Bài viết
Phương pháp mới phát hiện URL lừa đảo sử dụng thuật toán học máy kết hợp
- Nguyễn Mạnh Thắng · Academy of Cryptography Techniques (VN)
- Lê Quang Anh (VN)
- Hứa Song Toàn (VN)
- Nguyễn Quốc Trung (VN)
Tóm tắt
Tóm tắt—Tấn công lừa đảo là một loại tấn công mạng nhắm vào sự tin tưởng của người dùng bằng cách che giấu ý đồ ác ý của cuộc tấn công dưới dạng thông tin của các nguồn có uy tín. Mục tiêu là lấy cắp dữ liệu nhạy cảm của nạn nhân (thông tin ngân hàng, nhân dạng xã hội, thông tin đăng nhập,...) với nhiều mục đích khác nhau (bán để kiếm lợi nhuận, thực hiện việc đánh cắp danh tính, sử dụng như một đòn bẩy cho cuộc tấn công leo thang). Vào năm 2022, số lượng cuộc tấn công lừa đảo được báo cáo sẽ đạt đến con số khổng lồ là 255 triệu trường hợp, tăng 61% so với năm 2021. Bên cạnh đó các phương pháp hiện có để phát hiện đường dẫn URL lừa đảo bộc lộ nhiều sự hạn chế. Bài báo đề xuất một phương pháp để tăng độ chính xác trong việc phát hiện các URL độc hại bằng cách sử dụng các phương pháp học máy Vector Hỗ trợ Tuyến tính và đa thức Naive Bayes kết hợp với kĩ thuật voting (bỏ phiếu).
Lượt tải theo tháng
Di chuột vào cột để xem số lượt tải.
Cách trích dẫn
Nguyễn Mạnh Thắng, Lê Quang Anh, Hứa Song Toàn, Nguyễn Quốc Trung (2023). Phương pháp mới phát hiện URL lừa đảo sử dụng thuật toán học máy kết hợp. Tạp chí Khoa học và Công nghệ trong lĩnh vực An toàn thông tin, 2(19), 15-28. https://doi.org/10.54654/isj.v2i19.978
Tài liệu tham khảo
- 1.. What is URL phishing [Digital resource].– URL: https://surfshark.com/blog/what-is-url-phishing (access date: 15.12.2022).
- 2.. Charan A. N. S., Chen Y. H., Chen J. L. Phishing Websites Detection using Machine Learning with URL Analysis /2022 IEEE World Conference on Applied Intelligence and Computing (AIC).– IEEE, 2022.– P. 808-812.
- 3.. Uddin M. M. et al. A Comparative Analysis of Machine Learning-Based Website Phishing Detection Using URL Information //2022 5th International Conference on Pattern Recognition and Artificial Intelligence (PRAI).– IEEE, 2022.– P. 220-224.
- 4.. Sindhu S. et al. Phishing detection using random forest, SVM and neural network with backpropagation //2020 International Conference on Smart Technologies in Computing, Electrical and Electronics (ICSTCEE).– IEEE, 2020, – P. 391-394.
- 5.. Athulya A. A., Praveen K. Towards the detection of phishing attacks //2020 4th international conference on trends in electronics and informatics (ICOEI)(48184).– IEEE, 2020, – P. 337-343.
- 6.. Bouijij H., Berqia A. Machine learning algorithms evaluation for phishing URL classification //2021 4th International Symposium on Advanced
- 7.Electrical and Communication Technologies (ISAECT).– IEEE, 2021.– P. 01-05.
- 8.. Amen K., Zohdy M., Mahmoud M. Machine Learning for Multiple Stage Phishing URL Prediction //2021 International Conference on
- 9.Computational Science and Computational Intelligence (CSCI).– IEEE, 2021.– P. 794-800.
- 10.. Dr U. S., Patil A., Mohana M. Malicious URL Detection and Classification Analysis using Machine Learning Models //2023 International Conference on Intelligent Data Communication Technologies and Internet of Things (IDCIoT).– IEEE, 2023.– P. 470-476.
- 11.. Phising and Benign Websites [Digital resource] ¬– URL: https://www.kaggle.com/datasets/peyamowar/phishing-and-benign- website (access date: 15.12.2022.).
- 12.. Phising Site URL [Digital resource].– URL: https://www.kaggle.com/datasets/taruntiwarihp/phishing-site-URL (access date 15.12.2022).
- 13.. Urlib.parse library [Digital resource].– URL: https://docs.python.org/3/library/urllib.parse.html (access date: 15.12.2022).
- 14.. Linear support vector classifier [Digital resource].– URL: https://scikitlearn.org/stable/modules/generated/sklearn.svm.LinearSVC.html (access date: 15.12.2022).
- 15.. Logistic regression [Digital resource].– URL: https://scikitlearn.org/stable/modules/generated/sklearn.linear model.LogisticRegression.html (access date: 15.12.2022).
- 16.. Multinomial naive Bayes [Digital resource].– URL: https://scikitlearn.org/stable/modules/generated/sklearn.naive bayes.MultinomialNB.html (access date: 15.12.2022).
- 17.. Decision tree classifier [Digital resource].– URL: https://scikitlearn.org/stable/modules/generated/sklearn.tree.DecisionTreeClassifier.html
- 18.(access date: 15.12.2022).
- 19.. Random forest classifier [Digital resource].– URL: https://scikitlearn.org/stable/modules/generated/sklearn.ensemble.RandomForestClassifier.html (access date: 15.12.2022)
- 20.. Voting classifier [Digital resource].– URL: https://scikitlearn.org/stable/modules/generated/sklearn.ensemble.VotingClassifier.html (access date: 15.12.2022).
- 21.. Thang, N. M., & Luong, T. T. (2022). Algorithm for detecting attacks on Web applications based on machine learning methods and attributes queries. Journal of Science and Technology on Information Security, 2(14), 26-34.
Bài viết liên quan
- Algorithm for detecting attacks on Web applications based on machine learning methods and attributes queries
- A new approach to improving web application firewall performance based on support vector machine method with analysis of Http request
- A new approach to improving web application firewall performance based on support vector machine method with analysis of Http request
- AI-Enhanced SQL Injection Detection Framework: A Novel Approach Combines LLMs with Traditional Fuzzing to Improve Web Application Vulnerability Detection