The rise of phishing attacks threatens cybersecurity worldwide, attacking individuals, organizations, and vital infrastructure. Phishers use deceptive methods to deceive users into divulging sensitive information, often imitating legitimate websites. Early detection of phishing websites is an essential line of defense against these malicious activities. Traditional phishing detection methods often concentrate on URL analysis, blacklisting, or heuristic rules, which can be circumvented by attackers employing sophisticated techniques. Most researchers examine the phishing website’s URLs. Less attention is paid to the website textual contents analysis for phishing website detection due to its risky nature. The textual contents of the website pose essential information formation and offer a deeper and more comprehensive way to identify phishing risks. This chapter presents a novel method (Weighted Average Word2Vec—WAW2Vec) for detecting phishing websites based on the textual content of websites. To process the website’s content, the weighted average word embedding is deployed. Seven machine learning models are tested to assess performance. The outcome demonstrates that the weighted average word embedding with a random forest algorithm achieves 96% accuracy.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Leveraging Textual Web Content for Phishing Website Detection with Weighted Average Word Embedding and Machine Learning

  • Saleem Raja Abdul Samad,
  • Sundaravadivazhagan Balasubramaniyan,
  • Pradeepa Ganesan,
  • Madhavan Sridharan,
  • Justin Rajasekaran,
  • Amina Salim Mohammed Al Jabri

摘要

The rise of phishing attacks threatens cybersecurity worldwide, attacking individuals, organizations, and vital infrastructure. Phishers use deceptive methods to deceive users into divulging sensitive information, often imitating legitimate websites. Early detection of phishing websites is an essential line of defense against these malicious activities. Traditional phishing detection methods often concentrate on URL analysis, blacklisting, or heuristic rules, which can be circumvented by attackers employing sophisticated techniques. Most researchers examine the phishing website’s URLs. Less attention is paid to the website textual contents analysis for phishing website detection due to its risky nature. The textual contents of the website pose essential information formation and offer a deeper and more comprehensive way to identify phishing risks. This chapter presents a novel method (Weighted Average Word2Vec—WAW2Vec) for detecting phishing websites based on the textual content of websites. To process the website’s content, the weighted average word embedding is deployed. Seven machine learning models are tested to assess performance. The outcome demonstrates that the weighted average word embedding with a random forest algorithm achieves 96% accuracy.