Abstract
Most phishing attacks succeed because the ignorant victims enter their credentials after clicking on a fraudulent link. These deceptive links often result from domain squatting or URL obfuscation, also known as brand-jacking tactics, involve subtle alterations to original URLs. However, this aspect is overlooked by most research works, which tend to emphasize lexical characteristics of URLs while ignoring brand-jacking indicators. This work attempts to improve the existing URL-based phishing detection techniques by employing a layered approach. The squatting/obfuscation layer classifies a URL as phishing, based on the presence of brand-jacking characteristics. URLs which pass this initial screening are forwarded to the second layer, which determines their legitimacy through machine learning classifiers based on lexical features. Applying machine learning only to URLs passing the first layer significantly reduces computational overhead without compromising accuracy or relying on a third party. Among the classifiers evaluated, XGBoost delivered the best accuracy of 99.35%. The average response time of 12.49 milliseconds advocates for the potential of the proposed approach for real-time applications. Qualitative and quantitative comparisons with existing methods are performed to demonstrate the efficacy of the proposed work.
Author supplied keywords
Cite
CITATION STYLE
Goenka, R., Chawla, M., & Tiwari, N. (2025). Enhanced Phishing Detection Approach Using a Layered Model: Domain Squatting and URL Obfuscation Identification and Lexical Feature-Based Classification. IEEE Access, 13, 187285–187306. https://doi.org/10.1109/ACCESS.2025.3626819
Register to see more suggestions
Mendeley helps you to discover research relevant for your work.