SMARTPHISH: HYBRID PHISHING WEBSITE DETECTION USING URL AND BEHAVIORAL FEATURES
Keywords:
Phishing Detection, URL Feature Extraction, Webpage Behavioral Indicators, Random Forest, XGBoost, Machine LearningAbstract
Phishing attacks remain one of the most prevalent forms of cybercrime, targeting individuals and organizations by impersonating legitimate websites to steal sensitive credentials and financial information. Despite the availability of browser-based blacklists and security warnings, phishing websites continue to evade detection by frequently rotating domains and mimicking trusted platforms. This paper presents Smart Phish, a hybrid phishing detection system that combines URL-based structural features with webpage behavioral indicators to improve detection accuracy using lightweight machine learning models. The proposed system extracts 24 features from two complementary sources: lexical and structural properties of URLs (domain length, use of IP addresses, presence of special characters, HTTPS usage) and webpage behavioral indicators derived from HTML content analysis (redirect patterns, form action attributes, hidden input elements, external link ratios, and suspicious JavaScript constructs). Two classification models, Random Forest and XGBoost, are trained and evaluated on a publicly available benchmark dataset comprising 10,208 phishing and legitimate URLs. Experimental results show that the hybrid feature approach achieves 95.2% classification accuracy using Random Forest, with a false positive rate of 3.8% and ROC-AUC of 0.982. The hybrid approach outperforms URL-only classification by 3.4 percentage points. The system operates with low computational overhead, making it practical for browser extension or lightweight server-side deployment without requiring GPU infrastructure or proprietary threat feeds. Smart Phish provides a reproducible and interpretable approach to phishing detection.
References
I. R. S. Rao and A. R. Pais, "Detection of phishing websites using an efficient feature-based machine learning framework," Neural Comput. Appl., vol. 31, no. 8, pp. 3851-3873, Aug. 2019.
II. Anti-Phishing Working Group (APWG), "Phishing Activity Trends Report, 4th Quarter 2023," APWG, Tech. Rep., 2024.
III. A. Oest et al., "Inside a phisher's mind: Understanding the anti-phishing ecosystem through phishing kit analysis," in Proc. APWG Symposium on eCrime, 2018, pp. 1-13.
IV. M. Khonji, Y. Iraqi, and A. Jones, "Phishing detection: A literature survey," IEEE Commun. Surveys Tuts., vol. 15, no. 4, pp. 2091-2121, 2013.
V. I. Fette, N. Sadeh, and A. Tomasic, "Learning to detect phishing emails," in Proc. 16th Intl. Conf. World Wide Web (WWW), 2007, pp. 649-656.
VI. S. Tan, J. Yang, and K. Kuang, "Phishing website detection using URL-based features," in Proc. IEEE IIH-MSP, 2019, pp. 195-202.
VII. A. Subasi et al., "Intelligent phishing website detection using random forest classifier," in Proc. ICECTA, 2017, pp. 1-5.
VIII. L. Breiman, "Random forests," Mach. Learn., vol. 45, no. 1, pp. 5-32, Oct. 2001.
IX. T. Chen and C. Guestrin, "XGBoost: A scalable tree boosting system," in Proc. 22nd ACM SIGKDD, 2016, pp. 785-794.
X. R. Mohammad, F. Thabtah, and L. McCluskey, "Phishing websites features," Univ. Huddersfield, Tech. Rep., 2015. UCI ML Repository.
XI. F. Pedregosa et al., "Scikit-learn: Machine learning in Python," J. Mach. Learn. Res., vol. 12, pp. 2825-2830, 2011.
XII. B. Sahingoz et al., "Machine learning based phishing detection from URLs," Expert Syst. Appl., vol. 117, pp. 345-357, Mar. 2019.
XIII. E. Zhu et al., "OFS-NN: An effective phishing websites detection model based on optimal feature selection and neural network," IEEE Access, vol. 8, pp. 179-192, 2020.
XIV. G. Xiang et al., "CANTINA+: A feature-rich ML framework for detecting phishing web sites," ACM Trans. Inf. Syst. Secur., vol. 14, no. 2, pp. 1-28, Sep. 2011.
XV. K. L. Chiew et al., "A new hybrid ensemble feature selection framework for machine learning-based phishing detection," Inf. Sci., vol. 484, pp. 153-166, May 2019.
XVI. J. Mao, W. Tian, P. Li, T. Wei, and Z. Liang, “Phishing-alarm: Robust and efficient phishing detection via page component similarity,” IEEE Access, vol. 5, pp. 17020–17030, 2017.
XVII. Y. Cao, W. Han, and Y. Le, “Anti-phishing based on automated individual white-list,” in Proc. ACM Workshop on Digital Identity Management (DIM), 2008, pp. 51–60.
XVIII. C. Whittaker, B. Ryner, and M. Nazif, “Large-scale automatic classification of phishing pages,” in Proc. Network and Distributed System Security Symposium (NDSS), 2010, pp. 1–14.
XIX. C. Opara, D. Chukwudebe, and A. Adewumi, “HTMLPhish: Enabling phishing webpage detection through deep learning on HTML content,” in Proc. Int. Joint Conf. Neural Networks (IJCNN), 2020, pp. 1–8.
XX. S. Marchal, J. Francois, R. State, and T. Engel, “PhishStorm: Detecting phishing with streaming analytics,” IEEE Transactions on Network and Service Management, vol. 11, no. 4, pp. 458–471, 2014.
XXI. R. S. Rao and A. R. Pais, “Jail-Phish: An improved search engine based phishing detection system,” Computers & Security, vol. 83, pp. 246–267, 2019.
XXII. S. Naylani, A. Fadlil, and I. Riadi, “Phishing website detection using multilayer machine learning techniques,” in Proc. Int. Conf. Cyber and IT Service Management (CITSM), 2020, pp. 1–6.
XXIII. S. C. Jeeva and E. B. Rajsingh, “Intelligent phishing URL detection using association rule mining,” Human-centric Computing and Information Sciences, vol. 6, no. 1, pp. 1–19, 2016.
XXIV. S. Marchal, J. Francois, R. State, and T. Engel, “PhishStorm: Detecting phishing with streaming analytics,” IEEE Transactions on Network and Service Management, vol. 11, no. 4, pp. 458–471, 2014.
XXV. M. Aburrous, M. A. Hossain, K. Dahal, and F. Thabtah, “Intelligent phishing detection system for e-banking using fuzzy data mining,” Expert Systems with Applications, vol. 37, no. 12, pp. 7913–7921, 2010.
XXVI. P. Prakash, M. Kumar, R. R. Kompella, and M. Gupta, “PhishNet: Predictive blacklisting to detect phishing attacks,” in Proc. IEEE INFOCOM, 2010, pp. 1–5.
XXVII. S. Al-Janabi, I. Al-Shourbaji, M. Shojafar, and A. Abraham, “Hybrid and ensemble machine learning approaches for phishing detection,” Journal of Intelligent Systems, vol. 26, no. 3, pp. 509–521, 2017.
XXVIII. A. Ubing, N. A. M. Nayan, and M. A. M. Basir, “Feature selection and ensemble learning for phishing website detection,” International Journal of Advanced Computer Science and Applications, vol. 10, no. 11, pp. 436–442, 2019.
XXIX. Y. Chen, K. Li, and W. Zheng, “A comparative study of gradient boosting algorithms for phishing website detection,” in Proc. Int. Conf. Intelligent Computing and Applications, 2018, pp. 85–92.
XXX. E. Gabrilovich and S. Markovitch, “Text categorization with many redundant features: Using aggressive feature selection to make SVMs competitive with C4.5,” in Proc. 21st Int. Conf. Machine Learning (ICML), 2004, pp. 321–328.
XXXI. J. Ma, L. K. Saul, S. Savage, and G. M. Voelker, “Beyond blacklists: Learning to detect malicious web sites from suspicious URLs,” in Proc. ACM SIGKDD Int. Conf. Knowledge Discovery and Data Mining, 2009, pp. 1245–1254.
XXXII. A. Blum, B. Wardman, T. Solorio, and G. Warner, “Lexical feature based phishing URL detection using online learning,” in Proc. ACM Workshop on Artificial Intelligence and Security, 2010, pp. 54–60.
XXXIII. Y. Shen, X. Zhang, and J. Hu, “Phishing website detection using natural language processing and machine learning,” IEEE Access, vol. 9, pp. 11245–11256, 2021.
XXXIV. OpenPhish, “OpenPhish Phishing Intelligence,” 2015.
XXXV. PhishTank, “PhishTank Developer Information,” 2006.
Additional Files
Published
How to Cite
Issue
Section
License
Copyright (c) 2026 International Educational Journal of Science and Engineering

This work is licensed under a Creative Commons Attribution 4.0 International License.