Method for real-time phishing response and system thereof

KR1020260122741APending Publication Date: 2026-08-12THINKPOOL
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
KR · KR
Patent Type
Applications
Current Assignee / Owner
Filing Date
2025-03-06
Publication Date
2026-08-12

Smart Images

  • Figure PAT00003_ABST
    Figure PAT00003_ABST
Patent Text Reader

Abstract

A real-time phishing response method and system are disclosed. The above real-time phishing response method includes a step in which a system acquires the content of a conversation between conversation participants; a step in which the system analyzes the acquired content of the conversation to determine whether phishing has occurred; and a step in which, if the system determines as a result of the determination that there is a possibility of phishing, the system induces the target to express response information for phishing confirmation.
Need to check novelty before this filing date? Find Prior Art

Description

Technology Field

[0001] The present invention relates to a method and system for responding to digital fraud, such as real-time voice phishing.

[0002] More specifically, the invention relates to a technical concept that enables real-time response to digital fraud, such as voice phishing, during communication processes, such as phone calls or chats, through pre-set response information (password, body movements, etc.) between a target of phishing and a person who has a certain relationship (e.g., family relationship, friend relationship, acquaintance relationship, etc.) with said target. Background Technology

[0003] Crimes involving digital fraud, such as voice phishing (digital fraud involves committing fraud using various means of communication, such as phone calls, chatting, and messengers, with voice phishing using phone calls being a representative method. Since digital fraud utilizes similar methods and aims for the same purpose despite differences in means, the following explanation will focus on 'voice phishing.' It can be easily inferred by an average expert in the technical field of this invention that the technical concept of this invention can be implemented in various ways through chatting, messengers, etc.), are becoming increasingly sophisticated, and the scale of damage is also gradually growing. Voice phishing crimes target not only the elderly and infirm but are carried out in various ways; as they primarily exploit the fear and urgency of victims to inflict financial losses, the suffering of the victims is immense.

[0004] Generally, technical concepts for preventing voice phishing crimes include methods to determine whether a call is voice phishing by utilizing the caller's number or location. Additionally, methods for analyzing conversation patterns used in voice phishing have also been announced.

[0005] However, these conventional methods are insufficient to prevent voice phishing crimes that are continuously evolving and becoming more sophisticated. In particular, when phishing criminals feign urgency during a call, victims are inevitably bound to fall for them.

[0006] Therefore, a technical concept is required that determines the possibility of phishing, artificially makes the target aware of the potential for phishing crime, and simultaneously responds to phishing crimes in real time using phishing confirmation messages and / or equivalent response information, such as passwords known only between the target and relevant parties.

[0007] In addition, a technical concept is required that enables real-time notification of call information to relevant crime prevention agencies (e.g., the National Police Agency) during a call to assist in the apprehension of criminals. Prior art literature

[0008] - Korean Registered Patent (Registration No. 10-2711745, "Method and System for Detecting Voice Phishing Using Artificial Intelligence Technology") - Korean Registered Patent (Registration No. 10-1731545, "System and Method for Alerting Voice Phishing Risk During a Call") The problem to be solved

[0009] The technical problem that the present invention aims to solve is to provide a technical concept that prevents being deceived by phishing crimes by not only determining the possibility of phishing in real time during a conversation (including various digital communication means such as chatting and messengers as well as phone calls) and warning the subject of the possibility of phishing, but also inducing the expression of a phishing confirmation message during the conversation (speech in the case of a phone call, text or voice input in the case of chatting / messenger) based on information known only between the subject and the relevant parties (pre-set password, physical signal, or specific information known only to the parties, etc.), and enabling countermeasures to be taken based on the response.

[0010] In addition, it provides a technical concept that can more effectively prevent being deceived by phishing crimes by allowing phishing confirmation messages to be individually set for each person involved with the target and enabling the target to express the phishing confirmation message based on this.

[0011] In addition, it provides a technical concept that allows the target to identify a relative (e.g., a specific family member) of the target being impersonated by a phishing criminal in real time during a conversation, and enables the target to check the location of the relative during the conversation (while the call is being connected in the case of a phone call, or before the chat window closes in the case of a chat such as a messenger), thereby enabling the target not to be easily deceived even when a phishing criminal impersonates a relative to mislead them. means of solving the problem

[0012] A real-time phishing response method according to the technical concept of the present invention comprises the steps of: a system acquiring the content of a conversation between conversation participants; the system analyzing the acquired content of the conversation to determine whether phishing has occurred; and, if the system determines that there is a possibility of phishing as a result of the determination, the system inducing the target to express response information for phishing confirmation.

[0013] The above real-time phishing response method may further include a step in which the system performs phishing response measures based on whether the response information is expressed by the target.

[0014] The step of the system inducing a subject to express response information for phishing confirmation includes the step of transmitting warning information to the subject's terminal among the conversation participants to cause the subject to express a predetermined phishing confirmation message, or the step of the system expressing a predetermined phishing confirmation message to the subject's terminal during the conversation, and is characterized by performing phishing countermeasures based on whether the response information corresponding to the phishing confirmation message is expressed by the subject.

[0015] The step of performing phishing countermeasures based on whether the above response information is expressed by the target person may include the step of the system receiving from the target person terminal whether response information corresponding to the phishing confirmation message is expressed by the target person.

[0016] The above real-time phishing response method may further include the step of the system receiving and storing the target's phishing confirmation message and the response information from the target's terminal in advance.

[0017] The step of performing phishing countermeasures based on whether response information corresponding to the phishing confirmation message is expressed by the target may include the step of the system determining whether the response information is expressed by the target's terminal within a predetermined time or a predetermined number of words after the phishing confirmation message is expressed by the target's terminal or the system.

[0018] The step of the system receiving and storing the phishing confirmation message and the response information of the subject from the subject's terminal in advance may include the step of the system storing the phishing confirmation message and the response information set for each party according to the relationship with the subject from the subject's terminal.

[0019] The above real-time phishing response method may further include a step of identifying an impersonating party through the conversation when the system determines, based on a judgment result, that there is a possibility of phishing, and may be characterized by the system inducing the target to express the response information corresponding to the identified party.

[0020] The above real-time phishing response method may further include the step of the system verifying the terminal location information of the relevant party and transmitting it to the target's terminal.

[0021] The step of transmitting warning information to the terminal of a target among the above conversational participants so that the target expresses a predetermined phishing confirmation message may include the step of the system transmitting the warning information containing the phishing confirmation message to the target's terminal.

[0022] The step of the system performing phishing countermeasures based on whether response information corresponding to the phishing confirmation message is expressed by the target may include the step of the system transmitting phishing conversation information to a predetermined relevant agency system while the conversation is connected.

[0023] A real-time phishing response method according to another embodiment of the present invention includes the steps of: a system analyzing the content of a conversation between conversation participants to determine whether phishing has occurred; if the system determines that there is a possibility of phishing as a result of the determination, identifying a person impersonating through the conversation; and the system confirming the terminal location information of the identified person and transmitting it to the target's terminal.

[0024] The above method can be implemented by a computer program installed in a data processing device and recorded on a computer-readable recording medium.

[0025] A real-time phishing response system according to an example of the present invention includes a processor and a storage device storing a program, wherein the processor drives the program to acquire the content of a conversation between interlocutors, analyzes the content of the conversation to determine whether phishing has occurred, and if it is determined that there is a possibility of phishing as a result of the determination, induces the target to express response information for phishing confirmation.

[0026] A real-time phishing response system according to another example of the present invention includes a processor and a storage device storing a program. The processor runs the program to analyze the content of a conversation between interlocutors and determines whether phishing has occurred. If the system determines that there is a possibility of phishing, it identifies an official who is impersonating through the conversation, verifies the terminal location information of the identified official, and transmits it to the target's terminal. Effects of the invention

[0027] According to the technical concept of the present invention, it is not limited to merely determining the possibility of phishing in real time during a conversation and warning the subject of the possibility of phishing, but also inducing the expression of a phishing confirmation message during the conversation based on information known only between the subject and the relevant parties, and enabling countermeasures to be taken based on the response, thereby having the effect of preventing being deceived by phishing crimes.

[0028] In addition, phishing confirmation messages can be individually set for each person involved with the target, and by allowing the target to express the phishing confirmation message based on this, it is possible to more effectively prevent them from being deceived by phishing crimes.

[0029] In addition, by identifying the person's associate (e.g., a specific family member) that the phishing criminal is impersonating in real time during the conversation and allowing the target to check the location of such associate during the conversation (e.g., while a phone call is connected), it has the effect of not easily being deceived even when the phishing criminal impersonates an associate to mislead the target. Brief explanation of the drawing

[0030] A brief description of each drawing is provided to help to better understand the drawings cited in the detailed description of the invention. FIG. 1 is a diagram illustrating schematic system configurations for implementing a real-time phishing response method according to the technical concept of the present invention. FIG. 2 is a diagram illustrating the schematic configuration of a real-time phishing response system according to an embodiment of the present invention. FIG. 3 is a diagram showing a flowchart for explaining a real-time phishing response method according to an embodiment of the present invention. FIG. 4 is a diagram illustrating a phishing confirmation message and a corresponding response according to an embodiment of the present invention. FIG. 5 is a diagram illustrating a method to respond to phishing using location information of relevant parties according to an embodiment of the present invention. Specific details for implementing the invention

[0031] The present invention is capable of various modifications and may have various embodiments; specific embodiments are illustrated in the drawings and described in detail in the detailed description. However, this is not intended to limit the present invention to specific embodiments, and it should be understood that it includes all modifications, equivalents, and substitutions that fall within the spirit and scope of the present invention. In describing the present invention, detailed descriptions of related prior art are omitted if it is determined that such detailed descriptions may obscure the essence of the present invention.

[0032] Terms such as "first," "second," etc., may be used to describe various components, but said components shall not be limited by said terms. These terms are used solely for the purpose of distinguishing one component from another.

[0033] The terms used in this application are used merely to describe specific embodiments and are not intended to limit the invention. The singular expression includes the plural expression unless the context clearly indicates otherwise.

[0034] In this specification, terms such as “comprising” or “having” are intended to specify the existence of the features, numbers, steps, actions, components, parts, or combinations thereof described in the specification, and should be understood as not precluding the existence or addition of one or more other features, numbers, steps, actions, components, parts, or combinations thereof.

[0035] Furthermore, in this specification, when one component 'transmits' data to another component, it means that the component may transmit the data directly to the other component or transmit the data to the other component through at least one other component. Conversely, when one component 'transmits' data directly to another component, it means that the data is transmitted from the component to the other component without passing through another component.

[0036] Hereinafter, the present invention will be described in detail with reference to the attached drawings, focusing on embodiments of the invention. Identical reference numerals in each drawing indicate identical components.

[0037] FIG. 1 is a diagram illustrating schematic system configurations for implementing a real-time phishing response method according to the technical concept of the present invention.

[0038] Referring to FIG. 1, in order to implement a real-time phishing response method according to the technical concept of the present invention, a real-time phishing response system (200) can be implemented.

[0039] The above real-time phishing response system (200) can acquire the content of a conversation (e.g., a conversation via phone call / video call or a conversation via chat) performed by a subject using the subject's terminal (100) in accordance with the technical concept of the present invention. To this end, the above real-time phishing response system (200) may communicate with a conversation application (e.g., a phone application, a chat application, etc.) that performs the conversation, and if necessary, may monitor the conversation application in the background or acquire voice signals input into a speaker or microphone, and can acquire the content of the conversation performed through the conversation application in various ways.

[0040] Furthermore, it may refer to a system that determines whether the aforementioned conversation is phishing (e.g., voice phishing or phishing via text, etc.) and, based on the determination result, performs measures to induce the target to express predetermined response information. Additionally, it may refer to a system that performs predetermined countermeasures based on the response information.

[0041] To this end, the real-time phishing response system (200) can finally confirm whether phishing is occurring based on whether the subject can answer with response information (e.g., a secret code set between family or acquaintances, a physical signal, or information known only to family or acquaintances, etc.) in accordance with the technical concept of the present invention. The response information may be information set jointly in a predetermined group (e.g., a family or acquaintance gathering, etc.) or information set 1:1 between the parties. In addition, the response information may be information that is predetermined, or even if it is not predetermined, it may be the correct answer to a question or phishing confirmation message, which is information that the conversation partner, that is, the person being impersonated by phishing (e.g., the subject's son, daughter, etc.), would know if they were the genuine party. The phishing confirmation message may be a message requesting the subject to express (e.g., speech, text input, gesture, etc.) what the predetermined response information is, or a message requesting the expression of information that is not predetermined but would be known if they were the genuine party.

[0042] The above real-time phishing response system (200) can induce the target to express response information (e.g., speech, etc.).

[0043] For example, this may be accomplished by having the subject express a phishing confirmation message requesting the subject to express the above response information, and then having the subject express the above response information as a response to the phishing confirmation message. Then, depending on whether the above response information is correct, the real-time phishing response system (200) may finally confirm whether it is phishing.

[0044] In any case, the real-time phishing response system (200) may enable a phishing confirmation message to be transmitted to the subject so that the subject may express response information. For example, the subject may be able to confirm the phishing confirmation message through voice utterance or text input. To this end, the real-time phishing response system (200) may directly transmit the phishing confirmation message to the subject terminal (300), or, as described above, transmit a predetermined warning information to the subject terminal (100) so that the subject may express the phishing confirmation message. In the case where the above real-time phishing response system (200) directly transmits a phishing confirmation message to the target terminal (300), for example, to implement the technical concept of the present invention, the application installed on the target terminal (100) may generate the phishing confirmation message stored in advance as voice information and transmit it to the target terminal (300) through a call, or the application may be implemented to input the phishing confirmation message as text. To this end, communication may be enabled between the application and a telephone application / chat application installed on the target terminal (100) that can perform a conversation. According to an embodiment, the real-time phishing response system (200) may be implemented to directly generate the phishing confirmation message information through a system (not shown) for a call connection of a mobile communication operator (or a communication connection of a operator that mediates chatting or messenger, etc.) and transmit it to the target terminal (300) (in cases where communication is made via chatting or messenger, it may be transmitted through a mediating means, and the result is the same as the method of transmission to the target terminal (300)). In any case, it is sufficient if the real-time phishing response system (200) can automatically transmit information corresponding to the phishing confirmation message to the target terminal (300) even if the target does not express the phishing confirmation message.

[0045] Of course, according to other embodiments, the real-time phishing response system (200) may induce the target to directly express a phishing confirmation message (e.g., speech or text input), and thereby determine whether phishing has occurred by checking whether appropriate response information is expressed from the target terminal (300).

[0046] The above real-time phishing response system (200) may refer to a system in which a specific hardware and a program (application) for performing functions defined in this specification are organically combined. If necessary, the above real-time phishing response system (200) may be a system in which the program is installed on a specific server, but is not limited thereto. According to an embodiment, the above real-time phishing response system (200) may refer to a system in which a client (application) installed on a target terminal (100) and a server are implemented in a server-client manner, and in such a case, the above real-time phishing response system (200) may refer to a system in which the hardware of the server and the target terminal (100), the client program, and the server program are organically combined.

[0047] According to the embodiment, the real-time phishing response system (200) may be implemented solely by an application installed on the target terminal (100), or it may be implemented by a mobile carrier's system capable of verifying conversation content, or by a service provider's system that provides chatting or messenger services capable of verifying digital communication content. It will be easily inferred by an average expert in the technical field of the present invention that various embodiments are possible regarding which hardware the real-time phishing response system (200) is installed and implemented to realize the technical concept of the present invention.

[0048] In the following specification, the statement that the real-time phishing response system (200) performs a function may include all cases where the application installed on the target terminal (100) performs the function, where the server performs the function, or where the application and the server cooperate to perform the function.

[0049] The above real-time phishing response system (200) can determine whether phishing has occurred by analyzing the conversation between the target terminal (300) and the target terminal (100). To this end, the above real-time phishing response system (200) can analyze the conversation between the target terminal (300) and the target terminal (100).

[0050] According to one embodiment, when the conversation is conducted via telephone, voice information corresponding to the telephone call may be converted into text, and Speech To Text (STT) for this purpose may be performed by the real-time phishing response system (200). For example, an application installed on a part of the real-time phishing response system (200), namely the target terminal (100), may perform STT, or the application may transmit voice information to a server, and another part of the real-time phishing response system (200), namely the server, may perform STT. Since methods or techniques for performing such STT are widely known, a detailed description is omitted in this specification, and the explanation is provided on the premise that voice information can be converted into text in any way. Of course, if the conversation is conducted via chat, such text conversion may not be performed.

[0051] Furthermore, phishing criminals may conduct voice phishing calls by mimicking the voice of the target's associate—specifically, a family member or acquaintance used for the phishing attempt—and in such cases, the likelihood of the target falling victim to phishing increases. For instance, a voice phishing criminal can conduct a call by modulating their voice to match that of the impersonating associate through a specific AI model. Consequently, converting the voice information during the call into text and analyzing it allows for a more objective determination of phishing, as this eliminates the consideration of the impersonating associate's vocal tone. Additionally, with the recent emergence of AI technologies capable of facial transformation, criminals may conduct phishing via video calls, which further increases the risk of falling victim; therefore, such text-based phishing detection can be effective.

[0052] Then, the real-time phishing response system (200) can analyze the call content changed into text and determine whether it is phishing in the first place. Of course, not only the call content changed into text, but also the call voice information itself can be used to determine whether it is phishing, and in such cases, it may mean that characteristic features included in the voice, such as pitch and tone in the voice information, can be used to determine whether it is phishing.

[0053] There are various ways in which the above-mentioned real-time phishing response system (200) determines whether phishing is occurring. For example, methods that determine whether phishing is occurring based on keywords mainly used in phishing, or methods that learn phishing cases and determine whether the current conversation is phishing based on artificial intelligence are widely known.

[0054] For example, a deep learning model trained using multiple phishing cases as training data may be provided, and the trained deep learning model may be implemented as a classification model that classifies whether or not it is phishing when text corresponding to the content of a conversation is input.

[0055] It is possible to determine whether text corresponding to conversation content is phishing in various other ways, and since examples of such cases are described in the prior art documents mentioned above and various other known documents, a detailed description is omitted in this specification.

[0056] When the real-time phishing response system (200) analyzes the conversation content and determines whether it is phishing (i.e., determines that there is a possibility of phishing), the real-time phishing response system (200) may induce the subject to express response information. This expression of response information may be achieved by the real-time phishing response system (200) directly transmitting voice information or text information corresponding to a phishing confirmation message to the subject's terminal (300). Additionally, according to another embodiment, warning information may be transmitted to the target's terminal (100) among the conversation participants. The transmitted warning information may include content that causes the subject to express a predetermined phishing confirmation message, and the subject may express the phishing confirmation message after confirming the warning information.

[0057] That is, the warning information in this specification is not merely information indicating that the current conversation may be phishing, but can also perform the function of indicating to display a predetermined phishing confirmation message.

[0058] According to one example, the warning information itself may include a phishing confirmation message pre-set by the subject, and according to another embodiment, the warning information may not include the phishing confirmation message itself, but may be a message that merely instructs the subject to express a phishing confirmation message that the subject already knows.

[0059] The above phishing confirmation message may refer to response information or information requesting such information that is known only between parties who have a specific relationship with the subject (e.g., family, friends, etc.). For example, the subject may agree with family members in advance on a phishing confirmation message and corresponding response information, such as a password. In this case, when the subject expresses the phishing confirmation message, the final confirmation of whether phishing has occurred can be made based on whether the agreed-upon response information is expressed from the subject's terminal (300).

[0060] According to the embodiment, the phishing confirmation message may be information known to both the subject and the relevant party, even if it has not been agreed upon in advance between the subject and the relevant party. For example, if the subject and the relevant party (e.g., family) dine out, the phishing confirmation message may be a question asking about the menu, the location of the meal, or other information that the subject and the relevant party know jointly. The phishing confirmation message may not have been agreed upon in advance between the subject and the relevant party. Even in this case, the real-time phishing response system (200) can significantly reduce the possibility of falling victim to a phishing crime by transmitting and providing guidance warning information through the phishing confirmation message, stating that the current conversation is highly likely to be phishing and that there is a probability that the subject may be impersonating the subject's relevant party.

[0061] Meanwhile, when a pre-agreed phishing confirmation message between the subject and the relevant parties is used, the real-time phishing response system (200) may also store the phishing confirmation message between the subject and the relevant parties and the corresponding response information in advance.

[0062] In such cases, the real-time phishing response system (200) can determine whether response information is expressed from the target terminal (300) after a phishing confirmation message is expressed from the target terminal (100) based on warning information, and can automatically take response measures based on this.

[0063] The subject may also use the subject terminal (100) to register a phishing confirmation message and corresponding response information to be used by relevant parties in advance in the real-time phishing response system (200).

[0064] In addition, according to the embodiment, the subject may use the subject terminal (100) to register different phishing confirmation messages and corresponding response information for each related party. For example, a phishing confirmation message 1 and response information 1 may be registered with family member 1, and a phishing confirmation message 2 and response information 2 may be registered with family member 2. Additionally, a phishing confirmation message 3 and response information 3 may be registered with friend 1.

[0065] In such cases, even if phishing confirmation messages and response information are exposed by phishing criminals due to the theft or leakage of personal information, the information may not spread to targets other than the exposed individual, thereby enabling safer identification of phishing crimes.

[0066] And the above real-time phishing response system (200) monitors whether response information corresponding to the phishing confirmation message expressed by the target is expressed from the target terminal (300), i.e., the counterparty conversing with the target or the target terminal (300), and if the response information is not expressed or incorrect response information is expressed, it can perform a predetermined phishing response measure.

[0067] Meanwhile, there may be cases where the phishing confirmation message and the corresponding response information are not registered in advance, that is, cases where the real-time phishing response system (200) cannot determine whether appropriate response information has been expressed from the target terminal (300). For example, if a phishing call impersonating one of the target's family members is received by the target, the target may ask for the location where they had dinner yesterday evening via a phishing confirmation message based on the warning information, and in such cases, the target may directly inform the real-time phishing response system (200) whether response information corresponding to the phishing confirmation message has been spoken from the target terminal (300). For example, the real-time phishing response system (200) may transmit warning information to induce the phishing confirmation message to be expressed (e.g., spoken or text input) and may provide a predetermined UI that allows the target to input whether accurate response information has been expressed from the target terminal (300). Then, the subject may input whether to display response information to the real-time phishing response system (200) using the above UI, thereby allowing the real-time phishing response system (200) to perform necessary phishing response measures.

[0068] Meanwhile, the real-time phishing response system (200) can automatically determine whether response information corresponding to a phishing confirmation message expressed by the target is expressed from the target terminal (300). At this time, it can monitor whether the response information is expressed according to a predetermined standard. For example, the real-time phishing response system (200) can monitor whether the response information is expressed from the target terminal (300) within a predetermined time or a predetermined number of words after the phishing confirmation message is expressed from the target terminal (100). And only when the response information is expressed while satisfying these standards can it be determined that the response information is expressed normally and that the currently ongoing call is not a phishing call. This is because a phishing criminal may intentionally avoid expressing the response information or change the conversation to a different topic, and in such cases, it may be safer to treat it as a phishing conversation.

[0069] Furthermore, according to the technical concept of the present invention, the real-time phishing response system (200) can identify who the person being impersonated is that the target terminal (300) is impersonating. For example, the real-time phishing response system (200) can analyze the conversation between the target terminal (300) and the target terminal (100) to determine, through the conversation, who the target terminal (300) is currently impersonating, that is, who the person being impersonated is. Here, the term "person being impersonated" may include not only cases where the phishing perpetrator actually impersonates the person in question, but also cases where the person being impersonated is used to perform phishing, i.e., the person being impersonated.

[0070] For example, if the target's terminal (300) is a terminal used by a phishing criminal and the target's child is impersonated or the child is in a critical situation, the child may be the person involved in the impersonation. Alternatively, if the target's spouse is impersonated or the spouse is in a critical situation, the spouse may be the person being impersonated, i.e., the person involved in the impersonation.

[0071] Identifying the person impersonating the subject can be achieved, for example, by analyzing the conversation content and checking for the presence of words indicating a relationship with the subject (e.g., family relationship, acquaintance relationship, etc.), and it is also possible to identify the person impersonating the subject based on context using natural language analysis methods. Such natural language analysis can be achieved by training a separate artificial intelligence model to identify the person impersonating the subject, or by extracting keywords indicating the relationship using widely known Named Entity Recognition (NER) technology. For example, an average expert in the technical field of the present invention would easily infer that the person impersonating the subject can be identified through keywords indicating the relationship with the subject (e.g., dad, mom, uncle, friend, etc.).

[0072] Then, by analyzing the conversation content of the real-time phishing response system (200), the impersonating party can be identified. In this case, even if the target registers different phishing confirmation messages and response information for each party in the real-time phishing response system (200), the warning information can include the phishing confirmation message between the target and the party set for the impersonating party and transmit it to the target terminal (100). Additionally, the real-time phishing response system (200) can automatically determine whether the response information set for the impersonating party is being displayed.

[0073] In addition, according to an embodiment, the real-time phishing response system (200) can identify the actual location of the impersonating party and use this to enable the target to respond to phishing. To this end, it goes without saying that an application for implementing the technical concept of the present invention can be installed on each of the target's parties' terminals.

[0074] Then, for example, a phishing criminal may use the target terminal (300) to communicate with the target terminal (100) and attempt to perform phishing, and at this time, may attempt to perform phishing by impersonating the target's child.

[0075] Then, the real-time phishing response system (200) analyzes the conversation content to primarily determine whether it is phishing, and if it is determined to be phishing, it can identify the person impersonating (e.g., Child 1) based on the current conversation content. Then, the real-time phishing response system (200) can determine the location of the person impersonating (e.g., Child 1). To do this, the real-time phishing response system (200) requests the telecommunications carrier system (400) to look up the location of the person impersonating (e.g., Child 1), and in response, receives the location of the person impersonating (e.g., Child 1) from the telecommunications carrier system (400). Then, the real-time phishing response system (200) can transmit the location of the person impersonating to the target terminal (100).

[0076] According to another embodiment, as described above, an application for implementing the technical concept of the present invention may be installed on the terminals (e.g., mobile phones) of the subjects' associates. In such cases, when the real-time phishing response system (200) analyzes the conversation content to identify the impersonating associate, it may receive the location from the application installed on the impersonating associate's terminal. The impersonating associate can be identified from the phishing conversation in various ways, and once such an impersonating associate is identified, there is a significant effect in that one can avoid being deceived by phishing simply by knowing the impersonating associate's current location.

[0077] For example, the location of an impersonating person (e.g., child 1) can be included in warning information and transmitted to the target terminal (100), and in this case, the location of the impersonating person itself may become a phishing confirmation message. Then the target can ask the impersonating person for their current location, and if a location different from the current location is displayed from the target terminal (300), the real-time phishing response system (200) can determine that the current conversation is ultimately a phishing call and perform phishing response measures.

[0078] Alternatively, the location of the impersonating party may be provided to the target as additional information, and a pre-configured phishing confirmation message may be displayed separately. In such cases, the phishing status can be verified through a double check that confirms not only whether the phishing confirmation message and corresponding response information are displayed, but also the location of the impersonating party.

[0079] Meanwhile, the phishing response measures performed by the real-time phishing response system (200) may be performed automatically by the real-time phishing response system (200) and may be reported to relevant agencies (e.g., financial institutions, police departments, etc.). Furthermore, not only may the system report to the relevant agencies, but phishing conversation information, that is, information regarding the conversation between the current target terminal (100) and the victim terminal (300), may also be transmitted to the relevant agencies. In the case where the conversation is a phone call, the phishing conversation information may include, for example, the caller's number, the recipient's number, and the content of the call. Since the real-time phishing response system (200) can determine whether phishing is occurring in real time during the call, the phishing call information can be transmitted to relevant agencies while the call is in progress, which may help in rapid crime prevention and / or the apprehension of criminals. Of course, in cases where the conversation takes place through chat, information about such conversation (e.g., conversation content, sender number or ID, etc., collectible meaningful information) may be transmitted to relevant organizations before the conversation ends (e.g., closing the chat window).

[0080] Ultimately, according to the technical concept of the present invention, after primarily determining whether a currently ongoing conversation is a phishing conversation based on artificial intelligence or other predetermined rule bases, if it is primarily determined to be a phishing call (i.e., after determining that there is a possibility of phishing), a final determination can be made secondarily based on whether the subject expresses response information. In addition, depending on the embodiment, an additional determination may be made through the location of the impersonating party, and such location of the impersonating party may be used as a phishing confirmation message or utilized as an additional determination factor separate from the phishing confirmation message.

[0081] In the event that it is determined to be a phishing conversation, the real-time phishing response system (200) can take effective measures for rapid response and apprehending the phishing criminal by transmitting phishing conversation information to relevant agencies while the conversation is in progress (i.e., while the call is connected or before the conversation ends).

[0082] Hereinafter, this specification describes, by way of example, cases where a conversation takes place via telephone, but it is obvious that the technical concept of the present invention can also be applied to conversations via chat, etc.

[0083] The schematic configuration of the real-time phishing response system (200) for implementing such technical ideas may be as shown in FIG. 2.

[0084] FIG. 2 is a diagram illustrating the schematic configuration of a real-time phishing response system according to an embodiment of the present invention.

[0085] Referring to FIG. 2, the real-time phishing response system (200) may be equipped with a memory (storage device) (220) in which a program for implementing the technical concept of the present invention is stored, and a processor (210) for executing the program stored in the memory (220).

[0086] An average expert in the technical field of the present invention will be able to easily infer that the above processor (210) may be named by various names, such as CPU, GPU, and / or mobile processor, depending on the implementation example of the real-time phishing response system (200). Furthermore, as described above, the real-time phishing response system (200) may be implemented by organically combining a plurality of physical devices, and in such a case, an average expert in the technical field of the present invention will be able to easily infer that the real-time phishing response system (200) of the present invention may be implemented by providing at least one processor (210) for each physical device. For example, the real-time phishing response system (200) may be implemented by a target terminal (100) and a server that communicates with an application installed on the target terminal (100), and in such a case, it goes without saying that a processor (210) and / or memory (220) may be provided in the target terminal (100) and the server, respectively.

[0087] The memory (220) may be implemented as any type of storage device that the processor (210) can access to store the program and to perform the following: a primary determination of whether a conversation is phishing through analysis of conversation content by running the program, transmission of a phishing confirmation message, transmission of warning information, monitoring of whether response information corresponding to the phishing confirmation message is expressed, and phishing response measures. Additionally, depending on the hardware implementation example, the memory (220) may be implemented as multiple storage devices rather than a single storage device. Furthermore, the memory (220) may include not only a main memory but also a temporary memory. It may also be implemented as volatile memory or non-volatile memory, and may be defined to include all forms of information storage means implemented to store the program and enable it to be run by the processor.

[0088] In addition, various peripheral devices (peripheral device 1 to peripheral device N, 230, 231) may be further provided according to an embodiment of the above system (200). For example, an average expert in the art of the present invention will be able to easily infer that a keyboard, monitor, graphics card, communication device, etc., may be further included in the real-time phishing response system (200) as peripheral devices.

[0089] Hereinafter, an average expert in the technical field of the present invention will be able to easily infer that when the real-time phishing response system (200) performs a function in the present specification, it means that the processor (210) runs a program provided in the memory (220) to perform the function.

[0090] A general real-time phishing response method performed by the above-mentioned real-time phishing response system (200) for this purpose will be explained with reference to FIG. 3.

[0091] FIG. 3 is a diagram showing a flowchart for explaining a real-time phishing response method according to an embodiment of the present invention. FIG. 3 illustrates, by way of example, a case where a conversation takes place via telephone call, but as previously mentioned, the technical concept of the present invention can be applied to various forms of conversation, such as chatting.

[0092] Referring to FIG. 3, a real-time phishing response method according to an embodiment of the present invention includes a process in which the real-time phishing response system (200) analyzes the content of a conversation (e.g., a call) between a target terminal (300) and a target terminal (100) (S100). Of course, prior to this, the real-time phishing response system (200) may further include a step of obtaining the content of the conversation.

[0093] As previously mentioned, the process of analyzing such conversation content may include, for example, a process in which an application installed on a target terminal (100) directly transmits voice information corresponding to the call to a server or converts it into text. Of course, this process may not be included when a chat conversation is performed. The application may be implemented to receive conversations by communicating with a conversation application (e.g., a phone application or a chat application) that performs phone calls or chats.

[0094] And, based on the text, it can be determined in advance whether it is a phishing conversation (S110). As previously mentioned, this indirect determination of whether it is a phishing conversation can be implemented by training an artificial intelligence model to classify phishing conversations, or by using a keyword-based rule-based method or various other methods.

[0095] And if it is primarily determined to be a phishing conversation (S110), the real-time phishing response system (200) can induce the subject to express response information (e.g., utterance) (S120). Inducing the expression of response information may include cases where the real-time phishing response system (200) transmits warning information to the subject terminal (100) (S121) and induces the subject to express a phishing confirmation message in response to the transmitted warning information (S123). According to another embodiment, as described above, the real-time phishing response system (200) may include cases where it induces the expression of response information by directly transmitting information corresponding to the phishing confirmation message to the subject terminal (300) (S125).

[0096] In the former case, as previously stated, the warning information may be a message that induces the target to express a phishing confirmation message, and depending on the embodiment, the warning information may or may not include a phishing confirmation message.

[0097] In any case, the subject who has confirmed the above warning information may express a phishing confirmation message (S123). The phishing confirmation message may be information that has been agreed upon in advance between the subject and the relevant parties and is stored in the real-time phishing response system (200) as described above, or it may be information known only to the subject and the relevant parties even if it is not stored in the real-time phishing response system (200).

[0098] As previously mentioned, whether the person impersonating the subject in the conversation currently being conducted is related to the subject can be determined by the subject themselves, or can be identified by the real-time phishing response system (200) as described above.

[0099] And as previously mentioned, when an impersonating party is identified by the real-time phishing response system (200), the real-time phishing response system (200) can further transmit location information of the impersonating party to the target terminal (100).

[0100] Meanwhile, after the induction of the expression of the above response information is performed by the real-time phishing response system (200) (S120), the real-time phishing response system (200) can monitor whether the response information corresponding to the phishing confirmation message is expressed from the target terminal (300) (e.g., spoken or text input, etc.) (S140).

[0101] As previously described, if a phishing confirmation message and corresponding response information are not registered in the real-time phishing response system (200), the subject may be allowed to directly input whether the response information is displayed through a predetermined UI, thereby allowing the real-time phishing response system (200) to finally determine whether the response information is displayed.

[0102] In addition, the expression of such response information is not determined by waiting indefinitely, but can be judged not to be phishing only if it is expressed from the target terminal (300) within a predetermined time after the expression of the phishing confirmation message or is included within a predetermined number of words.

[0103] And if no response information corresponding to the phishing confirmation message is expressed, the real-time phishing response system (200) can automatically perform phishing response measures (S150).

[0104] Meanwhile, as described above, the subject can respond more effectively to phishing crimes by setting different phishing confirmation messages and response information for each of their stakeholders. An example of this will be explained with reference to Fig. 4.

[0105] FIG. 4 is a diagram illustrating a phishing confirmation message and a corresponding response according to an embodiment of the present invention.

[0106] Referring to FIG. 4, the subject can set different phishing confirmation messages and corresponding responses for each of their stakeholders. These phishing confirmation messages and response information for each stakeholder can be stored in advance in the real-time phishing response system (200).

[0107] For example, for Family 1, Message 1 can be set as a phishing confirmation message, and the response information for it can be set as Response 1. And it may be desirable to share this set information with Family 1 in advance.

[0108] For example, for Family 2, Message 2 can be set as a phishing confirmation message, and the response information for it can be set as Response 2. It may also be desirable to share this configured information with Family 2 in advance.

[0109] In addition, according to the embodiment, the subject may also set another acquaintance (e.g., friend, coworker, etc.) 1 who is not a family member as a related party, and in such case, Message 3 may be set as a phishing confirmation message for Acquaintance 1, and the response information for this may be set as Response 3. It may also be desirable to share this set information with Acquaintance 1 in advance.

[0110] Then, for example, if a call received from the target terminal (300) is initially determined to be a phishing call by the real-time phishing response system (200), the real-time phishing response system (200) can guide the target to speak message 1 if the person being impersonated by the target terminal (300) is family member 1, the real-time phishing response system (200) can guide the target to speak message 2 if the person being impersonated is family member 2, and the real-time phishing response system (200) can guide the target to speak message 3 if the person being impersonated is acquaintance 1.

[0111] In addition, if different phishing confirmation messages are set for each party as described above, the phishing confirmation message corresponding to the impersonating party may be included in the warning information and transmitted.

[0112] To this end, the real-time phishing response system (200) can first identify who the impersonating party is by analyzing the conversation content, and can send a phishing confirmation message (e.g., Message 1) set for the identified impersonating party (e.g., Family 1) to the target terminal (100) by including it in the warning information. Then, it can monitor whether the response information (e.g., Response 1) set for the impersonating party is displayed from the target terminal (300).

[0113] Meanwhile, according to the technical concept of the present invention, the real-time phishing response system (200) can identify the impersonating party, confirm the location of the impersonating party, and transmit it to the target, and such an example will be explained with reference to FIG. 5.

[0114] FIG. 5 is a drawing for explaining a method to respond to phishing using location information of relevant parties according to an embodiment of the present invention.

[0115] Referring to FIG. 5, as described above, the real-time phishing response system (200) can analyze the content of a conversation (e.g., a phone call) between a target terminal (300) and a target terminal (100) (S200).

[0116] And it can primarily determine whether it is a phishing conversation (S210).

[0117] If it is determined that the conversation is a phishing conversation, the target terminal (300) can analyze the conversation content to identify the person being impersonated by the target terminal (300), i.e., the person being impersonated (S220).

[0118] When an impersonating official is identified, the real-time phishing response system (200) can include a phishing confirmation message set for the impersonating official in the warning information and transmit it as described above (S230), and accordingly, the target may be made to express the phishing confirmation message set for the impersonating official.

[0119] In addition, the location information of the impersonating party's terminal, i.e., the current actual location information of the impersonating party, may be included in the warning information and transmitted (S240), thereby allowing the target to additionally verify whether the current conversation is a phishing conversation. Of course, the location information of the impersonating party may be transmitted separately from the warning information, and depending on the embodiment, not only the phishing confirmation message set for the impersonating party but also the location information of the impersonating party may be used as a phishing confirmation message.

[0120] Ultimately, according to the technical concept of the present invention, even if exposed to voice phishing or phishing via chat, information is provided to be displayed to the target to verify in real-time whether it is phishing during the conversation, thereby enabling the determination of phishing status in real-time. As previously mentioned, such information may be a phishing confirmation message or location information of the impersonating party, and it goes without saying that both types of information can be used.

[0121] Meanwhile, according to an embodiment, the real-time phishing response system (200) may include a processor and a memory that stores a program executed by the processor. The processor may include a single-core CPU or a multi-core CPU. The memory may include high-speed random access memory and may include one or more non-volatile memories such as magnetic disk storage devices, flash memory devices, or other non-volatile solid-state memory devices. Access to memory by the processor and other components may be controlled by a memory controller.

[0122] Meanwhile, the method according to an embodiment of the present invention may be implemented in the form of computer-readable program instructions and stored on a computer-readable recording medium, and the control program and target program according to an embodiment of the present invention may also be stored on a computer-readable recording medium. A computer-readable recording medium includes all types of recording devices in which data that can be read by a computer system is stored.

[0123] The program instructions recorded on the recording medium may be those specifically designed and configured for the present invention, or they may be those known and available to those skilled in the art of software.

[0124] Examples of computer-readable recording media include magnetic media such as hard disks, floppy disks, and magnetic tapes; optical media such as CD-ROMs and DVDs; magneto-optical media such as floptical disks; and hardware devices specifically configured to store and execute program instructions, such as ROM, RAM, and flash memory. Additionally, computer-readable recording media may be distributed across networked computer systems, allowing computer-readable code to be stored and executed in a distributed manner.

[0125] Examples of program instructions include not only machine code, such as that generated by a compiler, but also high-level language code that can be executed by a device that processes information electronically using an interpreter, such as a computer.

[0126] The hardware device described above may be configured to operate as one or more software modules to perform the operation of the present invention, and vice versa.

[0127] The foregoing description of the present invention is for illustrative purposes only, and those skilled in the art will understand that other specific forms can be easily modified without altering the technical spirit or essential features of the present invention. Therefore, the embodiments described above should be understood as illustrative in all respects and not restrictive. For example, each component described as a single unit may be implemented in a distributed manner, and components described as distributed may likewise be implemented in a combined form.

Claims

Claim 1 A real-time phishing response method comprising: a step in which a system acquires the content of a conversation between conversation participants; a step in which the system analyzes the acquired content of the conversation to determine whether phishing has occurred; and a step in which, if the system determines as a result of the determination that there is a possibility of phishing, the system induces the target to express response information for phishing confirmation. Claim 2 In claim 1, the real-time phishing response method further comprises the step of the system performing a phishing response measure based on whether the response information is expressed by the target. Claim 3 A real-time phishing response method according to claim 1, wherein the step of the system inducing a subject to express response information for phishing confirmation includes: a step of transmitting warning information to the terminal of a subject among the conversation participants to cause the subject to express a predetermined phishing confirmation message; or a step of the system expressing a predetermined phishing confirmation message to the terminal of the subject during the conversation, and performing phishing response measures based on whether the response information corresponding to the phishing confirmation message is expressed by the subject. Claim 4 In paragraph 3, the step of performing a phishing response measure based on whether the response information is expressed by the subject includes the step of the system receiving from the subject terminal whether the response information corresponding to the phishing confirmation message is expressed by the subject. Claim 5 In paragraph 3, the real-time phishing response method further comprises the step of the system receiving and storing the target's phishing confirmation message and the response information from the target's terminal in advance. Claim 6 In paragraph 3, the step of performing a phishing response measure based on whether response information corresponding to the phishing confirmation message is expressed by the subject includes the step of the system determining whether the response information is expressed by the subject's terminal within a predetermined time or a predetermined number of words after the phishing confirmation message is expressed by the subject's terminal or the system. Claim 7 In claim 5, the step of the system receiving and storing the phishing confirmation message and the response information of the subject from the subject's terminal in advance includes the step of the system storing the phishing confirmation message and response information set by relevant parties according to the relationship with the subject from the subject's terminal, in a real-time phishing response method. Claim 8 In claim 7, the real-time phishing response method further includes the step of identifying a person impersonating through the conversation when the system determines that there is a possibility of phishing based on the judgment result, and is characterized by the system inducing the target to express the response information corresponding to the identified person. Claim 9 In claim 7, the real-time phishing response method further comprises the step of the system verifying the terminal location information of the relevant party and transmitting it to the terminal of the target. Claim 10 In paragraph 3, the step of transmitting warning information to the terminal of a target among the conversational participants so that the target expresses a predetermined phishing confirmation message comprises the step of the system transmitting the warning information including the phishing confirmation message to the target's terminal. Claim 11 In paragraph 2, the step of the system performing phishing response measures based on whether response information corresponding to the phishing confirmation message is expressed by the target person comprises the step of the system transmitting phishing conversation information to a predetermined relevant agency system while the conversation is connected. Claim 12 A real-time phishing response method comprising: a step in which a system analyzes the content of a conversation between conversation participants to determine whether phishing has occurred; a step in which, if the system determines as a result of the determination that there is a possibility of phishing, a step in which a person impersonating through the conversation is identified; and a step in which the system confirms the terminal location information of the identified person and transmits it to the target's terminal. Claim 13 A computer program recorded on a computer-readable recording medium for performing a method described in any one of claims 1 to 12, installed in a data processing device. Claim 14 A real-time phishing response system comprising a processor and a storage device in which a program is stored, wherein the processor drives the program to obtain the content of a conversation between conversation participants, analyzes the content of the conversation to determine whether phishing has occurred, and if the determination result indicates that there is a possibility of phishing, induces the target to express response information for phishing confirmation. Claim 15 A real-time phishing response system comprising a processor; a storage device in which a program is stored, wherein the processor drives the program to analyze the content of a conversation between conversation participants to determine whether phishing has occurred, and if the system determines that there is a possibility of phishing as a result of the determination, it identifies a person impersonating through the conversation, verifies the terminal location information of the identified person, and transmits it to the target's terminal.