DETEKSI WEBSITE PHISHING MENGGUNAKAN EKSTRAKSI FITUR HIBRIDA URL-HTML DAN ENSEMBLE MACHINE LEARNING
DOI:
https://doi.org/10.70248/jrsit.v4i1.4517Keywords:
Phishing, Hybrid feature, Machine learning, Ensemble Learning, XGBoost, Random ForestAbstract
Penelitian ini mengusulkan pengembangan System for Ensemble Phishing & HTML Intelligent Analysis (SEPHIA), sebuah sistem deteksi website phishing berbasis ekstraksi fitur hibrida. Pendekatan ini mengombinasikan 16 fitur leksikal URL dan 14 fitur perilaku struktural Document Object Model (DOM) HTML. Proses klasifikasi dilakukan menggunakan algoritma Ensemble Machine Learning ( Random Forest dan Extreme Gradient Boosting / XGBoost) dengan mekanisme Soft Voting untuk menangani ketidakseimbangan data. Model dilatih menggunakan dataset gabungan dari repositori OpenPhish dan Majestic Million sejumlah 5.000 sampel data. Hasil evaluasi kinerja pada 1.000 data uji (498 Legitimate dan 502 Phishing) menunjukkan model ensemble ini mencapai tingkat Akurasi 99,10%, Presisi 99,60%, Sensitivitas (Recall) 98,61%, dan F1-Score 0,991. Integrasi lapisan Rule-Based (Protokol Veto Merek) dan mekanisme Heuristic Fallback pada antarmuka sistem terbukti secara signifikan memblokir serangan Typosquatting dan tautan tidak aktif..
References
Anti-Phishing Working Group (APWG), “Phishing Activity Trends Report: 4th Quarter 2023,” APWG, Tech. Rep., Jan. 2024. [Online]. Available: https://apwg.org/trendsreports/
Federal Bureau of Investigation (FBI), “Internet Crime Report 2023,” FBI Internet Crime Complaint Center (IC3), Tech. Rep., Mar. 2024. [Online]. Available: https://www.ic3.gov/
Badan Siber dan Sandi Negara (BSSN), “Laporan Tahunan Keamanan Siber Indonesia 2023,” BSSN, Jakarta, Indonesia, Laporan Tahunan, 2024. [Online]. Available: https://bssn.go.id/
M. Wajid, M. A. Khan, and J. Kim, “Ensemble learning-powered URL phishing detection,” Computers & Security, vol. 136, p. 103646, Jan. 2024, doi: 10.1016/j.cose.2023.103646.
Y. Wang, X. Zhang, and Y. Liu, “Website phishing detection using HTML content features,” Journal of Information Security and Applications, vol. 58, p. 102705, May 2021, doi: 10.1016/j.jisa.2020.102705.
A. Karim, M. Shahroz, K. Mustofa, and J. H. Abawajy, “Phishing detection system through hybrid machine learning based on URL,” IEEE Access, vol. 11, pp. 36805–36822, Mar. 2023, doi: 10.1109/ACCESS.2023.3252504.
I. Syarif and R. Mardiyanto, “Web phishing detection using feature engineering and deep learning approaches,” Journal of Computer Science and Information Technologies, vol. 5, no. 1, pp. 45–56, 2024, doi: 10.35308/jcsit.v5i1.8912.
S. Kumar, P. Mishra, and R. Singh, “Phishing detection using XGBoost algorithm,” International Journal of Information Security, vol. 22, no. 4, pp. 921–935, Aug. 2023, doi: 10.1007/s10207-023-00684-x.
A. K. Jain and B. B. Gupta, “A survey of phishing attack techniques, defence mechanisms and open challenges,” Enterprise Information Systems, vol. 16, no. 4, pp. 527–565, Apr. 2022, doi: 10.1080/17517575.2021.1894353.
J. Huang, X. Yang, and Y. Liu, “Stacking ensemble learning for phishing website detection,” Expert Systems with Applications, vol. 195, p. 116564, Jun. 2022, doi: 10.1016/j.eswa.2022.116564.
N. A. Ghani and W. L. Al-Yaseen, “Ensemble machine learning for phishing website detection,” Journal of Information Security and Applications, vol. 73, p. 103443, Mar. 2023, doi: 10.1016/j.jisa.2023.103443.
Y. Gao and H. Xu, “Phishing website detection using ensemble learning techniques,” Applied Soft Computing, vol. 116, p. 108329, Mar. 2022, doi: 10.1016/j.asoc.2021.108329.
Z. Benenson, F. Gassmann, and R. Landwirth, “Machine learning techniques for phishing detection: A comparative study,” in Proc. IEEE Security and Privacy Workshops (SPW), San Francisco, CA, USA, 2021, pp. 1–8, doi: 10.1109/SPW53761.2021.00012.
S. Balamurugan et al., “An efficient phishing website detection using Random Forest classifier,” in Proc. IEEE Int. Conf. Smart Tech. Syst. Next Generation Computing (ICSTSN), Villupuram, India, 2022, pp. 1–6, doi: 10.1109/ICSTSN53084.2022.9761345.
European Union Agency for Cybersecurity (ENISA), “ENISA Threat Landscape 2023,” ENISA, Tech. Rep., Oct. 2023. [Online]. Available: https://www.enisa.europa.eu/publications/enisa-threat-landscape-2023
T. Saito and M. Rehmsmeier, “The Precision-Recall plot is more informative than the ROC plot when evaluating binary classifiers,” PLoS ONE, vol. 10, no. 3, p. e0118432, Mar. 2015, doi: 10.1371/journal.pone.0118432.
A. Géron, Hands-on Machine Learning with Scikit-Learn, Keras, and TensorFlow, 3rd ed. Sebastopol, CA, USA: O’Reilly Media, 2022.




















