发表机构
Foundation for Research and Technology - Hellas (FORTH); University of Crete; Keysight AI Labs(希腊研究与技术基金会; 克里特大学; 是德科技AI实验室)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
COBRA提出一种内容无关的注册时检测框架,通过聚类新注册域名的词汇和结构特征,在零日实现高精度(98.5%)可疑域名检测,并比传统威胁情报服务提前识别80%的恶意域名。
AI 中文摘要
恶意域名的使用是网络攻击(如网络钓鱼、恶意软件分发、冒充和欺诈交易)的核心。由于域名注册成本低廉且易于大规模部署,它们仍然是各行业网络犯罪中最常见和最具破坏性的工具之一。主动检测对于缩短这一脆弱性窗口并防止对用户造成伤害至关重要。在这项工作中,我们提出了COBRA:一种内容无关的、注册时检测框架,用于从第零天起识别和分析可疑域名。我们的方法不依赖任何基于内容的特征,使我们能够在域名填充内容之前对其进行分类。我们分析新注册域名的名称,并采用聚类技术根据词汇和结构相似性对其进行分组。我们使用包含150万个新创建域名的真实世界数据评估了我们的方法,证明COBRA以98.5%的精确度检测可疑域名,识别出超过47,000个不同的新注册可疑域名。此外,我们的结果表明,域名聚类能够实现准确的早期检测,使我们能够比最广泛使用的威胁情报服务之一更早地识别80%的可疑或恶意域名,而该服务在某些情况下可能需要长达7天的时间。
英文摘要
The use of malicious domains is central to cyberattacks such as phishing, malware distribution, impersonation, and fraudulent transactions. Because domains are inexpensive to register and easy to deploy at scale, they remain one of the most common and damaging tools used in cybercrime across industries. Proactive detection is essential to reducing this window of vulnerability and preventing harm to users. In this work, we propose COBRA: a content-agnostic, registration-time detection framework for identifying and analyzing suspicious domains from day zero. Our approach does not rely on any content-based features, allowing us to classify a domain even before it is populated with content. We analyze the names of newly registered domains and employ a clustering technique to group them based on lexical and structural similarity. We evaluate our methodology using real-world data consisting of 1.5M newly created domains, demonstrating that COBRA detects suspicious domains with a precision of 98.5%, identifying more than 47K distinct newly registered suspicious domains. Furthermore, our results show that domain-name clustering enables accurate early detection, allowing us to identify 80% of suspicious or malicious domains earlier than one of the most widely used threat-intelligence services, which in some cases may require up to 7 days.
Journal refProceedings of the 23rd International Conference on Security and Cryptography - Volume 1: SECRYPT; ISBN 978-989-758-858-7; ISSN 2184-7711, SciTePress, 2026, pages 37-48