A malicious domain name detection method and system based on bimodal fusion

By constructing a dual-modal fusion architecture of graph attention network and large language model, the problems of false positives and false negatives in malicious domain name detection in existing technologies are solved, and accurate detection is achieved in complex attack scenarios.

CN122372310APending Publication Date: 2026-07-10UNIV OF JINAN
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
UNIV OF JINAN
Filing Date
2026-05-08
Publication Date
2026-07-10

AI Technical Summary

Technical Problem

Existing malicious domain name detection methods based on graph structure and semantic features cannot effectively detect malicious domain names that are "abnormal in topological association but normal in character features" or "abnormal in character features but lack historical association" in complex attack scenarios, resulting in false positives or false negatives and inaccurate detection.

Method used

A dual-modal fusion architecture combining graph attention networks and large language models is constructed. By building a heterogeneous information network, topological structure modality and semantic feature modality are extracted. Evidence chain backtracking and fusion are performed using multi-head graph attention networks and large language models to achieve accurate detection of malicious domain names.

Benefits of technology

It enables accurate detection of malicious domains in complex scenarios such as abnormal topological associations but normal character features and abnormal character features but lack of historical associations, avoiding false positives and false negatives and improving the accuracy of security analysis.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122372310A_ABST
    Figure CN122372310A_ABST
Patent Text Reader

Abstract

This invention discloses a malicious domain name detection method and system based on bimodal fusion, belonging to the field of information security technology. Addressing the problems of existing malicious domain name detection methods, such as the cold start dilemma of new domain names in graph models, the lack of interpretability in deep learning models, and the inability to collaboratively verify topological and semantic modalities due to their separation, this invention constructs a heterogeneous information network containing multiple entities to extract topological structure modalities and high-confidence evidence chains. These evidence chains are then transformed into natural language text, and semantic feature modalities are extracted through large language model reasoning. Weighted fusion is performed by calculating the similarity of the bimodal spatial angle, achieving effective detection of newly registered isolated domain names and improving the accuracy and reliability of malicious domain name detection.
Need to check novelty before this filing date? Find Prior Art