DETEKSI WEBSITE PHISHING MENGGUNAKAN EKSTRAKSI FITUR HIBRIDA URL-HTML DAN ENSEMBLE MACHINE LEARNING

Authors

  • M Maulana Fathul Muin Program Studi Teknik Informatika, Fakultas Teknologi Industri, Universitas Islam Sultan Agung
  • Bagus Satrio Waluyo Poetro Universitas Islam Sultan Agung

DOI:

https://doi.org/10.70248/jrsit.v4i1.4517

Keywords:

Phishing, Hybrid feature, Machine learning, Ensemble Learning, XGBoost, Random Forest

Abstract

Penelitian ini mengusulkan pengembangan System for Ensemble Phishing & HTML Intelligent Analysis (SEPHIA), sebuah sistem deteksi website phishing berbasis  ekstraksi fitur hibrida. Pendekatan ini mengombinasikan  16 fitur leksikal URL dan 14 fitur perilaku struktural Document Object Model (DOM) HTML. Proses klasifikasi dilakukan menggunakan algoritma Ensemble Machine Learning ( Random Forest dan Extreme Gradient Boosting / XGBoost) dengan mekanisme Soft Voting untuk menangani ketidakseimbangan data. Model dilatih menggunakan dataset gabungan dari repositori OpenPhish dan Majestic Million  sejumlah 5.000 sampel data. Hasil evaluasi kinerja pada 1.000 data uji (498 Legitimate dan 502 Phishing) menunjukkan model ensemble ini mencapai tingkat  Akurasi 99,10%, Presisi 99,60%, Sensitivitas (Recall) 98,61%, dan F1-Score 0,991. Integrasi lapisan Rule-Based (Protokol Veto Merek) dan mekanisme Heuristic Fallback pada antarmuka sistem terbukti secara signifikan memblokir serangan Typosquatting dan tautan tidak aktif..

References

Anti-Phishing Working Group (APWG), “Phishing Activity Trends Report: 4th Quarter 2023,” APWG, Tech. Rep., Jan. 2024. [Online]. Available: https://apwg.org/trendsreports/

Federal Bureau of Investigation (FBI), “Internet Crime Report 2023,” FBI Internet Crime Complaint Center (IC3), Tech. Rep., Mar. 2024. [Online]. Available: https://www.ic3.gov/

Badan Siber dan Sandi Negara (BSSN), “Laporan Tahunan Keamanan Siber Indonesia 2023,” BSSN, Jakarta, Indonesia, Laporan Tahunan, 2024. [Online]. Available: https://bssn.go.id/

M. Wajid, M. A. Khan, and J. Kim, “Ensemble learning-powered URL phishing detection,” Computers & Security, vol. 136, p. 103646, Jan. 2024, doi: 10.1016/j.cose.2023.103646.

Y. Wang, X. Zhang, and Y. Liu, “Website phishing detection using HTML content features,” Journal of Information Security and Applications, vol. 58, p. 102705, May 2021, doi: 10.1016/j.jisa.2020.102705.

A. Karim, M. Shahroz, K. Mustofa, and J. H. Abawajy, “Phishing detection system through hybrid machine learning based on URL,” IEEE Access, vol. 11, pp. 36805–36822, Mar. 2023, doi: 10.1109/ACCESS.2023.3252504.

I. Syarif and R. Mardiyanto, “Web phishing detection using feature engineering and deep learning approaches,” Journal of Computer Science and Information Technologies, vol. 5, no. 1, pp. 45–56, 2024, doi: 10.35308/jcsit.v5i1.8912.

S. Kumar, P. Mishra, and R. Singh, “Phishing detection using XGBoost algorithm,” International Journal of Information Security, vol. 22, no. 4, pp. 921–935, Aug. 2023, doi: 10.1007/s10207-023-00684-x.

A. K. Jain and B. B. Gupta, “A survey of phishing attack techniques, defence mechanisms and open challenges,” Enterprise Information Systems, vol. 16, no. 4, pp. 527–565, Apr. 2022, doi: 10.1080/17517575.2021.1894353.

J. Huang, X. Yang, and Y. Liu, “Stacking ensemble learning for phishing website detection,” Expert Systems with Applications, vol. 195, p. 116564, Jun. 2022, doi: 10.1016/j.eswa.2022.116564.

N. A. Ghani and W. L. Al-Yaseen, “Ensemble machine learning for phishing website detection,” Journal of Information Security and Applications, vol. 73, p. 103443, Mar. 2023, doi: 10.1016/j.jisa.2023.103443.

Y. Gao and H. Xu, “Phishing website detection using ensemble learning techniques,” Applied Soft Computing, vol. 116, p. 108329, Mar. 2022, doi: 10.1016/j.asoc.2021.108329.

Z. Benenson, F. Gassmann, and R. Landwirth, “Machine learning techniques for phishing detection: A comparative study,” in Proc. IEEE Security and Privacy Workshops (SPW), San Francisco, CA, USA, 2021, pp. 1–8, doi: 10.1109/SPW53761.2021.00012.

S. Balamurugan et al., “An efficient phishing website detection using Random Forest classifier,” in Proc. IEEE Int. Conf. Smart Tech. Syst. Next Generation Computing (ICSTSN), Villupuram, India, 2022, pp. 1–6, doi: 10.1109/ICSTSN53084.2022.9761345.

European Union Agency for Cybersecurity (ENISA), “ENISA Threat Landscape 2023,” ENISA, Tech. Rep., Oct. 2023. [Online]. Available: https://www.enisa.europa.eu/publications/enisa-threat-landscape-2023

T. Saito and M. Rehmsmeier, “The Precision-Recall plot is more informative than the ROC plot when evaluating binary classifiers,” PLoS ONE, vol. 10, no. 3, p. e0118432, Mar. 2015, doi: 10.1371/journal.pone.0118432.

A. Géron, Hands-on Machine Learning with Scikit-Learn, Keras, and TensorFlow, 3rd ed. Sebastopol, CA, USA: O’Reilly Media, 2022.

Downloads

Published

2026-08-31

How to Cite

M Maulana Fathul Muin, & Bagus Satrio Waluyo Poetro. (2026). DETEKSI WEBSITE PHISHING MENGGUNAKAN EKSTRAKSI FITUR HIBRIDA URL-HTML DAN ENSEMBLE MACHINE LEARNING. Jurnal Rekayasa Sistem Informasi Dan Teknologi, 4(1), 01–08. https://doi.org/10.70248/jrsit.v4i1.4517

Issue

Section

Artikel

Most read articles by the same author(s)