Summary: | In recent years, cyber threats including malicious software, virus, spam, and phishing have grown aggressively via compromised Uniform Resource Locators (URLs). However, the current phishing URL detection solutions based on supervised learning use labeled data for training and classification, leading to the dependency on known attacking patterns. These approaches have limitations in fighting against evolving phishing tactics, resulting in a lack of robustness and sustainability. In this study, an unsupervised transformer model is proposed to address the drawbacks of the existing methods which use supervised learning to combat zero-day phishing attacks. Specifically, Bidirectional Encoder Representations from Transformers (BERT) is adopted in this paper to classify malicious URLs. The proposed model was trained on a public dataset and benchmarked with various baseline models using several performance metrics. Results obtained from the experiments showed that BERT-Medium achieved the highest detection accuracy of 98.55% among numerous transformer based models and outperformed other text embedding and deep learning techniques, indicating that the proposed solution is effective and robust in detecting phishing URLs. © 2023 IEEE.
|