Skip to content

FEAT : 인프라 정리 + PhiUSIIL Baseline 확보 / FN 9건 한계 식별 #1

Description

@kim-subsub

문제

PhiUSIIL test 5,000건 중 9건의 phishing URL을 정상으로 분류 (Recall 0.9964).
9건 모두 character pattern으로 정상 URL과 구분 불가능한 형태.

FN 사례

score URL
0.2706 https://www.vmailmessage.com
0.1013 https://www.smtd.jp.zhukoudai.com
0.0180 https://www.filmsrip.stream
0.0028 https://www.semana-apenas.com
0.0017 https://www.dficohsa.com
0.0010 https://www.sorrentinovini.com
0.0009 https://www.vticket.eu
0.0005 https://www.insideoutconstructionva.com
0.0004 https://www.radiantcs.com.pk

가설

  • 9건 모두 https://www.{도메인}.{tld} 단순 형태, path/의심 character 없음
  • 8건은 score < 0.02 → threshold 튜닝(0.5→0.3)으로 1건만 추가 검출
  • URL 문자열만으론 "평범해 보이는 신규 phishing 도메인" 본질적 구분 불가
  • 예외 1건: smtd.jp.zhukoudai.com (nested subdomain 위장) — 학습 가능했어야 함

작업 항목

  • WHOIS 등록일자 feature 통합 (신규 도메인 = 위험 신호)
  • DNS / TLD reputation feature 검토
  • PhiUSIIL의 미사용 55개 컬럼 활용 검토 (현재 URL 1개만 사용)
  • 모델 구조: kernel_size에 6~7 추가, nested subdomain 패턴 강화
  • 데이터: nested subdomain phishing 케이스 의도적 추가

목표 지표

  • Recall 0.9964 → 0.9990 이상
  • FN 9 → 2 이하 (smtd 같은 명백한 위장만 남기기)

참고

  • baseline 확보 PR: #(PR번호)
  • 관련 README 목표: 2번(성능 향상), 3번(모델 구조 개선)

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions