结合关联规则与SVM,提升钓鱼网站识别准确率至98.3%。
A Predicting Phishing Websites Using Support Vector Machine and MultiClass Classification Based on Association Rule Techniques
- 用关联规则生成特征与规则,SVM进行多分类预测。
- 达98.30%准确率,AUC为98%,误判率极低。
- 适合网络安全研究者与反钓鱼系统开发者参考。
钓鱼攻击是一种针对用户的语义攻击,相较于病毒和黑客攻击,是新兴的网络犯罪。由于钓鱼网站导致组织崩溃、信息窃取和资金转移,造成重大经济损失,学者们虽尝试多种检测方法,但尚未达成最优算法共识。本研究整合支持向量机(SVM)与基于关联规则的多类分类(MCAR)技术,构建混合模型以提升钓鱼网站预测能力。实验使用来自PhishTank和Yahoo目录的11,056个网站数据。MCAR用于特征提取与规则生成,SVM负责分类与预测。结果表明,该方法实现98.30%分类准确率,计算耗时2205.33秒,误差率最低;AUC达到98%,显示分类性能优异;系数决定度达82.84%,表明模型对钓鱼网站预测具有较强解释力。融合两技术优势,显著提升检测精度。
原文摘要 · Abstract (English)
Phishing is a semantic attack which targets the user rather than the computer. It is a new Internet crime in comparison with other forms such as virus and hacking. Considering the damage phishing websites has caused to various economies by collapsing organizations, stealing information and financial diversion, various researchers have embarked on different ways of detecting phishing websites but there has been no agreement about the best algorithm to be used for prediction. This study is interested in integrating the strengths of two algorithms, Support Vector Machines (SVM) and Multi-Class Classification Rules based on Association Rules (MCAR) to establish a strong and better means of predicting phishing websites. A total of 11,056 websites were used from both PhishTank and yahoo directory to verify the effectiveness of this approach. Feature extraction and rules generation were done by the MCAR technique; classification and prediction were done by SVM technique. The result showed that the technique achieved 98.30% classification accuracy with a computation time of 2205.33s with minimum error rate. It showed a total of 98% Area under the Curve (AUC) which showed the proportion of accuracy in classifying phishing websites. The model showed 82.84% variance in the prediction of phishing websites based on the coefficient of determination. The use of two techniques together in detecting phishing websites produced a more accurate result as it combined the strength of both techniques respectively. This research work centralized on this advantage by building a hybrid of two techniques to help produce a more accurate result.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。