Real-time malicious URL detection

Descripción:

Malicious URLs are constantly used for phishing, malware distribution and other illegal activities. Because benign URLs are needed for the Internet to function, malicious URLs are hard to block. While several works have focused on offline classification of malicious URLs, real-time detection still needs to be investigated. This paper evaluates the performance of real-time malicious URL detection using two techniques: blacklist methods and machine learning methods, deployed in both local and cloud environments. The study highlights significant differences in latency and connection failure rates under various load conditions, providing insights into the strengths and limitations of each approach. The blacklist method consistently demonstrates lower latency, making it suitable for scenarios requiring quick response times, though its stability may be compromised under high loads in a local setup. In contrast, the machine learning method offers advanced detection capabilities but exhibits higher latency, particularly in local environments, due to its resource-intensive nature. The cloud environment mitigates some latency issues but still lags behind the blacklist method in terms of speed. The findings emphasize that most latency stems from the verification process, with the local environment requiring significant optimization to reduce delays. The study concludes that implementing a proxy for real-time URL detection is viable, especially in cloud environments, where resource management can better handle increased demand.

Tipo de publicación: Conference Paper

Publicado en: 2024 IEEE Latin-American Conference on Communications (LATINCOM)

Autores
  • Orozco, Diego
  • Quesada, Luis
  • Ramírez-Benavides, Kryscia
  • Lara, Adrian

Investigadores del CITIC asociados a la publicación
Dr. Luis Quesada Quirós
Dra. Kryscia Ramírez Benavides
Dr. Adrian Lara Petitdemange

Proyecto asociado a la publicación
Edificios inteligentes y computación afectiva para mejorar la interacción humano robot

DOI BIBTEXT

Datos bibliográficos
Cita bibliográfica
Real-time malicious URL detection