arXiv論文メモ
新着一覧
cs.CR · 掲載先の記載あり

登録直後のドメイン名から不審なドメインを検出するCOBRA

COBRA: A Content-Agnostic Framework for Zero-Day Detection of Suspicious Domains

Alexandros Fourtounis, Emmanouil Papadogiannakis, Panagiotis Papadopoulos, Nicolas Kourtellis, Evangelos Markatos

この論文をやさしく読む

ひとことで言うと

Webサイトの内容がまだない段階でも、新しく登録されたドメイン名の似かよりから不審なものを探す方法。

何に役立つ?

考えられる用途は、フィッシングなどに使われる可能性のあるドメインを、登録直後に調査対象へ挙げることである。

この研究の面白いところ

150万件を評価し、適合率98.5%と報告した。既存の脅威情報サービスより早く見つけた割合も測っている。

どこまで分かった?

適合率は検出したものの正確さであり、すべての悪意あるドメインを発見した割合ではない。『80%早い』は比較した一つのサービスに対する結果である。

v1のアブストラクトに基づくAI解説。日本語訳とは別に、用途の解釈を含みます。

アブストラクトの日本語訳

悪意のあるドメインは、フィッシング、マルウェア配布、なりすまし、詐欺的な取引などの攻撃で中心的に使われる。ドメインは安価に登録でき、大量に展開しやすいため、さまざまな業界で一般的かつ被害の大きいサイバー犯罪の道具であり続けている。脆弱な時間帯を短くして利用者への被害を防ぐには、先回りした検出が不可欠である。本研究は、登録された初日から不審なドメインを見つけて分析する、コンテンツに依存しない検出の枠組みCOBRAを提案する。コンテンツ由来の特徴を一切使わないため、ドメインに内容が置かれる前でも分類できる。新規登録ドメインの名前を分析し、語彙的・構造的な類似性に基づくクラスタリングでグループ化する。実際に新規作成された150万件のドメインで評価した結果、COBRAは適合率98.5%で不審なドメインを検出し、異なる新規登録の不審ドメインを4万7千件以上特定した。さらに、名前のクラスタリングによる早期検出で、不審または悪意のあるドメインの80%を、広く使われる脅威情報サービスの一つより早く特定できた。そのサービスでは、場合によって検出に最大7日かかることがある。

v1の要旨から自動生成。本文の精読・人による確認は未実施。

初稿
2026-09-22(UTC)
最新改訂
2026-09-22 · v1
査読・掲載
掲載先の記載あり

著者による掲載先の記載:Proceedings of the 23rd International Conference on Security and Cryptography - Volume 1: SECRYPT; ISBN 978-989-758-858-7; ISSN 2184-7711, SciTePress, 2026, pages 37-48。出版社での独立確認は未実施です。

arXivで読むPDFDOI

更新履歴

取得できた版を表示。版の更新は査読済みを意味しません。過去版の本文差分は未解析です。

原文の要旨

The use of malicious domains is central to cyberattacks such as phishing, malware distribution, impersonation, and fraudulent transactions. Because domains are inexpensive to register and easy to deploy at scale, they remain one of the most common and damaging tools used in cybercrime across industries. Proactive detection is essential to reducing this window of vulnerability and preventing harm to users. In this work, we propose COBRA: a content-agnostic, registration-time detection framework for identifying and analyzing suspicious domains from day zero. Our approach does not rely on any content-based features, allowing us to classify a domain even before it is populated with content. We analyze the names of newly registered domains and employ a clustering technique to group them based on lexical and structural similarity. We evaluate our methodology using real-world data consisting of 1.5M newly created domains, demonstrating that COBRA detects suspicious domains with a precision of 98.5%, identifying more than 47K distinct newly registered suspicious domains. Furthermore, our results show that domain-name clustering enables accurate early detection, allowing us to identify 80% of suspicious or malicious domains earlier than one of the most widely used threat-intelligence services, which in some cases may require up to 7 days.

arXiv ID: 2609.25882 / 要約の誤りについて