DomainLynx: Advancing LLM Techniques for Robust Domain Squatting Detection
Daiki Chiba, Hiroki Nakano, Takashi Koide · IEEE Access · 2025
Domain squatting, the malicious registration of deceptive domain names, poses a significant threat to Internet security. This study presents an enhanced version of DomainLynx, a system leveraging Large Language Models (LLMs) for detecting domain squatting. We introduce novel techniques that combine LLMs with domain-specific knowledge to identify a wide range of squatting tactics, including complex hybrid methods that merge multiple deception techniques. Our improved system features refined detection algorithms and an advanced validation process that significantly reduces false positives while maintaining high accuracy. Comprehensive evaluations using various LLM configurations demonstrate DomainLynx’s superior performance. Using a state-of-the-art LLM, the system achieved 94.7% accuracy on a diverse dataset of 1,649 squatting domains. In a month-long real-world test, DomainLynx detected 34,359 potential squatting domains from 2.09 million new registrations, outperforming existing methods by 2.5 times. Further analysis confirmed the system’s effectiveness across different squatting types. We also present case studies of hybrid-squatting domains, such as those combining typos with brand impersonation, offering insights into emerging threats. This research advances Internet security by providing a more accurate, adaptable, and thoroughly evaluated LLM-based tool for combating evolving domain squatting threats, contributing to safer online environments for users and organizations worldwide.