Generative Adverserial Analysis of Phishing Attacks on Static and Dynamic Content of Webpages
Alexander O'Mara, Izzat Mahmoud Alsmadi, Ahmed F. AlEroud · 2021
In this paper, we studied the phishing problem from data analytics and AI-powered adversarial attacks perspectives. We evaluated several static and dynamic features that can be used as good models' predictors. Unlike the URL, which can be easily crafted to evade detection, the page static and dynamic content cannot be easily changed without changing what is presented to the potential victim. We evaluated several conventional and ensemble-based models and reported the best models and settings of models that showed high prediction accuracy. We then analyzed the feasibility of evading phishing classifiers by perturbing static and dynamic features using AI generative models then test both conventional and ensemble classifiers. Our results shows that the analysis of static and dynamic features of web pages has good potential in the area adversarial learning to generate phishing attacks. The results yield that it is more challenging to evade phishing classifiers relying on dynamic content features, which offers a good level of robustness against evasion tactics.