Phishing URL Detection System Using Random Forest and Gradient Boosting for Cybercrime Prevention

Authors

DOI:

https://doi.org/10.22303/csrid-.17.3.2025.296-310

Keywords:

Cybersecurity, Gradient Boosting, Machine Learning, Phising URL, Random Forest, Streamlit

Abstract

Phishing attacks through malicious URLs have become a critical cybersecurity threat, resulting in substantial financial losses and data exposures on a global scale. Conventional approaches like blacklisting and rule-based detection often fall behind as phishing methods become more advanced, including zero-day phishing URLs. In this research, machine learning models based on Random Forest and Gradient Boosting are designed and tested to accurately identify phishing URLs. The dataset, obtained from Kaggle, consists of 11,430 URLs with extracted features representing URL characteristics such as length, subdomain count, HTTPS status, and domain age. The two models underwent training and validation with the help of stratified train-test splits and cross-validation techniques. To evaluate the models, several performance indicators—such as accuracy, precision, recall, F1-score, and ROC AUC—were applied. Results from the experiments reveal that Gradient Boosting slightly exceeds the performance of Random Forest, achieving an accuracy of 98.0%, precision of 98.1%, and an F1-score of 98.0%. The best-performing model was integrated into a web application built with Streamlit, providing real-time phishing detection for end-users. This research contributes to developing adaptive and efficient phishing URL detection systems, enhancing cybersecurity defenses against evolving phishing threats. The implementation demonstrates practical applicability and ease of use for non-expert users.

References

Abad, S., Gholamy, H., & Aslani, M. (2023). Classification of Malicious URLs Using Machine Learning. Sensors, 23(18). https://doi.org/10.3390/s23187760

Abbas, A. (2024). Evolving Phishing Defense : Innovative Defense Mechanisms and Effective Evolving Phishing Defense : Innovative Defense Mechanisms and Effective Measurement Strategies Date : September , 2024. September. https://doi.org/10.13140/RG.2.2.18505.97128

Alanezi, M. (2021). Phishing Detection Methods: A Review. Technium: Romanian Journal of Applied Sciences and Technology, 3(9), 19–35. https://doi.org/10.47577/technium.v3i9.4973

Alhashmi, A. A., Alashjaee, A. M., Darem, A. A., Alanazi, A. F., & Effghi, R. (2023). An Ensemble-based Fraud Detection Model for Financial Transaction Cyber Threat Classification and Countermeasures. Engineering, Technology and Applied Science Research, 13(6), 12433–12439. https://doi.org/10.48084/etasr.6401

Alkhalil, Z., Hewage, C., Nawaf, L., & Khan, I. (2021). Phishing Attacks: A Recent Comprehensive Study and a New Anatomy. Frontiers in Computer Science, 3(March), 1–23. https://doi.org/10.3389/fcomp.2021.563060

Do, N. Q., Selamat, A., Krejcar, O., Herrera-Viedma, E., & Fujita, H. (2022). Deep Learning for Phishing Detection: Taxonomy, Current Challenges and Future Directions. IEEE Access, 10, 36429–36463. https://doi.org/10.1109/ACCESS.2022.3151903

Economy, C., Technologies, D., Economy, P., Fraud, F., Costs, S., & Losses, M. (1869). The economic impact of phishing, vishing, online marketplaces, and emerging cybercrimes: exposing the cybercrime economy and social costs in the modern era of digital fraud - an assessment. 11(9), 215–229.

Goud, N. S., & Mathur, A. (2021). Feature Engineering Framework to detect Phishing Websites using URL Analysis. International Journal of Advanced Computer Science and Applications, 12(7), 295–303. https://doi.org/10.14569/IJACSA.2021.0120733

Hannousse, A., & Yahiouche, S. (2021). Towards benchmark datasets for machine learning based website phishing detection: An experimental study. Engineering Applications of Artificial Intelligence, 104, 1–21. https://doi.org/10.1016/j.engappai.2021.104347

Imani, M., Beikmohammadi, A., & Arabnia, H. R. (2025). Comprehensive Analysis of Random Forest and XGBoost Performance with SMOTE, ADASYN, and GNUS Under Varying Imbalance Levels. Technologies, 13(3), 1–40. https://doi.org/10.3390/technologies13030088

Innab, N., Osman, A. A. F., Ataelfadiel, M. A. M., Abu-Zanona, M., Elzaghmouri, B. M., Zawaideh, F. H., & Alawneh, M. F. (2024). Phishing Attacks Detection Using EnsembleMachine Learning Algorithms. Computers, Materials and Continua, 80(1), 1325–1345. https://doi.org/10.32604/cmc.2024.051778

Iyana Kumar. (2023). Emerging Threats in Cybersecurity: A Review Article. International Journal of Applied and Natural Sciences Journal Homepage, 1–9. http://bluemarkpublishers.com/index.php/IJANS

Kara, I., Ok, M., & Ozaday, A. (2022). Characteristics of Understanding URLs and Domain Names Features: The Detection of Phishing Websites with Machine Learning Methods. IEEE Access, 10(December), 124420–124428. https://doi.org/10.1109/ACCESS.2022.3223111

Kheruddin, M. S., Adam, M., Mohd Zuber, E., Mukhlis, M., Radzai, M., Syafiq, M., Kheruddin, B., Bin, E., Zuber, M., & Bin, M. M. (2024). Phishing Attacks: Unraveling Tactics, Threats, and Defenses in the Cybersecurity Landscape. Advance.Sagepub.Com. https://advance.sagepub.com/doi/full/10.22541/au.170534654.48067877/v1

Kulkarni, A., Balachandran, V., & Das, T. (2024). Phishing Webpage Detection: Unveiling the Threat Landscape and Investigating Detection Techniques. IEEE Communications Surveys and Tutorials, Ml. https://doi.org/10.1109/COMST.2024.3441752

Omari, K. (2023). Phishing Detection using Gradient Boosting Classifier. Procedia Computer Science, 230(2023), 120–127. https://doi.org/10.1016/j.procs.2023.12.067

Salloum, S., Gaber, T., Vadera, S., & Shaalan, K. (2022). A Systematic Literature Review on Phishing Email Detection Using Natural Language Processing Techniques. IEEE Access, 10, 65703–65727. https://doi.org/10.1109/ACCESS.2022.3183083

Stender, S., Bulkot, O., Iastremska, O., Saienko, V., & Pereguda, Y. (2024). Digital Transformation of the National Economy of Ukraine: Challenges and Opportunities. Financial and Credit Activity: Problems of Theory and Practice, 2(55), 333–345. https://doi.org/10.55643/fcaptp.2.55.2024.4328

Tang, L., & Mahmoud, Q. H. (2021). A Survey of Machine Learning-Based Solutions for Phishing Website Detection. Machine Learning and Knowledge Extraction, 3(3), 672–694. https://doi.org/10.3390/make3030034

Downloads

Published

2025-10-30

How to Cite

Phishing URL Detection System Using Random Forest and Gradient Boosting for Cybercrime Prevention. (2025). CSRID (Computer Science Research and Its Development Journal), 17(3), 296-310. https://doi.org/10.22303/csrid-.17.3.2025.296-310

Similar Articles

1-10 of 29

You may also start an advanced similarity search for this article.

Most read articles by the same author(s)