Phishing attack is an analogy derived from “fishing” for victims. It is a malicious practice of deceiving individuals into divulging sensitive information. It remains a persistent threat in the digital landscape, undermining the integrity of communication networks, financial systems, and personal data security. Attackers trick people on the internet by making fake web pages that look real, trying to get personal information. People have come up with ways to stop this, like blacklists or whitelists, and other smart methods, but users still get attacked. In this paper, we suggest a machine learning and deep learning backed way to check if a URL is safe or not before someone clicks on it and gets attacked. Methods, especially those employing statistical learning algorithms for classification, have the issue of false positives. This paper adds to the expanding realm of cybersecurity knowledge by offering a novel way of detecting phishy websites using the header analysis as well as exploration of URL phishing, along with practical strategies for reducing its risks. Logistic Regression outperformed in URL analysis, followed by Random Forest and Support Vector Machine, meanwhile, CNN backed ResNet50 excelled in image analysis, followed by Support Vector Machine backed with feature extraction. ResNet50 maintained superiority across datasets, affirming its effectiveness for phishing image detection tasks.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Detection of Phishing Websites Based on URL, Response, and Image Analysis

  • Ankita Bansal,
  • Ayush Chaudhary,
  • Fahim Iqbal,
  • Harshit K. Gautam

摘要

Phishing attack is an analogy derived from “fishing” for victims. It is a malicious practice of deceiving individuals into divulging sensitive information. It remains a persistent threat in the digital landscape, undermining the integrity of communication networks, financial systems, and personal data security. Attackers trick people on the internet by making fake web pages that look real, trying to get personal information. People have come up with ways to stop this, like blacklists or whitelists, and other smart methods, but users still get attacked. In this paper, we suggest a machine learning and deep learning backed way to check if a URL is safe or not before someone clicks on it and gets attacked. Methods, especially those employing statistical learning algorithms for classification, have the issue of false positives. This paper adds to the expanding realm of cybersecurity knowledge by offering a novel way of detecting phishy websites using the header analysis as well as exploration of URL phishing, along with practical strategies for reducing its risks. Logistic Regression outperformed in URL analysis, followed by Random Forest and Support Vector Machine, meanwhile, CNN backed ResNet50 excelled in image analysis, followed by Support Vector Machine backed with feature extraction. ResNet50 maintained superiority across datasets, affirming its effectiveness for phishing image detection tasks.