Unlock instant, AI-driven research and patent intelligence for your innovation.

Method and device for detecting phishing web pages

A technology of phishing webpages and detection methods, which is applied in transmission systems, electrical components, etc., can solve problems such as unrecognizable, undetectable phishing webpages, and inability to cope with new phishing webpages, so as to improve accuracy and reduce storage resources and processing resources. occupancy, saving hardware configuration and resource consumption effects

Active Publication Date: 2020-09-29
ALIBABA GRP HLDG LTD
View PDF7 Cites 0 Cited by
  • Summary
  • Abstract
  • Description
  • Claims
  • Application Information

AI Technical Summary

Problems solved by technology

[0004] However, this conventional machine detection method has been unable to cope with the endless new phishing webpages. In order to bypass the webpage detection, the new phishing webpage usually judges whether it is currently being visited by a real person or a machine detection. If it is recognized as a machine detection, it will feed back a non-phishing webpage. , causing the detection engine to miss
[0005] Specifically, the webpage source files of new phishing webpages are usually configured with the text or picture features of normal webpages, and only after the browser rendering behavior determines that the webpage is visited by a real person, the phishing webpage will be rendered, thus making the non-browser environment The detection of phishing webpages cannot obtain the basis for identifying phishing webpages, and phishing webpages cannot be detected
Furthermore, even if the browser environment is used to detect phishing webpages, some phishing webpages will also detect whether there is a mouse movement event in the current environment and whether Flash is supported when the webpage is rendered. , so that it is not possible to recognize
[0006] In addition, there is a browser-based non-machine detection solution. When a user visits a page in the browser, it can immediately detect whether the page that has been opened is a phishing website. However, this solution can only detect the URL that the user is visiting, and cannot perform batch chemical detection

Method used

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
View more

Image

Smart Image Click on the blue labels to locate them in the text.
Viewing Examples
Smart Image
  • Method and device for detecting phishing web pages
  • Method and device for detecting phishing web pages
  • Method and device for detecting phishing web pages

Examples

Experimental program
Comparison scheme
Effect test

Embodiment 1

[0061] refer to figure 1 , which shows a flow chart of the steps of Embodiment 1 of a method for detecting phishing webpages of the present application, which may specifically include the following steps:

[0062] Step 101, calling a web page rendering program to access the web page to be detected.

[0063] The embodiment of the present application calls the webpage rendering program to access the webpage to be detected, so that the phishing webpage can be opened normally in the rendering environment, and avoids the problem that the phishing webpage cannot be detected because the phishing webpage uses the webpage source file of the normal webpage.

[0064] The web page rendering program may be any program capable of rendering web pages, such as a browser or other APP capable of rendering web pages.

[0065] Step 102, during the process of rendering the webpage to be detected, send a user operation event to the webpage to be detected.

[0066] Webpage rendering is also called...

Embodiment 2

[0088] refer to figure 2 , which shows a flow chart of the steps of Embodiment 2 of a phishing web page detection method of the present application, which may specifically include the following steps:

[0089] Step 201, calling a web page rendering program to access the web page to be detected.

[0090] Step 202, during the process of rendering the webpage to be detected, send a user operation event to the webpage to be detected.

[0091] Step 203, extracting image features of the webpage to be detected.

[0092] Step 204, identifying whether the webpage to be detected is a phishing webpage based on the obtained image features.

[0093] In this embodiment, image features are preferably used to identify phishing webpages. Correspondingly, when identifying image features, if the display is based on the rendering result of the webpage to be detected, the preferred way to extract image features may be to take a screenshot of the rendered webpage to be detected; if it is not ba...

Embodiment 3

[0122] refer to Figure 4 , which shows a structural block diagram of an embodiment of a device for detecting phishing webpages of the present application, which may specifically include the following modules:

[0123] A webpage access module 301, configured to invoke a webpage rendering program to access a webpage to be detected;

[0124] An event sending module 302, configured to send a user operation event to the webpage to be detected during the process of rendering the webpage to be detected;

[0125] The rendered webpage detection module 303 is configured to detect phishing webpages based on the rendering results of the webpages to be detected.

[0126] In the embodiment of the present application, preferably, the web page rendering program is a real browser or a simulated browser supporting at least one network protocol.

[0127] In the embodiment of the present application, preferably, the web page rendering program is a real browser or a simulated browser written ba...

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

PUM

No PUM Login to View More

Abstract

The application provides a phishing webpage detection method and a device. The method includes the following steps: calling a webpage rendering program to access a webpage to be detected; sending a user operation event to the webpage to be detected in the rendering process of the webpage to be detected; and detecting whether the webpage to be detected is a phishing webpage based on the rendering result of the webpage to be detected. According to the embodiment of the invention, a phishing webpage is normally opened in a rendering environment, and the problem that a phishing webpage using the webpage source file of a normal webpage cannot be detected is avoided. In the rendering process of the webpage to be detected, a user operation event is sent to the webpage to be detected to simulate an environment in which a real person browses a webpage. A phishing webpage will open the original page after monitoring the user operation event. Thus, further detection can be carried out to avoid the problem that a phishing webpage shows a non-phishing webpage when detecting webpage access by a non-real person and thus the phishing webpage cannot be detected. The accuracy of webpage detection is improved.

Description

technical field [0001] The present application relates to the field of webpage processing, in particular to a method for detecting phishing webpages and a device for detecting phishing webpages. Background technique [0002] Phishing webpages mainly fake the URL address or page content of real websites, pretend to be webpages such as banking and e-commerce, or use loopholes in real webpage server programs to insert dangerous webpage codes into webpages to Defraud users of personal information such as bank or credit card account numbers and passwords. [0003] When a conventional phishing web detection scheme detects whether a URL is a phishing web page, it obtains the returned web page source file, such as an HTML (Hypertext Markup Language) file, by visiting the URL, and parses and extracts the text or image features therein, and further based on the extracted text or image features for recognition. [0004] However, this conventional machine detection method has been una...

Claims

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

Application Information

Patent Timeline
no application Login to View More
Patent Type & Authority Patents(China)
IPC IPC(8): H04L29/06
CPCH04L63/1483
Inventor 叶敏
Owner ALIBABA GRP HLDG LTD