Phishing Infrastructure as a Digital Sovereignty Threat: An Explainable Structural URL Analysis

Authors

  • Achmad Fauzan Universitas Muhammadiyah Purwokerto Author
  • Tito Pinandita Universiti Teknikal Malaysia Author
  • Aulia Desy Nur Utomo Universitas Telkom Purwokerto Author

Keywords:

phishing infrastructure, digital sovereignty, explainable cybersecurity, structural url analysis, cross-border cyber threats, cyber governance, sovereign cyberspace

Abstract

Phishing has evolved into a distributed cyber infrastructure operating across globally interconnected digital environments. Modern phishing campaigns increasingly exploit lexical manipulation, hierarchical domain structures, and cross-border hosting ecosystems to imitate legitimate services while evading conventional detection systems. However, existing phishing research remains predominantly focused on predictive accuracy and deep learning optimization, with limited attention to interpretability, infrastructure behavior, and digital sovereignty implications. This study investigates phishing infrastructures through an explainable structural URL analysis framework while examining their relationship with fragmented cyberspace governance. A quantitative exploratory approach was employed using phishing and legitimate URLs collected from multiple public cybersecurity repositories. Structural feature extraction included URL length, entropy, numerical tokenization, suspicious lexical indicators, HTTPS presence, subdomain complexity, and top-level domain (TLD) distribution. Statistical analysis and explainable Logistic Regression modeling were subsequently applied to identify significant structural phishing characteristics and feature influence patterns. The results demonstrate that phishing URLs exhibit substantially higher lexical complexity, entropy variation, numerical obfuscation, and hierarchical subdomain manipulation compared with legitimate domains. Numerical patterns, suspicious keywords, entropy-related randomness, and structural domain engineering were identified as major contributors to phishing classification. The findings further reveal that several non-.com TLD ecosystems are disproportionately associated with phishing infrastructures, indicating opportunistic exploitation of fragmented and globally distributed governance environments. This study contributes to cybersecurity research by reframing phishing not only as a technical cybercrime issue, but also as a digital sovereignty and governance challenge embedded within transnational cyberspace infrastructures. The findings highlight the importance of explainable and infrastructure-aware cybersecurity approaches for supporting more resilient cross-border cyber governance frameworks.

Downloads

Download data is not yet available.

References

Basit, A., Zafar, M., Liu, X., Javed, A. R., Jalil, Z., & Kifayat, K. (2021). A comprehensive survey of AI-enabled phishing attacks detection techniques. Telecommunication Systems, 76(1), 139–154. https://doi.org/10.1007/s11235-020-00733-2

Capuano, N., Fenza, G., Loia, V., & Stanzione, C. (2022). Explainable Artificial Intelligence in CyberSecurity: A Survey. IEEE Access, 10, 93575–93600. https://doi.org/10.1109/ACCESS.2022.3204171

Catal, C., Giray, G., Tekinerdogan, B., Kumar, S., & Shukla, S. (2022). Applications of deep learning for phishing detection: a systematic literature review. Knowledge and Information Systems, 64(6), 1457–1500. https://doi.org/10.1007/s10115-022-01672-x

Couture, S., Toupin, S., & Mayoral Baños, A. (2024). Resisting and Claiming Digital Sovereignty: The Cases of Civil Society and Indigenous Groups. Policy & Internet, 16(4), 739–749. https://doi.org/10.1002/poi3.434

Donnelly, S., Ríos Camacho, E., & Heidebrecht, S. (2024). Digital sovereignty as control: the regulation of digital finance in the European Union. Journal of European Public Policy, 31(8), 2226–2249. https://doi.org/10.1080/13501763.2023.2295520

El Aassal, A., Baki, S., Das, A., & Verma, R. M. (2020). An In-Depth Benchmarking and Evaluation of Phishing Detection Research for Security Needs. IEEE Access, 8, 22170–22192. https://doi.org/10.1109/ACCESS.2020.2969780

Flonk, D., Jachtenfuchs, M., & Obendiek, A. (2024). Controlling internet content in the EU: towards digital sovereignty. Journal of European Public Policy, 31(8), 2316–2342. https://doi.org/10.1080/13501763.2024.2309179

Fratini, S., Hine, E., Novelli, C., Roberts, H., & Floridi, L. (2024). Digital Sovereignty: A Descriptive Analysis and a Critical Evaluation of Existing Models. Digital Society, 3(3), 59. https://doi.org/10.1007/s44206-024-00146-7

Ganz, A., Camellini, M., Hine, E., Novelli, C., Roberts, H., & Floridi, L. (2025). Correction: Submarine Cables and the Risks to Digital Sovereignty. Minds and Machines, 35(1), 7. https://doi.org/10.1007/s11023-024-09707-8

Glasze, G., Cattaruzza, A., Douzet, F., Dammann, F., Bertran, M.-G., Bômont, C., Braun, M., Danet, D., Desforges, A., Géry, A., Grumbach, S., Hummel, P., Limonier, K., Münßinger, M., Nicolai, F., Pétiniaud, L., Winkler, J., & Zanin, C. (2023). Contested Spatialities of Digital Sovereignty. Geopolitics, 28(2), 919–958. https://doi.org/10.1080/14650045.2022.2050070

Gordon, G. (2024). Digital sovereignty, digital infrastructures, and quantum horizons. AI & SOCIETY, 39(1), 125–137. https://doi.org/10.1007/s00146-023-01729-7

Heiding, F., Schneier, B., Vishwanath, A., Bernstein, J., & Park, P. S. (2024). Devising and Detecting Phishing Emails Using Large Language Models. IEEE Access, 12, 42131–42146. https://doi.org/10.1109/ACCESS.2024.3375882

Hellmeier, M., Pampus, J., Qarawlus, H., & Howar, F. (2023). Implementing Data Sovereignty: Requirements & Challenges from Practice. Proceedings of the 18th International Conference on Availability, Reliability and Security, 1–9. https://doi.org/10.1145/3600160.3604995

Hurst, W., & Shone, N. (2024). Critical infrastructure security: Cyber-threats, legacy systems and weakening segmentation. In Management and Engineering of Critical Infrastructures (pp. 265–286). Elsevier. https://doi.org/10.1016/B978-0-323-99330-2.00010-6

Jain, A. K., & Gupta, B. B. (2018). Towards detection of phishing websites on client-side using machine learning based approach. Telecommunication Systems, 68(4), 687–700. https://doi.org/10.1007/s11235-017-0414-0

Katsikas, S. K. (2025). Towards a cybersecurity-oriented research agenda for digital sovereignty. Procedia Computer Science, 254, 279–288. https://doi.org/10.1016/j.procs.2025.02.087

Li, W., Xiong, B., & Yang, C. (2024). A roadmap to achieving a healthier information ecosystem through GDPR implementation and privacy compliance technologies. Journal of the Association for Information Science and Technology, 75(10), 1182–1201. https://doi.org/10.1002/asi.24878

Linh, D. M., & Hung, T. C. (2025). A feature-engineered dataset of benign and phishing URLs for machine learning and large language models evaluation. Data in Brief, 63, 112162. https://doi.org/10.1016/j.dib.2025.112162

Mahajan, S. (2023). Phishing uniform resource locator detection using machine learning: A step towards secure system. SECURITY AND PRIVACY, 6(6). https://doi.org/10.1002/spy2.311

Marchal, S., Francois, J., State, R., & Engel, T. (2014). PhishStorm: Detecting Phishing With Streaming Analytics. IEEE Transactions on Network and Service Management, 11(4), 458–471. https://doi.org/10.1109/TNSM.2014.2377295

Misra, S., Barik, K., & Kvalvik, P. (2025). Trust in Digital Sovereignty: A Review of Security, Privacy, and Governance Challenges. Public Organization Review. https://doi.org/10.1007/s11115-025-00968-0

Musiani, F. (2022). Infrastructuring digital sovereignty: a research agenda for an infrastructure-based sociology of digital self-determination practices. Information, Communication & Society, 25(6), 785–800. https://doi.org/10.1080/1369118X.2022.2049850

Nagy, N., Aljabri, M., Shaahid, A., Ahmed, A. A., Alnasser, F., Almakramy, L., Alhadab, M., & Alfaddagh, S. (2023). Phishing URLs Detection Using Sequential and Parallel ML Techniques: Comparative Analysis. Sensors, 23(7), 3467. https://doi.org/10.3390/s23073467

Popescul, D., & Radu, L. D. (2025). AI in phishing detection: a bibliometric review. Frontiers in Artificial Intelligence, 8. https://doi.org/10.3389/frai.2025.1496580

Potpelwar, R. S., Kulkarni, U. V., & Waghmare, J. M. (2025). LegitPhish: A large-scale annotated dataset for URL-based phishing detection. Data in Brief, 63, 111972. https://doi.org/10.1016/j.dib.2025.111972

Prasad, A., & Chandra, S. (2024). PhiUSIIL: A diverse security profile empowered phishing URL detection framework based on similarity index and incremental learning. Computers & Security, 136, 103545. https://doi.org/10.1016/j.cose.2023.103545

Rao, R. S., & Pais, A. R. (2019). Detection of phishing websites using an efficient feature-based machine learning framework. Neural Computing and Applications, 31(8), 3851–3873. https://doi.org/10.1007/s00521-017-3305-0

Sabella, D., Maloor, K., Smith, N., Vanderveen, M., & Kourtis, A. (2024). Edge Computing Cybersecurity standards: protecting infrastructure and applications. IEEE Access, 1–1. https://doi.org/10.1109/ACCESS.2024.3506212

Safi, A., & Singh, S. (2023). A systematic literature review on phishing website detection techniques. Journal of King Saud University - Computer and Information Sciences, 35(2), 590–611. https://doi.org/10.1016/j.jksuci.2023.01.004

Silva, C. M. R. da, Feitosa, E. L., & Garcia, V. C. (2020). Heuristic-based strategy for Phishing prediction: A survey of URL-based approach. Computers & Security, 88, 101613. https://doi.org/10.1016/j.cose.2019.101613

Somesha, M., Pais, A. R., Rao, R. S., & Rathour, V. S. (2020). Efficient deep learning techniques for the detection of phishing websites. Sādhanā, 45(1), 165. https://doi.org/10.1007/s12046-020-01392-4

Tan, K. L., Chi, C.-H., & Lam, K.-Y. (2024). Survey on Digital Sovereignty and Identity: From Digitization to Digitalization. ACM Computing Surveys, 56(3), 1–36. https://doi.org/10.1145/3616400

Uddin, K. M. M., Biswas, N., Rikta, S. T., Nur ‐A‐Alam, Md., & Mostafiz, R. (2025). Explainable Machine Learning for Phishing Site Detection: A High‐Efficiency Approach Using Boosting Models and SHAP. The Journal of Engineering, 2025(1). https://doi.org/10.1049/tje2.70110

Walden, I., & Michels, J. D. (2024). Getting Critical: Making Sense of the EU Cybersecurity Framework for Cloud Providers (pp. 9–38). https://doi.org/10.1007/978-3-031-41820-4_2

Wang, W., Zhang, F., Luo, X., & Zhang, S. (2019). PDRCNN: Precise Phishing Detection with Recurrent Convolutional Neural Networks. Security and Communication Networks, 2019, 1–15. https://doi.org/10.1155/2019/2595794

Wilk-Jakubowski, J. L., Pawlik, L., Wilk-Jakubowski, G., & Sikora, A. (2025). Machine Learning and Neural Networks for Phishing Detection: A Systematic Review (2017–2024). Electronics, 14(18), 3744. https://doi.org/10.3390/electronics14183744

Xiang, G., Hong, J., Rose, C. P., & Cranor, L. (2011). CANTINA+. ACM Transactions on Information and System Security, 14(2), 1–28. https://doi.org/10.1145/2019599.2019606

Downloads

Published

2026-01-15

Issue

Section

Articles

How to Cite

Phishing Infrastructure as a Digital Sovereignty Threat: An Explainable Structural URL Analysis. (2026). International Journal of Applied Information Systems and Cybersecurity, 1(1), 60-81. https://ejournal.global-scientificjournal.org/ijaisc/article/view/63