{"id":{"repo_id":"unm","oai_identifier":"oai:digitalrepository.unm.edu:ece_etds-1062"},"canonical_url":"https://search.dev.ndltd.org/etd/unm/oai:digitalrepository.unm.edu:ece_etds-1062","repository":{"repo_id":"unm","name":"University of New Mexico","base_url":"https://digitalrepository.unm.edu/do/oai/"},"display":{"title":"A Lexical Approach for Classifying Malicious URLs","abstract":"Given the continuous growth of illicit activities on the Internet, there is a need for intelligent systems to identify malicious web pages. It has been shown that URL anal- ysis is an e\\u21b5ective tool for detecting phishing, malware, and other attacks. Previous studies have performed URL classification using a combination of lexical features, network tra c, hosting information, and other strategies. These approaches require time-intensive lookups which introduce significant delay in real-time systems. This paper describes a lightweight approach for classifying malicious web pages using URL lexical analysis alone. The goal is to explore the upper-bound of the classification accuracy of a purely lexical approach. Another aim is to develop an approach which could be used in a real-time system. These goal culminate in the development of a classification system based on lexical analysis of URLs. It correctly classifies URLs of malicious web pages with 99.1% accuracy, a 0.4% false positive rate, an F1-Score of 98.7, and requires 0.62 milliseconds on average. This method substantially out- performs previously published algorithms on out-of-sample data.","abstract_html":"Given the continuous growth of illicit activities on the Internet, there is a need for intelligent systems to identify malicious web pages. It has been shown that URL anal- ysis is an e\\u21b5ective tool for detecting phishing, malware, and other attacks. Previous studies have performed URL classification using a combination of lexical features, network tra c, hosting information, and other strategies. These approaches require time-intensive lookups which introduce significant delay in real-time systems. This paper describes a lightweight approach for classifying malicious web pages using URL lexical analysis alone. The goal is to explore the upper-bound of the classification accuracy of a purely lexical approach. Another aim is to develop an approach which could be used in a real-time system. These goal culminate in the development of a classification system based on lexical analysis of URLs. It correctly classifies URLs of malicious web pages with 99.1% accuracy, a 0.4% false positive rate, an F1-Score of 98.7, and requires 0.62 milliseconds on average. This method substantially out- performs previously published algorithms on out-of-sample data.","abstract_has_math":false,"creators":["Darling, Michael"],"institution":null,"degree_name":"Computer Engineering","degree_level":"Thesis","degree_discipline":"Electrical and Computer Engineering","degree_department":null,"school":null,"contributors":["Heileman, Greg","Jordan, Ramiro","Lamb, Chris"],"advisors":[],"committee_chairs":[],"committee_members":[],"year":2015,"date_issued":"2015-09-01T07:00:00Z","date_published":"2015-09-01T07:00:00Z","updated_at":"2026-07-24T05:27:10Z","subjects":["Machine Learning","Malware Detection","Classification","Malicious Web Pages","Supervised Learning","Natural Language Processing"],"languages":["English"],"rights":[],"rights_urls":[],"identifier_entries":[]},"links":{"outbound_url":"https://digitalrepository.unm.edu/ece_etds/63","outbound_label":"Repository record","outbound_source":"dc:identifier"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor","label":"Contributor","values":["Heileman, Greg","Jordan, Ramiro","Lamb, Chris"]},{"key":"dc:creator","label":"Author","values":["Darling, Michael"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"thesis:degree_discipline","label":"Discipline","values":["Electrical and Computer Engineering"]},{"key":"thesis:degree_level","label":"Degree Level","values":["Thesis","Masters"]},{"key":"thesis:degree_name","label":"Degree Name","values":["Computer Engineering"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["Machine Learning","Malware Detection","Classification","Malicious Web Pages","Supervised Learning","Natural Language Processing"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:language","label":"Dc Language","values":["English"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier","label":"Identifier","values":["https://digitalrepository.unm.edu/ece_etds/63"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description.abstract","label":"Abstract","values":["Given the continuous growth of illicit activities on the Internet, there is a need for intelligent systems to identify malicious web pages. It has been shown that URL anal- ysis is an e\\u21b5ective tool for detecting phishing, malware, and other attacks. Previous studies have performed URL classification using a combination of lexical features, network tra c, hosting information, and other strategies. These approaches require time-intensive lookups which introduce significant delay in real-time systems. This paper describes a lightweight approach for classifying malicious web pages using URL lexical analysis alone. The goal is to explore the upper-bound of the classification accuracy of a purely lexical approach. Another aim is to develop an approach which could be used in a real-time system. These goal culminate in the development of a classification system based on lexical analysis of URLs. It correctly classifies URLs of malicious web pages with 99.1% accuracy, a 0.4% false positive rate, an F1-Score of 98.7, and requires 0.62 milliseconds on average. This method substantially out- performs previously published algorithms on out-of-sample data."]},{"key":"dc:title","label":"Title","values":["A Lexical Approach for Classifying Malicious URLs"]}]}],"canonical_facts":{"dc:contributor":["Heileman, Greg","Jordan, Ramiro","Lamb, Chris"],"dc:creator":["Darling, Michael"],"dc:description.abstract":["Given the continuous growth of illicit activities on the Internet, there is a need for intelligent systems to identify malicious web pages. It has been shown that URL anal- ysis is an e\\u21b5ective tool for detecting phishing, malware, and other attacks. Previous studies have performed URL classification using a combination of lexical features, network tra c, hosting information, and other strategies. These approaches require time-intensive lookups which introduce significant delay in real-time systems. This paper describes a lightweight approach for classifying malicious web pages using URL lexical analysis alone. The goal is to explore the upper-bound of the classification accuracy of a purely lexical approach. Another aim is to develop an approach which could be used in a real-time system. These goal culminate in the development of a classification system based on lexical analysis of URLs. It correctly classifies URLs of malicious web pages with 99.1% accuracy, a 0.4% false positive rate, an F1-Score of 98.7, and requires 0.62 milliseconds on average. This method substantially out- performs previously published algorithms on out-of-sample data."],"dc:identifier":["https://digitalrepository.unm.edu/ece_etds/63"],"dc:language":["English"],"dc:subject":["Machine Learning","Malware Detection","Classification","Malicious Web Pages","Supervised Learning","Natural Language Processing"],"dc:title":["A Lexical Approach for Classifying Malicious URLs"],"thesis:degree_discipline":["Electrical and Computer Engineering"],"thesis:degree_level":["Thesis","Masters"],"thesis:degree_name":["Computer Engineering"]},"updated_at":"2026-07-24T05:27:10Z"}