发表机构
Federal University of Technology, Minna(尼日利亚明纳联邦科技大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
针对尼日利亚金融科技钓鱼邮件,提出结合发件人检查与BiLSTM分类的Gmail扩展原型,实现高精度检测,但需进一步评估端到端性能。
AI 中文摘要
冒充尼日利亚金融科技服务提供商的钓鱼邮件可能结合欺骗性发件人地址、相似链接和本地熟悉的语言。本研究提出一个Gmail浏览器扩展,将发件人域名和URL检查与双向长短期记忆(BiLSTM)分类器相结合。该扩展将可见发件人地址和链接与八个金融科技平台的配置文件进行比较,从本地托管的Flask服务获取钓鱼概率,并在打开邮件时显示合法、警告或钓鱼判定。BiLSTM分类器在从59,622封钓鱼和合法邮件清理后的数据集中抽取的8,943条测试消息上进行了评估。测试混淆矩阵记录了4,308个真阴性、0个假阳性、1个假阴性和4,634个真阳性。这些计数对应99.99%的准确率、100.00%的精确率、99.98%的召回率和99.99%的F1分数。分词序列分析显示训练集和测试集之间存在5.79%的重叠,这可能高估了对独立消息的性能估计。Gmail演示展示了集成扩展产生用户可见的判定,但完整系统未在标记测试集上评估。研究结果证实了所实现原型的可行性,同时将其端到端检测性能和泛化到未见攻击的能力留待进一步评估。
英文摘要
Phishing emails that impersonate Nigerian fintech providers can combine deceptive sender addresses, lookalike links, and locally familiar language. This study presents a Gmail browser extension that integrates sender-domain and URL checks with a bidirectional long short-term memory (BiLSTM) classifier. The extension compares visible sender addresses and links with profiles for eight fintech platforms, obtains a phishing probability from a locally hosted Flask service, and displays a legitimate, warning, or phishing verdict when an email is opened. The BiLSTM classifier was evaluated on 8,943 test messages from a cleaned dataset of 59,622 phishing and legitimate emails. The test confusion matrix recorded 4,308 true negatives, no false positives, one false negative, and 4,634 true positives. These counts correspond to 99.99% accuracy, 100.00% precision, 99.98% recall, and 99.99% F1 score. Tokenized sequence analysis identified 5.79% overlap between the training and test sets, which may inflate performance estimates for independent messages. A Gmail demonstration showed the integrated extension producing user-visible verdicts, although the complete system was not evaluated on a labeled test set. The findings establish the feasibility of the implemented prototype while leaving its end-to-end detection performance and generalization to unseen attacks open for further evaluation.
Comments9 pages, 4 figures