A Comprehensive Evaluation of Webpage Content Features for Detecting Malicious Websites

John McGahagan, Darshan Bhansali, Ciro Pinto-Coelho, Michel Schatkin Cukier · 2019

Security researchers have used features gathered from webpage content (both HTML and JavaScript) to detect malicious websites. Although webpage content features have shown promise, little emphasis is placed on finding new webpage content features for malicious website detection. We address this gap by conducting a comprehensive evaluation of webpage content features to assess whether additional webpage content features improve detection of malicious websites. We study webpage content features from 5,931 malicious websites from the Cisco Talos Intelligence Group including websites associated with phishing, drive-by downloads, and command and control infrastructure and 34,778 benign websites from the Alexa list. We collect 1,865 webpage content features from these websites and select 26 for additional analysis. Among these, 9 have been studied in prior research, while the remaining 17 have not. We build eight supervised learning models and observe that the ones built from the 26 features outperform models built with features from prior research and do so with 48% fewer features. We apply two feature transformation techniques and further show the ability of the 26 features to detect malicious websites. From our study, we postulate that new, unstudied, webpage content features will improve detection of malicious websites.

Read the paper · More papers on PaperTik