Digital fraud prevention method and corresponding electronic device, system, computer program product and media
The method improves cyberattack detection by capturing and analyzing audiovisual content from user interfaces, correlating with trusted data sources to identify fraud risks, addressing the limitations of existing solutions that focus only on immediate application interface actions.
Patent Information
- Application Number
- FR2024005263
- Authority / Receiving Office
- FR · FR
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-05-23
- Publication Date
- 2025-11-28
AI Technical Summary
Existing cyber-malware solutions are inadequate in detecting sophisticated and varied cyberattacks, particularly phishing attacks, as they focus solely on immediate actions within the application interface, failing to recognize potential scams through alternative channels.
A digital fraud prevention method that captures audiovisual content from a user interface, performs contextual and semantic analysis, and correlates it with trusted data sources to identify inconsistencies, triggering an alert message when potential fraud is detected.
Enhances the detection of cyberattacks by analyzing additional elements beyond the application interface, improving the reliability of fraud prevention by identifying scams through channels like phone calls or face-to-face interactions.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
Title of the invention: Method for preventing digital fraud and corresponding electronic device, system, computer program product and media 1. Technical field
[0001] This application relates to the field of telecommunications and more specifically to the field of protecting users of telecommunications systems against cyberattacks. It concerns in particular a method for preventing digital fraud, implemented by one or more electronic devices, as well as the electronic devices, computer program products and corresponding recording media. 2. State of the art
[0002] Nowadays, system and telecommunications users are increasingly targeted by cyberattacks. The techniques used in these cyberattacks, or digital frauds, are becoming increasingly sophisticated and varied, and are sometimes very difficult for a targeted user to detect. Furthermore, a single attacker can very quickly change the form of their attacks (for example, by creating multiple ephemeral websites).
[0003] Among the most widespread attacks, we note in particular the so-called phishing attacks where a malicious third party adopts a false identity (often that of a trusted third party) to deceive a user and / or induce them to provide sensitive information (personal, banking data, etc.) and / or to carry out actions such as a payment of money (by bank transfer for example).
[0004] Numerous solutions have been developed to combat this cyber-malicious activity, particularly phishing. However, commercially available solutions are unable to eradicate all forms of cyber-malicious activity.
[0005] There is therefore a need for a solution that improves upon existing cyber-malware solutions on the market. 3. Description of the invention
[0006] This application aims to improve the situation by means of a digital fraud prevention process comprising: - Obtaining audiovisual content resulting from the capture of information rendered by a computer application on a user interface of an electronic device; - a conditional rendering of an alert message on said user interface taking into account a presence in said audiovisual content obtained from less a first element of content encouraging contact with a third party other than via the said computer application.
[0007] Audiovisual content means content having at least one audio, video and / or textual component, such as an image or a video for example. Depending on the embodiment, it may be "fixed" content (already recorded), or dynamic content (stream).
[0008] According to at least one embodiment, said information is a web page or a message received via email.
[0009] According to at least one embodiment, the first content element belongs to a type of content element representing at least one of the following items: - a telephone number; - a physical location.
[0010] According to at least one embodiment, the first content element is obtained by a contextual and / or semantic analysis of the audiovisual content.
[0011] According to at least one embodiment, said conditional rendering takes into account a consistency between said first content element and at least one associated data in a data source, certified reliable by a trusted third party, to a second content element obtained during said analysis.
[0012] According to at least one embodiment, in the event of detection of an inconsistency between said first content element and said at least one data, the method includes a recording of said other data in a first set of content elements associated with a risk of digital fraud.
[0013] According to at least one embodiment, said second content element belongs to a group comprising:
[0014] - a logo of an organization;
[0015] - an identifier of an organization;
[0016] -a label of an organization;
[0017] - a combination of at least two of the above content elements.
[0018] According to at least one embodiment, said conditional rendering takes into account a membership of said first content element in a second set of content elements certified as reliable by a trusted third party.
[0019] According to at least one embodiment, said conditional rendering takes into account the membership of said first content element in a third set of content elements already associated in a data structure with a digital fraud risk. This third set of content elements may, for example, be the same set of content elements as the first set of content elements associated with a digital fraud risk introduced above.
[0020] The features, presented in isolation in this application in connection with certain embodiments of at least one of the methods of obtaining and / or rendering of this application may be combined with each other according to other embodiments of this method.
[0021] According to another aspect, the present application also relates to an electronic device adapted to implement at least one of the methods of obtaining and / or rendering of the present application in any of its embodiments.
[0022] For example, the present application thus relates to an electronic device comprising at least one processor configured to implement digital fraud prevention comprising, - Obtaining audiovisual content resulting from the capture of information rendered by a computer application on a user interface of an electronic device; - a conditional rendering of an alert message on said user interface taking into account the presence in said audiovisual content obtained of at least one first element of content encouraging contact with a third party other than via said computer application.
[0023] According to another aspect, the present application also relates to a telecommunications system comprising at least one electronic device adapted to implement the prevention method of the present application in any of its embodiments.
[0024] Thus, the present application relates for example to a telecommunications system comprising at least one electronic device comprising at least one processor configured to implement digital fraud prevention comprising, - Obtaining audiovisual content from the capture of information rendered by a computer application on a user interface of an electronic device; - a conditional rendering of an alert message on said user interface taking into account the presence in said audiovisual content obtained of at least one first element of content encouraging contact with a third party other than via said computer application.
[0025] This application also relates to a computer program comprising instructions for implementing the various embodiments of the above prevention method, when the program is executed by a processor and a recording medium readable by an electronic device and on which the computer program and the corresponding information medium are recorded.
[0026] For example, the present application thus relates to a computer program comprising instructions for implementation, when the program is executed by a processor of an electronic device, of a digital fraud prevention process comprising, - Obtaining audiovisual content resulting from the capture of information rendered by a computer application on a user interface of an electronic device; - a conditional rendering of an alert message on said user interface taking into account the presence in said audiovisual content obtained of at least one first element of content encouraging contact with a third party other than via said computer application.
[0027] For example, the present application also relates to a processor-readable information carrier of an electronic device on which is recorded a computer program comprising instructions for implementing, when the program is executed by the processor, a digital fraud prevention method comprising, - Obtaining audiovisual content resulting from the capture of information rendered by a computer application on a user interface of an electronic device; - a conditional rendering of an alert message on said user interface taking into account the presence in said audiovisual content obtained of at least one first element of content encouraging contact with a third party other than via said computer application.
[0028] The programs mentioned above may use any programming language, and be in the form of source code, object code, or intermediate code between source code and object code, such as in a partially compiled form, or in any other desirable form.
[0029] The information (or recording) media referred to in this application may be any entity or device capable of storing the program. For example, a medium may include a storage means, such as a ROM, for example a CD-ROM or a microelectronic circuit ROM, or a magnetic recording means.
[0030] Such a means of storage can, for example, be a hard drive, a flash memory, etc.
[0031] On the other hand, an information medium can be a transmissible medium such as an electrical or optical signal, which can be transmitted via an electrical or optical cable, by radio, or by other means. A program according to the invention can, in particular, be downloaded onto an Internet-type network.
[0032] Alternatively, an information (or recording) medium may be an integrated circuit in which a program is incorporated, the circuit being adapted to execute or to be used in the execution of any of the embodiments of the process that is the subject of this patent application.
[0033] Generally speaking, in the present application, obtaining an element means, for example, receiving that element from a communication network, acquiring that element (via, for example, user interface elements or sensors), creating that element by various processing means such as copying, encoding, decoding, transformation, etc., and / or accessing that element from a local or remote storage medium accessible to at least one device implementing, at least partially, that obtaining. 4. Brief description of the drawings
[0034] Other features and advantages of the invention will become more apparent upon reading the following description of particular embodiments, given by way of simple illustrative and non-limiting examples, and the accompanying drawings, among which:
[0035] Figure 1 presents a simplified view of a system, cited by way of example, in which at least some embodiments of the method of the present application can be implemented.
[0036] Figure 2 presents a simplified view of a device adapted to implement at least certain embodiments of the process of the present application.
[0037] Figure 3 presents an overview of the process of the present application, in some of its embodiments.
[0038] Figure 4 presents, on the one hand, an example of a fraudulent web page and, on the other hand, of an alert message, rendered on a user interface of a device such as device 200 of Figure 2, implementing the method of the present application, in some of its embodiments. 5. Description of the implementation methods
[0039] The present application proposes a solution for detecting digital fraud based on capturing information rendered by a computer application on a user interface of an electronic device and correlating it with data from at least one other data source (for example, from various sources).
[0040] The proposed solution is an "Over The Top" (OTT) solution, meaning it is located "above" (or on top of) the applications running on the electronic device and can run regardless of the application currently running on the terminal. Such a solution offers the advantage, at least in some embodiments, of being independent of the operating system of the device on which the prevention method is implemented and of the applications running on that device.
[0041] By data from various sources, we mean here data related to contextual information constructed in relation to the user's activity. It can This refers to structured data stored internally within the electronic device or externally to that device (for example, structured data stored on a database or a third-party server).
[0042] These data sources may vary depending on the user's activity (web browsing, etc.), as well as the information displayed on the device's user interface. For example, when the displayed information relates to a company, one of the data sources may be a register listing all companies created in a geographical area (such as a country), like the "infogreffe" © website in France.
[0043] The solution focuses in particular on identifying, within the information displayed on the application interface, elements that could encourage a user to contact a malicious third party without using that application interface. These elements could include, for example, a telephone number to call, an email address to use, and / or a physical address to visit or to whom to send paper documents.
[0044] The proposed solution can thus help detect cyberattacks that might go unnoticed by solutions (such as certain prior art solutions) focusing on the "immediate" means of action provided by the computer application that generated the rendering to a user via its application interface (presenting the rendered information). The inventors ingeniously observed that a cyberattack could be merely the beginning of a scam carried out through a channel other than the application interface in question (during a phone call or a face-to-face meeting, for example). Monitoring interactions made via the application interface will therefore not be sufficient in such a situation.
[0045] Thus, for example, a very simple web page presenting the activities of a company, without containing an access link (or "Uniform Resource Locator" (URL)) to another page, or any graphical element for entering information, will be considered harmless from the outset by certain prior art solutions because it does not directly allow the provision of confidential information and cannot redirect the user to a potentially malicious site. Therefore, these prior art solutions will not analyze it. Conversely, the solution of this application will analyze other elements present on the page to detect, by correlation with at least one data source, a possible malicious and / or fraudulent context.
[0046] The present application is now described in more detail in connection with the figures presented.
[0047] Figure 1 represents a telecommunications system 100 in which certain embodiments of the invention can be implemented. The system 100 comprises one or more electronic devices, at least some of which can communicate with each other via one or more communication networks 160, possibly interconnected (for example via an interconnection device 140 (also called a gateway), such as a local area network or LAN (Local Area Network) and / or a wide area network, or WAN (Wide Area Network). Examples of networks may include a corporate or home LAN and / or a WAN of the internet, or cellular, GSM - Global System for Mobile Communications, UMTS - Universal Mobile Telecommunications System, Wifi - Wireless, etc. type.
[0048] As illustrated in [Fig. 1], the system 100 may also include one or more electronic devices, such as a terminal 110, 112 (such as a laptop, smartphone, and / or tablet), an augmented, mixed, or virtual reality headset, a connected object, and / or a server 130, for example, an application server, a storage device 150, 152. The system may also include network management and / or interconnection elements (not shown). These electronic devices may be associated with at least one user 120 (for example, via a user account accessible by login), and some of the electronic devices 110, 112 may be associated with the same user. At least one computer application 170 may run, at least partially, on at least one of the devices and, in particular, provide an application interface to a user 120 of a terminal 110, 112 of the system.
[0049] Figure 2 illustrates a simplified structure of an electronic device 200 of the system 100, for example device 110, 112, 130 or 140 of Figure 1, adapted to implement the principles of the present application. Depending on the embodiment, it may be a server, a gateway and / or a terminal.
[0050] The device 200 includes, in particular, at least one memory M 210. The device 200 may, in particular, include a buffer memory, volatile memory, for example of the RAM (Random Access Memory) type, and / or non-volatile memory (for example of the ROM (Read Only Memory) type). The device 200 may also include a processing unit UT 220, equipped, for example, with at least one processor P 222, and driven by a computer program PG 212 stored in memory M 210. At initialization, the code instructions of the computer program PG are, for example, loaded into RAM before being executed by the processor P. Said at least one processor P 222 of the processing unit UT 220 may, in particular, implement, individually or collectively, any one of the embodiments of at least one of the prevention methods of this application (described in particular in relation to [Fig.3]), according to the instructions of the PG computer program.
[0051] The device may also include, or be coupled to, at least one FO 230 input / output module, such as a communication module, enabling, for example, the device 200 to communicate with other devices of the system 100, via wired or wireless communication interfaces, and / or such as an interface module with a user of the device (also referred to more simply in this application as a "user interface").
[0052] The user interface of the device means, for example, an interface integrated into the device 200, or a part of a third-party device connected to this device by wired or wireless means. For example, it could be a secondary screen of the device, a camera (enabling the acquisition of gesture commands from an operator, for example), or a set of loudspeakers connected wirelessly to the device.
[0053] A user interface can in particular be an "output" user interface adapted for rendering (or controlling rendering) an output element of a computer application used by the device 200 (such as a web page), for example an application running at least partially on the device 200 or an "online" application running at least partially remotely, for example on the server 130 of the system 100. Examples of output user interfaces of the device include one or more screens, in particular at least one graphics screen (touchscreen for example), one or more speakers, a connected headset (in particular an augmented, mixed or virtual reality headset).
[0054] By rendering, we mean here a display (or "output" according to English terminology) on at least one user interface, in any form whatsoever, for example including textual, audio and / or video components, or a combination of such components.
[0055] Furthermore, a user interface can be an "input" user interface adapted for acquiring a command from a user of the device 200 or for entering information by a user of the device 200. This can include an action (command, entry, etc.) to be performed in connection with an item rendered by the device 200 and to be transmitted to a computer application running at least partially on the device 200 or to an "online" application running at least partially remotely, for example on a server (not shown) of the system 100. Examples of input user interfaces of the device 200 include a sensor, an audio and / or video acquisition means (for example a microphone, a camera (webcam), a means of acquiring a command (key(s), for example a keyboard, button, mouse, touchscreen actuator), etc.
[0056] Some user interfaces (such as a touch screen) can be input / output user interfaces, allowing both the rendering of information and user actions.
[0057] Here, "application interface" refers to the application elements rendered by an application via an output (or input / output) user interface of the device 200 and the elements of interaction with the application presented on this output interface (in particular input forms, clickable link, etc.) and actionable via an input (or input / output) interface of the device (keyboard, mouse, touch screen, etc.).
[0058] Said at least one microprocessor of the device 200 can in particular be adapted to implement the process of the present application.
[0059] Thus, said at least one microprocessor of device 200 can in particular be adapted to implement digital fraud prevention including: - Obtaining audiovisual content from the capture of information rendered by a computer application on a user interface of an electronic device; - a conditional rendering of an alert message on said user interface taking into account the presence in said audiovisual content obtained of at least one first element of content encouraging contact with a third party other than via said computer application.
[0060] For example, the device 200 may include (or be coupled to) at least one communication module adapted for receiving audiovisual content and / or sending an alert from or to a third-party device.
[0061] It is noted that according to the embodiments, the device can be the device 110, 112 on which the application interface to be evaluated is rendered or a device "supervising" a device 110,112 on which the application interface to be evaluated is rendered.
[0062] Thus, in certain embodiments, the device 200 may include (or be coupled to) at least one module for capturing audiovisual content rendered on a user output interface (of the device 200 or of a third-party device). Such a capture module may, for example, correspond to audiovisual stream acquisition equipment (hardware module) (such as smart glasses, an augmented or virtual reality headset, a camera, a microphone, etc.) or to a software module such as an application probe, internal to the device 200, capable of detecting (capturing) and collecting information rendered to a user on an output interface of the device 200. For example, in the case of an email rendered on a screen of the device 200, a camera of the device may acquire an image of the rendered email and an application probe may capture an HTML description of the email.An application probe can sometimes prove more reliable than certain character recognition techniques, for example OCR (Optical Character Recognition), since it . directly captures the data, unlike character recognition techniques which obtain this data by interpreting the acquired elements, with the associated risk of error.
[0063] This image or the description of this image can then be processed by one or more modules of the device 200 (for example modules of the program P loaded by the processing unit of the device 200).
[0064] For the sake of simplicity, in the remainder of this application, audiovisual content (image and / or audio) and its description (for example in html form) will be considered equivalent.
[0065] For example, the program P of the device 200 may include a management module (detection, recognition) for events related to the activity of the user of said device 200. For example, when the device 200 is a computer or a smartphone, the detection module may detect a change in active windows, determine the name of an active application, capture audiovisual content (or its description), such as an audio and / or video stream if the device 200 is an AR / VR headset. The program P may also include a context management module, responsible for performing a contextual analysis of the obtained audiovisual content, and a module responsible for verifying the consistency of the elements resulting from the contextual analysis to detect possible fraud.
[0066] Some of the above input / output modules are optional and may therefore be absent from device 200 in certain embodiments. In particular, if the process is implemented locally by device 200, communication modules adapted for receiving audiovisual content and / or sending an alert message from / to another device may be optional in certain embodiments.
[0067] On the contrary, in some of its embodiments, the process can be implemented in a distributed manner between at least two devices 110, 112, 130, 140, 150, 152 of the system 100.
[0068] The term "module" or the term "component" or "element" of the device refers here to a hardware element, in particular a wired one, or a software element, or a combination of at least one hardware element and at least one software element. The method according to the invention can therefore be implemented in various ways, in particular in wired and / or software form.
[0069] We now present in more detail certain embodiments of the prevention process 300 of this application.
[0070] As shown in [Fig. 3], the method 300 may include obtaining 310 audiovisual content rendered on an application interface. For example, this may be an image, such as an image from a video-type audiovisual stream acquired or received in real time (via a capture or communication module of the device 200 according to the embodiments) and representative of the rendering on a graphic screen of the device 200 of an application 170. It can also be a voice content in some embodiments.
[0071] In addition, or alternatively, the method may include obtaining a description of the rendered audiovisual content. The description may, for example, be generated by an application probe. It may, in particular, be a representation in a computer language using tags to describe the elements of digital content (web page, email, etc.) (nature, size, color, positioning, labels, structure, etc.) and the links between these elements, or between these elements and external elements. Examples of such languages are HTML (HyperText Markup Language), CSS (Cascading Style Sheets), and / or JavaScript. An example of an HTML description is provided in Appendix 1. As illustrated, the process may include an analysis of the obtained content and / or the description obtained of that content (or its description), for example, to identify the displayed data. For instance, the analysis may include the extraction of informative elements from the obtained audiovisual content (and / or its description). For example, in the case of obtained content with a visual component, this may involve using image analysis techniques to detect image fragments likely to correspond to objects of interest (logo, text, etc.), precisely "outlining" these objects of interest, and, when they are likely to contain text, applying character recognition techniques (for example, "optical character recognition" or OCR) to these image fragments to extract textual elements (words or strings of characters).Image analysis can also provide 322 pieces of positioning information for these objects of interest (text, logo, etc.) within the audiovisual content.
[0072] In the case of audiovisual content including a voice sequence, audio analysis techniques can for example be applied to enable word recognition in this sequence (in particular speech-to-text conversion techniques (or "Speech To Text" according to English terminology), to which positioning information in the sequence can also be associated.
[0073] As mentioned above, the analysis may also include an analysis of a description obtained from the audiovisual content. This analysis may, for example, make it possible to detect (and extract) informative elements in the description similar to those detected via image analysis (logos, text, etc.). An analysis of a A descriptive approach can sometimes allow for more reliable detection of text and other elements within the content, since these are explicitly indicated in the description and not "deduced" from image processing, which is subject to potential errors or inaccuracies. Furthermore, an analysis based on application probes can prove simpler, and therefore less demanding in terms of memory and processing resources, than an analysis using image processing.
[0074] An analysis of a content description can also allow, at least in some embodiments, the detection and extraction of informative elements not detectable visually or by audio analysis on the content, such as an internet access present in the content but appearing (visually) on the content with a label different from the actual address of this access, or a url present in the content but hidden (visually) from a user.
[0075] As illustrated, the process 300 can also include obtaining 323 the "fraud" context of the content, i.e., a corpus of data on which the assessment 330 of a fraud risk associated with the content will be based. This obtaining can include searching the extracted information 321 from the content and / or its description for elements relevant in a fraud context (such as logos, meaningful words, and / or named entities that may be important for predicting (detecting) fraudulent content (i.e., for assessing the risk that the content is fraudulent). For example, such named entities may include a company name, a telephone number, an internet address, an email address, a web address (or URL, for Uniform Resource Locator), etc. All this data forms the "context" of the content to be assessed.
[0076] As illustrated, process 300 may include an evaluation 330 of the (fraud) context obtained.
[0077] Optionally, this evaluation 330 may include a check 331 that at least one context element of a certain type (internet address, domain name, telephone number, etc.) belongs to at least one set (for example, one or more lists) of elements of the same type already classified as reliable; and / or, conversely, a check 332 that such context element(s) belong to at least one set (for example, one or more lists) of elements of the same type already classified as representative of a cyberattack. These checks may be optional in certain embodiments.
[0078] The assessment 330 of the fraud context may also include, for example, a verification 337 of the consistency between at least two elements of the content's fraud context.
[0079] For example, the method may include a check 337 of the consistency of at least one first element of the context of a first type with at least one associated element, external to the context, of at least one second element of the context, this associated element being the second element of a type corresponding to the first type of this first element. This element may be associated with the second element in at least one data source accessible (locally or remotely) to the device 200 and considered reliable.
[0080] Thus, put more simply, if the context of fraud includes a first element and a second element, the process may include a check 337 of the consistency of the first element of the context with an element external to the context, of the same type (or of a similar type) as the first element of the context, and obtained from the second element.
[0081] More specifically, the method may include obtaining at least a first data structure describing and providing access to at least one reliable data source (capable of providing this external element in our example above). Alternatively, the method may include obtaining a path to such a first data structure.
[0082] The first data structure can for example be obtained 333 by accessing a configuration file prior to the execution, or initialization, of the process 300. It can also be built dynamically by a supervisory operator and received prior to or during the execution of the process 300 (for example during each evolution of this data structure).
[0083] The first data structure can, for example, be obtained 333 (by accessing at least one local or remote file) each time audiovisual content is obtained, or alternatively, each time content is analyzed (for example, just before, during, or just after the content is obtained or analyzed). In certain embodiments, the first data structure can also be obtained via a configuration file prior to the execution and / or initialization of process 300.
[0084] Note that the first data structure can evolve over time, so it may be possible to add new data sources and associated descriptions to the first data structure, to modify them (access path and / or description) or to delete them.
[0085] As illustrated, the process may include access 334 (reading) to the first data structure obtained 333.
[0086] The first data structure may include, in particular, an identifier and / or a path to at least one data source considered reliable. It may also include, in association with the identifier and / or the path of This source provides a description of the types of data accessible through this reliable data source.
[0087] The first data structure can, for example, take the form of a list, a database, or a lookup table.
[0088] Examples of reliable data sources include government data sources (e.g., business registers) or private data sources (e.g., telephone number registers) verified, for example, by a trusted third party. It may also be one or more data sources maintained by the same party implementing the process described in this application (e.g., a data source such as a list of subscribers to a communication network, managed internally by a telephone operator, such as the applicant). A data source may take the form, for example, of one or more files, at least one database, a web service (e.g., an online application), etc.
[0089] A data source can, for example, provide access to secondary data structures that link certain data together. For example, the first data structure can contain an address (or access link (URL for example)) of a first data source, corresponding to a government business register, to which is associated, in the first structure, a description listing the information accessible via this first data source (i.e. the description of the "second" data structure that this data source contains (Company name, company address, Company identifier, code and / or description of the company activity, etc.).Similarly, in this example, the first data structure can also contain an address of a second data source, corresponding to a register of postal addresses, telephone numbers and / or company websites, to which is associated, in the first structure, a description listing the information accessible via this second data source (Company name, Company ID, date of company creation, company address, URL of the company website, main telephone number, etc.).
[0090] Similarly, in this example, the first data structure may also contain an address of a third data source, corresponding to a register of company trademarks, to which is associated, in the first structure, a description listing the information accessible via this third data source (Company name, current logo, former logos, sound motif ('jingle' according to English terminology) specific to the company, etc.).
[0091] It is noted that, as this example shows, a data source can provide access to data other than textual data, such as image or audio data.
[0092] According to a first example, the first data structure can be represented as a lookup table associating the address of a source with data an n-tuple describing the different types of data accessible via this source.
[0093] Thus, the above example can be represented in the form of the following table ("table 1"):
[0094] [Tables 1] Access Source Description URL1 (Company Name, Postal Address, Company ID, Activity) URL2 (Company Name, Company ID, Company Creation Date, Postal Address, Company Website URL, Telephone Number) URL3 (Company Name, Current Logo, Old Logo, Jingle)
[0095] According to a second example, the first data structure can be represented in the form of the following table (“table 2”), listing the possible data types (descriptors) of the sources and associating, for each source and each possible data type, a boolean value indicating whether the source actually leads to data of the type concerned, (a boolean value “True” being, for example, indicated below by an “X”, and a boolean value “False” by an absence of an “X”),
[0096] [Tables2] RI Access Exit Descriptions Company Postal Address® Company Name Activity Company Creation Company Website URL® Telephone Address Logo! Old Logo® URL? s X* X® A* S 52 X« « X® 32 X® X® Xs X® Ci •Œ s Ci 32 33 Ci X® x« "T
[0097] As illustrated in [Fig. 3], the method 300 may, in certain embodiments, include a selection 335 of at least one data source from the first data structure, taking into account a similarity between:
[0098] - on the one hand, the type of at least one first element of the context (whether it is (verify) and a data type included in the description associated with the data source in the first data structure, and
[0099] - on the other hand, another type of data included in the description associated with the source of data in the first data structure and the type of at least one second element of the context (through which the verification can be carried out).
[0100] Depending on the embodiments, and depending on the types of context elements, similarity is understood to mean either identical types (for example a first element of type "telephone number" versus a presence of the data type "telephone number" in the description of a source), or types corresponding to at least partially identical data (for example a first element of type "email" versus a presence of the data type "domain name" in the description of a source, the email associated with a company logically having to incorporate the company's domain name).
[0101] The method 300 may include accessing 336 at least one selected data source to obtain at least one element external to the context of fraud and associated, in the data source, with the second context element and a verification 337 of the consistency between this external element and the first context element whose consistency is to be verified.
[0102] Consistency checking can be performed iteratively on several context elements (to be checked). For example, in some embodiments, it can be performed for each context element from the application interface. In particular, the method can include a consistency check of (seemingly innocuous) context elements that do not allow online data entry or access to another webpage / website, such as a company registration number in an official national register listing business creations, for example.
[0103] Depending on the embodiment, a variable number of data sources can be selected to verify the consistency of a first context element. Increasing the number of selected data sources can improve the reliability of the prevention process in certain embodiments (for example, by guarding against the potential corruption of a data source that was nevertheless considered reliable). Limiting the number of data sources selected to verify the consistency of the same context element can help to limit the processing time and / or complexity during consistency checking (for example, by avoiding duplication of certain checks when several data sources allow access to external elements of the same type as a first element to be checked).
[0104] In certain embodiments, the data sources can be used in a cascading fashion, so as to be able to perform a consistency check between several elements of the fraud context via the use of intermediate data sources comprising complementary data types. For example, if the fraud context includes an element of type Type-1, and a second element of type Type-2, one can perform, in a cascading fashion, access to a first data source whose description includes data of Type-1, Type-3) then access to a second data source including data of type (Type-3, Type-4, Type-5) then access to a second data source including data of type (Type-5, Type-6, Type-2).
[0105] The method may include processing 340 of the evaluation result. This processing may include generating 341 a message informing of the result of the consistency check. Depending on the embodiment, the message may be rendered and / or stored locally and / or transmitted to another device (for example, via another user device or to a monitoring device).
[0106] This message may be optional when consistency check 337 did not detect any inconsistency.
[0107] This message may correspond to an alert when consistency check 337 has resulted in the detection of at least one inconsistency for at least one element of the context.
[0108] If the consistency check 337 results in the detection of at least one inconsistency for at least one context element, the process may include adding 342 at least one designation piece of information relating to the checked application interface, and / or the inconsistent context element, to a data structure containing data identified as representative of a cyberattack. Such a data structure may be used subsequently in the process of this application (e.g., step 332) or by any other process (e.g., another fraud prevention process of the applicant).
[0109] An example of implementation of the process of this application is presented below in conjunction with [Fig. 4]. In our example, a user of an electronic terminal searches the internet for a firewood supplier. They access one of the sites suggested by their terminal's search engine. The site they access displays the homepage 410 illustrated in [Fig. 4].
[0110] Process 300 is initiated by displaying the 410 homepage (or alternatively by activating the link presented by the search engine and giving access to this 410 homepage).
[0111] According to the method, a capture 310 of the content displayed on the homepage 410 is performed, the captured content is analyzed 320 to extract words and obtain the context of fraud, and an evaluation 330 of the context is performed. This evaluation results in the detection of an inconsistency between the company name and the telephone number displayed on the homepage. An alert is generated. In the illustrated example, this alert generation includes the display of an informational message 420 on the electronic terminal screen.
[0112] In the illustrated example, the process may also include saving all elements of the homepage detected as inconsistent (element types, element values, etc.) to a remote server. The alert may further include sending a message to a supervisory third party. In our example, this is a third party managing a data structure listing fraudster telephone numbers and offering an alert service to its users (such as the applicant's "Orange Telephony" service). The fraudulent telephone number is added to the supervisory third party's data structure so that users of the service can be alerted to the fraud risk associated with that telephone number. Appendix 1
[0113] {
[0114] {
[0115] "type": {
[0116] “value”: “web_navigator”,
[0117] "conf": 0.86
[0118] },
[0119] "content":[
[0120] {
[0121] "area_type": {
[0122] "value": "web_site_url",
[0123] "conf": 0.86
[0124] },
[0125] "bbox": [{"x":l, "y": 1, "w": 923, "h": 60}],
[0126] "data": [
[0127] {
[0128] "type": "web_site_url",
[0129] "mimetype":"text / x-uri",
[0130] "bbox": [{"x":l, "y": 1, "w": 323, "h": 12}],
[0131] "value" : "http : / / info-edf .com / we2345 ",
[0132] "conf": 0.98
[0133] }
[0134] },
[0135] {
[0136] "area_type": {
[0137] "value": "organization_info",
[0138] "conf": 0.76
[0139] },
[0140] "bbox": [{"x":l, "y": 70, "w": 723, "h": 300}],
[0141] "data": [
[0142] {
[0143] "type”: "logo",
[0144] "mimetype":"image / jpg",
[0145] "bbox": [{"x":12, "y": 23, "w": 123, "h": 123}],
[0146] "value": "EDF",
[0147] "conf": 0.78
[0148] },
[0149] {
[0150] "type": "Organization",
[0151] "mimetype":"text / *",
[0152] "bbox": [{"x":123, "y": 330, "w": 223, "h": 12}],
[0153] "value": "EDF",
[0154] "conf": 0.98
[0155] },
[0156] {
[0157] "type": "mail",
[0158] "mimetype" : "text / plain",
[0159] "bbox": [{"x":123, "y": 400, "w": 183, "h": 12}],
[0160] "value" : "contact@ edf.com",
[0161] "hidden_value": "contact@info-edf.com",
[0162] "conf": 0.78
[0163] },
[0164] {
[0165] "type": "phone",
[0166] "mimetype" : "text / plain",
[0167] "bbox": [{"x":123, "y": 450, "w": 120, "h": 12}],
[0168] "value":"09.98.33.21.42",
[0169] "conf": 0.97
[0170] }
[0171] },
[0172]
[0173] }
Claims
Demands
1. A method for preventing digital fraud comprising: - obtaining audiovisual content from the capture of information rendered by a computer application on a user interface of an electronic device; - conditionally rendering an alert message on said user interface taking into account the presence in said audiovisual content obtained of at least one first element of content encouraging contact with a third party other than via said computer application.
2. A prevention method according to claim 1 wherein said information is a web page or a message received via email.
3. A prevention method according to claim 1 or 2 wherein the first content element belongs to a type of content element representing at least one of the following items: - a telephone number; - a physical location.
4. A prevention method according to any one of claims 1 to 3 wherein the first content element is obtained by a contextual and / or semantic analysis of the audiovisual content.
5. A prevention method according to any one of claims 1 to 4 wherein said conditional rendering takes into account a consistency between said first content element and at least one associated data in a data source, certified reliable by a trusted third party, to a second content element obtained during said analysis.
6. A prevention method according to claim 5 wherein, in the event of detection of an inconsistency between said first content element and said at least one data point, the method comprises a recording of said first element in a first set of content elements associated with a risk of digital fraud.
7. A prevention method according to claim 5 or 6 wherein said second content element belongs to a group comprising: - an organization logo; - an organization identifier; - an organization label; - a combination of at least two of the above content elements.
8. A prevention method according to any one of claims 1 to 7 wherein said conditional rendering takes into account a membership of said first content element in a second set of content elements certified as reliable by a trusted third party.
9. A prevention method according to any one of claims 1 to 8 wherein said conditional rendering takes into account a membership of said first content element in a third set of content elements already associated in a data structure with a risk of digital fraud.
10. Electronic device comprising at least one processor configured to implement digital fraud prevention comprising: - obtaining audiovisual content from the capture of information rendered by a computer application on a user interface of an electronic device; - conditional rendering of an alert message on said user interface taking into account the presence in said audiovisual content obtained of at least one first element of content inciting contact with a third party other than via said computer application.
Citation Information
Patent Citations
Phishing website identification method and system
CN108566399A
Method and apparatus for image recognition services
EP3239919A1
Anti-phishing system and method using computer vision to match identifiable key information
US10999322B1
Detecting and Protecting Against Employee Targeted Phishing Attacks
US20230188564A1