Improving Web Security through Machine Learning: A Feature-Based Methodology for Detecting Phishing URLs
Reem Alzu’bi, Tariq Bishtawi, Hassan Kassem · Engineering Technology & Applied Science Research · 2025
Phishing attacks remain a significant and evolving threat to web security, often using malicious URLs to deceive users into sharing personal information. This study employs a detailed, feature-based approach to develop a machine learning method for detecting phishing URLs. The analysis includes four advanced machine learning classifiers that utilize comprehensive features from lexical patterns, host-based, and content-based URL characteristics. These classifiers are Random Forest (RF), Decision Tree (DT), Support Vector Machine (SVM) with a Radial Basis Function (RBF) kernel, and Extreme Gradient Boosting (XGBoost). Results demonstrate that ensemble methods outperform individual models in phishing detection, with XGB and RF achieving higher accuracy, precision, and recall across all metrics. These findings contribute to the development of real-time phishing detection tools, although effective feature engineering and model selection remain crucial for enhancing internet security.