Method and apparatus for detecting URLs associated with phishing sites using artificial intelligence algorithms

The use of AI algorithms and blockchain for preprocessing and analyzing URLs improves phishing site detection by examining webpage content, addressing the limitations of conventional methods in detecting sophisticated phishing attempts.

JP7742193B2Active Publication Date: 2025-09-19NURILAB CO LTD
View PDF 8 Cites 0 Cited by

Patent Information

Application Number
JP2024552663
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2023-07-24
Filing Date
2023-09-26
Publication Date
2025-09-19
Estimated Expiration
2043-09-26

AI Technical Summary

Technical Problem

Conventional methods struggle to effectively detect phishing sites due to the increasing sophistication of phishing techniques, leading to inconsistent and inadequate detection of phishing attempts.

Method used

A method and apparatus using artificial intelligence algorithms to preprocess URLs, analyze webpage content, and utilize databases and AI models to identify phishing sites, incorporating blockchain for secure storage and management.

Benefits of technology

Enhances phishing site detection efficiency by analyzing webpage content rather than relying on specific text patterns, providing more accurate and secure identification of phishing URLs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007742193000002
    Figure 0007742193000002
  • Figure 0007742193000003
    Figure 0007742193000003
  • Figure 0007742193000004
    Figure 0007742193000004
Patent Text Reader

Abstract

A method and apparatus for detecting URLs associated with phishing sites is disclosed. According to one embodiment of the present disclosure, a method for detecting URLs associated with phishing sites, performed by an apparatus, may include the steps of: obtaining a target URL associated with a first URL included in a text message; determining whether the target URL is included in at least one of a first DB or a second DB; accessing the target URL and capturing a first webpage screen based on determining that the target URL is not included in at least one of the first DB or the second DB; storing information related to the target URL via the first webpage screen in a result DB; and, based on determining that the target URL is not identified as being associated with a phishing site based on the multiple types of data, inputting the multiple types of data into a first artificial intelligence model to obtain information related to the target URL and storing the information related to the target URL in the result DB.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] This disclosure relates to techniques for detecting phishing sites, and more particularly to methods and apparatus for detecting uniform resource locators (URLs) associated with phishing sites using artificial intelligence algorithms. [Background technology]

[0002] Phishing refers to a cybercrime that illegally collects and uses personal and financial information through spoofed financial websites (fake financial websites) or spoofed emails (fake emails). With the remarkable development of information and communication technology in recent years, phishing methods have become increasingly sophisticated, resulting in exponentially increasing damage. Various technologies have been developed and implemented to prevent such phishing.

[0003] Previously, technology was introduced that would recognize specific words contained in a phishing email (phishing SMS) and detect phishing attempts via a server connected via a communications network, notifying the parties involved in the call.

[0004] However, not only are victims' responses to phishing emails inconsistent, but the structure of phishing emails is becoming increasingly sophisticated, meaning that conventional technologies are unable to adequately detect and report phishing attempts. Summary of the Invention [Problem to be solved by the invention]

[0005] This disclosure has been created to solve the above-mentioned inconveniences, and the purpose of this disclosure is to provide a method and apparatus for detecting URLs associated with phishing sites using an artificial intelligence algorithm.

[0006] The objects of this disclosure are not limited to the objects mentioned above, and other unmentioned objects and advantages of the present invention can be understood from the following description and will become more apparent from the embodiments of this disclosure. Furthermore, it will be easily understood that the objects and advantages of this disclosure can be realized by the means and combinations thereof set forth in the claims. [Means for solving the problem]

[0007] According to one embodiment of the present disclosure, a device performs a uniform resource locator (URL) search associated with a phishing site. A method for detecting a phishing site (a phishing site locator) may include the steps of: performing a preprocessing operation on a first URL included in a text message to obtain a target URL associated with the first URL; verifying whether the target URL is included in at least one of a first database (DB) storing information about a plurality of phishing sites or a second DB storing information about a plurality of non-phishing sites; accessing the target URL and capturing a first webpage screen corresponding to the target URL based on the verification that the target URL is not included in at least one of the first DB and the second DB; storing information related to the target URL in a result DB based on whether it is determined that the target URL is associated with a phishing site based on the plurality of type data acquired through the first webpage screen; and inputting the plurality of type data into a first artificial intelligence model to obtain information related to the target URL and storing the information related to the target URL in the result DB based on the verification that the target URL is not associated with a phishing site based on the plurality of type data.

[0008] In addition, the preprocessing operation for the first URL may include an operation of removing spaces included in the first URL, an operation of converting at least one special character included in the first URL to a normal character, an operation of converting lowercase letters included in the first URL to uppercase letters, an operation of removing subordinate directory information from the first URL, and an operation of obtaining redirect information linked to the first URL.

[0009] Furthermore, the multiple types of data may include character strings, scripts, comments, and image data extracted from the first web page screen, and based on the existence of specific data among the data for multiple sites stored in the similarity DB whose similarity with the character strings and image data extracted from the first web page screen exceeds a threshold, it may be identified whether the target URL is linked to a phishing site based on i) the scripts and comments included in a specific site corresponding to the specific data, and ii) the scripts and comments extracted from the first web page screen.

[0010] Furthermore, a character string on the first web page screen may be extracted by performing optical character recognition (OCR) on the first web page screen, and if the character string is not associated with the script, the comment, or the image data, the target URL may be identified as being associated with a phishing site.

[0011] Furthermore, if there is no specific data in the similarity DB whose similarity exceeds the threshold, it is determined that it has not been identified whether the target URL is linked to a phishing site based on the multiple types of data, and the artificial intelligence model may be trained to output information related to the target URL including at least one of the type of site corresponding to the target URL, the probability that the target URL is linked to a phishing site, and a description of the site corresponding to the target URL output based on the first webpage based on the multiple types of data.

[0012] Furthermore, based on the text message being input from an application that executes a method for detecting URLs associated with the phishing site or a chat room associated with the application, information related to the target URL may be transmitted via a control UI (user interface) of the device or the chat room, and based on the target URL being associated with the phishing site, connection to the target URL may be blocked.

[0013] Furthermore, the step of storing information related to the target URL in the result DB may further include the steps of: generating a first block based on a first hash value corresponding to the information related to the target URL; acquiring information indicating differences between the first website screen and the second website screen based on a change of the website screen corresponding to the target URL from the first website screen to a second website screen; generating a second block based on a second hash value corresponding to the acquired information indicating differences; and linking the second block to the first block to store a blockchain related to the target URL in the result DB.

[0014] According to one embodiment of the present disclosure, an apparatus for detecting a uniform resource locator (URL) associated with a phishing site includes one or more memories; and one or more processors, wherein the one or more processors may be configured to: perform a preprocessing operation on a first URL included in a text message to obtain a target URL associated with the first URL; check whether the target URL is included in at least one of a first database (DB) storing information about a plurality of phishing sites or a second DB storing information about a plurality of non-phishing sites; access the target URL and capture a first webpage screen corresponding to the target URL based on the determination that the target URL is not included in at least one of the first DB and the second DB; store information related to the target URL in a result DB based on the determination that the target URL is not included in at least one of the first DB and the second DB; and input the data of the plurality of types into a first artificial intelligence model to obtain information related to the target URL and store the information related to the target URL in the result DB based on the determination that the target URL is not included in at least one of the first DB and the second DB.

[0015] The one or more processors may also be configured to: generate a first block based on a first hash value corresponding to information related to the target URL; acquire information indicating differences between the first website screen and the second website screen based on a change of the website screen corresponding to the target URL from the first website screen to a second website screen; generate a second block based on a second hash value corresponding to the acquired information indicating differences; link the second block to the first block, and store a blockchain related to the target URL in the result DB.

[0016] The above solutions to the problems are not intended to be exhaustive. Various features of the present disclosure and their attendant advantages and benefits will be better understood with reference to the following specific embodiments. [Effects of the Invention]

[0017] Various embodiments of this disclosure enable methods and apparatus to be provided that use artificial intelligence algorithms to detect URLs associated with phishing sites.

[0018] Various embodiments of this disclosure enable more efficient detection of phishing sites by detecting whether a website is a phishing site based on the content of the website associated with the URL, rather than simply detecting specific characters contained in a text message.

[0019] The effects of this disclosure are not limited to the effects mentioned above, and other effects not mentioned will be clearly understood by those skilled in the art from the following description. [Brief explanation of the drawings]

[0020] [Figure 1]FIG. 1 is a block diagram illustrating a configuration of a device for detecting a URL associated with a phishing site according to an embodiment of the present disclosure. [Figure 2] FIG. 1 is a flow chart illustrating a method for detecting a URL associated with a phishing site according to an embodiment of the present disclosure. [Figure 3] FIG. 10 is a diagram for explaining a method for identifying whether a target URL is associated with a phishing site based on a similarity DB according to an embodiment of the present disclosure. [Figure 4a] 10A and 10B are diagrams for explaining examples of information related to a target URL and a result DB according to an embodiment of the present disclosure. [Figure 4b] 10A and 10B are diagrams for explaining examples of information related to a target URL and a result DB according to an embodiment of the present disclosure. [Figure 4c] 10A and 10B are diagrams for explaining examples of information related to a target URL and a result DB according to an embodiment of the present disclosure. [Figure 5a] FIG. 10 is a diagram illustrating a process for outputting information related to a target URL according to an embodiment of the present disclosure. [Figure 5b] FIG. 10 is a diagram illustrating a process for outputting information related to a target URL according to an embodiment of the present disclosure. [Figure 5c] FIG. 10 is a diagram illustrating a process for outputting information related to a target URL according to an embodiment of the present disclosure. [Figure 5d] FIG. 10 is a diagram illustrating a process for outputting information related to a target URL according to an embodiment of the present disclosure. DETAILED DESCRIPTION OF THE INVENTION

[0021] The advantages and features of the present disclosure, as well as methods for achieving them, will become more apparent from the following detailed description of the embodiments in conjunction with the accompanying drawings. However, the present disclosure is not limited to the embodiments disclosed below, and can be embodied in various different forms. These embodiments are provided solely to complete the disclosure of the present disclosure and to fully convey the scope of the disclosure to those skilled in the art. The present disclosure is only defined by the scope of the claims.

[0022] The terms used in this specification are merely used to describe the embodiments and are not intended to limit the disclosure. In this specification, singular expressions include plural expressions unless the context clearly dictates otherwise. As used in this specification, the terms "comprises" and / or "comprising" do not exclude the presence or addition of one or more other elements in addition to the elements mentioned.

[0023] Throughout this specification, the same reference numerals refer to the same elements, and the term "and / or" includes each of the elements and any combination of one or more of the elements. Although terms such as "first," "second," and the like may be used to describe various elements, it should be understood that these elements are not limited by these terms. These terms are used merely to distinguish one element from another. Therefore, it should be understood that a first element referred to below may also be a second element within the technical spirit of this disclosure.

[0024] Unless otherwise specified herein or clearly contradicted by the context, all terms used herein, including technical and scientific terms, may be used in the same manner as commonly understood by a person of ordinary skill in the art to which this disclosure pertains. In addition, commonly used and dictionary-defined terms are not to be construed as idealized or overly formal unless expressly defined in this application.

[0025] Spatially relative terms such as "below," "beneath," "lower," "above," "upper," etc., may be used to easily describe the relationship of one component to another, as shown. Spatially relative terms should be understood to include different orientations of components in use or operation in addition to the orientations shown in the figures.

[0026] For example, if the illustrated components are turned over, a component described as "below" or "beneath" another component may then be positioned "above" the other component. Thus, the exemplary terms "below" or "under" can encompass an orientation of below and above. Components may be oriented in other directions, and thus spatially relative terms may be interpreted accordingly.

[0027] A method and apparatus for detecting a uniform resource locator (URL) associated with a phishing site will be described below with reference to the accompanying drawings.

[0028] 1 is a block diagram illustrating the configuration of a device for detecting URLs associated with phishing sites according to an embodiment of the present disclosure. The devices illustrated in FIG. 1 include, but are not limited to, smartphones, tablet PCs, wearable devices, and laptop computers.

[0029] 1, the device 100 may include a memory 110, a communication module 120, a display 130, and a processor 140. However, this disclosure is not limited thereto, and the software and hardware configuration of the device 100 may be modified / added / omitted within a scope obvious to a person skilled in the art depending on the required operation.

[0030] The memory 110 can store data supporting various functions of the device 100 and programs for the operation of the control unit, can store input / output data (e.g., various databases (DBs), information related to input URLs, etc.), can store a number of application programs (or applications) run by the device, and data and commands for the operation of the device. At least some of these application programs can be downloaded from an external device via wireless communication.

[0031] Such memory 110 may include at least one type of storage medium selected from the group consisting of a flash memory type, a hard disk type, a solid state disk type, a solid disk drive type (SDD), a multimedia card micro type, a card-type memory (e.g., SD or XD memory), a random access memory (RAM), a static random access memory (SRAM), a read-only memory (ROM), an electrically erasable programmable read-only memory (EEPROM), a programmable read-only memory (PROM), a magnetic memory, a magnetic disk, and an optical disk. Furthermore, the memory 110 may be a database separate from the device but connected by wire or wirelessly.

[0032] The communication module 120 may include one or more components that enable communication with external devices. For example, the communication module 120 may include at least one of a wireless communication module, a wired communication module, or a location information module.

[0033] For example, the communication module 120 can receive, from another device, information about a plurality of URLs that have been checked for phishing sites and the results of checking the URLs for phishing sites.

[0034] Here, examples of wireless communication modules include Wi-Fi modules, WiBro (Wireless Broadband) modules, as well as wireless communication modules that support a wide variety of wireless communication methods, such as Global System for Mobile Communication (GSM), Code Division Multiple Access (CDMA), Wideband Code Division Multiple Access (WCDMA), Universal Mobile Telecommunications System (UMTS), Time Division Multiple Access (TDMA), Long Term Evolution (LTE), 4G (Fourth Generation Mobile Communication System), 5G (Fifth Generation Mobile Communication System), and 6G (Sixth Generation Mobile Communication System).

[0035] Display 130 displays (outputs) information (e.g., information related to a URL included in a text message) processed by device 100. For example, the display can display start-up screen information of an application program (for example, an application) run on device 100, or user interface (UI) or graphic user interface (GUI) information based on such start-up screen information.

[0036] The processor 140 may be implemented by a memory that stores data related to an algorithm or a program that reproduces the algorithm for controlling the operation of the components in the device 100, and at least one processor (not shown) that performs the above-described operations using the data stored in the memory. In this case, the memory and the processor may be implemented as separate chips, or the memory and the processor may be implemented as a single chip.

[0037] That is, the processor 140 can control the overall operation and functionality of the device by controlling the components within the device 100. The processor can control any one or more of the above-mentioned components in combination to implement various embodiments of this disclosure on the device, as illustrated in the following figures.

[0038] 2 is a flow diagram illustrating a method for detecting URLs associated with phishing sites according to one embodiment of the present disclosure. The operation of the device illustrated in FIG. 2 can be performed via an application and / or website related to the method by which the device detects URLs associated with phishing sites.

[0039] Additionally or alternatively, the device may perform the operations described in FIG. 2 using a server that stores a database for detecting URLs associated with phishing sites.

[0040] The device may perform a pre-processing operation on a first URL included in the text message to obtain a target URL associated with the first URL (S210).

[0041] Here, text messages encompass short mail (SMS (short message for mobile phones)), messages transmitted via instant messaging applications, messages transmitted via quick panels and / or pop-up windows, etc. However, this is merely one embodiment, and text messages may encompass messages entered / transmitted via various media.

[0042] The device may detect and extract a first URL contained in the text message and perform a preprocessing operation on the first URL.

[0043] For example, the preprocessing operation for the first URL may include an operation of removing spaces contained in the first URL, an operation of converting at least one special character contained in the first URL to a common character, an operation of converting lowercase letters contained in the first URL to uppercase letters, an operation of removing subordinate directory information from the first URL, and an operation of obtaining redirect information linked to the first URL.

[0044] Specifically, first, the device can perform space processing on special characters such as a line feed character and a TAB character included in the first URL. The device can convert a specific character included in the first URL into a character with a similar shape (for example, converting "(" to "C")). The device can also convert predefined special characters (for example, " TIFF0007742193000001.tif66" to "R") can be converted to general characters.

[0045] In addition, the device may extract only the pure URL portion from the first URL, excluding any subordinate directories. The device may convert uppercase letters included in the extracted URL portion to lowercase. The device may request head information for the extracted URL portion. For example, if 'Status_code' is 200, the device may obtain the target URL redirected from the first URL through 'Response.headers[Location]' information. In other words, the target URL refers to the actual URL that can be connected by entering / selecting the first URL.

[0046] Additionally or alternatively, the device can automatically recognize malicious code cases using scripts uploaded to specific sites and obtain target URLs.

[0047] For example, if the first URL is "www.abcd.com?redirect=www.defg.com", the device can automatically recognize the malicious code case and identify that the target URL corresponding to the first URL is "www.defg.com".

[0048] The device can check whether the target URL is included in at least one of a first DB that stores information about multiple phishing sites or a second DB (e.g., a white DB) that stores information about multiple non-phishing sites (S220).

[0049] Here, the first DB may include a list of multiple phishing sites, at least one URL associated with the phishing site, etc. If the target URL obtained by performing a preprocessing operation on the first URL is included in the first DB, the device can determine that the first URL is associated with the phishing site.

[0050] For example, if a URL obtained by converting special characters contained in the first URL into ordinary characters is included in the first DB, the device can determine that the first URL is associated with a phishing site. The device can determine whether the first URL is associated with a phishing site by determining whether the URL obtained each time a preprocessing operation is performed is included in the first DB.

[0051] The second DB may include a list of multiple non-phishing sites, at least one URL associated with the non-phishing site, etc. If the target URL obtained by performing a preprocessing operation on the first URL is included in the second DB, the device can determine that the first URL is not associated with a phishing site.

[0052] The device can determine whether the first URL is associated with a phishing site by determining whether the acquired URL is included in the second DB each time the preprocessing operation is performed.

[0053] Based on confirming that the target URL is not included in at least one of the first DB or the second DB, the device can access the target URL and then capture a first webpage screen corresponding to the target URL (S230).

[0054] That is, the device can obtain the first web page screen by connecting to the finally obtained target URL address. Additionally or alternatively, the device can obtain domain name system (DNS) information of the target URL.

[0055] The device can extract and obtain multiple types of data (eg, tags, scripts, general text, comments, image data, etc.) from the first web page screen.

[0056] Here, if the script included in the first web page screen is obfuscated / encrypted, the device may decrypt the script. Additionally or alternatively, the device may obtain information about the script by applying an algorithm, such as a JavaScript emulator, to the script included in the first web page screen.

[0057] The device can identify whether the target URL is associated with a phishing site based on the multiple types of data acquired through the first web page screen (S240).

[0058] As an example of this disclosure, based on identifying whether the target URL is associated with a phishing site based on multiple types of data obtained via the first web page screen, the device can store information related to the target URL in a result DB (S250-Y).

[0059] Here, the information related to the target URL may include a text message containing the target URL, a type of site corresponding to the target URL, image data of a website screen corresponding to the target URL, a probability that the target URL is linked to a phishing site, a description of the site corresponding to the target URL output based on the first webpage, etc.

[0060] The similarity DB refers to a database that stores tags, scripts, general text, comments, and image data related to multiple URL addresses. The device can obtain similarities between multiple types of data extracted from the first website screen and data stored in the similarity DB. The device can identify whether a specific URL is associated with a phishing site by using specific data from the similarity DB whose similarity exceeds a threshold.

[0061] Based on the existence of specific data among the data for multiple sites stored in the similarity DB whose similarity with the string and image data extracted from the first web page screen exceeds a threshold value, the device can identify whether the target URL is linked to a phishing site based on i) the scripts and comments contained in the specific site corresponding to the specific data, and ii) the scripts and comments extracted from the first web page screen.

[0062] The process by which the device uses the similarity DB to identify whether the target URL is associated with a phishing site based on multiple types of data will be described in detail with reference to FIG.

[0063] In another example of this disclosure, based on the fact that it is not possible to identify whether the target URL is associated with a phishing site based on multiple types of data, the device can input the multiple types of data into a first artificial intelligence model to obtain information related to the target URL, and store the information related to the target URL in a result DB (S250-N).

[0064] Here, the inability to identify whether the target URL is associated with a phishing site based on the multiple types of data may mean that there is no data associated with the multiple types of data in the similarity DB. If information related to the target URL cannot be obtained through the similarity DB, the device can input the multiple types of data into the first artificial intelligence model to obtain information related to the target URL.

[0065] Here, the first artificial intelligence model may be trained to output at least one of the following based on multiple types of data: a type of site corresponding to the target URL, a probability that the target URL is linked to a phishing site, and a description of the site corresponding to the target URL output based on the first web page.

[0066] By way of example, the first artificial intelligence model may include one or more neural networks for performing generative artificial intelligence operations, although this disclosure is not limited in any way thereto.

[0067] The device can build a result DB based on information related to the target URL. Types of data built in the result DB will be described in detail with reference to Figures 4a to 4c.

[0068] As a further example of this disclosure, if the string extracted via OCR differs from the text, script, comments, and image data extracted from the first website, it can be considered that additional string has been inserted on top of the first website screen to deceive the user.

[0069] In this way, the device can extract character strings on the first webpage screen as one of a plurality of types of data by performing optical character recognition (OCR) on the first webpage screen. If the character strings extracted from the first webpage screen are not associated with the scripts, comments, and image data extracted from the first website, the device can identify the target URL as being associated with a phishing site.

[0070] In a further example of this disclosure, based on a text message being input from an application that executes a method for detecting URLs associated with phishing sites or a chat room associated with the application, the device can transmit information regarding the target URL via a control user interface (UI) (e.g., a quick panel) or chat room of the device, and if the target URL is identified as being associated with a phishing site, the device can block the connection to the target URL.

[0071] As a further example of this disclosure, the device may build a result database based on blockchain, which allows for more secure and efficient storage and management of URL information associated with phishing sites.

[0072] Specifically, the device can generate a first block based on a first hash value corresponding to information related to the target URL, where the block refers to a bundle of valid information, and can include a block hash value that serves as a block identifier, a previous block hash value, a Merkle root, transaction information, etc.

[0073] The device may monitor whether a website screen corresponding to the target URL is changed to another screen. Based on the change from a first website screen to a second website screen (i.e., the configuration of the first website screen is changed, etc.), the device may acquire information indicating differences between the first website screen and the second website screen. The device may generate a second block based on a second hash value corresponding to the acquired information indicating the identified differences. The device may link the second block to the first block and store a blockchain related to the target URL in a result DB.

[0074] FIG. 3 is a diagram for explaining a method for identifying whether a target URL is associated with a phishing site based on a similarity DB according to an embodiment of the present disclosure.

[0075] The device can identify whether or not there is a character string stored in the similarity DB whose similarity to the character string extracted from the first web page screen exceeds a first threshold value (S310).

[0076] Specifically, the device can acquire an SSDEEP hash value for a character string extracted from a first web page screen. The device can acquire a similarity between the SSDEEP hash value for the acquired character string and SSDEEP hash values ​​for multiple character strings stored in the similarity DB. This allows the device to identify whether or not there is a character string stored in the similarity DB whose similarity to the character string extracted from the first web page screen exceeds a first threshold.

[0077] If the similarity DB does not contain a character string whose similarity to the character string extracted from the first webpage screen exceeds a first threshold, the device can determine that the target URL has not been identified as being associated with a phishing site based on the multiple types of data. The device can also input the multiple types of data into a first artificial intelligence model.

[0078] Assume that the similarity DB contains a character string whose similarity to the character string extracted from the first web page screen exceeds a first threshold value. In this case, the device can identify whether or not there is an image stored in the similarity DB whose similarity to the image extracted from the first web page screen exceeds a second threshold value (S320).

[0079] The device can acquire a hash value for an image extracted from the first web page screen. The device can acquire a similarity between the hash value for the acquired image and hash values ​​for multiple images stored in the similarity DB. This allows the device to identify whether or not there is an image stored in the similarity DB whose similarity to the image extracted from the first web page screen exceeds a second threshold.

[0080] If the similarity DB does not contain any image whose similarity to the image extracted from the first webpage screen exceeds the second threshold, the device can determine that the target URL has not been identified as being associated with a phishing site based on the multiple types of data. The device can also input the multiple types of data into the first artificial intelligence model.

[0081] Assume that a specific character string and a specific image exist in the image DB whose similarity to the character string and image extracted from the first web page screen exceeds a threshold value. The device can identify scripts and comments included in a specific site associated with the specific character string and the specific image.

[0082] The device may identify whether the similarity between the script and comments extracted from the first web page screen and the script and comments included in the specific site exceeds a third threshold (S330).

[0083] If the similarity between the script and comments extracted from the first webpage screen and the script and comments contained in the particular site does not exceed a third threshold, the device can identify the target URL as associated with a phishing site.

[0084] Assume that the similarity between the script and comment extracted from the first webpage screen and the script and comment included in the specific site exceeds a third threshold value, in which case the device can check whether the IP country information of the site associated with the target URL matches the IP country information of the specific site and whether the domain of the site associated with the target URL is one year old (S340).

[0085] If the IP country information of the site associated with the target URL matches the IP country information of the specific site, and the domain of the site associated with the target URL is one year old, the device can identify the site associated with the target URL as a normal site.

[0086] If the IP country information of the site associated with the target URL does not match the IP country information of the particular site, or if the domain of the site associated with the target URL is less than one year old, the device can identify the target URL as being associated with a phishing site.

[0087] Additionally or alternatively, the procedures and operations described with reference to FIG. 3 may be performed via a second AI model.

[0088] Specifically, when text, images, scripts, and comments extracted from a first webpage screen are input as input data, the second AI model can be trained to output information regarding whether the input data (i.e., multiple types of data) should be input to the first AI model or whether the target URL is associated with a legitimate / phishing site. That is, the second AI model can be trained to perform the operations of steps S310 to S340 based on the above-described input data.

[0089] 4a to 4c are diagrams illustrating examples of information related to a target URL and a result DB according to one embodiment of the present disclosure.

[0090] 4A illustrates an example of information related to a target URL output by the device, which may include the content of a text message containing the first URL, the target URL, output data of the first AI model (if data is input to the first AI model), DNS information associated with the target URL, and the type of site associated with the target URL.

[0091] FIG. 4b illustrates an example of a result DB constructed based on information related to the target URL.

[0092] For example, the result DB may include the ID of the information related to the target URL, the content of the text message containing the first URL, the target URL, the output data of the first artificial intelligence model (if data is input into the first artificial intelligence model), the IP address of the user (i.e., the device), DNS information associated with the target URL, and the type of query entered that is associated with the target URL.

[0093] FIG. 4c illustrates information related to the target URL stored in the similarity DB or the like.

[0094] For example, information related to the target URL stored in a similarity database or the like may include the target URL, the IP address actually connected when connecting to the target URL, information about the country in which the IP address is located, a value obtained by extracting only the JavaScript portion from the HTML code downloaded when connecting to the target URL and storing the SSDEEP hash, a value obtained by separately extracting only the displayed character string portion from the HTML code downloaded when connecting to the target URL and storing the SSDEEP hash, a value obtained by separately extracting only the annotation portion in the source code from the HTML code downloaded when connecting to the target URL and storing the SSDEEP hash, a value obtained by storing an image hash for the image to measure the similarity of the image captured when connecting to the target URL, and a hash value for the character string extracted from the captured image.

[0095] 5a to 5d are diagrams illustrating a process of outputting information related to a target URL according to one embodiment of the present disclosure.

[0096] In one example of this disclosure, as shown in Figure 5a, a text message 510 containing a first URL may be copied and then entered into a chat room associated with an application that executes a method for detecting URLs associated with phishing sites. The device may obtain information related to a target URL corresponding to the first URL according to the scheme described in Figures 1 to 4c, and output information 520 through the chat room that allows access to the obtained information related to the target URL.

[0097] In another example of the present disclosure, as shown in FIG. 5b, a first URL may be entered into an input window 530-1 on an application that executes a method for detecting URLs associated with phishing sites. The device may then display, in any area of ​​the application, a list 530-2 of URLs that have been checked on other devices to determine whether they are associated with phishing sites. By selecting one of the URLs included in the list 530-2, the device may provide the results of checking the selected URL.

[0098] The device can obtain information related to a target URL corresponding to the first URL according to the methods described in Figures 1 to 4c. For example, as shown in Figure 5c, the device can output information 540 through a control UI (e.g., a quick panel) 540 that allows access to the obtained information related to the target URL.

[0099] As yet another example, as shown in FIG. 5d, information related to the acquired target URL (e.g., information indicating whether the target URL is associated with a phishing site, the first website screen of the target URL, etc.) can be output via a separate application screen 550.

[0100] The embodiments and accompanying drawings described in this disclosure merely exemplify some of the technical ideas incorporated in this disclosure. Therefore, it is clear that the embodiments disclosed in this specification are intended to explain, not to limit, the technical ideas of this disclosure, and therefore do not limit the scope of the technical ideas of the present invention.

[0101] All modified embodiments and specific embodiments that can be easily inferred by a person skilled in the art within the scope of the technical ideas contained in the specification and drawings of this disclosure should be construed as being included in the scope of rights of this disclosure. [Explanation of symbols]

[0102] 100 devices 110 memory 120 Communication Module 130 Display

Claims

1. A method for detecting a uniform resource locator (URL) associated with a phishing site, the method being performed by a device, the method comprising: performing a pre-processing operation on a first URL included in a text message to obtain a target URL associated with the first URL; determining whether the target URL is included in at least one of a first database (DB) storing information about a plurality of phishing sites and a second database storing information about a plurality of non-phishing sites; based on confirmation that the target URL is not included in at least one of the first DB and the second DB, accessing the target URL and then capturing a first web page screen corresponding to the target URL; storing information related to the target URL in a result DB based on whether the target URL is associated with a phishing site based on the plurality of types of data acquired via the first web page screen; inputting the plurality of types of data into a first artificial intelligence model to obtain information related to the target URL based on the fact that it is not possible to identify whether the target URL is associated with a phishing site based on the plurality of types of data, and storing the information related to the target URL in the result DB; Including, The step of storing information related to the target URL in the result DB includes: generating a first block based on a first hash value corresponding to information related to the target URL; obtaining information indicating differences between the first website screen and the second website screen based on the website screen corresponding to the target URL being changed from the first website screen to a second website screen; generating a second block based on a second hash value corresponding to the obtained information indicating the difference; Attaching the second block to the first block and storing a blockchain related to the target URL in the result DB; The method further comprises:

2. The preprocessing operation for the first URL includes:

2. The method of claim 1, further comprising the steps of: removing spaces from the first URL; converting at least one special character from the first URL to a common character; converting lowercase characters from the first URL to uppercase characters; removing subordinate directory information from the first URL; and obtaining redirect information linked to the first URL.

3. The plurality of types of data are The extracted text includes a character string, a script, a comment, and image data from the first web page screen; The method of claim 1, wherein, based on the presence of specific data among the data for each of a plurality of sites stored in a similarity DB, whose similarity with the character string and image data extracted from the first web page screen exceeds a threshold, it is identified whether the target URL is linked to a phishing site based on i) scripts and comments contained in a specific site corresponding to the specific data, and ii) scripts and comments extracted from the first web page screen.

4. extracting character strings on the first web page screen by performing optical character recognition (OCR) on the first web page screen; The method of claim 3 , wherein the target URL is identified as being associated with a phishing site if the string is not associated with the script, the comment, and the image data.

5. If the similarity DB does not contain specific data whose similarity exceeds the threshold value, it is determined that whether or not the target URL is associated with a phishing site has not been identified based on the multiple types of data, 4. The method of claim 3, wherein the artificial intelligence model is trained to output information related to the target URL, the information including at least one of a type of site corresponding to the target URL based on the plurality of types of data, a probability that the target URL is associated with a phishing site, and a description of the site corresponding to the target URL output based on the first web page.

6. information related to the target URL is transmitted via a control user interface (UI) of the device or a chat room based on the text message being input from an application that executes a method for detecting a URL associated with the phishing site or a chat room associated with the application; The method of claim 1 , wherein a connection to the target URL is blocked based on the target URL being associated with a phishing site.

7. An apparatus for detecting a uniform resource locator (URL) associated with a phishing site, the apparatus comprising: one or more memories; one or more processors; Equipped with The one or more processors: performing a pre-processing operation on a first URL included in a text message to obtain a target URL associated with the first URL; determining whether the target URL is included in at least one of a first database (DB) storing information about a plurality of phishing sites and a second database storing information about a plurality of non-phishing sites; based on confirmation that the target URL is not included in at least one of the first DB and the second DB, accessing the target URL and then capturing a first web page screen corresponding to the target URL; storing information related to the target URL in a result DB based on whether the target URL is associated with a phishing site based on the plurality of types of data acquired via the first web page screen; based on the plurality of types of data, whether or not the target URL is associated with a phishing site cannot be identified, the plurality of types of data is input into a first artificial intelligence model to obtain information related to the target URL, and the information related to the target URL is stored in the result DB; generating a first block based on a first hash value corresponding to information related to the target URL; When the website screen corresponding to the target URL is changed from the first website screen to a second website screen, information indicating a difference between the first website screen and the second website screen is obtained; generating a second block based on a second hash value corresponding to the acquired information indicating the difference; The apparatus is configured to chain the second block to the first block and store a blockchain associated with the target URL in the results DB.

8. The preprocessing operation for the first URL includes:

8. The apparatus of claim 7, further comprising: an operation of removing spaces included in the first URL; an operation of converting at least one special character included in the first URL to a common character; an operation of converting lowercase letters included in the first URL to uppercase letters; an operation of removing subordinate directory information from the first URL; and an operation of obtaining redirect information linked to the first URL.

9. The plurality of types of data are The extracted text, script, comment, and image data are included in the first web page screen. The device of claim 8, wherein, based on the presence of specific data among the data for each of a plurality of sites stored in a similarity DB, whose similarity with the character string and image data extracted from the first web page screen exceeds a threshold, it is identified whether the target URL is linked to a phishing site based on i) scripts and comments contained in a specific site corresponding to the specific data, and ii) scripts and comments extracted from the first web page screen.

10. extracting character strings on the first web page screen by performing optical character recognition (OCR) on the first web page screen; The apparatus of claim 9 , wherein the target URL is identified as being associated with a phishing site if the string is not associated with the script, the comment, and the image data.

11. If the similarity DB does not contain specific data whose similarity exceeds the threshold value, it is determined that whether or not the target URL is associated with a phishing site has not been identified based on the multiple types of data, 10. The device of claim 9, wherein the artificial intelligence model is trained to output information related to the target URL, the information including at least one of a type of site corresponding to the target URL, a probability that the target URL is associated with a phishing site, and a description of the site corresponding to the target URL output based on the first web page, based on the plurality of types of data.

12. information related to the target URL is transmitted via a control user interface (UI) of the device or a chat room based on the text message being input from an application that executes a method for detecting a URL associated with the phishing site or a chat room associated with the application; The apparatus of claim 7 , wherein the connection to the target URL is blocked based on the target URL being associated with a phishing site.

Citation Information

Patent Citations

  • Phishing Campaign Detection

    JP2022532600A

  • Metadata-based phishing attack detection and prevention

    JP2023522530A

  • Malicious domain hosting type classification system and method

    JP2023525653A

  • Apparatus and method for protecting access to phishing site

    US20070233643A1

  • System and method of analyzing web addresses

    US20080133540A1