Method for managing internet browsing on a terminal

The internet navigation management process addresses the inadequacies of existing security measures by using a predictive model to analyze website metrics in real-time, providing effective protection against phishing and malicious sites without relying on centralized servers.

FR3155331A1Inactive Publication Date: 2025-05-16ORANGE SA
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
FR2023012526
Authority / Receiving Office
FR · FR
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-11-15
Publication Date
2025-05-16
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

Existing internet navigation security measures are inadequate in preventing users from accessing phishing sites that imitate legitimate websites, as they rely on centralized servers that can be reactive and vulnerable to countermeasures by attackers.

Method used

A process for managing internet navigation that involves obtaining metrics from target websites and analyzing them using a predictive model to provide a trust score, allowing for real-time protection without relying on centralized servers or suspicious address lists.

Benefits of technology

This solution provides effective real-time protection against phishing and other malicious sites by analyzing website metrics at the time of access, reducing the risk of users interacting with dangerous websites and maintaining user confidentiality.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

Method for managing Internet browsing on a terminal. The invention relates to a method for managing Internet browsing on a terminal, implemented by a management entity (100), characterized in that it comprises the following steps: Obtaining metrics (FTR) of a website, referred to as the target site (S1, S2, S3), to which access is requested by the terminal (DVC); Analyzing said metrics (FTR) by a predictive model (MDL) providing data (SCR) representative of a confidence score relating to the target site (S1, S2, S3); Action (ACT) relating to the Internet browsing of the terminal (DVC) based on the representative data (SCR) provided by the predictive model (MDL). Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

Title of the invention: Method for managing Internet browsing on a terminal Technical field

[0001] The technical field is that of Internet navigation.

[0002] More specifically, the invention relates to a method for securing Internet browsing on a terminal. The terminal in question may be any terminal used to browse the Internet via an Internet browser. Possible terminals for browsing the Internet include computers, whether portable or fixed, but also smartphones, or larger terminals, such as touchscreen tablets or phablets, or smaller terminals, such as smartwatches or any other connected object. The terminal may also be the on-board computer of a vehicle, for example a connected car.The terminal can also be a games console, connected to the Internet via a home network, or an in-flight entertainment system offered to passengers of a vehicle such as an airplane, boat, train, coach, taxi or private car.

[0003] One of the most common attacks in the field of Internet browsing is phishing of users through an attacker's website that imitates a legitimate website. In this attack, a user will be led by any means, for example an email containing a link, to connect to a website, called the attacker's site. The email will, for example, contain a message indicating that the reader must pay a bill, or has won a gift, or any other enticing information, which will lead the user to click on the link contained in the email, which triggers the navigation of his Internet browser to the link contained in the email.The attacking site, which the user is encouraged to navigate, imitates the website of a legitimate organization, for example the website of a bank, a telecommunications operator, a commercial site or any other possible site. We can also speak of a trusted site, for the site of such a legitimate organization. Once on the attacking site, while believing he is browsing a trusted website, the user will provide information, for example a credit card number, believing he is providing it to the legitimate organization, whose website the attacking site imitates. The information thus provided can then be used directly by the attacker. for example, to carry out banking transactions or identity theft, or will be traded on underground markets where this type of data is traded. Phishing attacks can also be used to trick a remote worker into believing that they are connecting to their company's website remotely. The remote worker will then provide their credentials to the site, which impersonates their employer's site. The attacker can then use their credentials to connect to the company's legitimate website, impersonating the remote worker in order to carry out further attacks by gaining direct access to the company's information system. State of the art

[0004] The attack described above has seen the development of several forms of parry.

[0005] The first defense is to detect phishing messages. These messages, which encourage the user to connect to the attacking site, can be emails, or SMS messages (acronym for Short Messages Service) received by mobile phones, or messages from email services such as Messenger, WhatsApp, Telegram or any other service. Detection tools present in the servers transmitting messages between terminals, or present in the terminals themselves, will then focus on detecting phishing messages. These messages will then be either directly deleted, or transmitted to their recipients with very visible warnings encouraging the user to be wary and not to follow the Internet browsing links present, unless they are sure of the legitimacy of the message.

[0006] Such phishing message detection systems are well established, but are not fully effective. Phishing messages may not be detected, or users may ignore warnings, or users may navigate to attacking sites, which impersonate legitimate sites, without having been lured to the attacking site by a phishing message. There is therefore a need to secure Internet browsing, to prevent a user from browsing a site that impersonates a legitimate site, and this independently of the protective measures aimed at reducing phishing messages.

[0007] Existing navigation security measures generally rely on the processing of URL addresses (acronym for Uniform Resource Locator) used for Internet navigation.

[0008] An attacker who builds a website that spoofs a legitimate site will start by obtaining an Internet address close enough to that of the legitimate site to fool users. For example, the French Social Security uses the domain name ameli.fr for its website. An attacker will seek the right to use the amelii.fr address to build a website imitating the legitimate site, then attract users to this site with phishing messages. Another attack technique will involve registering domain names that contain the usurped name by surrounding it with other meaningful keywords. For example, also for the French Social Security, the domain payments-ameli.info could be created by attackers.

[0009] Regardless of the domain name chosen by the attacker, a measure to secure browsing then consists of the use, by Internet browsers, of lists of suspicious addresses. Centralized servers analyze suspicious websites, for example by identifying sites linked to by phishing messages and thus establish lists of suspicious sites. The analyses carried out by these servers can use several techniques, including machine learning techniques. These lists can be distributed to browsers, thus allowing browsers to block their users when they try to go to a suspicious site, or to warn them, depending on the browser's policy and the type of lists established by the server.

[0010] Analysis servers can also respond to a request from a browser, which submits a website address to a server, which can tell it whether the address in question belongs to an already established list, or which will launch a dedicated analysis of the website corresponding to the address submitted by the browser.

[0011] Security measures based on lists of suspicious addresses have several flaws. First of all, they are not reactive enough. When an attacker prepares a website usurping a legitimate site, only a few hours will pass between the reservation of the domain name to have an address of the attacking site, the deployment of the attacking site, and the sending of the phishing messages. During this very short period, it is likely that the analysis servers which, a priori, seek to analyze all existing Internet sites, will not have started their navigation on the new domain reserved by the attacker and then the analysis of the site usurping the legitimate site. A server which seeks to analyze suspicious sites and then to distribute lists of addresses to browsers to block therefore risks being overtaken by attackers. Speed ​​can be improved if browsers themselves submit the addresses to be analyzed to servers.But this implies that the servers are informed of the Internet addresses to which the browser wishes to go. This poses a confidentiality problem: in fact, the user of the Internet browser may not wish to entrust to a third-party server the Internet address to which he wishes to navigate, even in exchange for information on the security of this address.

[0012] In addition, when the analysis is performed by a server, the latter will have to interact with the crawled site. Attackers who set up a site spoofing a legitimate site can learn to recognize crawl servers. When a site spoofing a legitimate site detects that a crawl server, known to the attackers, has started crawling it, the spoofing site can implement countermeasures that will complicate the server's crawling work, for example by blocking its requests, delaying them, or presenting the server with a harmless version rather than the version dedicated to standard browsers.

[0013] Finally, attackers can set up a seemingly benign site when they purchase a domain name. The analysis servers that will analyze this site will then be deceived. It is at the moment when the attackers launch their phishing campaign, by sending messages in large quantities, that they will replace the seemingly benign site with the real attacking site. The possibility of detecting the attack by analysis servers is thus delayed as much as possible by the attackers.

[0014] The invention improves the situation. Statement of the invention

[0015] According to a functional aspect, the invention relates to a method for managing Internet browsing of a terminal, implemented by a management entity, characterized in that it comprises the following steps: • Obtaining metrics from a website, called the target site, to which access is requested by the terminal; • Analysis of said metrics by a predictive model providing data representative of a confidence score relating to the target site; • Action relating to the terminal’s Internet browsing based on the representative data provided by the predictive model.

[0016] The term “metrics” used here can be translated into English by the term features.

[0017] Thanks to the invention, the user of a terminal comprising an Internet browser has protection against dangerous Internet sites during his Internet browsing. This protection is obtained without a centralized server having to distribute lists of addresses of suspicious sites, lists which are then saved by the Internet browsers of the terminals, and used for example to block the user's browsing.

[0018] According to the invention, metrics are obtained from a website and then analyzed by a predictive model. This model is derived from machine learning. For example, it may be an artificial neural network. Such a model was learned from website metrics. The same metrics are obtained from a site, called the target site, to which access is requested, i.e. to which a user wishes to go, which results in a request from the user's terminal to this website. Since the prediction model has been trained using the same metrics, it will be able to immediately provide a relevant score on the danger of the site to which the user wishes to navigate as soon as the obtained metrics are provided to it. The protection of the terminal user is thus ensured. Since the model has already learned the characteristics of dangerous websites, and since obtaining the metrics is sufficiently fast, our invention has the necessary responsiveness to website spoofing attacks if we compare it to solutions based on the maintenance and updating of website addresses.

[0019] Thanks to our invention, the interaction with the website which may be an attacking site is done at the level of the terminal's Internet browser. The latter obtains the metrics of the website by looking at its characteristics and performing calculations based on them. In this way, there is no direct interaction between an analysis server and a potentially dangerous site. The dangerous site cannot therefore detect that it is interacting with an analysis server and it will therefore not put in place camouflage measures.

[0020] Furthermore, the analysis is performed at the precise moment when access is requested to the target site by the terminal, and not when an analysis server, which browses the Internet, requests it. The analysis is therefore performed at the moment when the user may have been led to request access to the attacking site by a phishing campaign. In the case where the attackers use a seemingly benign site to deceive the analysis servers, our invention resists this countermeasure by the attackers. Indeed, the site that is analyzed in our invention is indeed the one accessed by the user's terminal, and which is therefore potentially dangerous, and not a benign site used to deceive analysis servers before the attack is triggered.

[0021] According to a first particular embodiment of the invention, the analysis by the predictive model is at least partly transferred to a device external to the terminal.

[0022] According to another embodiment of the invention, which may be implemented alternatively or cumulatively with the previous embodiment, the management entity is included in an Internet browser executed by the terminal.

[0023] Thanks to these embodiments, the performance of our invention is improved. Indeed, a predictive model such as used in our invention cannot be maintained in an Internet browser given its size, and also the necessary frequency of its updating. The model is therefore hosted in a remote server to which the management entity, which may itself be present in the Internet browser, will submit website metrics. In such an architecture, where a remote server analyzes websites to answer questions from Internet browsers on the safety or danger of websites, a problem is that of respect the privacy of users' Internet browsing. Indeed, the server to which analyses are requested may be submitted addresses of sites to which users wish to browse, and such submissions may be intercepted by attackers, or the remote server may be hacked. Our solution does indeed use a remote server that will analyze a given website on demand to determine whether it is dangerous or not. But our invention makes it possible to achieve this result without the user having to provide the addresses of the sites they are browsing. Only the metrics of the target website are submitted to the server, and not the address of the target site itself. The privacy of the user's browsing is therefore well respected.

[0024] Another advantage of this distribution of analyses between a management entity included in an Internet browser of the terminal and a predictive model hosted in a server is to avoid direct interaction between an analysis server and dangerous sites. We have seen that managers of dangerous sites can identify that analysis servers make repeated requests on sites in order to analyze them. In this case, the dangerous sites are camouflaged to avoid being detected. In the architecture proposed in this embodiment, the server does not interact directly with the target site. It is a standard Internet browser that obtains the metrics of the target site by an interaction that cannot be distinguished from the interaction of a browser without analysis capabilities. Once the metrics are obtained, they are submitted to the predictive model hosted in a server.This one therefore does not have to interact directly with the target site which may be a dangerous site.

[0025] The architecture of this embodiment therefore combines the advantages of centralization for the predictive model, which makes it possible to have a large model, taking into account a very large number of metrics, which can be updated easily and of decentralization of obtaining the metrics of the target sites, which is done at the level of the Internet browsers, during the standard navigation of the users, which makes it possible to avoid arousing the suspicions of the managers of dangerous sites and which shortens the calculation and obtaining times of the metrics.

[0026] The management entity will most of the time be included in an Internet browser present in the terminal. It will be for example a module which will use an extension mechanism provided by the vast majority of available Internet browsers, such as Firefox and Chrome. But it is possible to imagine an architecture in which the management entity is a separate program, hosted in the terminal, and which interacts with the Internet browser of the terminal in order to carry out the method of managing the Internet navigation of the terminal according to the invention which secures the Internet navigation of the terminal and its user.

[0027] According to another embodiment of the invention, which may be implemented alternatively or cumulatively with the previous mode, the analysis by the predictive model comprises an analysis carried out by a predictive model, called the first model, present in the terminal, and an analysis carried out by another predictive model, called the second model, transferred to a device external to the terminal, the analysis by the second model being carried out according to the result of the analysis by the first model.

[0028] In this embodiment, a first model, simpler and smaller in size, is present in the terminal and performs a first analysis. Depending on the result of this first analysis, a second analysis can be performed by querying a second model, more detailed than the first model and larger in size. This second model, given its size, is present in a device external to the terminal. The second analysis is performed for example when there is a suspicion that the analyzed site may be malicious, but without total guarantee. The second model, more detailed, then makes it possible to remove the ambiguity that remains after the first analysis.

[0029] Thanks to this embodiment, it is possible to combine the advantages of a decentralized mode, in which a small-sized model is present in the terminal browsers, and a more centralized mode, in which a large-sized model is present in a centralized server. The analysis carried out by the model present in the terminal browsers generally makes it possible to give a first rapid response of harmlessness or danger. It is when this first analysis does not make it possible to decide with sufficient certainty that a second analysis is carried out with the second model, transferred to a device external to the terminal.

[0030] According to another embodiment of the invention, which may be implemented alternatively or cumulatively with the previous embodiment, the action relating to Internet browsing of the terminal comprises a display on the terminal of a notice determined as a function of the data provided representative of a confidence score relating to the target site.

[0031] Thanks to this embodiment, a first protective measure consists of alerting the user of the terminal by displaying a notice relating to the danger of the Internet site to which access is requested. The predictive model will give a confidence score from the metrics obtained. This confidence score is dependent on the form of the predictive model. If the predictive model is a neural network, for example, it may provide as a result a more or less large real number. Such a real number cannot be presented in a raw form to the user. An opinion must be deduced from it, for example by defining confidence scales grouping score intervals. The opinions can range from "dangerous" to "harmless", possibly with qualifications such as "completely" or "rather". Colors or logos can be used to have a simple presentation of the opinion to the user.It is this notice on the site whose access is requested that the terminal, via the browser. The Internet will present itself to the user so that he is warned of its possible danger or, on the contrary, reassured as to its harmlessness.

[0032] According to another embodiment of the invention, which may be implemented alternatively or cumulatively with the preceding embodiments, the action relating to the user's navigation comprises blocking the terminal's Internet navigation.

[0033] Thanks to this embodiment, the user of the Internet browser is protected during his navigation. This navigation is blocked if the trust score reaches a threshold such that the blocking of navigation is deemed necessary. In this way, the user is immediately protected from potentially dangerous Internet sites.

[0034] According to another embodiment of the invention, which may be implemented alternatively or cumulatively with the preceding embodiments, the target site comprises a form comprising at least one field to be completed and the action relating to Internet navigation of the terminal comprises the deletion of at least part of the form fields present in the target site.

[0035] Thanks to this embodiment, the user of the Internet browser is protected during his navigation. Obtaining the metrics of the target site takes a certain amount of time, as does the analysis of these by the predictive model. It is possible to envisage an embodiment of Internet navigation according to the invention in which users will only go to target sites once the analysis of these has been carried out. But the mode which will be most often carried out will consist of carrying out the obtaining of the metrics and the analysis of these in parallel with the Internet navigation of the user's terminal. In this mode of analysis and navigation in parallel, it will happen that a user begins to fill in form fields, therefore begins to provide sensitive data, on a site whose analysis of the metrics will reveal that it is dangerous.The action taken by the management entity will then include deleting form fields in an attempt to prevent the user's private data from being provided to the dangerous site. This deletion action may be combined with blocking navigation and warning the user.

[0036] According to another embodiment of the invention, which may be implemented alternatively or cumulatively with the preceding embodiments, the data representative of a confidence score relating to the target site is supplemented by an indication of an Internet site distinct from the target site.

[0037] Thanks to this embodiment, the analysis of the metrics is supplemented by an analysis which seeks to determine which is the legitimate site usurped when the analysis of the metrics shows that the target site is actually usurping a legitimate site. The proposal of the legitimate site will thus make it possible to redirect the user's navigation towards the correct site. A site which is not necessarily the usurped site but a harmless site can be proposed in addition to the analysis even if the latter does not discover the legitimate site. spoofed by the target site.

[0038] According to another embodiment of the invention, which may be implemented alternatively or cumulatively with the preceding embodiments, the analysis comprises a screenshot of a page of the target site, the extraction of images from the screenshot and the analysis of the extracted images by an image recognition algorithm.

[0039] Thanks to this embodiment, the determination of the usurped legitimate site is facilitated. This determination will be based on analyses of images extracted from the target site. In particular, one or more screenshots of the target site will then make it possible to extract images present therein. Among these extracted images, in the case of a site usurping the identity of a legitimate site, we will find images imitating or copying images such as logos present or expected on the legitimate site. An image recognition algorithm trained on a base of images present on legitimate sites, such as the logos of the institutions owning the sites in question for example, will then be able to recognize the images extracted from the screenshot(s) as copies or imitations of these logos. Once this recognition is successful, it is then easy to say which is the legitimate site usurped by the target site.The legitimate site can then be offered to the user to continue browsing to the site they actually want to access, even though they had been guided to an attacking site by a phishing message.

[0040] According to another embodiment of the invention, which may be implemented alternatively or cumulatively with the previous embodiments, the screenshot of a page of the target site is subject to a request for authorization from the user.

[0041] The transfer of a screenshot of the target site may pose a problem of confidentiality of the user's navigation that the transfer of metrics does not pose. Thanks to this embodiment, this functionality is subject to authorization from the user in order to preserve this confidentiality or, in any case, to ensure that the user is informed of this transfer.

[0042] According to another embodiment of the invention, which may be implemented alternatively or cumulatively with the preceding embodiments, at least one of the metrics is obtained from at least one piece of information among the following categories of information: • Information relating to the Internet address of the target site; • Information relating to past navigation of the terminal; • Information relating to the contents of the pages of the target site, before or after rendering and execution of code contained in the target site; • Reputation information obtained from external services; • Information relating to cryptographic certificates used by the site target.

[0043] By means of this embodiment, all categories of information that can signal the dangerousness of a site are used. A large number of metrics can be obtained from the information in these categories. A predictive model, for example a neural network, can then be learned by a supervised learning method, for example, that is to say that the metrics corresponding to sites known to be dangerous are provided as input to the learning of the predictive model, with the additional information that these metrics are obtained from a dangerous site.

[0044] According to another embodiment of the invention, which may be implemented alternatively or cumulatively with the preceding embodiments, the predictive model is enriched with metrics obtained and other information relating to the target site.

[0045] Thanks to this embodiment, the predictive model is enriched by user navigation. The management entities present in the Internet browsers can transmit to the predictive model the metrics that they collect as they navigate the Internet. Users can also be asked for opinions regarding the safety and danger of the Internet sites they browse. All of this information, namely the metrics of the sites and the associated opinions, can then enrich the predictive model and refine its opinions thanks to this large quantity of data.

[0046] According to a first material aspect, the invention relates to a management entity capable of carrying out a method for managing Internet browsing of a terminal comprising the following modules: • Module for obtaining metrics from a website, called the target site, to which access is requested by the terminal; • Module for analyzing said metrics using a predictive model providing data representative of a confidence score relating to the target site; • Action module relating to Internet browsing on the terminal based on the representative data provided by the predictive model.

[0047] Note that in the present text, the terms “module” or “entity” can correspond to a software component as well as to a hardware component or to a set of hardware and software components, a software component itself corresponding to one or more computer programs or sub-programs or more generally to any element of a program capable of implementing a function or a set of functions as described for the modules concerned. In the same way, a hardware component corresponds to any element of a hardware assembly capable of implementing a function or a set of functions for the module concerned (integrated circuit, smart card, memory card, etc.).

[0048] The management entity includes an analysis module. The analysis uses a predictive model. In general, this model is transferred to a device external to the terminal, in other words hosted by a remote server. In this case, the analysis module included in the management entity will then at least carry out the transmission of the metrics and the reception of the data representative of the confidence score. The rest of the analysis is then transferred to a device external to the terminal.

[0049] According to another material aspect, the invention relates to a terminal comprising a management entity according to the invention.

[0050] The terminal mentioned here may be any type of terminal that includes an Internet browser. We can mention computers, portable or fixed, but also smartphones or larger terminals, such as touch tablets or phablets or smaller terminals, such as smart watches or any other connected object. The terminal may also be the on-board computer of a vehicle, for example a connected car. The management entity may then be a component of the Internet browser of the terminal, or a separate program that communicates with the Internet browser, inside the terminal, using for example a software bus or any other communication element of the terminal.

[0051] According to another material aspect, the invention relates to a computer program capable of being implemented by a terminal, the program comprising code instructions which, when executed by a processor, carries out the steps of the management method defined above.

[0052] Finally, according to another material aspect, the invention relates to a data medium on which is recorded a computer program comprising sequences of instructions for implementing the management method defined above.

[0053] The data carriers may be any entity or device capable of storing the programs. For example, the carriers may comprise a storage means, such as a ROM, for example a CD ROM or a microelectronic circuit ROM, or a magnetic recording means such as a hard disk. Furthermore, the carriers may be transmissible media such as an electrical or optical signal, which may be conveyed via an electrical or optical cable, by radio or by other means. The programs according to the invention may in particular be downloaded from a network such as the Internet. Alternatively, the information carrier may be an integrated circuit in which the program is incorporated, the circuit being adapted to execute or to be used in the execution of the method in question. Brief description of the figures

[0054] The invention will be better understood on reading the following description, given by way of example, and made with reference to the appended drawings in which:

[0055] [Fig. 1] represents a terminal and an Internet browser comprising an entity of management according to the invention, used when a user is browsing the Internet.

[0056] [Fig.2] illustrates an example of steps implemented within the framework of a rea lization of the invention.

[0057] [Fig.3] represents a terminal and an Internet browser comprising an entity of management according to the invention, presenting a different architecture than that of [Fig.l]. Detailed description

[0058] [Fig.l] represents an exemplary embodiment of the invention among those possible.

[0059] In this example, [Fig.l] describes a DVC terminal including a BWR Internet browser. The term "browser" is chosen as a translation of the English browser. The BWR browser itself comprises a management entity 100. The management entity 100, in other embodiments, may be a program separate from the BWR browser, which communicates with it. It is also possible to imagine an embodiment in which the management entity 100 is not included in the DVC terminal, but receives the information necessary for executing the management method from the BWR browser. For example, a management entity 100 could be deployed in a home gateway and carry out the management method for all the DVC terminals present in the local network of the home gateway.

[0060] The management entity 100 itself comprises three modules: • Module 101 is a module for obtaining website metrics. • Module 102 is a module allowing the analysis of metrics by a predictive model and obtaining data representative of a confidence score relating to a website. • Module 103 is a module allowing an action to be carried out relating to the navigation of the DVC terminal on a website.

[0061] [Fig.l] shows an exemplary embodiment of the invention in which the management entity 100 is included in the BWR browser. Most browsers offer an extension mechanism that allows the basic functions of an Internet browser to be supplemented by other functionalities. The management entity 100 may be an extension of the BWR Internet browser and will then be included in it. In other embodiments, the management entity 100 is a program running in the DVC terminal and which communicates with the BWR Internet browser to carry out the steps of the method according to the invention. In other embodiments, the management entity 100 executes outside the DVC terminal and performs the management process by communicating with it.

[0062] The DVC terminal has the hardware architecture of a conventional computer. It includes in particular a processor, a RAM type random access memory and a read-only memory such as a Flash or ROM type memory (memories not shown in the figure) as well as input-output devices such as keyboards and / or screens (not shown in the figure). The DVC terminal can be a desktop or laptop computer, or a smartphone, or a touchscreen tablet or a phablet, or even a connected object such as a connected watch. The DVC terminal can also be the on-board computer of a motor vehicle, or a multimedia system embedded in a vehicle, i.e. an in-flight entertainment system intended for passengers, for example in a car, but also in an airplane, a coach, a train or a ship.The DVC terminal can also be a game console or any other equipment that can perform functions similar to the equipment mentioned above.

[0063] In all cases, the DVC terminal comprises an Internet browser BWR. This is a program that allows the user of the DVC terminal to access a website and interact with it. The browser BWR displays to the user, via the screen of the DVC terminal, the content of a website. The user can then provide, via the input devices of the DVC terminal such as a keyboard or a touch screen presenting a virtual keyboard, or by voice commands picked up by a microphone of the terminal, data which are addressed to the website. The management entity 100 can be included in the browser BWR, for example by using an extension mechanism, or can be a program running in the DVC terminal in parallel with the browser BWR, or a program running outside the DVC terminal, managing the management method for several terminals in parallel.For example, the management entity 100 may be a program running in an access gateway and carrying out the method according to the invention for all the DVC terminals present in the local network created by the access gateway.

[0064] In the example represented by [Fig.l], the DVC terminal can connect to a NET communication network. This NET communication network can be, for example, the Internet network. It is via the NET communication network that the BWR Internet browser can interact with Internet sites. Three Internet sites SI, S2, S3 are represented in [Fig.l]. In general, the interaction of the BWR browser with the sites SI, S2, S3 is done using the HTTP protocol (acronym for Hypertext Transfer Protocol) but other protocols can also be used.

[0065] The management entity 100 interacts with a predictive model MDL. In the exemplary embodiment of the invention presented in [Fig.l], the predictive model MDL is hosted by an SRV device external to the DVC terminal. The SRV device will for example be a computer server. In all cases, it will have the hardware architecture of a conventional computer. It may also be a virtual machine running in a cloud computing system or a set of one or more containers comprising the programs and data necessary to run the predictive model MDL. The management entity 100 can use the communication network NET in order to interact with the SRV device and thus with the predictive model MDL.The management entity 100 may also use a network separate from the NET network, for example a virtual private network (translation of the English Virtual Private Network) in order to ensure better confidentiality and security for communications between the DVC terminal and the SVR device.

[0066] An advantage of the architecture presented in [Fig.l] is to be able to have a large MDL predictive model, and therefore able to take into account a large number of parameters. It would not be efficient for such a large MDL predictive model to be distributed in all the BWR Internet browsers comprising a management entity 100 carrying out the method according to the invention. By maintaining a centralized MDL predictive model, hosted in an SRV server, the question of the size of the MDL model does not have to be taken into account. In addition, the centralized architecture described in [Fig.l] makes it possible to avoid developing a mechanism for distributing the MDL predictive model as well as an update mechanism in order to ensure that it is always relevant.

[0067] In other exemplary embodiments, the MDL predictive model may be present in the DVC terminal. For example, the MDL model may be a module of the management entity 100. This solution has the advantage of facilitating the interrogation of the MDL predictive model by the management entity 100 in comparison with the architecture represented in [Fig.l] in which the MDL predictive model is hosted by an SRV server. In other exemplary embodiments, the management entity 100 uses several prediction models which may be present in the DVC terminal or in a separate SVR device.

[0068] The method according to the invention is carried out by the management entity 100 during Internet browsing by the user of the DVC terminal via the BWR browser included in the DVC terminal.

[0069] During this navigation, the BWR browser will interact with a website such as SI, S2, S3. This interaction allows the module 101 of the management entity 100 to obtain a whole set of FTR metrics (translation of English features) from a site that the user seems to want to visit. FTR metrics are obtained from information relating to interaction according to the http protocol with the sites SI, S2, S3. These FTR metrics will then be submitted to the MDL predictive model.

[0070] FTR metrics are for example obtained from the address of the site SI, S2, S3, also called URL (acronym for Uniform Resource Locator). The FTR metrics obtained from the URL of the site SI, S2, S3 are for example the following: • Total length of the URL; • Average length of the different words in the URL; • Presence or absence of a subdomain in the URL; • Depth, total length, average word length, number of hyphens and number of digits present in the subdomain; • Depth, total length, average word length, number of hyphens and number of digits present in the domain; • Presence of a path in the URL; • Depth, total length, average word length, number of hyphens and number of digits present in the path; • Presence of parameters in the URL.

[0071] Those skilled in the art will know the meanings of the terms domain, subdomain, path and parameters in this context. To give an example, in the following URL:

[0072] http: / / ventes.orange.fr / exemple / client?terminal=phone

[0073] the string "orange" is the domain; the string "fr" is the top level domain (translation of the English top level domain, whose acronym is TLD); the string "sales" is the subdomain; the string "example / client" is the path and the string "terminal=phone" indicates the presence of a "terminal" parameter which takes the value "phone".

[0074] Furthermore, the character string "http" indicates that the protocol for interaction with the Internet site is the HTTP protocol and not another protocol such as FTP (acronym for File Transfer Protocol) or HTTPS (encrypted version of the HTTP protocol).

[0075] FTR metrics obtained from the URL of the visited site are indicative of site addresses that are being circumvented, that seek to hide certain elements, or that seek to obtain unusual parameters, which is indicative of a phishing site seeking to impersonate a legitimate site.

[0076] Other FTR metrics can be obtained from the URL of the visited site than those presented above which are only non-limiting examples.

[0077] Other FTR metrics are obtained from data relating to the user's past navigation. For example, an FTR metric obtained is the number of redirects that led to the website SI, S2, S3 that will be analyzed. These redirects can be caused either by navigation according to the HTTP protocol or by instructions in a code hosted in the site(s) present on the navigation path. These codes will often be written in the Javascript language but any other language can be used. A high number of redirects can be indicative of concealment of the final addresses to which the user is led by an attacking site. Other FTR metrics obtained from the user's past navigation can be defined.

[0078] Other FTR metrics are obtained from information relating to the contents of the target site's pages, before or after rendering and execution of code (e.g. Javascript) contained in the target site. The FTR metrics obtained from the contents of the target site's pages are, for example, the following: • Presence or name of a TITLE tag, or title tag, in the page; • Presence or name of Hl tags, indicating the highest section level, and so a title, on the page; • Number of SCRIPT tags, i.e. indicating the presence of executable code; • Number of SCRIPT tags including resources hosted by the same domain name; • Number of SCRIPT tags including resources hosted by different domain names; • Number of SCRIPT tags including code contained directly in the target site page; • Number of links to other pages contained in the target site page; • Number of links pointing to pages hosted by the same name domain ; • Number of links pointing to pages hosted by different domain names; • Number of empty or inactive links; • Number of IMG tags, i.e. indicating or containing images; • Number of IMG tags displaying images hosted by the same name domain ; • Number of IMG tags displaying images hosted by different domain names; • Number of IMG tags displaying images contained directly in the target site page (in base64 format).

[0079] These metrics reveal the internal structure of the target site's pages SI, S2, S3. They may indicate that dangerous elements are hidden in this structure, for example in seemingly harmless images. Reference to external elements may also indicate a website usurping a legitimate site, while the legitimate site would only refer to elements present in the site itself.

[0080] Other FTR metrics can be obtained from the content of the pages of the visited sites and the FTR metrics defined above which are only possible examples.

[0081] Other FTR metrics are obtained from reputation information provided by external services. For example, services such as Google's search engine, which lists a very large proportion of existing websites and regularly scans the Internet to detect the appearance of new sites, use algorithms to measure the good reputation of a site, based on the number of links leading to the site. The result of these measurement algorithms can be made public. This is the case, for example, with Open PageRank, a free service provided by the company DomCop, which provides a figure calculated using the same algorithm as that used by Google to classify the reputation of sites. Other figures provided by external services can be used as FTR metrics.

[0082] Other FTR metrics can be obtained from the cryptographic certificates used and displayed by the target site. These FTR metrics are for example the following: • Presence or absence of TLS encryption (acronym for Transport Loyer Security, i.e. the standard encryption protocol used by websites); • Issuer of the certificate; • Age of the certificate.

[0083] Such FTR metrics can reveal the reputation of the certificate issuer, as well as whether periods of certificate issuer hijacking may have been exploited by attackers to forge false certificates. The very non-use of TLS is an important clue, as a legitimate site will tend to use a TLS certificate to guarantee its identity.

[0084] Other FTR metrics can be obtained from cryptographic certificates, such as a mismatch between a site address and the certificate present on the site.

[0085] Other types of FTR metrics can be obtained from the information accessible to the management entity 100, and in particular to the module 101 for obtaining FTR metrics, from the visited websites S1, S2, S3.

[0086] We recall that the interaction between the browser B WR and the websites SI, S2, S3 which gives access to this information and therefore makes it possible to obtain the FTR metrics is a interaction similar to that of any Internet browser with a website. This interaction therefore does not allow a potential attacking site among the sites SI, S2, S3 to detect that it is subject to analysis by the BWR browser and the management entity 100. A potential attacking site will therefore not implement concealment measures similar to those it can implement when it detects that a centralized site is carrying out a systematic analysis of the websites to detect attacking sites.

[0087] The module 101 for obtaining FTR metrics obtains the FTR metrics either by performing simple calculations or processing from the information accessible from the sites SI, S2, S3 or by querying third-party services, such as Open PageRank or others.

[0088] Once the FTR metrics are obtained, these are provided to the FTR metrics analysis module 102 by an MDL predictive model.

[0089] In the embodiment shown in [Fig.l], the MDL predictive model is hosted by an SRV device external to the DVC terminal. In other embodiments, the MDL model may be present in the management entity 100, for example as a component of the analysis module 102. In still other embodiments, the MDL predictive model may be a component of the BWR browser or of the DVC terminal. Finally, in other embodiments, the MDL predictive model may be separated into several components: a part of the MDL model may be present in the management entity 100 and carry out a first processing of the FTR metrics, then a subsequent processing may be carried out by a component of the MDL model hosted in a remote server. Finally, in other embodiments, several predictive models may be used, which may be present in the DVC terminal or in an SRV device external to the DVC terminal.

[0090] The advantages of these different architectures are as follows: • In a centralized architecture, where the MDL model is hosted in the SRV device separate from the DVC terminal, the MDL predictive model can be of a very large size, which would not be able to be handled by a component of the BWR browser. In addition, it can be updated easily, without having to set up a protocol for distributing the MDL model to all the DVC terminals or BWR browsers integrating a management entity 100 according to the invention. • In a decentralized architecture, where the MDL model is hosted in whole or in part in the management entity 100, the querying of the MDL model by the analysis module 102 is done instantaneously. In addition, when the MDL model is hosted in the BWR browser, it is available even in the event of unavailability of the SVR device.

[0091] A possible architecture is to use a predictive MDL model integrated into an SVR device, but that the BWR browsers implementing the invention also have in the management entity 100 a copy of the MDL model which is updated less frequently than the MDL model hosted in the SVR device which can be a centralized server. This copy of the MDL model can then be used in the event of unavailability of the SVR server.

[0092] In all cases, the predictive model MDL is provided as input with the FTR metrics obtained by the module 101 and will provide as output an SCR data item representative of a confidence score relating to the Internet site among the sites SI, S2, S3 for which the FTR metrics were obtained.

[0093] The MDL predictive model can be, for example, a neural network that has undergone supervised or unsupervised learning. In supervised learning, a training set is formed of FTR metrics obtained from websites that are known to be legitimate sites or attacking sites. The training will then make it possible to modify the parameters of the neural network so that, when submitted to it FTR metrics from a website, it can discriminate between those obtained from a legitimate site and those obtained from an attacking site. In unsupervised learning, the FTR metrics obtained from websites are used to train the MDL model without having a verdict as to whether or not the website is harmless. This makes it possible to include a large number of sites in the training set since a verdict does not have to be given for each site and its associated FTR metrics.These notions of supervised or unsupervised learning of a neural network are well known to specialists in neural networks and are not detailed further here.

[0094] When the MDL model is a neural network, it is possible to submit to it FTR metrics of the same type as those used for its training and it will be able to perform a discrimination as to the site for which the FTR metrics were obtained. This discrimination is translated into a confidence score of which a representative SCR data is then obtained by the analysis module 102.

[0095] The MDL predictive model may be of a type other than a neural network. The MDL model may be, for example, an expert system that uses a set of logical rules to derive the SCR data representative of a confidence score for the website for which the FTR metrics were obtained. Such logical rules translate the reasoning of an expert and must, in general, be created by a dedicated process. For example, such a rule could consist of saying that if, on the one hand, the website analyzed among the sites SI, S2, S3 displays words relating to a banking activity, such as “bank”, “bank card”, “transfer”, “payment”, “invoice”, and on the other hand, the analyzed website does not use any encryption, then the The analyzed site is probably an attacker site and not at all a legitimate bank site. The FTR metrics to apply this rule would therefore be the presence of certain words in the site on the one hand and the presence of a cryptographic certificate on the other hand and the SCR data would then be a binary result on the dangerousness of the analyzed site.

[0096] It is also possible to use an MDL predictive model which is a mathematical function calculated from the FTR metrics. For example, a linear function may exist between the risk that a site is an attacker site and one or more given FTR metrics, such as a reputation figure. Several functions can thus be combined to form the MDL predictive model.

[0097] In general, the MDL predictive model can be built using several techniques from the work of artificial intelligence and machine learning. For example, the MDL model can be formed from an artificial neural network supplemented by a set of rules from an expert system which make it possible to ensure that particularly relevant information (a very poor reputation score for example) will not be drowned in the set of FTR metrics used as input to the neural network forming the MDL model.

[0098] An important advantage of the invention is that the MDL predictive model only receives FTR metrics and not the identity of the site visited among the sites SI, S2, S3. Thus, the confidentiality of the user's Internet browsing is preserved even when the MDL predictive model is hosted by an SRV device which is a centralized server. The only information provided to the centralized SRV server is FTR metrics which do not allow the identity of the sites visited to be reconstructed but which still allow the MDL predictive model to provide a diagnosis as to the danger of the site visited.

[0099] The MDL predictive model can be enriched throughout the use of the method according to the invention by the FTR metrics which are submitted to it associated with other information relating to the site visited among the sites SI, S2, S3.

[0100] Once the analysis module 102 has produced SCR data representative of a confidence score relating to the visited website, the action module 103 will carry out an ACT action relating to Internet browsing to protect the user from a website detected as dangerous.

[0101] The action ACT relating to navigation can be of several types. First of all, in the general case, the SCR data representing a confidence score is such that the action module 103 can deduce therefrom that the site visited among the sites SI, S2, S3 is harmless and, in this case, the action ACT will consist of letting the user's terminal continue its navigation without intervention from the action module 103.

[0102] Another possible ACT action is the display to the user of information deduced from the SCR data relating to the confidence score. The MDL predictive model will give an SCR confidence score from the FTR metrics obtained. This confidence score, or the SCR data representative of this score, is dependent on the form of the MDL predictive model. If the MDL predictive model is a neural network, for example, it may provide as a result a more or less large real number. Such a real number cannot be presented in a raw form to the user. An opinion must be deduced from it, for example by defining confidence scales grouping score intervals. Opinions can range from "dangerous" to "harmless", possibly with qualifications such as "completely" or "rather". Colors or logos can be used to have a simple presentation of the opinion to the user.It is this notice on the site whose access is requested that the DVC terminal, for example via the BWR Internet browser, will present to the user so that he is warned of its possible danger or on the contrary reassured as to its harmlessness.

[0103] Another possibility of ACT action is to block the user's navigation. If the SCR data representative of the confidence score is sufficiently strong so that the diagnosis of danger of the site among the sites SI, S2, S3 is almost certain, the action module 103 will block navigation on the dangerous site in order to protect the user and prevent him from revealing sensitive data or the DVC terminal from being infected by software downloaded from the dangerous site.

[0104] Another possibility of ACT action is to erase the form fields present on the site among the sites SI, S2, S3 on which the user is currently browsing. Obtaining the FTR metrics of the target site takes a certain amount of time, as does the analysis of these by the MDL predictive model. It is possible to envisage an embodiment of Internet browsing according to the invention in which users will only go to target sites SI, S2, S3 once the analysis of these has been carried out. But the mode which will be most often carried out will consist of obtaining the FTR metrics and analyzing them in parallel with the user's Internet browsing. In this mode of analysis and browsing in parallel, it will happen that a user begins to fill in form fields, therefore begins to provide sensitive data, on a site whose analysis of the FTR metrics reveals that it is dangerous.The ACT action carried out by the module 103 of the management entity 100 will then include the deletion of at least part of the fields of the forms in order to attempt to prevent the provision of the user's private data to the dangerous site among the sites SI, S2, S3. This ACT deletion action may be combined with an ACT action of blocking Internet browsing and warning given to the user.

[0105] In some embodiments, the analysis module 102, in addition to providing a SCR data representing a confidence score relating to a given target site, will also provide an indication of a website distinct from the target site. The objective is, when the analysis of the FTR metrics by the MDL predictive model indicates that the target site is probably a site usurping the identity of a legitimate site, to seek to identify the legitimate site whose identity is usurped. When carrying out the ACT action, the module 103 will thus be able to either directly direct the user's navigation to the legitimate site or indicate to the user that the site on which he is browsing has been detected as usurping the identity of a legitimate site and will suggest that he continue his navigation on the legitimate site.

[0106] One way of carrying out this operation may be as follows. The analysis step carried out by the analysis module 102 may comprise a screenshot of one or more pages of the target site among the sites S1, S2, S3. This screenshot may then be processed according to known image processing algorithms to extract the images which correspond to logos present on the target Internet site. These extracted images may then be subjected to an image recognition algorithm which has a database of images such as logos present on a set of legitimate sites such as sites of financial organizations, companies, administrations which may be usurped by attacker sites. A conventional image recognition algorithm may then indicate that the images extracted from the target site are identical or very close to the images present on a given legitimate site.This result will be a clear indication that the target site is indeed trying to usurp the identity of a legitimate site, and, moreover, the identity of the legitimate site will thus be known. The analysis module 102 will then be able to provide this identity to the module 103 which will carry out an action ACT relating to the user's navigation by taking into account the legitimate site whose identity is usurped by an attacking site.

[0107] The analysis relating to the images displayed by the target site may either use an image recognition algorithm and an image database which will be hosted in a remote server, a server which may be the same SVR device which hosts the MDL predictive model or another server, or a virtual machine or a container running in a cloud computing architecture, or may be carried out directly in the management entity 100 which may embed the image recognition algorithm in the analysis module 102 as well as an image database.The advantages of these respective choices are similar to those relating to the choice of architecture made for hosting the MDL model, namely on the one hand the ease of updating and the possibility of handling a larger image base in the case of hosting by an SVR device external to the DVC terminal and on the other hand the faster response time and greater availability in the case of hosting directly by the management entity 100.

[0108] It may be noted that the transfer of an image capture from the target site to an SVR server, unlike the transfer of FTR metrics, may involve a breach of the confidentiality of the Internet browsing of the user of the DVC terminal via the BWR browser. To overcome this drawback, the transfer of the captured images may be subject to authorization requested from the user in certain embodiments.

[0109] [Fig.2], for its part, presents an example of steps implemented within the framework of an embodiment of the invention.

[0110] The BWR browser, when the DVC terminal and its user are browsing the Internet, will request REQ from Internet sites, here in this case firstly the SL site. This provides, via the HTTP protocol, data such as texts, images, contained in a page written in the HTML language (acronym for Hyper-Text Markup Language). This data allows the BWR browser to display the SI Internet site to the user. In parallel, or prior to the display of the site to the user, the management entity 100 present in the BWR browser, and more precisely the module 101, will obtain a whole series of FTR metrics. These FTR metrics are obtained from elements present in the page(s) of the SI site which are known to the BWR browser thanks to the REQ request.The analysis module 102 submits these FTR metrics to the predictive model MDL which will provide in response an SCR data item representing a trust score relating to the website SL. The management entity 100 will take a decision based on this SCR score which results in the performance of an ACT action. In this case, the browser BWR stops its navigation on the site SI, because the SCR data item indicates that this site is not trustworthy. An additional ACT action may be the deletion or the attempt to delete the data which may have already been provided by the user to the site SI via the browser BWR. The method according to the invention then continues with the user browsing the site S2, for which the browser BWR makes a request REQ in order to obtain HTML data. FTR metrics are extracted from this new HTML data, FTR metrics submitted to the predictive model MDL.This provides in response an SCR data representing a confidence score to be given to the site S2. This SCR confidence score does not indicate a dangerous site, so the navigation of the BWR browser continues on the site S2 by a new REQ request which will obtain a new HTML page. The method according to the invention thus takes place throughout the user's navigation on the Internet.

[0111] [Fig.3], for its part, presents another embodiment of the invention according to an architecture different from that already presented.

[0112] In this exemplary embodiment, the DVC terminal comprises a predictive model MDL1, called the first model. This model MDL1 can for example be included in the na BWR browser, for example in the analysis module 102 of the management entity 100. When the module 101 for obtaining the FTR metrics obtains the FTR metrics of a site SI, S2, S3, these can be immediately subjected to an analysis carried out by the analysis module 102 using the first predictive model MDL1. This first analysis may, depending on its results, be supplemented by an analysis carried out with another predictive model MDL2, called the second model MDL2, which is hosted in an SVR server separate from the DVC terminal. The first predictive model MDL1 may be a small model, easy to deploy in all the DVC terminals which implement the invention. The result of the analysis by this first model MDL1 can then be obtained quickly, especially since the first model MDL1 is present in the DVC terminal and therefore easy to access.The second MDL2 model, on the other hand, is much larger than the first MDL1 model and therefore cannot be deployed across all DVC terminals. It is hosted in an SVR server separate from the DVC terminals.

[0113] The analysis by the second MDL2 model will therefore not always be carried out in this example, which is indicated by a dotted arrow in [Fig. 3]. In all cases, the analysis module 102 produces SCR data representative of a confidence score. This SCR data can be obtained directly from the analysis carried out by the first predictive model MDL1. If an analysis is also carried out by the second predictive model MDL2, the SCR data representative of a confidence score can be that obtained by the analysis carried out by the second MDL2 model or obtained by combining the results of the analyses carried out by the first predictive model MDL1 and the second MDL2 model.

[0114] The management entity 100 will be able to continue carrying out the management method by carrying out an action ACT relating to the Internet navigation of the DVC terminal as a function of the SCR data representing a confidence score relating to the target site SI, S2, S3 which will have been obtained after analysis by the first predictive model MDL1 and possibly by the second model MDL2.

[0115] This example embodiment has the advantage of presenting an architecture that is both decentralized, with a first small predictive model MDL1, easy to distribute, which is found in the DVC terminals as close as possible to the analyses to be carried out, and a second predictive model MDL2, a priori much more detailed than the first predictive model MDL1, and therefore much more difficult to distribute and update, but which will provide more detailed analyses if those provided by the first model MDL1 are insufficient.

Claims

Claims

1. Method for managing the Internet browsing of a terminal (DVC), implemented by a management entity (100), characterized in that it comprises the following steps: • Obtaining metrics (FTR) of an Internet site, called target site (SI, S2, S3), to which access is requested by the terminal (DVC); • Analysis of said metrics (FTR) by a predictive model (MDL) providing data (SCR) representative of a confidence score relating to the target site (SI, S2, S3); • Action (ACT) relating to the Internet browsing of the terminal (DVC) as a function of the representative data (SCR) provided by the predictive model (MDL).

2. Management method according to claim 1, characterized in that the analysis by the predictive model (MDL) is at least partly transferred to a device (SVR) external to the terminal (DVC).

3. Management method according to claim 1, characterized in that the analysis by the predictive model (MDL) comprises an analysis carried out by a predictive model (MDL1), called the first model, present in the terminal (DVC), and an analysis carried out by another predictive model (MDL2), called the second model, transferred to a device (SVR) external to the terminal (DVC), the analysis by the second model (MDL2) being carried out as a function of the result of the analysis by the first model (MDL1).

4. Management method according to one of claims 1 to 3, characterized in that the target site (SI, S2, S3) comprises a form comprising at least one field to be completed, and in that the action (ACT) relating to Internet browsing of the terminal (DVC) comprises the deletion of at least part of the form fields present in the target site (SI, S2, S3).

5. Management method according to one of claims 1 to 4, characterized in that the data (SCR) representative of a confidence score relating to the target site (SI, S2, S3) is supplemented by an indication of an Internet site distinct from the target site (SI, S2, S3).

6. Management method according to one of claims 1 to 5 characterized in that the predictive model (MDL) is enriched with the metrics (FTR) obtained and other information relating to the target site (SI, S2, S3).

7. Management entity (100) capable of carrying out a method for managing the Internet browsing of a terminal (DVC) comprising the following modules: • Module (101) for obtaining metrics (FTR) of an Internet site (SI, S2, S3), called the target site, to which access is requested by the terminal (DVC); • Module (102) for analyzing said metrics (FTR) by a predictive model (MDL) providing data (SCR) representative of a confidence score relating to the target site (SI, S2, S3); • Module (103) for action (ACT) relating to the Internet browsing of the terminal (DVC) as a function of the representative data (SCR) provided by the predictive model (MDL).

8. Terminal (DVC) comprising a management entity (100) according to claim 7.

9. A computer program implementable by a management entity (100) according to claim 7, the program comprising code instructions which, when executed by a processor, performs the steps of the management method according to claim 1.

10. Data carrier on which is recorded a computer program according to claim 9 comprising sequences of instructions for implementing the management method according to claim 1.

Citation Information

Patent Citations

  • Security level determination of websites

    US20120017281A1

  • Utilizing machine learning models to process low-results web queries and generate web item deficiency predictions and corresponding user interfaces

    US20230350968A1