (POST /v1/domains/age, signed by the key of the box, see cloud; only the domain is sent, never the device nor anything else), the first query of a typing mistake or of a known name in front of another domain waiting 1.5 seconds at most (the queries asked meanwhile do not wait), then keeping the answer 7 days (an hour when not known); 20 questions an hour at most by box, so that a page that makes up hundreds of names cannot use the questions of the household. A domain of less than 30 days is young. Without an answer (the service unreachable, a registry without RDAP, the budget spent, the questions turned off), nothing is blocked: the name is told as before. Ask the online service the age of a suspicious domain turns the questions off, for the beacons too (see below).
  • Each name found is an alert (lookalike blocked, typosquat told, whatever its kind; detail name|imitated|kind[|young]; one a day by device and domain, and again when a name told is blocked once its age is known, with the device and never its person, see Alerts), and a line in the log for a name blocked. It is not an imitation puts the domain in the list of the names never taken for one (at most 200; a readable name is kept in its DNS form); a personal allow rule wins too.

GET /api/v1/lookalike gives enabled, typos, ask, protected (how many names), allowed and the names blocked and told of the last 30 days (each with name, readable, domain, the one to allow, imitates, why: homograph, typosquat, brandsub or combosquat, and young); PUT /api/v1/lookalike takes enabled, typos, ask and/or allowed (the whole list; audit lookalike.on/off, lookalike.typos.on/off, lookalike.ask.on/off, lookalike.allowed).