Design and Development of a Machine Learning-Based System for Detection of Phishing Websites

Authors

  • Dr. Rajesh Kumar Sharma

DOI:

https://doi.org/10.64882/ijrt.v14.i3.1912

Keywords:

phishing websites, machine learning, random forest, website classification, grouped holdout

Abstract

Based on the UCI Phishing Websites dataset, a replicable machine learning system was created to categorise phishing websites. It consists of 11,055 tagged examples and 30 pre-computed website characteristics. Data examination showed 5,785 distinct feature vectors and a lot of recurring patterns. Then, a grouped holdout was used to keep the same feature vectors together while splitting. The experiment contrasted a decision tree, a random forest, and a majority class baseline using a similar training and testing process. The random forest achieved 96.13% accuracy, 95.51% phishing precision, 96.00% phishing recall, 95.75% phishing F1 and 0.9939 ROC AUC on 2,144 heldout data. The confusion matrix yielded 935 properly identified phishing records, 39 missed phishing records, 44 false warnings, and 1,126 correctly categorised real data. Additional threshold, repeated-split and feature-removal analysis further illuminate the stability and limitations of this finding. The provided Python implementation generates the tables, execution outputs and graphs. The programme takes the 30 characteristics that are provided; to categorise a raw URL, an extra matching extraction step and provide external validation would be required.

References

Breiman, L. (2001). Random forests. Machine Learning, 45(1), 5–32. https://doi.org/10.1023/A:1010933404324

Mohammad, R., & McCluskey, L. (2012). Phishing Websites [Data set]. UCI Machine Learning Repository. https://doi.org/10.24432/C51W2X

Mohammad, R. M., Thabtah, F., & McCluskey, L. (2012). An assessment of features related to phishing websites using an automated technique. In 2012 International Conference for Internet Technology and Secured Transactions (pp. 492–497). IEEE. https://ieeexplore.ieee.org/document/6470857

Sahingoz, O. K., Buber, E., Demir, O., & Diri, B. (2019). Machine learning based phishing detection from URLs. Expert Systems with Applications, 117, 345–357. https://doi.org/10.1016/j.eswa.2018.09.029

scikit-learn developers. (n.d.). GroupShuffleSplit [Software documentation]. https://scikit-learn.org/stable/modules/generated/sklearn.model_selection.GroupShuffleSplit.html

Xiang, G., Hong, J., Rose, C. P., & Cranor, L. (2011). CANTINA+: A feature-rich machine learning framework for detecting phishing web sites. ACM Transactions on Information and System Security, 14(2), Article 21. https://doi.org/10.1145/2019599.2019606

Zhang, Y., Hong, J. I., & Cranor, L. F. (2007). CANTINA: A content-based approach to detecting phishing web sites. In Proceedings of the 16th International Conference on World Wide Web (pp. 639–648). ACM. https://doi.org/10.1145/1242572.1242659

Sahingoz, O. K., Buber, E., Demir, O., & Diri, B. (2019). Machine learning based phishing detection from URLs. Expert Systems with Applications, 117, 345–357. DOI: 10.1016/j.eswa.2018.09.029.

Chiew, K. L., Tan, C. L., Wong, K. S., Yong, K. S. C., & Tiong, W. K. (2019). A new hybrid ensemble feature selection framework for machine learning-based phishing detection system. Information Sciences, 484, 153–166. DOI: 10.1016/j.ins.2019.01.064.

Yang, P., Zhao, G., & Zeng, P. (2019). Phishing website detection based on multidimensional features driven by deep learning. IEEE Access, 7, 15196–15209. DOI: 10.1109/ACCESS.2019.2892066.

Jain, A. K., & Gupta, B. B. (2018). Towards detection of phishing websites on client-side using machine learning based approach. Telecommunication Systems, 68, 687–700. DOI: 10.1007/s11235-017-0414-0.

Aljofey, A., Jiang, Q., Rasool, A., Chen, H., Liu, W., Qu, Q., & Wang, Y. (2022). An effective detection approach for phishing websites using URL and HTML features. Scientific Reports, 12, 8842. DOI: 10.1038/s41598-022-10841-5.

Ahammad, S. K. H., Kale, S. D., Upadhye, G. D., Pande, S. D., Babu, E. V., Dhumane, A. V., & Jang Bahadur, D. K. (2022). Phishing URL detection using machine learning methods. Advances in Engineering Software, 173, 103288. DOI: 10.1016/j.advengsoft.2022.103288.

Hannousse, A., & Yahiouche, S. (2021). Towards benchmark datasets for machine learning based website phishing detection: An experimental study. Engineering Applications of Artificial Intelligence, 104, 104347. DOI: 10.1016/j.engappai.2021.104347.

Al-Sarem, M., Saeed, F., Al-Mekhlafi, Z. G., Mohammed, B. A., Al-Hadhrami, T., Alshammari, M. T., Alreshidi, A., & Alshammari, T. S. (2021). An optimized stacking ensemble model for phishing websites detection. Electronics, 10(11), 1285. DOI: 10.3390/electronics10111285.

Prasad, A., & Chandra, S. (2024). PhiUSIIL: A diverse security profile empowered phishing URL detection framework based on similarity index and incremental learning. Computers & Security, 136, 103545. DOI: 10.1016/j.cose.2023.103545.

Xiang, G., Hong, J., Rose, C. P., & Cranor, L. (2011). CANTINA+: A feature-rich machine learning framework for detecting phishing web sites. ACM Transactions on Information and System Security, 14(2), Article 21, 1–28. DOI: 10.1145/2019599.2019606.

Mohammad, R. M., Thabtah, F., & McCluskey, L. (2014). Predicting phishing websites based on self-structuring neural network. Neural Computing and Applications, 25(2), 443–458. DOI: 10.1007/s00521-013-1490-z.

Abdelhamid, N., Ayesh, A., & Thabtah, F. (2014). Phishing detection based associative classification data mining. Expert Systems with Applications, 41(13), 5948–5959. DOI: 10.1016/j.eswa.2014.03.019.

Marchal, S., François, J., State, R., & Engel, T. (2014). PhishStorm: Detecting phishing with streaming analytics. IEEE Transactions on Network and Service Management, 11(4), 458–471. DOI: 10.1109/TNSM.2014.2377295.

Marchal, S., Saari, K., Singh, N., & Asokan, N. (2016). Know your phish: Novel techniques for detecting phishing sites and their targets. 2016 IEEE 36th International Conference on Distributed Computing Systems (ICDCS), 323–333. DOI: 10.1109/ICDCS.2016.10.

Zouina, M., & Outtaj, B. (2017). A novel lightweight URL phishing detection system using SVM and similarity index. Human-centric Computing and Information Sciences, 7, 17. DOI: 10.1186/s13673-017-0098-1.

Mao, J., Tian, W., Li, P., Wei, T., & Liang, Z. (2017). Phishing-Alarm: Robust and efficient phishing detection via page component similarity. IEEE Access, 5, 17020–17030. DOI: 10.1109/ACCESS.2017.2743528.

Ma, J., Saul, L. K., Savage, S., & Voelker, G. M. (2009). Beyond blacklists: Learning to detect malicious web sites from suspicious URLs. Proceedings of the 15th ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, 1245–1254. DOI: 10.1145/1557019.1557153.

Le, A., Markopoulou, A., & Faloutsos, M. (2011). PhishDef: URL names say it all. Proceedings of IEEE INFOCOM 2011. DOI: 10.1109/INFCOM.2011.5934995.

Wei, W., Ke, Q., Nowak, J., Korytkowski, M., Scherer, R., & Woźniak, M. (2020). Accurate and fast URL phishing detector: A convolutional neural network approach. Computer Networks, 178, 107275. DOI: 10.1016/j.comnet.2020.107275.

Alani, M. M., & Tawfik, H. (2022). PhishNot: A cloud-based machine-learning approach to phishing URL detection. Computer Networks, 218, 109407. DOI: 10.1016/j.comnet.2022.109407.

Downloads

How to Cite

Dr. Rajesh Kumar Sharma. (2026). Design and Development of a Machine Learning-Based System for Detection of Phishing Websites. International Journal of Research & Technology, 14(3), 1399–1415. https://doi.org/10.64882/ijrt.v14.i3.1912

Similar Articles

<< < 28 29 30 31 32 33 34 35 36 37 > >> 

You may also start an advanced similarity search for this article.