COBRA: A Content-Agnostic Framework for Zero-Day Detection of Suspicious Domains
cs.CR
Submitted: 2026-09-22
Updated: 2026-09-22
Journal ref: Proceedings of the 23rd International Conference on Security and Cryptography - Volume 1: SECRYPT; ISBN 978-989-758-858-7; ISSN 2184-7711, SciTePress, 2026, pages 37-48
Code: https://github.com/AlexandrosFourtounis/suspicious-domains-clustered
License: http://creativecommons.org/licenses/by-nc-nd/4.0/
The gist: The use of malicious domains is central to cyberattacks such as phishing, malware distribution, impersonation, and fraudulent transactions.
Terminology
Abstract
The use of malicious domains is central to cyberattacks such as phishing, malware distribution, impersonation, and fraudulent transactions. Because domains are inexpensive to register and easy to deploy at scale, they remain one of the most common and damaging tools used in cybercrime across industries. Proactive detection is essential to reducing this window of vulnerability and preventing harm to users. In this work, we propose COBRA: a content-agnostic, registration-time detection framework for identifying and analyzing suspicious domains from day zero. Our approach does not rely on any content-based features, allowing us to classify a domain even before it is populated with content. We analyze the names of newly registered domains and employ a clustering technique to group them based on lexical and structural similarity. We evaluate our methodology using real-world data consisting of 1.5M newly created domains, demonstrating that COBRA detects suspicious domains with a precision of 98.5%, identifying more than 47K distinct newly registered suspicious domains. Furthermore, our results show that domain-name clustering enables accurate early detection, allowing us to identify 80% of suspicious or malicious domains earlier than one of the most widely used threat-intelligence services, which in some cases may require up to 7 days.
Sources
- Registration, Detection, and Deregistration: Analyzing DNS Abuse for Phishing Attacks
- Predicting Domain Generation Algorithms with Long Short-Term Memory Networks
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs