Everything Is in the Name - A URL Based Approach for Phishing Detection
Everything Is in the Name - A URL Based Approach for Phishing Detection
复制标题
一切皆在名称中 - 基于 URL 的网络钓鱼检测方法
DOI:
--
复制
发表时间:
2019
期刊:
影响因子:
--
通讯作者:
S. Lodha
中科院分区:
文献类型:
--
作者:
Harshal Tupsamudre;A. Singh;S. Lodha
Phishing attack, in which a user is tricked into revealing sensitive information on a spoofed website, is one of the most common threat to cybersecurity. Most modern web browsers counter phishing attacks using a blacklist of confirmed phishing URLs. However, one major disadvantage of the blacklist method is that it is ineffective against newly generated phishes. Machine learning based techniques that rely on features extracted from URL (e.g., URL length and bag-of-words) or web page (e.g., TF-IDF and form fields) are considered to be more effective in identifying new phishing attacks. The main benefit of using URL based features over page based features is that the machine learning model can classify new URLs on-the-fly even before the page is loaded by the web browser, thus avoiding other potential dangers such as drive-by download attacks and cryptojacking attacks.