Abstract
Nowadays, the majority of everyday computing devices, irrespective of their size and operating system, allow access to information and online services through web browsers. However, the pervasiveness of web browsing in our daily life does not come without security risks. This widespread practice of web browsing in combination with web users’ low situational awareness against cyber attacks, exposes them to a variety of threats, such as phishing, malware and profiling. Phishing attacks can compromise a target, individual or enterprise, through social interaction alone. Moreover, in the current threat landscape phishing attacks typically serve as an attack vector or initial step in a more complex campaign. To make matters worse, past work has demonstrated the inability of denylists, which are the default phishing countermeasure, to protect users from the dynamic nature of phishing URLs. In this context, our work uses supervised machine learning to block phishing attacks, based on a novel combination of features that are extracted solely from the URL. We evaluate our performance over time with a dataset which consists of active phishing attacks and compare it with Google Safe Browsing (GSB), i.e., the default security control in most popular web browsers. We find that our work outperforms GSB in all of our experiments, as well as performs well even against phishing URLs which are active one year after our model’s training.
Subject
Computer Networks and Communications
Reference47 articles.
1. Phishinghttps://www.merriam-webster.com/dictionary/phishing
2. Phishing Activity Trends Reportshttps://apwg.org/trendsreports/
3. Browser, OS, Search Engine Including Mobile Usage Sharehttps://gs.statcounter.com/
Cited by
35 articles.
订阅此论文施引文献
订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献
1. Advancing Network Security in Industrial IoT: A Deep Dive into AI-Enabled Intrusion Detection Systems;Advanced Engineering Informatics;2024-10
2. Detecting Deceptive URLs: Exploring Logistic Regression and Decision Tree Models;2024 IEEE Students Conference on Engineering and Systems (SCES);2024-06-21
3. Verification of Genuineness of Educational Internet Resources Using Machine Learning Methods;2024 4th International Conference on Technology Enhanced Learning in Higher Education (TELE);2024-06-20
4. Phishing Attacks and Detection Techniques: A Systematic Review;2024 International Conference on Science, Engineering and Business for Driving Sustainable Development Goals (SEB4SDG);2024-04-02
5. PRAY So You Don’t Become Prey;SN Computer Science;2024-03-14