paper-with-me

홈 › Papers

Can Features for Phishing URL Detection Be Trusted Across Diverse Datasets? A Case Study with Explainable AI

2024-11-14 · Maraz Mia, Darius Derakhshan, Mir Mehedi A. Pritom

Phishing has been a prevalent cyber threat that manipulates users into revealing sensitive private information through deceptive tactics, designed to masquerade as trustworthy entities. Over the years, proactively detection of phishing URLs (or websites) has been established as an widely-accepted defense approach. In literature, we often find supervised Machine Learning (ML) models with highly competitive performance for detecting phishing websites based on the extracted features from both phishing and benign (i.e., legitimate) websites. However, it is still unclear if these features or indicators are dependent on a particular dataset or they are generalized for overall phishing detection. In this paper, we delve deeper into this issue by analyzing two publicly available phishing URL datasets, where each dataset has its own set of unique and overlapping features related to URL string and website contents. We want to investigate if overlapping features are similar in nature across datasets and how does the model perform when trained on one dataset and tested on the other. We conduct practical experiments and leverage explainable AI (XAI) methods such as SHAP plots to provide insights into different features' contributions in case of phishing detection to answer our primary question, "Can features for phishing URL detection be trusted across diverse dataset?". Our case study experiment results show that features for phishing URL detection can often be dataset-dependent and thus may not be trusted across different datasets even though they share same set of feature behaviors.

📄 PDF Abstract BibTeX arXiv:2411.09813

Code (0)

등록된 구현이 없습니다.

Methods 이 논문이 사용한 방법론

SET Dynamic Sparse Training method where weight mask is updated randomly periodically
SHAP 설명 없음

Similar Papers 제목 키워드 기반

VisualPhishNet: Zero-Day Phishing Website Detection by Visual Similarity

2019-09-01 · Sahar Abdelnabi, Katharina Krombholz, Mario Fritz

Phishing websites are still a major threat in today's Internet ecosystem. Despite numerous previous efforts, similarity-based detection methods do not offer sufficient protection for the trusted websites - in particular …

Phishing Website DetectionTripletvalid

Towards Web Phishing Detection Limitations and Mitigation

2022-04-03 · Alsharif Abuadbba, Shuo Wang, Mahathir Almashor, Muhammed Ejaz Ahmed 외

Web phishing remains a serious cyber threat responsible for most data breaches. Machine Learning (ML)-based anti-phishing detectors are seen as an effective countermeasure, and are increasingly adopted by web-browsers an…

Attribute

Next-Generation Phishing: How LLM Agents Empower Cyber Attackers

2024-11-21 · Khalifa Afane, Wenqi Wei, Ying Mao, Junaid Farooq 외

The escalating threat of phishing emails has become increasingly sophisticated with the rise of Large Language Models (LLMs). As attackers exploit LLMs to craft more convincing and evasive phishing emails, it is crucial …

Data Augmentation

RAIDER: Reinforcement-aided Spear Phishing Detector

2021-05-17 · Keelan Evans, Alsharif Abuadbba, Tingmin Wu, Kristen Moore 외

Spear Phishing is a harmful cyber-attack facing business and individuals worldwide. Considerable research has been conducted recently into the use of Machine Learning (ML) techniques to detect spear-phishing emails. ML-b…

Binary Classificationreinforcement-learningReinforcement Learning (RL)

Fuzzy Rough Set Feature Selection to Enhance Phishing Attack Detection

2019-03-13 · Mahdieh Zabihimayvan, Derek Doran

Phishing as one of the most well-known cybercrime activities is a deception of online users to steal their personal or confidential information by impersonating a legitimate website. Several machine learning-based strate…

feature selection