PhishMon: A Machine Learning Framework for Detecting Phishing Webpages

被引:0
|
作者
Niakanlahiji, Amirreza [1 ]
Chu, Bei-Tseng [1 ]
Al-Shaer, Ehab [1 ]
机构
[1] UNC Charlotte, Software & Informat Syst, Charlotte, NC 28223 USA
关键词
Anti Phishing; Machine Learning Framework; COMPLEXITY;
D O I
暂无
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Despite numerous research efforts, phishing attacks remain prevalent and highly effective in luring unsuspecting users to reveal sensitive information, including account credentials and social security numbers. In this paper, we propose PhishMon, a new feature-rich machine learning framework to detect phishing webpages. It relies on a set of fifteen novel features that can he efficiently computed from a webpage without requiring third party services, such as search engines, or WHOIS servers. These features capture various characteristics of legitimate web applications as well as their underlying web infrastructures. Emulation of these features is costly for phishers as it demands to spend significantly more time and effort on their underlying infrastructures and web applications; in addition to the efforts required for replicating the appearance of target websites. Through extensive evaluation on a dataset consisting of 4,800 distinct phishing and 17,500 distinct benign webpages, we show that PhishMon can distinguish unseen phishing from legitimate webpages with a very high degree of accuracy. In our experiments, PhishMon achieved 95.4% accuracy with 1.3% false positive rate on a dataset containing unique phishing instances.
引用
收藏
页码:220 / 225
页数:6
相关论文
共 50 条
  • [1] Computer Vision Based Framework For Detecting Phishing Webpages
    Cernica, Ionut
    Popescu, Nirvana
    [J]. 2020 19TH ROEDUNET CONFERENCE: NETWORKING IN EDUCATION AND RESEARCH (ROEDUNET), 2020,
  • [2] A lightweight machine learning based security framework for detecting phishing attacks
    Kumar, Yogendra
    Subba, Basant
    [J]. 2021 INTERNATIONAL CONFERENCE ON COMMUNICATION SYSTEMS & NETWORKS (COMSNETS), 2021, : 184 - 188
  • [3] A comprehensive and efficacious architecture for detecting phishing webpages
    Gowtham, R.
    Krishnamurthi, Ilango
    [J]. COMPUTERS & SECURITY, 2014, 40 : 23 - 37
  • [4] DeltaPhish: Detecting Phishing Webpages in Compromised Websites
    Corona, Igino
    Biggio, Battista
    Contini, Matteo
    Piras, Luca
    Corda, Roberto
    Mereu, Mauro
    Mureddu, Guido
    Ariu, Davide
    Roli, Fabio
    [J]. COMPUTER SECURITY - ESORICS 2017, PT I, 2018, 10492 : 370 - 388
  • [5] Comparisons of machine learning techniques for detecting malicious webpages
    Kazemian, H. B.
    Ahmed, S.
    [J]. EXPERT SYSTEMS WITH APPLICATIONS, 2015, 42 (03) : 1166 - 1177
  • [6] Detecting Phishing Websites Using Machine Learning
    Alswailem, Amani
    Alabdullah, Bashayr
    Alrumayh, Norah
    Alsedrani, Aram
    [J]. 2019 2ND INTERNATIONAL CONFERENCE ON COMPUTER APPLICATIONS & INFORMATION SECURITY (ICCAIS), 2019,
  • [7] APuML: An Efficient Approach to Detect Mobile Phishing Webpages using Machine Learning
    Jain, Ankit Kumar
    Debnath, Ninmoy
    Jain, Arvind Kumar
    [J]. WIRELESS PERSONAL COMMUNICATIONS, 2022, 125 (04) : 3227 - 3248
  • [8] APuML: An Efficient Approach to Detect Mobile Phishing Webpages using Machine Learning
    Ankit Kumar Jain
    Ninmoy Debnath
    Arvind Kumar Jain
    [J]. Wireless Personal Communications, 2022, 125 : 3227 - 3248
  • [9] Detecting Phishing Website Using Machine Learning
    Alkawaz, Mohammed Hazim
    Steven, Stephanie Joanne
    Hajamydeen, Asif Iqbal
    [J]. 2020 16TH IEEE INTERNATIONAL COLLOQUIUM ON SIGNAL PROCESSING & ITS APPLICATIONS (CSPA 2020), 2020, : 111 - 114
  • [10] Detecting Phishing Domains Using Machine Learning
    Alnemari, Shouq
    Alshammari, Majid
    [J]. APPLIED SCIENCES-BASEL, 2023, 13 (08):