Phishing Campaign Detection Leveraging Deep Embedded Clustering Models

Ladataan...
suljettu
Julkaisu on tekijänoikeussäännösten alainen. Teosta voi lukea ja tulostaa henkilökohtaista käyttöä varten. Käyttö kaupallisiin tarkoituksiin on kielletty.
Lataukset3

Verkkojulkaisu

DOI

Tiivistelmä

Phishing is one of the most prevalent attack vectors in modern cyber threats, with attackers continuously adopting increasingly sophisticated techniques to evade detection systems and maximize the number of victims reached with minimal and reproducible effort. This has led to the widespread implementation of phishing campaigns, where multiple malicious websites and infrastructures are coordinated to support large-scale attacks. Consequently, phishing campaign detection has become a major area of interest, both from an internal organizational defense perspective and from a CTI information sharing point of view, which is the focus of this work. This thesis proposes an architecture for phishing campaign detection based on infrastructural website characteristics and leveraging Deep Clustering techniques to identify related phishing activities. Over 150,000 phishing websites are analyzed using infrastructural information such as DNS records, WHOIS data, X.509 certificates and website construction features. These data are used to train two Deep Embedded Clustering architectures capable of simultaneously learning latent feature representations and performing clustering operations. The quality of the generated clusters is evaluated through both standard internal clustering metrics and manual analysis. The manual evaluation leverages not only the tabular infrastructural features but also website screenshots, representing information not directly observed by the models during training. In addition, feature importance and explainability techniques are employed to better understand the reasoning behind the clustering behavior of the models. The experimental results demonstrate strong clustering performance, achieving on average a Silhouette Coefficient exceeding $0.9$ and a Davies–Bouldin Index below $1$. The manual analysis revealed coherent and meaningful campaign groupings, both in terms of visual similarity and consistency among infrastructural features. Finally, this work discusses the significance of the obtained results in comparison with existing methodologies proposed in the literature and outlines practical considerations and adjustments required for deploying the proposed architecture within a real-world CTI operational setting.

item.page.okmtext