Application of the parameter fuzzification method based on reference subenvironments forphishing attack detection

Authors

  • A. Korchenko, National Technical University Dnipro Polytechnic
  • M. Askerov State University of Information and Communication Technologies, Kyiv
  • I. Ireifidzh Opole University of Technology, Opole, Poland
  • K. Davydenko National Technical University Dnipro Polytechnic
  • A. Herasymenko State University of Information and Communication Technologies, Kyiv

DOI:

https://doi.org/10.31673/2412-9070.2026.043814

Abstract

The increasing number and complexity of phishing attacks, along with the continuous improvement of techniques for circumventing existing security mechanisms, necessitate the development of phishing detection methods capable of accounting for uncertainty in URL parameters and domain infrastructure characteristics. An analysis of current approaches has shown that methods based on threshold values, signature analysis, machine learning, and fuzzy logic have limitations in adapting to emerging types of attacks and do not provide a formalized procedure for parameter fuzzification tailored to the specific characteristics of phishing web resources. This study employs methods of system analysis, comparative analysis, mathematical modeling, and fuzzy logic. The research is based on the further development of an existing parameter fuzzification method using reference subenvironments through its adaptation to the specific characteristics of phishing URLs. For this purpose, phishing activity parameters were formalized, the corresponding linguistic terms were defined, correction reference values were established, and a fuzzification procedure was implemented for domain age, DNS change frequency, number of subdomains, URL length, and SSL/HTTPS protection status. The novelty of the study lies in extending the functional capabilities of the parameter fuzzification method based on reference subenvironments. By formalizing the transformation of current parameter values, mapping them onto two-dimensional current environments, and adapting the method to the specific characteristics of phishing URLs, it becomes possible to use the resulting fuzzified values in phishing attack detection procedures. As a result, fuzzified parameter values were obtained and used to assess the membership of current parameter values in the corresponding linguistic reference sets and to determine the two-dimensional reference region corresponding to the current level of the anomalous state induced by phishing activity. The proposed method can be used in the development of phishing attack detection systems, cybersecurity expert systems, decision support systems, and intelligent systems for phishing URL analysis.

Keywords: phishing, phishing URLs, phishing attack detection systems, cybersecurity, information security.

Published

2026-09-09

Issue

Section

Articles