Dual-Layered Approach for Malicious Domain Detection
Nadide Bilge Doğan, Alp Barış Beydemir, Şerif Bahtıyar, Umutcan Doğan · 2024
The Domain Name System (DNS) plays a critical role in network security, yet faces numerous attacks, particularly from malicious domains. In this research, we propose a novel method to reduce the attacks by combining a mixture of expert structure with DistilBERT and feature extraction from various data sources, including WHOIS API, IP Geolocation API, DNS Lookup API, and SSL Certificate Control API, to classify domain security status. Utilizing a double-layer structure, we initially classify URLs as benign, phishing, malware, or defacement categories using a mixture of experts. Subsequently, URLs were flagged with feature extraction methods for further categorization. This approach provides a robust classification accuracy that offers a comprehensive solution for detecting malicious domains.