Open Access Open Access  Restricted Access Subscription Access

Anti-Phish Guard: Intelligent Browser Extension for Real-Time Phishing Detection and Prevention

Goutham R, Gagandeep S, Adarsha ..

Abstract


Conventional web browsing places users at signifi-cant risk of phishing attacks, in which bad actors create malicious websites to deceptively render them vulnerable to the capture of sensitive information, typically through fake links and interfaces. Manual verification techniques are often slow, unreliable, and do not usually identify advanced phishing attacks. To address these issues, this paper describes the design and use of Anti-Phish Guard (APG), an intelligent web browser extension that provides real-time detection and protection against phishing attacks. The system is implemented in modern web technologies, including HTML, CSS, JavaScript, Manifest V3 format, and Node.js based backend APIs.

APG automatically scans URLs during page loading and during user interaction using heuristic checks, domain reputation analysis, and pattern-based detection. Untrusted links get flagged, and users receive alerts in real-time through the browser notifi-cation interface. The architecture uses the IP address metadata to find link authenticity and detects potential attackers, while also logging their patterns of attack. The cloud-based backend built using Node.js and MongoDB detects and dedicates known blacklisted URLs, stores records of attack logs, and syncs recent detections. Experimental evaluations show that the detection of phishing URLs is highly accurate and there are few false positives in detection patterns, demonstrating seamless use into normal workflows for browsing. The proposed solution offers a zero-trust model for phishing URL detection but at a secure, scalable, and user-friendly protective layer within the context of social media.


Full Text:

PDF

References


S. Aburajab, A. Alaraifi, and M. Alhammad, “A Comprehensive Survey on Phishing Attacks: Detection Techniques, Defense Mechanisms, and Challenges,” IEEE Access, vol. 10, pp. 120345–120367, 2022.

M. S. Alam and N. Saxena, “Design and Evaluation of Browser Extensions for Detecting Malicious URLs,” International Journal of Cybersecurity and Digital Forensics, vol. 11, no. 2, pp. 89–102, 2021.

Node.js Foundation, “Node.js Documentation,” 2024. [Online]. Avail-able: https://nodejs.org

MongoDB Inc., MongoDB: The Definitive Guide, 3rd ed., O’Reilly Media, 2022.

A. Yue and H. Wang, “Characterizing Insecure JavaScript Practices on the Web,” ACM Transactions on the Web, vol. 12, no. 4, pp. 1–25, Dec. 2018.

A. T. Zulkarnain et al., “IP Reputation-Based Detection Mechanisms for Cyber Threats,” IEEE Transactions on Information Forensics and Security, vol. 17, pp. 455–468, 2022.

M. Jones, “JSON Web Tokens (JWT): Internet Engineering Task Force Standard,” IETF RFC 7519, 2015.

J. Duckett, HTML & CSS: Design and Build Websites. Wiley, 2019.

Express.js Team, “Express.js Documentation,” 2024. [Online]. Available: https://expressjs.com

A. Jain and B. Gupta, “Phishing Detection: Analysis of Machine Learn-ing Techniques and Performance Evaluation,” IEEE Communications Surveys & Tutorials, vol. 23, no. 4, pp. 2351–2376, Dec. 2021.


Refbacks

  • There are currently no refbacks.