Detecting Brand Impersonation with Computer Vision and DNSRazzle

Presented at Kernelcon 2022, April 1, 2022, 4:20 p.m. (20 minutes)

Brand impersonation and BEC are complicated problems with no easy solution. There are numerous companies that claim to have the end all be all solution, but none had all of the features we at Baxter wanted. Last November this problem was dropped in my lap. I developed DNSRazzle to help us find brand impersonation, typo-squatting, and homoglyph domain names, in real time against an ever evolving adversary. This talk will show how to use DNSRazzle and computer vision to detect adversaries.


Presenters:

  • Skip Cruse
    Skip Cruse is the global lead for Red Teaming and Adversary Simulation at Baxter Healthcare. He discovered a knack for computers at an early age but has always enjoyed learning how things work -- whether it is a computer, an engine, or a simple machine. This curiosity naturally drew him to a love of learning how systems work through infiltration. As a hobbyist hacker, he has utilized these specialized skills in the community by joining groups such as the Pan American Information Network, and as a founding member of the resurgence of the w00w00 cybersecurity think tank. He has since found a professional niche in the offensive security field for the past 4 years.

Similar Presentations: