COBRA: A Content-Agnostic Framework for Zero-Day Detection of Suspicious Domains

📅 2026-09-22
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
本文提出COBRA框架,通过分析新注册域名的名称并使用聚类技术,在无需内容特征的情况下检测可疑域名,以提高零日检测精度。
📝 Abstract
The use of malicious domains is central to cyberattacks such as phishing, malware distribution, impersonation, and fraudulent transactions. Because domains are inexpensive to register and easy to deploy at scale, they remain one of the most common and damaging tools used in cybercrime across industries. Proactive detection is essential to reducing this window of vulnerability and preventing harm to users. In this work, we propose COBRA: a content-agnostic, registration-time detection framework for identifying and analyzing suspicious domains from day zero. Our approach does not rely on any content-based features, allowing us to classify a domain even before it is populated with content. We analyze the names of newly registered domains and employ a clustering technique to group them based on lexical and structural similarity. We evaluate our methodology using real-world data consisting of 1.5M newly created domains, demonstrating that COBRA detects suspicious domains with a precision of 98.5%, identifying more than 47K distinct newly registered suspicious domains. Furthermore, our results show that domain-name clustering enables accurate early detection, allowing us to identify 80% of suspicious or malicious domains earlier than one of the most widely used threat-intelligence services, which in some cases may require up to 7 days.
Problem

Research questions and friction points this paper is trying to address.

malicious domains
cyberattacks
proactive detection
suspicious domains
Innovation

Methods, ideas, or system contributions that make the work stand out.

Content-Agnostic
Zero-Day Detection
Clustering Technique
Suspicious Domains
🔎 Similar Papers