A New Model for Simultaneous Detection of Phishing and Darknet Websites
Xu Jie, Haoliang Lan, Ju Ao · 2021 7th International Conference on Computer and Communications (ICCC) · 2021
In order to develop darknet users and expand the influence of darknet sites, darknet web addresses will be published and spread through ordinary networks, such as embedded in normal web pages, hidden in e-mail, etc. If we can distinguish these darknet websites from ordinary network sites and filter them out in time, we can effectively prevent the spread of darknet websites and curb the development of darknet. Therefore, this paper studies the darknet sites detection. In the study, another kind of malicious network address - phishing site is considered. Firstly, the density based clustering algorithm is used to cluster the darknet websites, phishing websites and normal websites. A novel attribute -- label category similarity is defined to measure the association between different kinds of sites. The clustering results show that darknet sites can be gathered together unsupervised. This shows that the darknet site has its own characteristics, which can be distinguished from phishing websites and normal websites. In view of the hidden darknet sites, this paper proposes a multi domain model algorithm to detect these darknet sites whose top domain is disguised to normal one. The experimental results show that the classification accuracy of darknet sites and phishing sites can reach more than 90%.