Complementing Blacklists: An Enhanced Technique to Learn Detection of Zero-Hour Phishing URLs

Thomas Nagunwa, The Society of Digital Information and Wireless Communication · International Journal of Cyber-Security and Digital Forensics · 2015

Increased phishing attacks despite existing antiphishing tools suggests that the tools are not catching up with the attacks technically. Majority of the tools depend on blacklists which are way short in tackling zero-hour attacks, while existing heuristic tools are also less performing. We propose a machine learning classifier to complement a blacklist approach. The classifier uses a wide range of predictive features compared to those in similar studies, categorized as URL characteristics, web page contents, domain features and domain reputation/ranking. Using six different machine learning algorithms and a dataset of 890 URLs, our classifier achieved the best performance compared to similar solutions, attaining an accuracy of 99.89%, false positive 0.0% and false negative 0.1%. Domain reputation features were the most predictive while web page content features were the least ones. Individually, blacklist reputation and Alexa ranking were the most influential features whereas popup login windows and hexadecimal number were the least ones.

Read the paper · More papers on PaperTik