Machine Learning for Early Detection of Phishing URLs in Parked Domains: An Approach Applied to a Financial Institution

Jaqueline Damacena Duarte, Pedro Chagas, João Paulo C. L. da Costa, Elena J. da Costa, Laerte Peotta de Melo, Rafael Rabelo Nunes, Carlos V. N. Gabriel Soares, Thiago Erivan da Cunha Silva · IEEE Access · 2025

Phishing attacks remain a critical threat in the digital era, exploiting social engineering tactics to compromise user trust and sensitive information, often resulting in financial loss and identity theft. These attacks typically exploit multiple communication channels to impersonate trusted entities, inducing users to click on and access malicious Resource Locations (URLs). Early detection of these URLs can considerably reduce the volume and impact of these attacks. This paper proposes a machine learning-based framework for early detection of phishing URLs, specifically addressing newly registered and parked domains. Using a curated dataset comprising 211,659 URLs obtained from real-time SSL (Secure Sockets Layer) certificate monitoring, popular domain listings, and phishing incident reports, the methods encompass data pre-processing, feature engineering, and model optimization. A Light Gradient Boosting Machine classifier achieved recall of 96.02% and accuracy of 97.28% on a balanced dataset, validated through 10-fold cross-validation. Additionally, feature selection techniques reduced model complexity while maintaining detection effectiveness, facilitating practical deployment. The proposed frameworks provide a versatile tool for phishing prevention and brand protection, demonstrating potential applicability in sectors such as banking and e-commerce. This work contributes to proactive cybersecurity practices addressing evolving threats within digital ecosystems.

Read the paper · More papers on PaperTik