Browser Extension for Phishing Website Detection Using Machine Learning
DOI:
https://doi.org/10.21467/proceedings.7.5.5Keywords:
Browser Extension, Phishing Website Detection, Machine LearningAbstract
Phishing remains a major cybersecurity concern, where attackers steal sensitive data. Traditional methods of detection, such as blacklists and rule-based systems, tend to fail to detect new or emerging threats. To address this gap, we propose a machine learning–based browser extension that detects phishing websites in real time. The extension silently operates in the background of a user's web browser, examining factors including URL structure, webpage content, domain legitimacy, and visual signals to accurately classify them. Fundamentally, at its center is an XGBoostclassifier that has been trained on a well-filtered and varied dataset. When a phishing attempt is recognized, users are promptly notified with no perceptible interruption to their browsing session. The system achieved 95% accurate during testing and has good precision and recall rates that indicate its robustness. This lightweight and efficient tool not only secures users against online attacks but also learns to keep up with evolving attack trends. In the future, we intend to investigate deep learning methods and add support to additional browsers, solidifying user security in cyberspace.
References
[1] R. Verma and K. Das, “Suspicious URL Detection Using URL and Host-Based Features,” Proceedings of the 3rd ACM Workshop on Security and Artificial Intelligence, pp. 49–54, Oct. 2010. Access online on 30 May 2025 at https://dl.acm.org/doi/10.1145/1866423.1866435
[2] N. Abdelhamid, A. Ayesh, and F. Thabtah, “Phishing detection based on rough set theory,” Expert Systems with Applications, vol. 41, no. 13, pp. 5948–5959, Oct. 2014. Access online on 30 May 2025 at https://www.sciencedirect.com/science/article/pii/S0957417414001972
[3] R. B. Basnet, A. H. Sung, and Q. Liu, “Learning to detect phishing URLs,” International Journal of Research in Engineering and Technology, vol. 3, no. 6, pp. 11–24, June 2014. Access online on 30 May 2025 at https://ijret.org/volumes/2014v03/i06/IJRET20140306003.pdf
[4] Y. Zhang, J. Hong, and L. Cranor, “CANTINA: A content-based approach to detecting phishing web sites,” Proceedings of the 16th International Conference on World Wide Web (WWW '07), pp. 639–648, May 2007. Access online on 30 May 2025 at https://www.cs.cmu.edu/~pongle/phishing.pdf
[5] W. Liu, X. Deng, G. Huang, and A. Y. Fu, “An anti-phishing strategy based on visual similarity assessment,” IEEE Internet Computing, vol. 10, no. 2, pp. 58–65, Mar.–Apr. 2006. Access online on 30 May 2025 at https://ieeexplore.ieee.org/document/1607723
[6] J. Friedman, T. Hastie, and R. Tibshirani, The Elements of Statistical Learning: Data Mining, Inference, and Prediction, 2nd ed., Springer, 2009. Access online on 30 May 2025 at https://link.springer.com/book/10.1007/978-0-387-84858-7
Downloads
Published
Issue
Section
License

This work is licensed under a Creative Commons Attribution-NonCommercial 4.0 International License.