Homoglyph Attack Detection Model Using Machine Learning and Hash Function

被引:3
|
作者
Almuhaideb, Abdullah M. [1 ]
Aslam, Nida [2 ]
Alabdullatif, Almaha [2 ]
Altamimi, Sarah [2 ]
Alothman, Shooq [2 ]
Alhussain, Amnah [2 ]
Aldosari, Waad [2 ]
Alsunaidi, Shikah J. [2 ]
Alissa, Khalid A. [1 ]
机构
[1] Imam Abdulrahman Bin Faisal Univ, Coll Comp Sci & Informat Technol, Dept Networks & Commun, SAUDI ARAMCO Cybersecur Chair, POB 1982, Dammam 31441, Saudi Arabia
[2] Imam Abdulrahman Bin Faisal Univ, Coll Comp Sci & Informat Technol, Dept Comp Sci, POB 1982, Dammam 31441, Saudi Arabia
关键词
phishing detection; machine learning; forged websites; hash function; classification; PHISHING DETECTION; FEATURE-SELECTION;
D O I
10.3390/jsan11030054
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Phishing is still a major security threat in cyberspace. In phishing, attackers steal critical information from victims by presenting a spoofing/fake site that appears to be a visual clone of a legitimate site. Several Unicode characters are visually identical to ASCII characters. This similarity in characters is generally known as homoglyphs. Malicious adversaries utilize homoglyphs in URLs and DNS domains to target organizations. To reduce the risks caused by phishing attacks, effective ways of detecting phishing websites are urgently required. This paper proposes a homoglyph attack detection model that combines a hash function and machine learning. There are two phases to the model approach. The machine was being trained during the development phase. The deployment phase involved deploying the model with a Java interface and testing the outcomes through actual user interaction. The results are more accurate when the URL is hashed, as any little changes to the URL can be recognized. The homoglyph detector can be developed as a stand-alone software that is used as the initial step in requesting a webpage as it enhances browser security and protects websites from phishing attempts. To verify the effectiveness, we compared the proposed model on several criteria to existing phishing detection methods. By using the hash function, the proposed security features increase the overall security of the homoglyph attack detection in terms of accuracy, integrity, and availability. The experiment results showed that the model can detect phishing sites with an accuracy of 99.8% using Random Forest, and the hash function improves the accuracy of homoglyph attack detection.
引用
收藏
页数:18
相关论文
共 50 条
  • [31] Web Attack Intrusion Detection System Using Machine Learning Techniques
    Baklizi, Mahmoud Khalid
    Atoum, Issa
    Alkhazaleh, Mohammad
    Kanaker, Hasan
    Abdullah, Nibras
    Al-Wesabi, Ola A.
    Otoom, Ahmed Ali
    [J]. INTERNATIONAL JOURNAL OF ONLINE AND BIOMEDICAL ENGINEERING, 2024, 20 (03) : 24 - 38
  • [32] Proposing a Rank and Wormhole Attack Detection Framework using Machine Learning
    Fatima-tuz-Zahra
    Jhanjhi, N. Z.
    Brohi, Sarfraz Nawaz
    Malik, Nazir A.
    [J]. 2019 13TH INTERNATIONAL CONFERENCE ON MATHEMATICS, ACTUARIAL SCIENCE, COMPUTER SCIENCE AND STATISTICS (MACS-13), 2019,
  • [33] Performance evaluation of Botnet DDoS attack detection using machine learning
    Tong Anh Tuan
    Hoang Viet Long
    Le Hoang Son
    Raghvendra Kumar
    Ishaani Priyadarshini
    Nguyen Thi Kim Son
    [J]. Evolutionary Intelligence, 2020, 13 : 283 - 294
  • [34] Privilege Escalation Attack Detection and Mitigation in Cloud Using Machine Learning
    Mehmood, Muhammad
    Amin, Rashid
    Muslam, Muhana Magboul Ali
    Xie, Jiang
    Aldabbas, Hamza
    [J]. IEEE ACCESS, 2023, 11 : 46561 - 46576
  • [35] Injection attack detection using machine learning for smart IoT applications
    Gaber, Tarek
    El-Ghamry, Amir
    Hassanien, Aboul Ella
    [J]. PHYSICAL COMMUNICATION, 2022, 52
  • [36] Ransomware Attack Detection on the Internet of Things Using Machine Learning Algorithm
    Zewdie, Temechu Girma
    Girma, Anteneh
    Cotae, Paul
    [J]. HCI INTERNATIONAL 2022 - LATE BREAKING PAPERS: INTERACTING WITH EXTENDED REALITY AND ARTIFICIAL INTELLIGENCE, 2022, 13518 : 598 - 613
  • [37] Detection of Cyber Attack in Network Using different Machine Learning Approaches
    Bharath, B. Reddy
    Yaswanth, G.
    Santhankrishnan, C.
    [J]. JOURNAL OF PHARMACEUTICAL NEGATIVE RESULTS, 2022, 13 : 1529 - 1534
  • [38] DDoS Attack Detection on IoT Devices Using Machine Learning Techniques
    Kumar, Sunil
    Sahu, Rohit Kumar
    Rudra, Bhawana
    [J]. INTELLIGENT SYSTEMS DESIGN AND APPLICATIONS, ISDA 2021, 2022, 418 : 787 - 794
  • [39] Performance evaluation of Botnet DDoS attack detection using machine learning
    Tuan, Tong Anh
    Long, Hoang Viet
    Son, Le Hoang
    Kumar, Raghvendra
    Priyadarshini, Ishaani
    Son, Nguyen Thi Kim
    [J]. EVOLUTIONARY INTELLIGENCE, 2020, 13 (02) : 283 - 294
  • [40] Email fraud attack detection using hybrid machine learning approach
    Yaseen Y.A.
    Qasaimeh M.
    Al-Qassas R.S.
    Al-Fayoumi M.
    [J]. Recent Advances in Computer Science and Communications, 2021, 14 (05) : 1370 - 1380