{ "cells": [ { "cell_type": "markdown", "metadata": {}, "source": [ "# URL domain regisrtrar variation analysis\n", "\n", "Author: Pekka Helenius, 2021\n", "\n", "- Analyzes given URLs and stores results into a new JSON data file\n", "- Outputs associated domain registrars for each input URL as a plot\n", " - \"Phishing campaigns register domains of websites from the same registrar (than the legitimate URL)\"" ] }, { "cell_type": "code", "execution_count": 3, "metadata": {}, "outputs": [ { "name": "stdout", "output_type": "stream", "text": [ "URL data: https://hoxhunt.com/\n", "URL data: https://hs.fi\n", "URL data: https://ts.fi\n", "URL data: https://facebook.com\n", "Generate statistics: https://hoxhunt.com/\n" ] }, { "data": { "image/png": "\n", "text/plain": [ "
" ] }, "metadata": { "needs_background": "light" }, "output_type": "display_data" }, { "name": "stdout", "output_type": "stream", "text": [ "Generate statistics: https://hs.fi\n" ] }, { "data": { "image/png": "\n", "text/plain": [ "
" ] }, "metadata": { "needs_background": "light" }, "output_type": "display_data" }, { "name": "stdout", "output_type": "stream", "text": [ "Generate statistics: https://ts.fi\n" ] }, { "data": { "image/png": "\n", "text/plain": [ "
" ] }, "metadata": { "needs_background": "light" }, "output_type": "display_data" }, { "name": "stdout", "output_type": "stream", "text": [ "Generate statistics: https://facebook.com\n" ] }, { "data": { "image/png": "\n", "text/plain": [ "
" ] }, "metadata": { "needs_background": "light" }, "output_type": "display_data" } ], "source": [ "#!/bin/env python\n", "\n", "\"\"\"\n", "URL data extractor\n", "\n", "Pekka Helenius \n", "\n", "Requirements:\n", "\n", "Python 3\n", "Python 3 BeautifulSoup4 (python-beautifulsoup4)\n", "Python 3 whois (python-whois; PyPI)\n", "Python 3 JSON Schema (python-jsonschema)\n", "Python 3 Numpy (python-numpy)\n", "Python 3 matplotlib (python-matplotlib)\n", "\n", "TODO: URL domain part length comparison analysis\n", "TODO: URL non-TLD part length comparison analysis\n", " - in phishing webpages, URL tends to be much longer than legitimate webpages\n", " however, domains themselves tend to be much shorter (without TLD)\n", " - phishing URLs often contain more number of dots and subdomains than legitimate URLs\n", " - legitimate: robots.txt redirects bots to a legitimate domain rather than to the original phishing domain\n", "\n", "TODO: Website visual similarity analysis\n", "TODO: consistency of RDN usage in HTML data\n", "\"\"\"\n", "\n", "######################################\n", "\n", "%matplotlib inline\n", "import matplotlib.pyplot as plt\n", "\n", "from bs4 import BeautifulSoup as bs\n", "from collections import Counter\n", "from datetime import date, datetime\n", "import json\n", "import os\n", "import re\n", "import requests\n", "from time import sleep\n", "import urllib\n", "from whois import whois\n", "\n", "# Target URLs\n", "urls = [\n", " \"https://hoxhunt.com/\",\n", " \"https://hs.fi\",\n", " \"https://ts.fi\",\n", " \"https://facebook.com\"\n", "]\n", "\n", "# Some web servers may block our request unless we set a widely used, well-known user agent string\n", "request_headers = {\n", " 'User-Agent': 'Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.190 Safari/537.36'\n", "}\n", "\n", "# Date format for domain timestamps\n", "dateformat = \"%Y/%m/%d\"\n", "\n", "# All webpages may not like fetching data too fast\n", "# Sleep time in seconds\n", "sleep_interval_between_requests = 0.5\n", "\n", "# Write JSON results to a file?\n", "use_file = True\n", "# Full file path + name\n", "filename = os.getcwd() + \"/\" + \"url_info.json\"\n", "\n", "# Generate plot from existing JSON data?\n", "plot_only = False\n", "\n", "# Save generated plot images?\n", "save_plot_images = True\n", "\n", "# DPI of plot images\n", "plot_images_dpi = 150\n", "\n", "# Common link attribute references in various HTML elements\n", "link_refs = {\n", " 'a': 'href',\n", " 'img': 'src',\n", " 'script': 'src'\n", "}\n", "\n", "############################################################################\n", "############################################################################\n", "\n", "class json_url_data(object):\n", "\n", "# def __init__(self):\n", "\n", "######################################\n", " \"\"\"\n", " Set a new HTTP session and get response.\n", "\n", " Returns a requests.models.Response object.\n", " \"\"\"\n", " def set_session(self, url, method='get', redirects=True):\n", " \n", " # HTTP response status codes 1XX, 2XX and 3XX are OK\n", " # Treat other codes as errors\n", " sc = re.compile(r\"^[123]{1}[0-9]{2}\")\n", " \n", " sleep(sleep_interval_between_requests)\n", " \n", " try:\n", " session = requests.Session()\n", " response = session.request(method, url, headers=request_headers, allow_redirects=redirects)\n", " \n", " if not sc.match(str(response.status_code)):\n", " raise Exception(\"Error: got invalid response status from the web server\")\n", " return response\n", " \n", " except:\n", " raise Exception(\"Error: HTTP session could not be established. URL: '\" + url + \"' (method: \" + method + \")\") from None\n", "\n", "######################################\n", " \"\"\"\n", " Fetch HTML data.\n", "\n", " Returns a bs4.BeautifulSoup object.\n", " \"\"\"\n", " def get_html_data(self, url):\n", " \n", " try:\n", " data = bs(self.set_session(url).content, 'html.parser')\n", " return data\n", " except:\n", " raise Exception(\"Error: HTML data could not be retrieved\")\n", "\n", "######################################\n", " \"\"\"\n", " Get URL redirects and related HTTP status codes.\n", "\n", " Returns a list object.\n", " \"\"\"\n", " def get_url_redirects(self, url):\n", " \n", " response = self.set_session(url)\n", " list_data = []\n", " \n", " if response.history:\n", " \n", " for r in response.history:\n", " list_data.append({'redirect_url': r.url, 'status': r.status_code})\n", " \n", " return list_data\n", "\n", "######################################\n", " \"\"\"\n", " Extract title HTML element contents from given HTML data.\n", "\n", " Returns a string object.\n", " \"\"\"\n", " def get_webpage_title(self, url):\n", " \n", " html_data = self.get_html_data(url)\n", " \n", " title = html_data.title.string\n", " return title\n", "\n", "######################################\n", " \"\"\"\n", " Get WHOIS domain data.\n", "\n", " Returns a dict object.\n", " \"\"\"\n", " def get_whois_data(self, url):\n", " dict_data = whois(url)\n", " return dict_data\n", "\n", "######################################\n", " \"\"\"\n", " Get domain name based on WHOIS domain data.\n", " \"\"\"\n", " def get_domain_name(self, url):\n", " domain_name = self.get_whois_data(url).domain_name\n", " \n", " if type(domain_name) is list:\n", " return domain_name[0].lower()\n", " else:\n", " return domain_name.lower()\n", "\n", "######################################\n", " \"\"\"\n", " Get initial and final URLs\n", " \n", " Compare whether the final (destination) URL\n", " matches with the initial URL in a request.\n", " \n", " Returns a dict object.\n", " \"\"\"\n", " def get_startfinal_urls(self, url):\n", " \n", " response = self.set_session(url)\n", " end_url = response.url\n", " \n", " start_match = False\n", " final_match = False\n", " \n", " # dr = re.compile(r\"^([a-z]+://)?([^/]+)\")\n", " # dr_group_lastindex = dr.match(url).lastindex\n", " # domain_name = dr.match(url).group(dr_group_lastindex)\n", " \n", " domain_name = self.get_domain_name(url)\n", " \n", " if re.search(domain_name, end_url):\n", " final_match = True\n", " \n", " dict_data = {\n", " 'startfinal_urls': {\n", " 'start_url': {\n", " 'url': url\n", " },\n", " 'final_url': {\n", " 'url': end_url, 'domain_match': final_match\n", " }\n", " }\n", " }\n", " \n", " return dict_data\n", "\n", "######################################\n", " \"\"\"\n", " Get domain registrar\n", " \n", " Returns a dict object.\n", " \"\"\"\n", " def get_domain_registrar(self, url):\n", " dict_data = {'domain_registrar': self.get_whois_data(url).registrar }\n", " return dict_data\n", "\n", "######################################\n", " \"\"\"\n", " Do comparison between the domain name, extracted\n", " from WHOIS domain data and contents of a title HTML\n", " element, extracted from HTML data based on a given URL.\n", " \n", " Returns a dict object.\n", " \"\"\"\n", " def get_domain_title_match(self, url):\n", " \n", " domain_name = self.get_domain_name(url)\n", " title = self.get_webpage_title(url)\n", " \n", " # If is string:\n", " if type(domain_name) is str:\n", " if re.search(domain_name, title, re.IGNORECASE):\n", " match = True\n", " else:\n", " match = False\n", " \n", " # If is list:\n", " elif type(domain_name) is list:\n", " for d in domain_name:\n", " if re.search(d, title, re.IGNORECASE):\n", " match = True\n", " break\n", " else:\n", " match = False\n", " else:\n", " match = False\n", " \n", " dict_data = {\n", " 'webpage_title': title,\n", " 'domain_in_webpage_title': match\n", " }\n", " \n", " return dict_data\n", "\n", "######################################\n", " \"\"\"\n", " Get a single timestamp from given data\n", " \n", " Two scenarios are considered: dates argument is either\n", " a list or a string. If it is a list, then we need\n", " to decide which date value to extract.\n", " \n", " Returns a date object.\n", " \"\"\"\n", " def get_single_date(self, dates, newest=False):\n", " \n", " dates_epoch = []\n", " \n", " if type(dates) is list:\n", " for d in dates:\n", " dates_epoch.append(d.timestamp())\n", " else:\n", " dates_epoch.append(dates.timestamp())\n", " \n", " return datetime.fromtimestamp(sorted(dates_epoch, reverse=newest)[0])\n", "\n", "######################################\n", " \"\"\"\n", " Get domain time information based on WHOIS domain data.\n", " \n", " Returns a dict object.\n", " \"\"\"\n", " def get_domain_timeinfo(self, url):\n", " \n", " whois_data = self.get_whois_data(url)\n", " domain_creation_date = self.get_single_date(whois_data.creation_date, newest = False)\n", " domain_updated_date = self.get_single_date(whois_data.updated_date, newest = False)\n", " domain_expiration_date = self.get_single_date(whois_data.expiration_date, newest = False)\n", " \n", " dict_data = {\n", " 'domain_timestamps':\n", " {\n", " 'created': domain_creation_date.strftime(dateformat),\n", " 'updated': domain_updated_date.strftime(dateformat),\n", " 'expires': domain_expiration_date.strftime(dateformat)\n", " }\n", " }\n", " \n", " return dict_data\n", "\n", "######################################\n", " \"\"\"\n", " Get domain time information based on WHOIS domain data,\n", " relative to the current date (UTC time).\n", " \n", " Returns a dict object.\n", " \"\"\"\n", " def get_domain_timeinfo_relative(self, url):\n", " \n", " date_now = datetime.utcnow()\n", " \n", " whois_data = self.get_whois_data(url)\n", " domain_creation_date = self.get_single_date(whois_data.creation_date, newest = False)\n", " domain_updated_date = self.get_single_date(whois_data.updated_date, newest = False)\n", " domain_expiration_date = self.get_single_date(whois_data.expiration_date, newest = False)\n", " \n", " dict_data = {\n", " 'domain_timestamps_relative':\n", " {\n", " 'current_date': (date_now.strftime(dateformat)),\n", " 'created_days_ago': (date_now - domain_creation_date).days,\n", " 'updated_days_ago': (date_now - domain_updated_date).days,\n", " 'expires_days_left': (domain_expiration_date - date_now).days\n", " }\n", " }\n", " \n", " return dict_data\n", "\n", "######################################\n", " \"\"\"\n", " Determine whether URL matches syntaxes such as\n", " '../foo/bar/'\n", " '/foo/../../bar/,\n", " 'https://foo.bar/foo/../'\n", " \n", " etc.\n", " \n", " Returns a boolean object.\n", " \"\"\"\n", " def is_multidot_url(self, url):\n", " \n", " multidot = re.compile(r\".*[.]{2}/.*\")\n", " \n", " if multidot.match(url):\n", " return True\n", " return False\n", "\n", "######################################\n", " \"\"\"\n", " Get HTML element data from HTML data contents.\n", " \n", " Two fetching methods are supported:\n", " - A) use only HTML element/tag name and extract raw contents of\n", " these tags\n", " - B) use both HTML element/tag name and more fine-grained\n", " inner attribute name to determine which HTML elements are extracted\n", " \n", " Special case - URL link references:\n", " - attributes 'href' or 'src' are considered as link referrals and \n", " they are handled in a special way\n", " - A) link referrals to directly to domain are placed in 'self_refs' list\n", " (patterns: '/', '#', '../' and '/')\n", " - B) link referrals to external domains are placed in 'ext_refs' list\n", " (patterns such as 'https://foo.bar.dot/fancysite' etc.)\n", " \n", " - Both A) and B) link categories have 'normal' and 'multidot' subcategories\n", " - normal links do not contain pattern '../'\n", " - multidot links contain '../' pattern\n", " \n", " Returns a dict object.\n", " \"\"\"\n", " \n", " def get_tag_data(self, url, tag, attribute=None):\n", " \n", " html_data = self.get_html_data(url)\n", " domain_name = self.get_domain_name(url)\n", " data = []\n", " \n", " if attribute != None:\n", " \n", " for d in html_data.find_all(tag):\n", " \n", " # Ignore the HTML tag if it does not contain our attribute\n", " if d.get(attribute) != None:\n", " data.append(d.get(attribute))\n", " \n", " if attribute == 'href' or attribute == 'src':\n", " \n", " self_refs = { 'normal': [], 'multidot': []}\n", " ext_refs = { 'normal': [], 'multidot': []}\n", " \n", " # Syntax: '#', '/', '../'\n", " rs = re.compile(r\"^[/#]|^[.]{2}/.*\")\n", " \n", " # Syntax: ':/'\n", " rd = re.compile(r\"^[a-z]+:[a-z]+/\")\n", " \n", " # Syntax examples:\n", " # 'http://foo.bar/', 'https://foo.bar/, 'foo.bar/', 'https://virus.foo.bar/'\n", " rl = re.compile(r\"^([a-z]+://)?([^/]*\" + domain_name + \"/)\")\n", " \n", " for s in data:\n", " \n", " # Ignore mailto links\n", " if re.match(\"^mailto:\", s): continue\n", " \n", " if rs.match(s) or rl.match(s) or rd.match(s):\n", " if self.is_multidot_url(s):\n", " self_refs['multidot'].append(s)\n", " else:\n", " self_refs['normal'].append(s)\n", " else:\n", " \n", " if self.is_multidot_url(s):\n", " try:\n", " ext_refs['multidot'].append({'url': s, 'registrar': self.get_whois_data(s).registrar })\n", " except:\n", " # Fallback if WHOIS query fails\n", " ext_refs['normal'].append({'url': s, 'registrar': None })\n", " pass\n", " else:\n", " try:\n", " ext_refs['normal'].append({'url': s, 'registrar': self.get_whois_data(s).registrar })\n", " except:\n", " ext_refs['normal'].append({'url': s, 'registrar': None })\n", " pass\n", " \n", " data = None\n", " \n", " dict_data = {\n", " tag: {\n", " attribute + '_ext': (ext_refs),\n", " attribute + '_self': (self_refs)\n", " }\n", " }\n", " \n", " else:\n", " dict_data = {\n", " tag: {\n", " attribute: (data)\n", " }\n", " }\n", " \n", " else:\n", " for d in html_data.find_all(tag):\n", " data.append(d.prettify())\n", " \n", " dict_data = {\n", " tag: (data)\n", " }\n", " \n", " return dict_data\n", "\n", "######################################\n", " \"\"\"\n", " How many external URL links have same registrar than\n", " the webpage itself?\n", " \"\"\"\n", " def get_registrar_count(self, registrar, urls):\n", " \n", " i = 0\n", " \n", " for u in urls:\n", " for k,v in u.items():\n", " if k == 'registrar' and v == registrar:\n", " i += 1\n", " \n", " o = len(urls) - i\n", " \n", " dict_data = {\n", " 'same_registrar_count': i,\n", " 'other_registrar_count': o\n", " }\n", " \n", " return dict_data\n", "\n", "######################################\n", "\n", " \"\"\"\n", " Get values existing in a dict object,\n", " based on a known key string.\n", " \n", " Returns a list object.\n", " \n", " TODO: Major re-work for the fetch function\n", "\n", " TODO: Support for more sophisticated JSON key string filtering\n", " (possibility to use multiple keys for filtering)\n", " \"\"\"\n", " class json_fetcher(object):\n", "\n", " def __init__(self, dict_data, json_key):\n", " self.json_dict = json.loads(json.dumps(dict_data))\n", " self.json_key = json_key\n", "\n", " ##########\n", " # Ref: https://www.codespeedy.com/how-to-loop-through-json-with-subkeys-in-python/\n", " def fetch(self, jdata):\n", "\n", " if isinstance(jdata, dict):\n", "\n", " for k,v in jdata.items():\n", " if k == self.json_key:\n", " yield v\n", " elif isinstance(v, dict):\n", " for val in self.fetch(v):\n", " yield val\n", " elif isinstance(v, list):\n", " for l in v:\n", " if isinstance(l, dict):\n", " for ka,va in l.items():\n", " if ka == self.json_key:\n", " yield va\n", "\n", " elif isinstance(jdata, list):\n", " for l in jdata:\n", " if isinstance(l, dict):\n", " for k,v in l.items():\n", " if k == self.json_key:\n", " yield v\n", " elif isinstance(l, list):\n", " for lb in v:\n", " for ka,va in lb.items():\n", " if ka == self.json_key:\n", " yield va\n", "\n", " ##########\n", " def get_data(self, flatten=True):\n", "\n", " data_extract = []\n", " flat_data = []\n", "\n", " for i in self.fetch(self.json_dict):\n", " data_extract.append(i)\n", "\n", " # Flatten possible nested lists\n", " # (i.e. JSON data contains multiple keys in\n", " # different nested sections)\n", " def get_data_extract(ld):\n", " for l in ld:\n", " if isinstance(l, list):\n", " for la in get_data_extract(l):\n", " yield la\n", " else:\n", " yield l\n", "\n", " if flatten == True:\n", " for u in get_data_extract(data_extract):\n", " flat_data.append(u)\n", " \n", " return flat_data\n", " else:\n", " return data_extract\n", "\n", "######################################\n", " \"\"\"\n", " Compile URL related data.\n", " \"\"\"\n", " def get_url_data(self, url):\n", " \n", " # Dict object for simple, non-nested data\n", " data_simple = {}\n", "\n", " # Pre-defined dict object for specific data sets\n", " webpage_data = {}\n", " \n", " startfinal_url = self.get_startfinal_urls(url)\n", " redirect_url = self.get_url_redirects(url)\n", " domain_registrar = self.get_domain_registrar(url)\n", " domaintitle_match = self.get_domain_title_match(url)\n", " \n", " domain_time_relative = self.get_domain_timeinfo_relative(url)\n", " domain_time = self.get_domain_timeinfo(url)\n", " \n", " html_element_iframe = self.get_tag_data(url, 'iframe')\n", " html_element_a_href = self.get_tag_data(url, 'a', link_refs['a'])\n", " html_element_img_src = self.get_tag_data(url, 'img', link_refs['img'])\n", " html_element_script_src = self.get_tag_data(url, 'script', link_refs['script'])\n", "\n", " iframes_count = {\n", " 'iframes_count':\n", " len(self.json_fetcher(html_element_iframe, 'iframe').get_data())\n", " }\n", " \n", " multidot_urls_count = {\n", " 'multidot_url_count':\n", " len(self.json_fetcher(html_element_a_href, 'multidot').get_data()) + len(self.json_fetcher(html_element_img_src, 'multidot').get_data()) + len(self.json_fetcher(html_element_script_src, 'multidot').get_data())\n", " }\n", " \n", " ###################\n", " def get_total_registrars():\n", "\n", " same_registrar_counts = 0\n", " other_registrar_counts = 0\n", " for k,v in link_refs.items():\n", " \n", " html_element = self.get_tag_data(url, k, v)\n", " \n", " same_registrar_counts += self.get_registrar_count(\n", " domain_registrar['domain_registrar'],\n", " html_element[k][v + '_ext']['normal']\n", " )['same_registrar_count']\n", " \n", " other_registrar_counts += self.get_registrar_count(\n", " domain_registrar['domain_registrar'],\n", " html_element[k][v + '_ext']['normal']\n", " )['other_registrar_count']\n", " \n", " registrar_counts = {\n", " 'same_registrar_count': same_registrar_counts,\n", " 'other_registrar_count': other_registrar_counts\n", " }\n", " return registrar_counts\n", " \n", " # Avoid unnecessary nesting of the following data\n", " data_simple.update(domain_registrar)\n", " data_simple.update(domaintitle_match)\n", " data_simple.update(iframes_count)\n", " data_simple.update(multidot_urls_count)\n", " data_simple.update(get_total_registrars())\n", " \n", " url_data = dict({\n", " url: [\n", " data_simple,\n", " startfinal_url,\n", " {'redirects': redirect_url},\n", " \n", " domain_time_relative,\n", " domain_time,\n", " \n", " {'webpage_data': [\n", " html_element_iframe,\n", " html_element_a_href,\n", " html_element_img_src,\n", " html_element_script_src\n", " ]\n", " }\n", " ]\n", " })\n", " \n", " return url_data\n", "\n", "\n", "\n", "class write_operations(object):\n", "\n", " def __init__(self):\n", " self.filename = filename\n", "\n", "######################################\n", " \"\"\"\n", " Set JSON file name, append number suffix\n", " # if file exists already.\n", " \n", " Returns file name path.\n", " \"\"\"\n", " def set_filename(self):\n", " \n", " c = 0\n", " while True:\n", " if os.path.exists(self.filename):\n", " if c == 0:\n", " self.filename = self.filename + \".\" + str(c)\n", " else:\n", " self.filename = re.sub(\"[0-9]+$\", str(c), self.filename)\n", " else:\n", " break\n", " c += 1\n", " return self.filename\n", "\n", "######################################\n", " \"\"\"\n", " Append to a JSON file.\n", " \"\"\"\n", " def write_to_file(self, data):\n", " \n", " try:\n", " json_file = open(self.filename, \"a\")\n", " json_file.write(data)\n", " json_file.close()\n", " return 0\n", " except:\n", " return 1\n", "\n", "######################################\n", " \"\"\"\n", " Fetch all pre-defined URLs.\n", " \"\"\"\n", " def fetch_and_store_url_data(self, urls, use_file):\n", "\n", " data_parts = {}\n", " fetch_json_data = json_url_data()\n", "\n", " for u in urls:\n", " print(\"URL data: %s\" % u)\n", " try:\n", " data_parts.update(fetch_json_data.get_url_data(u))\n", " except:\n", " print(\"Failed: %s\" % u)\n", " pass\n", "\n", " json_data = json.dumps(data_parts)\n", "\n", " if use_file == True:\n", " self.write_to_file(json_data)\n", "\n", " return json_data\n", "\n", "######################################\n", "\"\"\"\n", "Visualize & summarize data.\n", "\"\"\"\n", "\n", "class data_visualization(object):\n", "\n", " def __init__(self, url, json_data):\n", " self.url = url\n", " self.json_data = json_data\n", "\n", " self.data = json.loads(json.dumps(self.json_data)).get(self.url)\n", " self.json_url_obj = json_url_data()\n", " self.domain_registrar = self.json_url_obj.get_domain_registrar(self.url)['domain_registrar']\n", " self.webpage_data = self.json_url_obj.json_fetcher(self.data, 'webpage_data').get_data()\n", "\n", " def get_urls_count_summary(self):\n", "\n", " unique_refs = []\n", "\n", " for k,v in link_refs.items():\n", " if v in unique_refs: continue\n", " unique_refs.append(v)\n", "\n", " def link_count(refs, suffix):\n", "\n", " urls_cnt = 0\n", "\n", " for u in self.webpage_data:\n", " for l in refs:\n", " urls = self.json_url_obj.json_fetcher(u, l + suffix).get_data()\n", " for n in urls:\n", " urls_cnt += len(n['normal'])\n", " urls_cnt += len(n['multidot'])\n", " return urls_cnt\n", "\n", " data = {\n", " 'local_urls': link_count(unique_refs, '_self'),\n", " 'external_urls': link_count(unique_refs, '_ext')\n", " }\n", " \n", " return data\n", "\n", " def get_registrars(self):\n", "\n", " registrars = []\n", " #registrars.append(self.domain_registrar)\n", "\n", " for w in self.webpage_data:\n", " webpage_registrars = self.json_url_obj.json_fetcher(w, 'registrar').get_data()\n", " for wa in webpage_registrars:\n", " if wa != None:\n", " registrars.append(wa)\n", " return registrars\n", "\n", " def get_registrar_count_summary(self):\n", " \n", " domain_counter = dict(Counter(self.get_registrars()))\n", " data = {'fetched_domains': domain_counter, 'url_domain_registrar': self.domain_registrar }\n", " return data\n", "\n", "######################################\n", "\"\"\"\n", "Execute the main program code.\n", "\n", "TODO: this code must figure out the correct JSON file\n", "if multiple generated files are present.\n", "\"\"\"\n", "if __name__ == '__main__':\n", "\n", " if plot_only == False:\n", " write_obj = write_operations()\n", " write_obj.set_filename()\n", " data = write_obj.fetch_and_store_url_data(urls, use_file)\n", "\n", " url_str_pattern = re.compile(r\"(^[a-z]+://)?([^/]*)\")\n", "\n", " if os.path.exists(filename):\n", " with open(filename, \"r\") as json_file:\n", " json_data = json.load(json_file)\n", " else:\n", " json_data = data\n", "\n", " # Get URLs from an available JSON data\n", " for key_url in json_data.keys():\n", " \n", " print(\"Generate statistics: %s\" % key_url)\n", "\n", " fig = plt.figure()\n", " fig_params = {\n", " 'xtick.labelsize': 8,\n", " 'figure.figsize': [9,8]\n", " # 'figure.constrained_layout.use': True\n", " }\n", " plt.rcParams.update(fig_params)\n", " \n", " domain_string = url_str_pattern.split(key_url)[2].replace('.','')\n", " summary = data_visualization(key_url, json_data)\n", " \n", " summary_registrars = summary.get_registrar_count_summary()['fetched_domains']\n", "\n", " x_r = list(summary_registrars.keys())\n", " y_r = list(summary_registrars.values())\n", " \n", " # Show bar values\n", " for index,data in enumerate(y_r):\n", " plt.text(x=index, y=data+0.5, s=data, fontdict=dict(fontsize=8))\n", " \n", " title_r = \"Domains associated with HTML URL data (\" + key_url + \")\"\n", " xlabel_r = \"Fetched domains\"\n", " ylabel_r = \"Domain count\"\n", "\n", " plt.bar(x_r, y_r, color=\"green\", edgecolor=\"black\")\n", " plt.title(title_r)\n", " plt.xlabel(xlabel_r)\n", " plt.ylabel(ylabel_r)\n", " plt.xticks(rotation=45, horizontalalignment=\"right\")\n", "\n", " if save_plot_images == True:\n", " plt.savefig(os.getcwd() + \"/\" + \"domain_figure_\" + domain_string + \".png\", dpi=plot_images_dpi)\n", " plt.show()\n", "\n", " #fig_u = plt.figure()\n", " \n", " #summary_urls = summary.get_urls_count_summary()\n", " \n", " #x_u = list(summary_urls.keys())\n", " #y_u = list(summary_urls.values())\n", " #title_u = \"Local and external URL references (\" + key_url + \")\"\n", " #xlabel_u = \"Fetched URLs\"\n", " #ylabel_u = \"URL count\"\n", " \n", " #plt.bar(x_u, y_u, color=\"blue\", edgecolor='black')\n", " #plt.title(title_u)\n", " #plt.xlabel(xlabel_u)\n", " #plt.ylabel(ylabel_u)\n", " #plt.show()\n" ] }, { "cell_type": "markdown", "metadata": {}, "source": [ "## Analysis\n", "\n", "| Website | Analysis | Top registrars |\n", "|--------------|--------------------------------------------------------------------------------|----------------------------------------|\n", "| HoxHunt | Great variation of different registrars | `MarkMonitor Inc.`, `CloudFlare Inc.` |\n", "| HS.fi | Average variation of different registrars, relies mostly on its own registrar | `Sanoma` |\n", "| TS.fi | Great variation of different registrars, uses mostly its own regisrtrar | `TS-Yhtymä Oy` |\n", "| Facebook | Very low variation of different registrars, relies on a single regisrtrar | `RegistrarSafe LLC` |" ] } ], "metadata": { "kernelspec": { "display_name": "Python 3", "language": "python", "name": "python3" }, "language_info": { "codemirror_mode": { "name": "ipython", "version": 3 }, "file_extension": ".py", "mimetype": "text/x-python", "name": "python", "nbconvert_exporter": "python", "pygments_lexer": "ipython3", "version": "3.8.5" } }, "nbformat": 4, "nbformat_minor": 4 }