Bài viết
Nâng cao hiệu quả mô hình học máy trong phát hiện tấn công lừa đảo website sử dụng đặc điểm hình thái trong phân tích URL
- Đặng Thị Mai (VN)
- Nguyễn Việt Hùng (VN)
Tóm tắt
Cùng với việc Internet ngày càng phát triển nhanh chóng thì những mối đe dọa cũng xuất hiện ngày càng nhiều, nổi bật là mối đe dọa về các website lừa đảo (phishing). Các website phishing được tạo ra với những nội dung nguy hại với mục đích tấn công vào người sử dụng truy cập vào chúng. Thủ đoạn tấn công này tiềm ẩn nguy cơ lớn đối với người dùng trên không gian mạng. Bài toán phát hiện và bóc gỡ những website phishing đã được quan tâm và nghiên cứu rộng rãi trong cộng đồng. Trong nghiên cứu này, chúng tôi đề xuất bộ thuộc tính hình thái trong phân tích đường dẫn URL, kết hợp với các phương pháp học máy để phát hiện ra các URL của các website lừa đảo. Kết quả đánh giá thử nghiệm trên bộ dữ liệu UCI Repository đã chứng minh tính hiệu quả của bộ thuộc tính trong phát hiện website phishing so với các phương pháp trước đây cả về các độ đo đánh giá (Accuracy, Precision, Recall và F1 Score).
Lượt tải theo tháng
Di chuột vào cột để xem số lượt tải.
Cách trích dẫn
Đặng Thị Mai, Nguyễn Việt Hùng (2024). Nâng cao hiệu quả mô hình học máy trong phát hiện tấn công lừa đảo website sử dụng đặc điểm hình thái trong phân tích URL. Tạp chí Khoa học và Công nghệ trong lĩnh vực An toàn thông tin, 2(22), 49-57. https://doi.org/10.54654/isj.v2i22.1040
Tiểu sử tác giả
Đặng Thị Mai
She received her BSc, MSc in Applied Mathematics and Informatics from Hanoi university of Natural Science, PhD degrees in Applied Mathematics from Moscow Institute of Physics and Technology in 2012.
Tài liệu tham khảo
- 1.Number of unique phishing sites detected worldwide from 3rd quarter 2013 to 1st quarter 2024 - https://www.statista.com/ - Last accessed: 6/2024.
- 2.Narendra. M. Shekokar, Chaitali Shah, Mrunal Mahajan, Shruti Rachh, An Ideal Approach for Detection and Prevention of Phishing Attacks, Procedia Computer Science, Volume 49, 2015, Pages 82-91.
- 3.S. A. Murad, N. Rahimi and A. J. Md Muzahid, "PhishGuard: Machine Learning-Powered Phishing URL Detection," 2023 Congress in Computer Science, Computer Engineering, & Applied Computing (CSCE), Las Vegas, NV, USA, 2023, pp. 2279-2284.
- 4.M. Aydin and N. Baykal, "Feature extraction and classification phishing websites based on URL," 2015 IEEE Conference on Communications and Network Security (CNS), Florence, Italy, 2015, pp. 769-770
- 5.Rami M. Mohammad, Fadi Thabtah, and Lee McCluskey.Phishing websites features, 2015. Unpublished. Available via:http://eprints.hud.ac.uk/24330/6/RamiPhishing_Websites_Features.pdf.
- 6.J. Kumar, A. Santhanavijayan, B. Janet, B. Rajendran and B. S. Bindhumadhava, "Phishing Website Classification and Detection Using Machine Learning," 2020 International Conference on Computer Communication and Informatics (ICCCI), Coimbatore, India, 2020, pp. 1-6.
- 7.Mehmet Korkmaz, Ozgur Koray Sahingoz, Banu Diri, Detection of phishing websites by using machine learning-based URL analysis, 11nth International Conference on Computing, Communication and Networking Technologies(ICCCNT), 2020.
- 8.M. N. Alam, D. Sarma, F. F. Lima, I. Saha, R. -E. -. Ulfath and S. Hossain, "Phishing Attacks Detection using Machine Learning Approach," 2020 Third International Conference on Smart Systems and Inventive Technology (ICSSIT), Tirunelveli, India, 2020, pp. 1173-1179.
- 9.Subasi, A.; Molah, E.; Almkallawi, F.; Chaudhery, T.J. Intelligent phishing website detection using random forest classifier. In Proceedings of the International Conference on Electrical and Computing Technologies and Applications (ICECTA), Phuket, Thailand, 12–13 October 2017; pp. 1–5.
- 10.Rishikesh Mahajan, and Irfan Siddavatam, Phishing website detection using machine learning algorithms, International Journal of Computer Applications(0975-8887), vol. 181, no. 23, 2018.
- 11.Khan, S.A.; Khan, W.; Hussain, A. Phishing Attacks and Websites Classification Using Machine Learning and Multiple Datasets (A Comparative Analysis). In Intelligent Computing Methodologies: 16th International Conference, ICIC 2020, Bari, Italy, 2–5 October 2020, Proceedings, Part III; Lecture Notes in Computer Science; Springer: Cham, Switzerland, 2020; Volume 12465.
- 12.Saleem Raja Abdul Samad, Sundarvadivazhagan Balasubaramanian, Amna Salim Al-Kaabi, Bhisham Sharma, Subrata Chowdhury, Abolfazl Mehbodniya, Julian L. Webber and Ali Bostani. Analysis of the Performance Impact of Fine-Tuned Machine Learning Model for Phishing URL Detection-Electronics 2023, 12, 1642.
- 13.S. C. Jeeva and E. B. Rajsingh, “Intelligent phishing url detection using association rule mining,” Human-centric Computing and Information Sciences, vol. 6, no. 1, Oct. 2016.
- 14.Thang, N. M., Anh, L. Q., Toan, H. S., & Trung, N. Q. (2023). A novel method for detecting URLs phishing using hybrid machine learning algorithm. Journal of Science and Technology on Information Security, 2(19), 15-28. https://doi.org/10.54654/isj.v2i19.978.
- 15.M.Babagoli, M. P.Aghababa, and V.Solouk, “Heuristic nonlinear regression strategy for detecting phishing websites,” Soft Computing, vol. 23, no. 12, pp. 4315–4327, 2018.
- 16.Shaoming Chen, Yiyang Wang, and Xingkai Cheng. An approach for detecting phishing websites by using search engine. In Proceedings of the 2023 4th International Conference on Machine Learning and Computer Application (ICMLCA '23).
- 17.Cho Do Xuan, Hoa Dinh Nguyen and Tisenko Victor Nikolaevich, “Malicious URL Detection based on Machine Learning” International Journal of Advanced Computer Science and Applications(IJACSA), 11(1), 2020. http://dx.doi.org/10.14569/IJACSA.2020.0110119.
- 18.Mohammad, R.; McCluskey, T.L.; Thabtah, F. UCI Machine Learning Repository: Phishing Websites Data Set. Available online: https://archive.ics.uci.edu/dataset/327/phishing+websites (accessed on 20 March, 2024).
- 19.Dutta AK. Detecting phishing websites using machine learning technique. PLoS One. 2021 Oct 11;16(10):e0258361. doi: 10.1371/journal.pone.0258361. PMID: 34634081; PMCID: PMC8504731.
- 20.S. Anderson, “A-Morphous Morphology” (2011). Cambridge University Press.
Bài viết liên quan
- Phát triển Framework ứng dụng AI hỗ trợ tự động khai thác lỗ hổng bảo mật
- Applying reinforcement learning in automated penetration testing
- Tự động chọn hàm bị loại bỏ trong kiểm thử bản vá khi sử dụng Thực thi tượng trưng lược bớt
- Ứng dụng mô hình học sâu trong phát hiện tấn công trinh sát mạng
- Nền tảng phân loại tấn công mạng dựa vào mô hình Autoencoder và công nghệ phân tích luồng trực tuyến
- Nâng cao hiệu quả phát hiện mã độc của mô hình deeplearning với phương pháp biểu diễn ảnh mới