Development of anti-phishing browser based on random forest and rule of extraction framework

被引:15
|
作者
Gowda, Mohith H. R. [1 ]
Adithya, M., V [2 ]
Prasad, Gunesh S. [3 ]
Vinay, S. [4 ]
机构
[1] PES Coll Engn, Comp Sci & Engn, 4011 Vasuda Krupa,3rd Cross, Mandya 571401, Karnataka, India
[2] PES Coll Engn, Comp Sci & Engn, 1932,1st Main Rd,Near Vinayaka Auto Stand, Mandya 571401, Karnataka, India
[3] PES Coll Engn, Comp Sci & Engn, 20-19,5th Cross,Near Shakthi Nagar Pk, Mysore 570019, Karnataka, India
[4] PES Coll Engn, Informat Sci & Engn, PES Engn Coll Rd,PES Coll Campus, Mandya 571401, Karnataka, India
关键词
Phishing attack; Machine learning; Intelligent browser engine; Rule of extraction algorithm; Browser architecture; EFFICIENT;
D O I
10.1186/s42400-020-00059-1
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Phishing is a technique under Social Engineering attacks which is most widely used to get user sensitive information, such as login credentials and credit and debit card information, etc. It is carried out by a person masquerading as an authentic individual. To protect web users from these attacks, various anti-phishing techniques are developed, but they fail to protect the user from these attacks in various ways. In this paper, we propose a novel technique to identify phishing websites effortlessly on the client side by proposing a novel browser architecture. In this system, we use the rule of extraction framework to extract the properties or features of a website using the URL only. This list consists of 30 different properties of a URL, which will later be used by the Random Forest Classification machine learning model to detect the authenticity of the website. A dataset consisting of 11,055 tuples is used to train the model. These processes are carried out on the client-side with the help of a redesigned browser architecture. Today Researches have come up with machine learning frameworks to detect phishing sites, but they are not in a state to be used by individuals having no technical knowledge. To make sure that these tools are accessible to every individual, we have improvised and introduced detection methods into the browser architecture named as 'Embedded Phishing Detection Browser' (EPDB), which is a novel method to preserve the existing user experience while improving the security. The newly designed browser architecture introduces a special segment to perform phishing detection operations in real-time. We have prototyped this technique to ensure maximum security, better accuracy of 99.36% in the identification of phishing websites in real-time.
引用
收藏
页数:14
相关论文
共 50 条
  • [1] Development of anti-phishing browser based on random forest and rule of extraction framework
    Mohith Gowda HR
    Adithya MV
    Gunesh Prasad S
    Vinay S
    Cybersecurity, 3
  • [2] Browser Extension based Hybrid Anti-Phishing Framework using Feature Selection
    Maurya, Swati
    Saini, Harpreet Singh
    Jain, Anurag
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2019, 10 (11) : 579 - 588
  • [3] A Honeypots Based Anti-Phishing Framework
    Chauhan, Shubhika
    Shiwani, Savita
    2014 INTERNATIONAL CONFERENCE ON CONTROL, INSTRUMENTATION, COMMUNICATION AND COMPUTATIONAL TECHNOLOGIES (ICCICCT), 2014, : 618 - 625
  • [4] A framework for assessment of anti-phishing preparedness
    Leung, Alvin Chung Man
    Bose, Indranil
    IMECS 2007: INTERNATIONAL MULTICONFERENCE OF ENGINEERS AND COMPUTER SCIENTISTS, VOLS I AND II, 2007, : 1020 - +
  • [5] Light weight anti-phishing with user whitelisting in a web browser
    Wang, Yue
    Agrawal, Rinky
    Choi, Baek-Young
    2008 IEEE REGION 5 CONFERENCE, 2008, : 39 - 42
  • [6] Anti-Phishing Using Hadoop-Framework
    Gavahane, Mayura
    Sequeira, Derick
    Pandey, Abhishek
    Shetty, Anush
    2015 INTERNATIONAL CONFERENCE ON TECHNOLOGY FOR SUSTAINABLE DEVELOPMENT (ICTSD-2015), 2015,
  • [7] Usability Evaluation of Active Anti-Phishing Browser Extensions for Persons with Visual Impairments
    Sonowal, Gunikhan
    Kuppusamy, K. S.
    Kumar, Ajit
    2017 4TH INTERNATIONAL CONFERENCE ON ADVANCED COMPUTING AND COMMUNICATION SYSTEMS (ICACCS), 2017,
  • [8] Research of the Anti-Phishing Technology Based on E-mail Extraction and Analysis
    Du, Yanhui
    Xue, Fu
    PROCEEDINGS OF 2013 INTERNATIONAL CONFERENCE ON INFORMATION SCIENCE AND CLOUD COMPUTING COMPANION (ISCC-C), 2014, : 60 - 65
  • [9] A Study of Anti-phishing Strategies Based on TRIZ
    Qi, Ming
    Zou, Chang-Yi
    NSWCTC 2009: INTERNATIONAL CONFERENCE ON NETWORKS SECURITY, WIRELESS COMMUNICATIONS AND TRUSTED COMPUTING, VOL 2, PROCEEDINGS, 2009, : 536 - 538
  • [10] An Anti-Phishing Method based on Feature Analysis
    Rajab, Majed
    2ND INTERNATIONAL CONFERENCE ON MACHINE LEARNING AND SOFT COMPUTING (ICMLSC 2018), 2015, : 133 - 139