International Peer-Reviewed Journal•Open Access•ISSN 2456-8880
irejournals@gmail.com•+91-7433024337

Home / Current Issue / Paper 1716247

1716247 Vol 9 · Issue 10 Download Paper

Phishing Website Detection Using Machine Learning

Mugunthan Kennedy K Dr. S. Sridevi Hariesh Kumar P Nanthakumar R

Subject area: Science,Engineering and Technology  ·  Area of research: Cybersecurity

DOI: 10.64388/IREV9I10-1716247

Abstract

Phishing attacks have been one of the biggest cybersecurity concerns, where attackers develop fraudulent websites that resemble legitimate online services to steal critical user information such as login credentials, bank account information, and other sensitive information. The conventional anti-phishing detection systems, such as blacklist-based systems, rule-based systems, etc., are found to be less effective in handling the detection of new phishing sites that emerge frequently in the world wide web. To overcome the limitations of the conventional systems, the authors of the current research propose a supervised machine learning-based anti-phishing detection system using a set of discriminative features extracted from the address bar, domain-based features, and other components of the webpage such as HTML and JavaScript code. A set of machine learning and deep learning-based classifiers have been trained and tested using a balanced set of legitimate and phishing URLs to evaluate the performance of the proposed system. The experimental results show that the proposed system achieves better performance in terms of accuracy, precision, and recall using ensemble-based models such as XGBoost in comparison to other state-of-the-art models.

Keywords

Phishing Detection, Machine Learning, Cyber Security, URL Features, Ensemble Learning.

References

[1] J. Ma, L. K. Saul, S. Savage, and G. M. Voelker, “Beyond blacklists: Learning to detect malicious web sites from suspicious URLs,” in Proceedings of the 15th ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, Paris, France, 2009, pp. 1245–1254.

[2] N. Abdelhamid, A. Ayesh, and F. Thabtah, “Phishing detection based associative classification data mining,” Expert Systems with Applications, vol. 41, no. 13, pp. 5948–5959, 2014.

[3] S. Marchal, G. Armano, T. Grondahl, K. Saari, N. Singh, N. Asokan, and A. Francillon, “Off-the-Hook: An efficient and usable client-side phishing prevention application,” IEEE Transactions on Computers, vol. 66, no. 10, pp. 1717–1733, 2016.

[4] K. L. Chiew, E. H. Chang, S. N. Sze, and W. K. Tiong, “Utilisation of website features for phishing detection,” Computers & Security, vol. 50, pp. 84–92, 2015.

[5] O. K. Sahingoz, E. Buber, O. Demir, and B. Diri, “Machine learning based phishing detection from URLs,” Expert Systems with Applications, vol. 117, pp. 345–357, 2019.

[6] UCI Machine Learning Repository, “Phishing Websites Data Set,” University of California, Irvine, 2019. Available: https://archive.ics.uci.edu/ml

[7] H. Le, Q. Pham, D. Sahoo, and S. C. H. Hoi, “URLNet: Learning a URL representation with deep learning for malicious URL detection,” in Proceedings of the 25th International World Wide Web Conference, 2018, pp. 93–102.

[8] F. Salahdine and N. Kaabouch, “Social engineering attacks: A survey,” Future Internet, vol. 11, no. 4, p. 89, 2020.

[9] R. Routh and D. Kshirsagar, “Phishing website detection using machine learning techniques,” International Journal of Computer Applications, vol. 174, no. 12, pp. 1–6, 2021.

[10] M. Aljabri, S. AlGhamdi, K. Almarhabi, and F. Alharbi, “Improved phishing website detection using ensemble machine learning techniques,” Applied Sciences, vol. 13, no. 8, p. 4649, 2023.

[11] S. Garera, N. Provos, M. Chew, and A. D. Rubin, “A framework for detection and measurement of phishing attacks,” in Proceedings of the 2007 ACM Workshop on Recurring Malcode, Alexandria, VA, USA, 2007, pp. 1–8.

[12] R. Verma and N. Das, “What you tweet matters: A new approach to phishing detection using machine learning,” in Proceedings of the 2017 IEEE International Conference on Data Mining Workshops (ICDMW), New Orleans, LA, USA, 2017, pp. 1109–1114.

[13] M. Aburrous, M. A. Hossain, F. Thabtah, and K. Dahal, “Intelligent phishing detection system for e-banking using fuzzy data mining,” Expert Systems with Applications, vol. 37, no. 12, pp. 7913–7921, 2010.

[14] Y. Zhang, J. Hong, and L. Cranor, “Cantina: A content-based approach to detecting phishing web sites,” in Proceedings of the 16th International World Wide Web Conference, Banff, Canada, 2007, pp. 639–648.

[15] M. Khonji, Y. Iraqi, and A. Jones, “Phishing detection: A literature survey,” IEEE Communications Surveys & Tutorials, vol. 15, no. 4, pp. 2091–2121, 2013.

How to cite this paper

Mugunthan Kennedy K, Dr. S. Sridevi, Hariesh Kumar P, Nanthakumar R "Phishing Website Detection Using Machine Learning" Iconic Research And Engineering Journals Volume 9 Issue 10 2026 Page 1292-1299 https://doi.org/10.64388/IREV9I10-1716247
Mugunthan Kennedy K, Dr. S. Sridevi, Hariesh Kumar P, Nanthakumar R "Phishing Website Detection Using Machine Learning" Iconic Research And Engineering Journals, vol. 9, no. 10, Apr. 2026, doi: https://doi.org/10.64388/IREV9I10-1716247
Mugunthan Kennedy K, Dr. S. Sridevi, Hariesh Kumar P, Nanthakumar R (2026). Phishing Website Detection Using Machine Learning. Iconic Research And Engineering Journals, 9(10). doi: https://doi.org/10.64388/IREV9I10-1716247
Mugunthan Kennedy K, Dr. S. Sridevi, Hariesh Kumar P, Nanthakumar R "Phishing Website Detection Using Machine Learning" Iconic Research And Engineering Journals, vol. 9, no. 10, Apr. 2026. Crossref, https://doi.org/10.64388/IREV9I10-1716247
@article{1716247,
      author = {Mugunthan Kennedy K, Dr. S. Sridevi, Hariesh Kumar P, Nanthakumar R},
      title = {Phishing Website Detection Using Machine Learning},
      journal = {Iconic Research And Engineering Journals},
      year = {2026},
      volume = {9},
      number = {10},
      pages = {1292-1299},
      issn = {2456-8880},
      url = {https://www.irejournals.com/formatedpaper/1716247.pdf},
      abstract = {Phishing attacks have been one of the biggest cybersecurity concerns, where attackers develop fraudulent websites that resemble legitimate online services to steal critical user information such as login credentials, bank account information, and other sensitive information. The conventional anti-phishing detection systems, such as blacklist-based systems, rule-based systems, etc., are found to be less effective in handling the detection of new phishing sites that emerge frequently in the world wide web. To overcome the limitations of the conventional systems, the authors of the current research propose a supervised machine learning-based anti-phishing detection system using a set of discriminative features extracted from the address bar, domain-based features, and other components of the webpage such as HTML and JavaScript code. A set of machine learning and deep learning-based classifiers have been trained and tested using a balanced set of legitimate and phishing URLs to evaluate the performance of the proposed system. The experimental results show that the proposed system achieves better performance in terms of accuracy, precision, and recall using ensemble-based models such as XGBoost in comparison to other state-of-the-art models.},
      keywords = {Phishing Detection, Machine Learning, Cyber Security, URL Features, Ensemble Learning.},
      month = {April},
      doi = {https://doi.org/10.64388/IREV9I10-1716247}
  }