Modeling Hybrid Feature-Based Phishing Websites Detection Using Machine Learning Techniques

被引:15
作者
Das Guptta S. [1 ]
Shahriar K.T. [1 ]
Alqahtani H. [3 ]
Alsalman D. [4 ]
Sarker I.H. [1 ]
机构
[1] Technology, Chittagong
[2] Unit of Cybersecurity, Department of Computer Science, Center of Artificial Intelligence, King Khalid University, Abha
[3] School of Engineering, Computing and Informatics, Dar Al-Hekma University, Jeddah
关键词
Anti-phishing; Cybersecurity; Hybrid feature; Hyperlink feature; Machine learning; Phishing detection; URL feature; XG Boost;
D O I
10.1007/s40745-022-00379-8
中图分类号
学科分类号
摘要
In this paper, we mainly present a machine learning based approach to detect real-time phishing websites by taking into account URL and hyperlink based hybrid features to achieve high accuracy without relying on any third-party systems. In phishing, the attackers typically try to deceive internet users by masking a webpage as an official genuine webpage to steal sensitive information such as usernames, passwords, social security numbers, credit card information, etc. Anti-phishing solutions like blacklist or whitelist, heuristic, and visual similarity based methods cannot detect zero-hour phishing attacks or brand-new websites. Moreover, earlier approaches are complex and unsuitable for real-time environments due to the dependency on third-party sources, such as a search engine. Hence, detecting recently developed phishing websites in a real-time environment is a great challenge in the domain of cybersecurity. To overcome these problems, this paper proposes a hybrid feature based anti-phishing strategy that extracts features from URL and hyperlink information of client-side only. We also develop a new dataset for the purpose of conducting experiments using popular machine learning classification techniques. Our experimental result shows that the proposed phishing detection approach is more effective having higher detection accuracy of 99.17% with the XG Boost technique than traditional approaches. © The Author(s), under exclusive licence to Springer-Verlag GmbH Germany, part of Springer Nature 2022.
引用
收藏
页码:217 / 242
页数:25
相关论文
共 41 条
[1]  
Sarker I.H., Furhad M.H., Nowrozy R., Ai-driven cybersecurity: an overview, security intelligence modeling and research directions, SN Comput Sci, 2, 3, pp. 1-18, (2021)
[2]  
The Latest Insights into the ‘state of digital’., (2021)
[3]  
Rao R.S., Pais A.R., Detection of phishing websites using an efficient feature-based machine learning framework, Neural Comput Appl, 31, 8, pp. 3851-3873, (2019)
[4]  
Jain A.K., Gupta B.B., A machine learning based approach for phishing detection using hyperlinks information, J Ambient Intell Human Comput, 10, 5, pp. 2015-2028, (2019)
[5]  
Sahingoz O.K., Buber E., Demir O., Diri B., Machine Learning Based Phishing Detection from Uris, (2017)
[6]  
Apwg Q4 2020 Report
[7]  
Internet Crime Complaint Center.
[8]  
Sarker Iqbal H., Data science and analytics: An overview from data-driven smart computing, decision-making and applications perspective, SN Comput Sci, (2021)
[9]  
Shi Y., Tian Y., Kou G., Peng Y., Li J., Optimization Based Data Mining: Theory and Applications, (2011)
[10]  
Iqbal H., Sarker A.C., Han J., Watters P., Automated Rule-Based Services with Intelligent Decision-Making. Context-Aware Machine Learning and Mobile Data Analytics, (2022)