Nurdin
Universitas Dipa Makassar, Indonesia

Published : 1 Documents Claim Missing Document
Claim Missing Document
Check
Articles

Found 1 Documents
Search

Lightweight Phishing URL Detection Using Four Entropy and Character-Pattern Features with XGBoost M Syukri Mustafa; Nurdin; Annah; Muh. Syahlan Natsir
Indonesian Journal of Enterprise Architecture Vol. 3 No. 3 (2026): Indonesian Journal of Enterprise Architecture
Publisher : Global Research and Collaboration

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.66314/ijea.v3i3.1128

Abstract

Phishing is among the most common cyber-threats, and the malicious URL is its primary delivery vector. Deep-learning detectors can achieve strong accuracy but often require large models, specialized hardware, or external look-ups (WHOIS, DNS, or page content), which limit their use in resource-constrained, privacy-sensitive, or offline settings. This study evaluates whether a minimal set of four intrinsic, character-level statistical features can provide strong within-dataset discrimination between phishing and benign URLs using XGBoost, positioning the work as a reproducible lightweight baseline rather than a new detection paradigm. Four features were computed from each URL with no external data: overall Shannon entropy, non-alphanumeric character count, the ratio of non-alphanumeric characters to URL length, and the Shannon entropy of the non-alphanumeric subset. Using the public Kaggle "Phishing and Malicious URL" dataset, only phishing and benign records were retained. After deduplication and the removal of malformed entries, exactly 451,325 URLs remained (224,040 phishing and 227,285 benign). Deduplication preceded a stratified 80:20 split to limit leakage, yielding 361,060 training and 90,265 test URLs. XGBoost was trained with fixed hyperparameters and a fixed random seed. On the held-out test set, the model attained an accuracy of 96.30%, precision of 95.70%, recall of 96.90%, F1-score of 96.29%, and ROC-AUC of 98.10%. URL entropy and the non-alphanumeric ratio were identified as the most influential features. An ablation study confirmed that non-alphanumeric entropy provides a crucial, non-redundant signal. Four compact, interpretable features offer an efficient baseline for phishing URL detection. A Flask REST prototype illustrates technical feasibility as a proof of concept only; external, temporal, and adversarial validation are required before any production deployment claims can be made.