Back to Search Start Over

Machine learning models for phishing detection from TLS traffic.

Authors :
Kumar, Munish
Kondaiah, Cheemaladinne
Pais, Alwyn Roshan
Rao, Routhu Srinivasa
Source :
Cluster Computing. Oct2023, Vol. 26 Issue 5, p3263-3277. 15p.
Publication Year :
2023

Abstract

Phishing is a fraudulent tactic for attackers to obtain victims personal information, such as passwords, account details, credit card details, and other sensitive information. Existing anti-phishing detection methods using at the application layer and cannot be applied at the transport layer. A novel machine learning (ML) based phishing detection technique from transport layer security (TLS) 1.2 and TLS 1.3 encrypted traffic without decryption is proposed in this paper. Our proposed model detects phishing URLs at the transport layer and classifies them as legitimate or phishing. The features are extracted from TLS 1.2 and TLS 1.3 traffic, and phishing detection is performed using ML algorithms based on the extracted features. The datasets for legitimate and phishing sites are created using features derived from TLS 1.2 and TLS 1.3 traffic. According to the experimental results, the proposed model effectively detects phishing URLs in encrypted traffic. The proposed model achieves an accuracy of 93.63% for Random Forest (RF), 95.07% for XGBoost (XGB), and the highest accuracy of 95.40% for Light GBM (LGBM). [ABSTRACT FROM AUTHOR]

Details

Language :
English
ISSN :
13867857
Volume :
26
Issue :
5
Database :
Academic Search Index
Journal :
Cluster Computing
Publication Type :
Academic Journal
Accession number :
170716741
Full Text :
https://doi.org/10.1007/s10586-023-04042-6