Dual-Layered Approach for Malicious Domain Detection

Nadide Bilge Doğan, Alp Barış Beydemir, Şerif Bahtıyar, Umutcan Doğan · 2024

The Domain Name System (DNS) plays a critical role in network security, yet faces numerous attacks, particularly from malicious domains. In this research, we propose a novel method to reduce the attacks by combining a mixture of expert structure with DistilBERT and feature extraction from various data sources, including WHOIS API, IP Geolocation API, DNS Lookup API, and SSL Certificate Control API, to classify domain security status. Utilizing a double-layer structure, we initially classify URLs as benign, phishing, malware, or defacement categories using a mixture of experts. Subsequently, URLs were flagged with feature extraction methods for further categorization. This approach provides a robust classification accuracy that offers a comprehensive solution for detecting malicious domains.

Read the paper · More papers on PaperTik