Hybrid Deep Learning Model for Early Phishing Attack Detection and Automated Cyber Threat Intelligence Analysis Systems
Rami Shehab: Vice-Presidency for Postgraduate Studies and Scientific Research, King Faisal University, 31982, Al-Ahsa, Saudi Arabia, SAU
Published: 2026/09/02
Pages: 33–59
Abstract
Phishing detectors typically only detect whether a message is a phishing attempt or not and offer little context to aid in incident response. This study is a contribution to fill this gap by providing a single framework for early detection and automatic generation of cyber threat intelligence based on URL. The proposed model is based on multi-kernel character convolution, BiLSTM attention, and 18 lexical–structural URL features, which are fused adaptively based on the samples. It was tested with a domain-grouped internal partitions set and an independent URL-phish test set. The source confidence, temporal freshness, entity correlation, ATT&CK mapping, and STIX 2.1 reporting were all used to enhance the high-risk predictions. The framework achieved 96.96% macro-F1, 96.51% phishing recall, and an MCC of 0.939 on the internal test set. Under cross-dataset evaluation, macro-F1 remained 95.57%, showing a smaller performance decline than conventional machine-learning, CNN–BiLSTM, transformer, and direct-fusion baselines. The CTI layer reached 92.8% indicator completeness, 93.8% entity F1, and 90.7% ATT&CK mapping F1, with a mean actionability score of 4.46/5. Adaptive evidence fusion improved detection stability, while conditional CTI enrichment converted suspicious URLs into structured and operationally useful intelligence.
Keywords
Hybrid Deep Learning Model for Early Phishing Attack Detection and Automated Cyber Threat Intelligence Analysis Systems is licensed under CC BY 4.0
References
- Hnamte, V., Nhung-Nguyen, H., Hussain, J., & Hwa-Kim, Y. (2023). A novel two-stage deep learning model for network intrusion detection: LSTM-AE. IEEE Access, 11, 37131–37148. https://doi.org/10.1109/ACCESS.2023.3266979
- Hosseinzadeh, M., Ali, U., Ali, S., Abbaszadi, R., Gharehchopogh, F. S., Khoshvaght, P., ... & Lansky, J. (2025). Improving phishing email detection performance through deep learning with adaptive optimization. Scientific Reports, 15(1), 36724. https://doi.org/10.1038/s41598-025-20668-5
- Charmet, F., Morikawa, T., Tanaka, A., & Takahashi, T. (2024). VORTEX: Visual phishing detectiOns aRe through EXplanations. ACM Transactions on Internet Technology, 24(2), Article 9. https://doi.org/10.1145/3654665
- Pira, L., & Ferrie, C. (2024). On the interpretability of quantum neural networks. Quantum Machine Intelligence, 6(2), 52.
- Kailas, S., & Roopalakshmi, R. (2025). “Think before you click”—Malicious URL detection in cybersecurity: A systematic review and research roadmap. IEEE Access, 13, 154305–154325. https://doi.org/10.1109/ACCESS.2025.3601387
- Sajid, M., Malik, K. R., Almogren, A., Malik, T. S., Khan, A. H., Tanveer, J., & Rehman, A. U. (2024). Enhancing intrusion detection: a hybrid machine and deep learning approach. Journal of Cloud Computing, 13(1), 123.
- Kongsorot, Y., Musikawan, P., Aimtongkham, P., You, I., Benslimane, A., & So-In, C. (2023). An intrusion detection and identification system for Internet of Things networks using a hybrid ensemble deep learning framework. IEEE Transactions on Sustainable Computing, 8(4), 596–613. https://doi.org/10.1109/TSUSC.2023.3303422
- Wisanwanichthan, T., & Thammawichai, M. (2021). A double-layered hybrid approach for network intrusion detection system using combined naive bayes and SVM. IEEE access, 9, 138432-138450.
- Panda, M., Abraham, A., & Patra, M. R. (2012). A hybrid intelligent approach for network intrusion detection. Procedia engineering, 30, 1-9.
- Goenka, R., Chawla, M., & Tiwari, N. (2025). Enhanced phishing detection approach using a layered model: Domain squatting and URL obfuscation identification and lexical feature-based classification. IEEE Access, 13, 187285–187306. https://doi.org/10.1109/ACCESS.2025.3626819
- Cohen, D., Te’eni, D., Yahav, I., Zagalsky, A., Schwartz, D., Silverman, G., ... & Makowski, J. (2025). Human–AI enhancement of cyber threat intelligence. International Journal of Information Security, 24(2), 99. https://doi.org/10.1007/s10207-025-01004-4
- Chung, Y. Y., & Wahid, N. (2012). A hybrid network intrusion detection system using simplified swarm optimization (SSO). Applied soft computing, 12(9), 3014-3022.
- Kulkarni, A., Balachandran, V., & Das, T. (2025). Phishing webpage detection: Unveiling the threat landscape and investigating detection techniques. IEEE Communications Surveys & Tutorials, 27(2), 974–1007. https://doi.org/10.1109/COMST.2024.3441752
- Mamodiya, U., Kishor, I., Naz, R., Almaiah, M., & Alqutaish, A. (2026). A hybrid blockchain-based framework for adaptive cyber-risk prediction and multi-layer threat mitigation in enterprise networks. Journal of Cybersecurity and Privacy, 6(3), 85. https://doi.org/10.3390/jcp6030085
- Dimitriadis, A., Papoutsis, A., Kavalieros, D., Tsikrika, T., Vrochidis, S., & Kompatsiaris, I. (2025). EVACTI: evaluating the actionability of cyber threat intelligence: A. Dimitriadis et al. International Journal of Information Security, 24(3), 123. https://doi.org/10.1007/s10207-025-01033-z
- Brezeanu, G., Archip, A., & Artene, C.-G. (2025). Phish Fighter: Self updating machine learning shield against phishing kits based on HTML code analysis. IEEE Access, 13, 4460–4486. https://doi.org/10.1109/ACCESS.2025.3525998
- Chen, Z., Liu, S.-Z., Huang, J., Xiu, Y.-H., Zhang, H., & Long, H.-X. (2024). Ethereum phishing scam detection based on data augmentation method and hybrid graph neural network model. Sensors, 24(12), 4022. https://doi.org/10.3390/s24124022
- Zhang, J., Sui, H., Sun, X., Ge, C., Zhou, L., & Susilo, W. (2024). GrabPhisher: Phishing scams detection in Ethereum via temporally evolving GNNs. IEEE Transactions on Services Computing, 17(6), 3727–3741. https://doi.org/10.1109/TSC.2024.3411449
- Schmitt, M. (2023). Securing the digital world: Protecting smart infrastructures and digital industries with artificial intelligence (AI)-enabled malware and intrusion detection. Journal of Industrial Information Integration, 36, 100520. https://doi.org/10.1016/j.jii.2023.100520
- Jiang, K., Wang, W., Wang, A., & Wu, H. (2020). Network intrusion detection combined hybrid sampling with deep hierarchical network. IEEE access, 8, 32464-32476.
- Babu, D. R. K., & Packialatha, A. (2023). Hybrid classification model with tuned weight for cyber attack detection: Big data perspective. Advances in Engineering Software, 177, 103408. https://doi.org/10.1016/j.advengsoft.2022.103408
- Jayanthi, S., Bavirthi, S. S., Murali, P., Kumar, K. V., Alkahtani, H. K., Ishak, M. K., & Mostafa, S. M. (2025). Advancements in cyberthreat intelligence through resource exhaustion attack detection using hybrid deep learning with heuristic search algorithms. Scientific Reports, 15(1), 30461. https://doi.org/10.1038/s41598-025-13305-8
- Govindarajan, M., & Chandrasekaran, R. M. (2011). Intrusion detection using neural based hybrid classification methods. Computer networks, 55(8), 1662-1671.
- Asiri, S., Xiao, Y., Alzahrani, S., Li, S., & Li, T. (2023). A survey of intelligent detection designs of HTML URL phishing attacks. IEEE Access, 11, 6421–6443. https://doi.org/10.1109/ACCESS.2023.3237798
- Susilo, B., Muis, A., & Sari, R. F. (2025). Intelligent intrusion detection system against various attacks based on a hybrid deep learning algorithm. Sensors, 25(2), 580. https://doi.org/10.3390/s25020580
- Gayathri, G. R., Sajjanhar, A., & Xiang, Y. (2024). Hybrid deep learning model using SPCAGAN augmentation for insider threat analysis. Expert Systems with Applications, 249, 123533. https://doi.org/10.1016/j.eswa.2024.123533
- Abbas, A., Salahuddin, M., Khan, M. Z., Khan, A. A., Zaman, F. U., Inam, S. A., ... & Khan, M. A. (2025). Machine learning-based hybrid technique to enhance cyber-attack perspective. Journal of Cloud Computing, 14(1), 57. https://doi.org/10.1186/s13677-025-00782-5
- Yang, T., & Sun, J. (2025). A hybrid ensemble deep learning framework with novel metaheuristic optimization for scalable malicious website detection. Scientific Reports, 15, 44630. https://doi.org/10.1038/s41598-025-33695-z
- Manivannan, A., & Amalanathan, A. (2025). GeoGuard: a hybrid deep learning intrusion detection system with integrated geo-intelligence and contextual awareness. IEEE Access. https://doi.org/10.1109/ACCESS.2025.3619557
- Song, Y., Zhang, D., Wang, J., Wang, Y., Wang, Y., & Ding, P. (2025). Application of deep learning in malware detection: a review. Journal of Big Data, 12(1), 99. https://doi.org/10.1186/s40537-025-01157-y
- Henry, S., Gautam, S., Khanna, S., Rabie, K., Shongwe, T., Bhattacharya, P., Sharma, B., & Chowdhury, S. (2023). Composition of hybrid deep learning model and feature optimization for intrusion detection system. Sensors, 23(2), 890. https://doi.org/10.3390/s23020890
- Arya, K., Siddhant, S., & Upadhyay, L. (2025). An explainable hybrid deep learning framework for network intrusion detection using feature-guided CNN models. IEEE Access, 13, 204954–204977. https://doi.org/10.1109/ACCESS.2025.3637857
- Dong, J.-D., Crichton, K., Yamada, A., Sawaya, Y., Cranor, L., & Christin, N. (2026). Accurate, generalizable, and practical behavioral models to identify impending user exposure to malicious websites. ACM Transactions on the Web, 20(1), Article 1, 1–31. https://doi.org/10.1145/3768587
- Mbura, R. K., Kato Benedicto, A., & Sinde, R. (2026). A novel hybrid approach for identification of discriminative features in phishing emails. IEEE Access, 14, 995–1013. https://doi.org/10.1109/ACCESS.2025.3649636
- Reda, S. A., Taie, S., & Shaheen, M. E. (2025). Hybrid MLOps framework for automated lifecycle management of adaptive phishing detection models. Scientific Reports, 15, 38478. https://doi.org/10.1038/s41598-025-23600-z
- Li, W., Manickam, S., & Chong, Y. W. (2025). FedPhishLLM: A privacy-preserving and explainable phishing detection mechanism using federated learning and LLMs. Journal of King Saud University–Computer and Information Sciences, 37, 252. https://doi.org/10.1007/s44443-025-00267-0
- Khan, S., Dilshad, N., Ahmad, N., Noor, S., & AlQahtani, S. A. (2025). Integrating AI in security information and event management for real time cyber defense. Scientific reports, 15(1), 35872. https://doi.org/10.1038/s41598-025-19689-x
- Ahmed, M., Altamimi, A. B., Khan, W., Alsaffar, M., Ahmad, A., Khan, Z. H., & Alreshidi, A. (2023). PhishCatcher: client-side defense against web spoofing attacks using machine learning. IEEE Access, 11, 61249-61263.
- Rashid, F., Doyle, B., Han, S. C., & Seneviratne, S. (2024). Phishing URL detection generalisation using unsupervised domain adaptation. Computer Networks, 245, 110398. https://doi.org/10.1016/j.comnet.2024.110398
- Mohammadzad, M., Karimpour, J., & Mahan, F. (2024). Cyber attacker’s next action prediction on dynamic real-time behavior model. Computers & Electrical Engineering, 113, 109031. https://doi.org/10.1016/j.compeleceng.2023.109031
- Wang, Z., Zhou, Y., Liu, H., Qiu, J., Fang, B., & Tian, Z. (2024). ThreatInsight: Innovating early threat detection through threat-intelligence-driven analysis and attribution. IEEE Transactions on Knowledge and Data Engineering, 36(12), 9388–9402. https://doi.org/10.1109/TKDE.2024.3474792
- Kavya, S., & Sumathi, D. (2025). Staying ahead of phishers: A review of recent advances and emerging methodologies in phishing detection. Artificial Intelligence Review, 58, 50. https://doi.org/10.1007/s10462-024-11055-z
- Alsubaei, F. S., Almazroi, A. A., & Ayub, N. (2024). Enhancing phishing detection: A novel hybrid deep learning framework for cybercrime forensics. IEEE Access, 12, 8373–8389. https://doi.org/10.1109/ACCESS.2024.3351946
- Elberri, M. A., Tokeşer, Ü., Rahebi, J., & Lopez-Guede, J. M. (2024). A cyber defense system against phishing attacks with deep learning game theory and LSTM-CNN with African vulture optimization algorithm (AVOA). International Journal of Information Security, 23(4), 2583-2606. https://doi.org/10.1007/s10207-024-00851-x
- Lee, S., Lee, K., Cho, S., & Choi, C. (2025). APTStop: A real-time framework for APT defense via strategic threat observation and prediction. IEEE Access, 13, 183134–183155. https://doi.org/10.1109/ACCESS.2025.3624035