Indonesian Journal of Enterprise Architecture
Vol. 3 No. 3 (2026): Indonesian Journal of Enterprise Architecture

Lightweight Phishing URL Detection Using Four Entropy and Character-Pattern Features with XGBoost

M Syukri Mustafa (Universitas Dipa Makassar, Indonesia)
Nurdin (Universitas Dipa Makassar, Indonesia)
Annah (Universitas Dipa Makassar, Indonesia)
Muh. Syahlan Natsir (Universitas Dipa Makassar, Indonesia)



Article Info

Publish Date
15 Aug 2026

Abstract

Phishing is among the most common cyber-threats, and the malicious URL is its primary delivery vector. Deep-learning detectors can achieve strong accuracy but often require large models, specialized hardware, or external look-ups (WHOIS, DNS, or page content), which limit their use in resource-constrained, privacy-sensitive, or offline settings. This study evaluates whether a minimal set of four intrinsic, character-level statistical features can provide strong within-dataset discrimination between phishing and benign URLs using XGBoost, positioning the work as a reproducible lightweight baseline rather than a new detection paradigm. Four features were computed from each URL with no external data: overall Shannon entropy, non-alphanumeric character count, the ratio of non-alphanumeric characters to URL length, and the Shannon entropy of the non-alphanumeric subset. Using the public Kaggle "Phishing and Malicious URL" dataset, only phishing and benign records were retained. After deduplication and the removal of malformed entries, exactly 451,325 URLs remained (224,040 phishing and 227,285 benign). Deduplication preceded a stratified 80:20 split to limit leakage, yielding 361,060 training and 90,265 test URLs. XGBoost was trained with fixed hyperparameters and a fixed random seed. On the held-out test set, the model attained an accuracy of 96.30%, precision of 95.70%, recall of 96.90%, F1-score of 96.29%, and ROC-AUC of 98.10%. URL entropy and the non-alphanumeric ratio were identified as the most influential features. An ablation study confirmed that non-alphanumeric entropy provides a crucial, non-redundant signal. Four compact, interpretable features offer an efficient baseline for phishing URL detection. A Flask REST prototype illustrates technical feasibility as a proof of concept only; external, temporal, and adversarial validation are required before any production deployment claims can be made.

Copyrights © 2026






Journal Info

Abbrev

IJEA

Publisher

Subject

Economics, Econometrics & Finance Social Sciences

Description

Business Strategic and Operations Management Digital Marketing and Consumer Studies Entrepreneurship and Management of Innovation Management of Technology and Innovation Data Analysis For Business Artificial Intelligence in Business Technology Adoption in ...