Phishing Infrastructure as a Digital Sovereignty Threat: An Explainable Structural URL Analysis
Keywords:
phishing infrastructure, digital sovereignty, explainable cybersecurity, structural url analysis, cross-border cyber threats, cyber governance, sovereign cyberspaceAbstract
Phishing has evolved into a distributed cyber infrastructure operating across globally interconnected digital environments. Modern phishing campaigns increasingly exploit lexical manipulation, hierarchical domain structures, and cross-border hosting ecosystems to imitate legitimate services while evading conventional detection systems. However, existing phishing research remains predominantly focused on predictive accuracy and deep learning optimization, with limited attention to interpretability, infrastructure behavior, and digital sovereignty implications. This study investigates phishing infrastructures through an explainable structural URL analysis framework while examining their relationship with fragmented cyberspace governance. A quantitative exploratory approach was employed using phishing and legitimate URLs collected from multiple public cybersecurity repositories. Structural feature extraction included URL length, entropy, numerical tokenization, suspicious lexical indicators, HTTPS presence, subdomain complexity, and top-level domain (TLD) distribution. Statistical analysis and explainable Logistic Regression modeling were subsequently applied to identify significant structural phishing characteristics and feature influence patterns. The results demonstrate that phishing URLs exhibit substantially higher lexical complexity, entropy variation, numerical obfuscation, and hierarchical subdomain manipulation compared with legitimate domains. Numerical patterns, suspicious keywords, entropy-related randomness, and structural domain engineering were identified as major contributors to phishing classification. The findings further reveal that several non-.com TLD ecosystems are disproportionately associated with phishing infrastructures, indicating opportunistic exploitation of fragmented and globally distributed governance environments. This study contributes to cybersecurity research by reframing phishing not only as a technical cybercrime issue, but also as a digital sovereignty and governance challenge embedded within transnational cyberspace infrastructures. The findings highlight the importance of explainable and infrastructure-aware cybersecurity approaches for supporting more resilient cross-border cyber governance frameworks.
Downloads
References
Basit, A., Zafar, M., Liu, X., Javed, A. R., Jalil, Z., & Kifayat, K. (2021). A comprehensive survey of AI-enabled phishing attacks detection techniques. Telecommunication Systems, 76(1), 139–154. https://doi.org/10.1007/s11235-020-00733-2
Capuano, N., Fenza, G., Loia, V., & Stanzione, C. (2022). Explainable Artificial Intelligence in CyberSecurity: A Survey. IEEE Access, 10, 93575–93600. https://doi.org/10.1109/ACCESS.2022.3204171
Catal, C., Giray, G., Tekinerdogan, B., Kumar, S., & Shukla, S. (2022). Applications of deep learning for phishing detection: a systematic literature review. Knowledge and Information Systems, 64(6), 1457–1500. https://doi.org/10.1007/s10115-022-01672-x
Couture, S., Toupin, S., & Mayoral Baños, A. (2024). Resisting and Claiming Digital Sovereignty: The Cases of Civil Society and Indigenous Groups. Policy & Internet, 16(4), 739–749. https://doi.org/10.1002/poi3.434
Donnelly, S., Ríos Camacho, E., & Heidebrecht, S. (2024). Digital sovereignty as control: the regulation of digital finance in the European Union. Journal of European Public Policy, 31(8), 2226–2249. https://doi.org/10.1080/13501763.2023.2295520
El Aassal, A., Baki, S., Das, A., & Verma, R. M. (2020). An In-Depth Benchmarking and Evaluation of Phishing Detection Research for Security Needs. IEEE Access, 8, 22170–22192. https://doi.org/10.1109/ACCESS.2020.2969780
Flonk, D., Jachtenfuchs, M., & Obendiek, A. (2024). Controlling internet content in the EU: towards digital sovereignty. Journal of European Public Policy, 31(8), 2316–2342. https://doi.org/10.1080/13501763.2024.2309179
Fratini, S., Hine, E., Novelli, C., Roberts, H., & Floridi, L. (2024). Digital Sovereignty: A Descriptive Analysis and a Critical Evaluation of Existing Models. Digital Society, 3(3), 59. https://doi.org/10.1007/s44206-024-00146-7
Ganz, A., Camellini, M., Hine, E., Novelli, C., Roberts, H., & Floridi, L. (2025). Correction: Submarine Cables and the Risks to Digital Sovereignty. Minds and Machines, 35(1), 7. https://doi.org/10.1007/s11023-024-09707-8
Glasze, G., Cattaruzza, A., Douzet, F., Dammann, F., Bertran, M.-G., Bômont, C., Braun, M., Danet, D., Desforges, A., Géry, A., Grumbach, S., Hummel, P., Limonier, K., Münßinger, M., Nicolai, F., Pétiniaud, L., Winkler, J., & Zanin, C. (2023). Contested Spatialities of Digital Sovereignty. Geopolitics, 28(2), 919–958. https://doi.org/10.1080/14650045.2022.2050070
Gordon, G. (2024). Digital sovereignty, digital infrastructures, and quantum horizons. AI & SOCIETY, 39(1), 125–137. https://doi.org/10.1007/s00146-023-01729-7
Heiding, F., Schneier, B., Vishwanath, A., Bernstein, J., & Park, P. S. (2024). Devising and Detecting Phishing Emails Using Large Language Models. IEEE Access, 12, 42131–42146. https://doi.org/10.1109/ACCESS.2024.3375882
Hellmeier, M., Pampus, J., Qarawlus, H., & Howar, F. (2023). Implementing Data Sovereignty: Requirements & Challenges from Practice. Proceedings of the 18th International Conference on Availability, Reliability and Security, 1–9. https://doi.org/10.1145/3600160.3604995
Hurst, W., & Shone, N. (2024). Critical infrastructure security: Cyber-threats, legacy systems and weakening segmentation. In Management and Engineering of Critical Infrastructures (pp. 265–286). Elsevier. https://doi.org/10.1016/B978-0-323-99330-2.00010-6
Jain, A. K., & Gupta, B. B. (2018). Towards detection of phishing websites on client-side using machine learning based approach. Telecommunication Systems, 68(4), 687–700. https://doi.org/10.1007/s11235-017-0414-0
Katsikas, S. K. (2025). Towards a cybersecurity-oriented research agenda for digital sovereignty. Procedia Computer Science, 254, 279–288. https://doi.org/10.1016/j.procs.2025.02.087
Li, W., Xiong, B., & Yang, C. (2024). A roadmap to achieving a healthier information ecosystem through GDPR implementation and privacy compliance technologies. Journal of the Association for Information Science and Technology, 75(10), 1182–1201. https://doi.org/10.1002/asi.24878
Linh, D. M., & Hung, T. C. (2025). A feature-engineered dataset of benign and phishing URLs for machine learning and large language models evaluation. Data in Brief, 63, 112162. https://doi.org/10.1016/j.dib.2025.112162
Mahajan, S. (2023). Phishing uniform resource locator detection using machine learning: A step towards secure system. SECURITY AND PRIVACY, 6(6). https://doi.org/10.1002/spy2.311
Marchal, S., Francois, J., State, R., & Engel, T. (2014). PhishStorm: Detecting Phishing With Streaming Analytics. IEEE Transactions on Network and Service Management, 11(4), 458–471. https://doi.org/10.1109/TNSM.2014.2377295
Misra, S., Barik, K., & Kvalvik, P. (2025). Trust in Digital Sovereignty: A Review of Security, Privacy, and Governance Challenges. Public Organization Review. https://doi.org/10.1007/s11115-025-00968-0
Musiani, F. (2022). Infrastructuring digital sovereignty: a research agenda for an infrastructure-based sociology of digital self-determination practices. Information, Communication & Society, 25(6), 785–800. https://doi.org/10.1080/1369118X.2022.2049850
Nagy, N., Aljabri, M., Shaahid, A., Ahmed, A. A., Alnasser, F., Almakramy, L., Alhadab, M., & Alfaddagh, S. (2023). Phishing URLs Detection Using Sequential and Parallel ML Techniques: Comparative Analysis. Sensors, 23(7), 3467. https://doi.org/10.3390/s23073467
Popescul, D., & Radu, L. D. (2025). AI in phishing detection: a bibliometric review. Frontiers in Artificial Intelligence, 8. https://doi.org/10.3389/frai.2025.1496580
Potpelwar, R. S., Kulkarni, U. V., & Waghmare, J. M. (2025). LegitPhish: A large-scale annotated dataset for URL-based phishing detection. Data in Brief, 63, 111972. https://doi.org/10.1016/j.dib.2025.111972
Prasad, A., & Chandra, S. (2024). PhiUSIIL: A diverse security profile empowered phishing URL detection framework based on similarity index and incremental learning. Computers & Security, 136, 103545. https://doi.org/10.1016/j.cose.2023.103545
Rao, R. S., & Pais, A. R. (2019). Detection of phishing websites using an efficient feature-based machine learning framework. Neural Computing and Applications, 31(8), 3851–3873. https://doi.org/10.1007/s00521-017-3305-0
Sabella, D., Maloor, K., Smith, N., Vanderveen, M., & Kourtis, A. (2024). Edge Computing Cybersecurity standards: protecting infrastructure and applications. IEEE Access, 1–1. https://doi.org/10.1109/ACCESS.2024.3506212
Safi, A., & Singh, S. (2023). A systematic literature review on phishing website detection techniques. Journal of King Saud University - Computer and Information Sciences, 35(2), 590–611. https://doi.org/10.1016/j.jksuci.2023.01.004
Silva, C. M. R. da, Feitosa, E. L., & Garcia, V. C. (2020). Heuristic-based strategy for Phishing prediction: A survey of URL-based approach. Computers & Security, 88, 101613. https://doi.org/10.1016/j.cose.2019.101613
Somesha, M., Pais, A. R., Rao, R. S., & Rathour, V. S. (2020). Efficient deep learning techniques for the detection of phishing websites. Sādhanā, 45(1), 165. https://doi.org/10.1007/s12046-020-01392-4
Tan, K. L., Chi, C.-H., & Lam, K.-Y. (2024). Survey on Digital Sovereignty and Identity: From Digitization to Digitalization. ACM Computing Surveys, 56(3), 1–36. https://doi.org/10.1145/3616400
Uddin, K. M. M., Biswas, N., Rikta, S. T., Nur ‐A‐Alam, Md., & Mostafiz, R. (2025). Explainable Machine Learning for Phishing Site Detection: A High‐Efficiency Approach Using Boosting Models and SHAP. The Journal of Engineering, 2025(1). https://doi.org/10.1049/tje2.70110
Walden, I., & Michels, J. D. (2024). Getting Critical: Making Sense of the EU Cybersecurity Framework for Cloud Providers (pp. 9–38). https://doi.org/10.1007/978-3-031-41820-4_2
Wang, W., Zhang, F., Luo, X., & Zhang, S. (2019). PDRCNN: Precise Phishing Detection with Recurrent Convolutional Neural Networks. Security and Communication Networks, 2019, 1–15. https://doi.org/10.1155/2019/2595794
Wilk-Jakubowski, J. L., Pawlik, L., Wilk-Jakubowski, G., & Sikora, A. (2025). Machine Learning and Neural Networks for Phishing Detection: A Systematic Review (2017–2024). Electronics, 14(18), 3744. https://doi.org/10.3390/electronics14183744
Xiang, G., Hong, J., Rose, C. P., & Cranor, L. (2011). CANTINA+. ACM Transactions on Information and System Security, 14(2), 1–28. https://doi.org/10.1145/2019599.2019606
Downloads
Published
Issue
Section
License
Copyright (c) 2026 Achmad Fauzan, Tito Pinandita, Aulia Desy Nur Utomo (Author)

This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.
