TARU PUBLICATIONS
Journal of Discrete Mathematical Sciences and Cryptography cover
Open Access ·Peer-reviewed·ISSN (Online): 2169-0065·ISSN (Print): 0972-0529

Monthly Journal: Publishes theoretical and applied research in all areas of Discrete Mathematical Sciences, Cryptography, Combinatorics, Elliptic Curves and Information Security.

Issues up to 2022 co-published with and available at:Taylor & Francis Online
submissions@tarupublications.com
Open Access Research Article

Privacy-preserving over encrypted data for web page phishing detection

* , , ,

* Corresponding author · click or hover a name for details

pp. 1413–1424Vol. 28Issue 4-BJune 2025DOI: 10.47974/JDMSC-2287 Crossmark XML
Received:
11 Feb 2025
Published Online:
26 Jun 2025
Article type:
Research Article
Language:
EN
Article no.:
JDMSC-2287
Pages:
1413–1424

Abstract

It tricked users into disclosing sensitive information through web page phishing. A traditional phishing detection method involves analyzing web pages and user behaviour using machine learning models, which require access to raw data, raising privacy concerns. Using homomorphic encryption and multiparty computation, this paper protects privacy in phishing detection. Security and privacy are enhanced by encrypting sensitive user data during the detection process. With this approach, Extreme Learning Machine (ELM) classification is combined with TF-IDF feature selection to detect phishing while maintaining optimal computational efficiency. According to our experimental results, this approach provides an accuracy of 93.5% and has low computational and communication costs, making it a viable solution for secure real-time phishing detection.

Keywords

Subject Classifications

93E1094A13

References

[1] P. Rani, S. Verma, S. P. Yadav, B. K. Rai, M. S. Naruka, and D. Kumar, “Simulation of the lightweight blockchain technique based on privacy and security for healthcare data for the cloud system,” International Journal of E-Health and Medical Communications (IJEHMC), vol. 13, no. 4, pp. 1–15 (2022).
[2] K. Butler, W. Enck, J. Plasterr, P. Traynor, and P. McDaniel, “Privacy Preserving Web-Based Email,” in Information Systems Security, vol. 4332, A. Bagchi and V. Atluri, Eds., in Lecture Notes in Computer Science, vol. 4332., Berlin, Heidelberg: Springer Berlin Heidelberg, pp. 116–131 (2006). doi: 10.1007/11961635_8.
[3] E. E. Lastdrager, “Achieving a consensual definition of phishing based on a systematic review of the literature,” Crime Sci, vol. 3, no. 1, p. 9 (Dec. 2014), doi: 10.1186/s40163-014-0009-y.
[4] B. Bhola, S. Misra, M. S. Obaidat, and A. Mukherjee, “Quality-enabled decentralized dynamic IoT platform with scalable resources integration,” IET Communications (2022).
[5] M. Khonji, Y. Iraqi, and A. Jones, “Phishing Detection: A Literature Survey,” IEEE Commun. Surv. Tutorials, vol. 15, no. 4, pp. 2091–2121 (2013), doi: 10.1109/SURV.2013.032213.00009.
[6] K. Pandove, A. Jindal, and R. Kumar, “Email spoofing,” International Journal of Computer Applications, vol. 5, no. 1, pp. 27–30 (2010).
[7] J. Hong, “The state of phishing attacks,” Commun. ACM, vol. 55, no. 1, pp. 74–81 (Jan. 2012), doi: 10.1145/2063176.2063197.
[8]  P. Rani, C. Sharma, J. V. N. Ramesh, S. Verma, R. Sharma, A. Alkhayyat, and S. Kumar, “Federated Learning-Based Misbehaviour Detection for the 5G-Enabled Internet of Vehicles,” IEEE Transactions on Consumer Electronics (2023).
[9] C. Ellison and B. Schneier, “Ten risks of PKI: What you’re not being told about public key infrastructure,” Comput Secur J, vol. 16, no. 1, pp. 1–7 (2000).
[10] L. Demir, A. Kumar, M. Cunche, and C. Lauradoux, “The pitfalls of hashing for privacy,” IEEE Communications Surveys & Tutorials, vol. 20, no. 1, pp. 551–565 (2017).
[11] T. Gerbet, A. Kumar, and C. Lauradoux, “A privacy analysis of Google and Yandex safe browsing,” in 2016 46th Annual IEEE/IFIP International Conference on Dependable Systems and Networks (DSN), IEEE, 2016, pp. 347–358. Accessed: Feb. 22 (2025). [Online]. Available: https://ieeexplore.ieee.org/abstract/document/7579754/
[12] P. Rani, P. N. Singh, S. Verma, N. Ali, P. K. Shukla, and M. Alhassan, “An implementation of modified blowfish technique with honey bee behaviour optimization for load balancing in the cloud system environment,” Wireless Communications and Mobile Computing, vol. 2022, pp. 1–14 (2022).
[13] A. Singh, S. Putluri, P. Rani, N. K. Agrawal, R. Sharma, E. Kariri, and D. G. Aray, “Smart Traffic Monitoring Through Real-Time Moving Vehicle Detection Using Deep Learning via Aerial Images for Consumer Application,” IEEE Trans. Consumer Electron., pp. 1–1 (2024), doi: 10.1109/TCE.2024.3445728.
[14] G. Goth, “Phishing attacks rising, but dollar losses down,” IEEE Secur. Privacy Mag., vol. 3, no. 1, p. 8 (Jan. 2005), doi: 10.1109/MSP.2005.21.
[15] S. Keelveedhi, M. Bellare, and T. Ristenpart, “{DupLESS}:{Server-Aided} encryption for deduplicated storage,” in 22nd USENIX security symposium (USENIX security 13), pp. 179–194 (2013). Accessed: Feb. 22, 2025. [Online]. Available: https://www.usenix.org/conference/usenixsecurity13/technical-sessions/presentation/bellare
[16] X. Yuan, X. Wang, C. Wang, C. Yu, and S. Nutanong, “Privacy-Preserving Similarity Joins Over Encrypted Data,” IEEE Trans.Inform.Forensic Secur., vol. 12, no. 11, pp. 2763–2775 (Nov. 2017), doi: 10.1109/TIFS.2017.2721221.
[17] Q. Wang, W. Guo, X. Du, and M. Guizani, “Privacy-Preserving Collaborative Model Learning: The Case of Word Vector Training,” IEEE Trans. Knowl. Data Eng., vol. 30, no. 12, pp. 2381–2393 (Dec. 2018), doi: 10.1109/TKDE.2018.2819673.
[18] MQ. Wang, W. Guo, X. Du, and M. Guizani, “An efficient algorithm to detect DDoS amplification attacks,” IFS, vol. 39, no. 6, pp. 8565–8572 (Dec. 2020), doi: 10.3233/JIFS-189173.
[19] T. Floyd, M. Grieco, and E. F. Reid, “Mining hospital data breach records: Cyber threats to U.S. hospitals,” in 2016 IEEE Conference on Intelligence and Security Informatics (ISI), Tucson, AZ, USA: IEEE, Sep. 2016), pp. 43–48. doi: 10.1109/ISI.2016.7745441.
[20] D. Kothandaraman, A. Kumar Sivaraman, S. Sundar, and K. Dhanalakshmi, “Energy and bandwidth based link stability routing algorithm for IoT,” Computers, Materials & Continua, vol. 70, no. 2, pp. 2817–2833 (2022). [Online]. Available: https://www.researchgate.net/profile/Arun-Kumar-Sivaraman/publication/354859362_Energy_and_Bandwidth_Based_Link_Stability_Routing_Algorithm_for_IoT/links/61518d7d154b3227a8b02408/Energy-and-Bandwidth-Based-Link-Stability-Routing-Algorithm-for-IoT.pdf. Accessed: Feb. 22, 2025.
[21] X. Liu, R. H. Deng, K.-K. R. Choo, and J. Weng, “An Efficient Privacy-Preserving Outsourced Calculation Toolkit With Multiple Keys,” IEEE Trans.Inform.Forensic Secur., vol. 11, no. 11, pp. 2401–2414 (Nov. 2016), doi: 10.1109/TIFS.2016.2573770.
[22] R. M. Mohammad, F. Thabtah, and L. McCluskey, “Predicting phishing websites based on self-structuring neural network,” Neural Comput & Applic, vol. 25, no. 2, pp. 443–458 (Aug. 2014), doi: 10.1007/s00521-013-1490-z.
[23] G.-B. Huang, Q.-Y. Zhu, and C.-K. Siew, “Extreme learning machine: theory and applications,” Neurocomputing, vol. 70, no. 1–3, pp. 489–501 (2006).
[24] G.-B. Huang, Q.-Y. Zhu, and C.-K. Siew, “Extreme learning machine: a new learning scheme of feed-forward neural networks,” in 2004 IEEE International Joint Conference on neural networks (IEEE Cat. No. 04CH37541), Ieee, pp. 985–990 (2004). Accessed: Feb. 26, 2025. [Online]. Available: https://ieeexplore.ieee.org/abstract/document/1380068/
[25] I. Guyon and A. Elisseeff, “An Introduction to Feature Extraction,” in Feature Extraction, vol. 207, I. Guyon, M. Nikravesh, S. Gunn, and L. A. Zadeh, Eds., in Studies in Fuzziness and Soft Computing, vol. 207., Berlin, Heidelberg: Springer Berlin Heidelberg, pp. 1–25 (2006). doi: 10.1007/978-3-540-35488-8_1.

Views: 173Downloads: 4Citations: 0