← All drillsPhishing & Malicious-URL Detector
What you'll be able to do- ✓Build a classifier that flags phishing and malicious URLs from the link text alone
- ✓Engineer lexical features from a raw URL the way a security analyst reads one
- ✓Score a security classifier honestly with precision, recall, and F1 — not just accuracy
- ✓Tune the decision threshold for a firewall, trading false alarms against missed attacks
- ✓Ship a reusable classify_url() detector plus a mini URL-firewall demo
Build the brain of an SMS/URL firewall — score a link as safe or phishing in real time, the way Google Safe Browsing, Proofpoint, and Cloudflare protect billions of users.
⌁ The engine behind safe-browsing and anti-phishing filters — Google Safe Browsing, Microsoft Defender, Proofpoint, Cloudflare — and the SMS/link firewalls telecom operators run.
Start this internshipCreate an account to unlock the 10 sections, the workbench, and AskThili.
BeginSections
1. Building a Phishing and Malicious-URL Detector
🔒 locked2. Lesson 1 - The problem & the data
🔒 locked3. Lesson 2 - Read a URL like an attacker
🔒 locked4. Lesson 3 - A baseline & why accuracy lies
🔒 locked5. Lesson 4 - Naive Bayes from scratch
🔒 locked6. Lesson 5 - Train / test — the honest score
🔒 locked7. Lesson 6 - Tuning the threshold
🔒 locked8. Lesson 7 - Production classifier
🔒 locked9. Lesson 8 - What the model learned & evasion
🔒 locked10. Lesson 9 - The phishing detector (ship it)
🔒 lockedDig deeper
📄Beyond Blacklists: Learning to Detect Malicious Web Sites from Suspicious URLs (Ma, Saul, Savage & Voelker, 2009, KDD)
paper🔗scikit-learn — Text feature extraction and classification
docs🔗PhishTank — a live community feed of verified phishing URLs
docsPart of these learning paths
I'm a security professional and I want to test AI/ML systems for vulnerabilities
View path →