NORMA eResearch @NCI Library

Detection of Malicious URLs through Lexical Feature Analysis using Machine Learning

Sivakumar, Sivaprakash (2025) Detection of Malicious URLs through Lexical Feature Analysis using Machine Learning. Masters thesis, Dublin, National College of Ireland.

[thumbnail of Master of Science]
Preview
PDF (Master of Science)
Download (813kB) | Preview
[thumbnail of Configuration Manual]
Preview
PDF (Configuration Manual)
Download (435kB) | Preview

Abstract

Bad URLs had been a major threat to phishing, malware proliferation, and web defacement activity but most of the current detection systems were by blacklist or content-based scan, neither of which had particularly worked well to keep up with new obfuscation techniques. The need to have a scalable, real-time, and lightweight detection mechanism had been met in this research by designing an improved approach to lexical-feature-based machine-learning in the ability to detect various types of malicious URLs. A set of 651,191 URLs (including 25–191 benign, 25–191 phishing, 25–191 malware and defacement) had been analysed and converted into a 24-dimensional lexical feature space which used structural, statistical, entropy-based, and keyword-driven features. Two monitored and assessed models were supervised models, one of them being a Random Forest classifier and the other being a Multi-Layer Perceptron trained on stratified sampling, and a class-balanced learning approach.

The Random Forest model has performed best with an accuracy of 93.21, which is better than the lexical benchmark widely mentioned by Joshi et al. Joshi et al. [2019]12, which had shown significant improvements in uncovering defacement and malware URLs. This result was predicted by theoretical results showing that enriched lexical cues could be found more efficient than standard string-based heuristics or a basic token feature when capturing complex obfuscation strategies, which is in line with previous studies on lexical URL analysis. Phishing URLs had been fairly challenging due to their visual similarity to legitimate domains and hybrid or semantic feature combination in future research might be required.

Item Type: Thesis (Masters)
Supervisors:
Name
Email
Sahni, Vikas
UNSPECIFIED
Subjects: Q Science > QA Mathematics > Computer software > Computer Security
T Technology > T Technology (General) > Information Technology > Computer software > Computer Security
Q Science > Q Science (General) > Self-organizing systems. Conscious automata > Machine learning
Divisions: School of Computing > Master of Science in Cyber Security
Depositing User: Ciara O'Brien
Date Deposited: 04 Sep 2026 11:02
Last Modified: 04 Sep 2026 11:02
URI: https://norma.ncirl.ie/id/eprint/9834

Actions (login required)

View Item View Item