Abstract
Phish Intention is an open-source Cybersecurity & Ethical Hacking project. PhishIntention: Phishing detection through webpage intention. Existing reference-based phishing detectors only capture brand intention, which makes them prone to false positives. PhishIntention is, to our knowledge, the first system to analyze both brand intention and credential-taking intention in a systematic way, and it powers a phishing-monitoring pipeline that reports phishing webpages daily with state-of-the-art precision. It is built using Python. The complete source code is publicly available on GitHub under the Creative Commons Zero v1.0 Universal, making it a useful reference for students building a Cybersecurity & Ethical Hacking mini project or final-year project.
1. Introduction
Existing reference-based phishing detectors only capture brand intention, which makes them prone to false positives. PhishIntention is, to our knowledge, the first system to analyze both brand intention and credential-taking intention in a systematic way, and it powers a phishing-monitoring pipeline that reports phishing webpages daily with state-of-the-art precision.
Official implementation of "Inferring Phishing Intention via Webpage Appearance and Dynamics: A Deep Vision-Based Approach" (USENIX Security 2022) — paper, project website.
Input: a screenshot (and optionally the HTML source). Output: Phish/Benign and the predicted phishing target.
2. Objective
PhishIntention: Phishing detection through webpage intention
This project demonstrates how Python can be applied to a real-world Cybersecurity & Ethical Hacking problem.
4. Technology Stack
- Abstract Layout Detector (AWL) — detect page elements (logos, inputs, buttons, …).
- OCR-aided Siamese Logo Comparison — if no brand is matched, return Benign; otherwise continue with the matched target.
- CRP Classifier — decide whether the page requests credentials (CRP). If yes, go to step 5; if no and the CRP locator has not run yet, go to step 4; otherwise return Benign.
- CRP Locator (dynamic analysis) — click login/signup links to reach a credential page. On success, restart from step 1 with the updated URL and screenshot; on failure, return Benign.
- Decision — a credential page with a matched brand inconsistent with the domain ⇒ Phish + target; otherwise Benign.
5. System Requirements
General requirements for this technology stack — check the README for exact versions.
- Python 3.8 or later
- pip / virtualenv for dependencies
- VS Code, PyCharm or Jupyter Notebook
- Git (to clone the repository)
6. Installation & Setup
git clone https://github.com/lindsey98/PhishIntention.git
cd PhishIntentiongit clone https://github.com/lindsey98/PhishIntention.git
cd PhishIntention
export KMP_DUPLICATE_LIB_OK=TRUE
# Install pixi (restart your terminal afterwards)
curl -fsSL https://pixi.sh/install.sh | sh
# Install Chrome (Ubuntu/Debian)
wget https://dl.google.com/linux/direct/google-chrome-stable_current_amd64.deb
sudo dpkg -i google-chrome-stable_current_amd64.deb
sudo apt-get install -f
pixi install
chmod +x scripts/setup.sh && ./scripts/setup.shgit clone https://github.com/lindsey98/PhishIntention.git
cd PhishIntention
export KMP_DUPLICATE_LIB_OK=TRUE
# Install pixi (restart your terminal afterwards)
curl -fsSL https://pixi.sh/install.sh | sh
# Install Chrome and expose it on PATH (use ~/.zshrc for zsh)
brew install --cask google-chrome
echo 'export CHROME_BIN="/Applications/Google Chrome.app/Contents/MacOS/Google Chrome"' >> ~/.bash_profile
echo 'export PATH="/Applications/Google Chrome.app/Contents/MacOS:$PATH"' >> ~/.bash_profile
source ~/.bash_profile
pixi install
chmod +x scripts/setup.sh && ./scripts/setup.shgit clone https://github.com/lindsey98/PhishIntention.git
cd PhishIntention
# Install latest Chrome and ChromeDriver
.\scripts\chrome_setup.bat
# Install pixi (restart your terminal afterwards)
powershell -ExecutionPolicy ByPass -c "irm -useb https://pixi.sh/install.ps1 | iex"
pixi install
.\scripts\setup.batpixi run python -m phishintention --folder datasets/test_sites --output_fn test.jsonFull setup instructions are in the project README.
7. Future Enhancements
Suggested extensions you can add to make this your own project.
- Add logging and alert notifications (email / Telegram)
- Write a threat model document for the tool
- Package it with Docker for safe lab testing
8. Viva / Review Questions
Common questions examiners ask for projects in this domain.
- Which threat or attack does this project defend against?
- What detection or protection technique is used and what are its limits?
- How are false positives and false negatives handled?
- Which cryptographic algorithms or security standards are involved?
- What legal and ethical rules apply when testing a tool like this?
9. Source Code & License
This project is developed by lindsey98 and published on GitHub under the Creative Commons Zero v1.0 Universal. Please follow the license terms and credit the original author when you use or modify this code.
Want to build this as your internship project?
Work on a Cybersecurity & Ethical Hacking project like this with mentor guidance, weekly reviews and an internship certificate from Training Trains, Erode — online or offline.
Apply for Cybersecurity & Ethical Hacking Internship