The increasing risk of cyber threats has significantly affected web-based services, especially phishing and malicious URLs, posing serious security challenges for both users and organizations. Previous detection approaches, such as blacklist-based, have difficulty detecting new threats or obfuscated malicious URLs. On the other hand, machine learning techniques (ML) have suffered from highly False Positive (FP) rates. In this study, we propose a hybrid multi-layer architecture for malicious URL detection by integrating blacklist verification, feature selection of URLs, an XGBoost-based classification technique, and rule-based post-processing. This proposed model works based on sequential layers to filter malicious URLs utilizing a blacklist dataset and then extract lexical features from URLs. Selecting features processed using the XGBoost classifier to distinguish between benign and malicious URLs. Then the final stage is to refine the classification results based on a rule-based preprocessing technique to enhance malicious URLs detection systems' performance and reduce FP rates. The experimental results show enhanced performance by achieving higher detection accuracy, lower FP, and improved computational efficiency compared to previous single-layer models. Our contribution in this study is to enhance the cybersecurity systems by providing a scalable and adaptive solution for real-world malicious URL detection systems.
Y. Khonji, A. Iraqi, and A. Jones, “Phishing detection: A literature survey,” IEEE Commun. Surveys Tuts., vol. 15, no. 4, pp. 2091-2121, 2013.
T. Moore and R. Clayton, “Examining the impact of website take-down on phishing,” in Proc. eCrime Researchers Summit, 2007.
H. R. Hassan, D. S. Ibrahim, and Z. T. Mustafa Al-Ta’i, “Advanced Human Activity Recognition Using Pose Estimation and Deep Learning Techniques,” in 2024 Antennas Design and Measurement International Conference (ADMInC), Saint Petersburg, Russian Federation, 2024, pp. 94-100, [Online]. Available: https://doi.org/10.1109/ADMInC63617.2024.10775304.
R. S. Rao and A. T. Ali, “Evasion techniques in phishing URL generation,” J. Cyber Secur. Technol., 2018.
M. Gupta, A. Kumar, and R. Rastogi, “Detecting phishing websites using heuristic rules,” Int. J. Comput. Appl., 2016.
D. S. Ibrahim, F. K. Zaidan, J. Kadum, H. H. Saleh, L. T. Rasheed, and W. S. Nsaif, “Routing Protocols-Based Clustering in WSNs,” in 2021 4th International Iraqi Conference on Engineering Technology and Their Applications (IICETA), Najaf, Iraq, 2021, pp. 201-205, [Online]. Available: https://doi.org/10.1109/IICETA51758.2021.9717419.
M. S. K. Sahoo, G. Sahoo, and S. Mohanty, “Malicious URL detection using machine learning: A survey,” Int. J. Appl. Eng. Res., 2017.
T. Chen and C. Guestrin, “XGBoost: A scalable tree boosting system,” in Proc. ACM SIGKDD Int. Conf. Knowl. Discov. Data Min. (KDD), 2016.
N. Jain and V. Gupta, “Performance analysis of ML classifiers for phishing detection,” Procedia Comput. Sci., 2019.
S. Abu-Nimeh, D. Nappa, X. Wang, and S. Nair, “Evaluation of classification techniques for phishing detection,” Inf. Secur. J., 2007.
P. K. Roy and S. Chandra, “Hybrid intrusion detection systems for cyber threats,” IEEE Access, 2020.
D. S. Ibrahim, S. T. Hasson, and P. A. Johnson, “Selecting an Optimal Cluster Head using PSO Algorithm in WSNs,” in 2022 International Conference on Software, Telecommunications and Computer Networks (SoftCOM), Split, Croatia, 2022, pp. 1-4, [Online]. Available: https://doi.org/10.23919/SoftCOM55329.2022.9911416.
A. M. Asiri and N. Marriwala, “A Literature Survey on LEACH Protocol and Its Descendants for Homogeneous and Heterogeneous Wireless Sensor Networks,” in Algorithms for Intelligent Systems, Springer, 2021, pp. 281-295.
A. Sahingoz, B. Buber, O. Demir, and B. Diri, “Machine learning based phishing detection from URLs,” Expert Syst. Appl., 2019.
K. Sahoo and B. Gupta, “A survey on malicious URL detection techniques,” J. Netw. Comput. Appl., 2017.
T. Chen and C. Guestrin, “XGBoost: Extreme gradient boosting,” in Proc. ACM SIGKDD Int. Conf. Knowl. Discov. Data Min. (KDD), 2016.
H. Aljofey, Q. Jiang, H. Qu, M. Huang, and J. Niyigena, “Deep learning-based phishing URL detection,” IEEE Access, 2020.
K. Aburrous, M. A. Hossain, K. Dahal, and F. Thabtah, “Intelligent phishing detection system using fuzzy rules,” Expert Syst. Appl., 2010.
M. Mafarja and S. Mirjalili, “Feature selection using hybrid PSO and GA for classification problems,” Appl. Soft Comput., 2018.
M. Rasulmukhamedov, A. Tukhtakhodjaev, and O. Turdiev, “Application of Machine Learning Algorithms for Optimizing Document Workflow Management in Railway Freight Transportation,” in Proc. Int. Conf. Applied Innovation in IT, vol. 13, no. 2, pp. 51-57, 2025.