A method for preventing phishing and an application for preventing phishing

KR103002631B1Active Publication Date: 2026-08-12정재웅
View PDF 4 Cites 0 Cited by

Patent Information

Authority / Receiving Office
KR · KR
Patent Type
Patents
Current Assignee / Owner
Filing Date
2026-02-11
Publication Date
2026-08-12

Smart Images

  • Figure 112026017895215-PAT00001_ABST
    Figure 112026017895215-PAT00001_ABST
Patent Text Reader

Abstract

The present invention detects whether a file is being transferred from an external terminal to a user terminal during a call between a user terminal and an external terminal, forcibly terminates the call with the external terminal if the file transferred during the call is suspected of being a phishing file, and blocks access to the internet site corresponding to the link if the link information included in a text message received by the user terminal is a phishing link, thereby preventing the user terminal from becoming a phishing zombie phone. This invention not only enables the fundamental prevention of phishing crimes but also provides the effect of protecting information-vulnerable groups, such as the elderly or people with disabilities who are unfamiliar with smartphone usage, from phishing crimes without any separate operation.
Need to check novelty before this filing date? Find Prior Art

Description

Technology Field

[0001] The present invention relates to a method for preventing phishing and an application for preventing phishing. More specifically, it relates to a technology that detects whether a file is being transmitted from an external terminal to a user terminal during a call between a user terminal and an external terminal, forcibly terminates the call with the external terminal if the file transmitted during the call is suspected of being a phishing file, and blocks access to an internet site corresponding to the link if the link information included in a text message received by the user terminal is a phishing link, thereby preventing the user terminal from being used for phishing crimes and preventing damage caused by phishing. Background Technology

[0003] With the recent widespread adoption of smartphones and advancements in mobile communication technology, phishing crimes—financial fraud committed via telephone—are continuously increasing, and the methods of phishing crimes are also evolving in diverse ways.

[0004] Phishing is a crime that involves illegally leaking another person's personal information from a smartphone and using that information to commit fraud.

[0005] In order to respond to evolving phishing crimes, various security technologies and services have been proposed in the past. For example, technologies have been developed to block suspected phishing numbers in advance based on a phone number database, to provide warning messages by analyzing specific keywords or voice patterns during a call, or to determine whether a received text message or link URL is malicious. However, these conventional technologies have the following limitations.

[0006] First, phone number-based blocking technology has a problem in that it is difficult to respond effectively when phishing criminals frequently change their caller ID or steal legitimate or another person's number; therefore, blocking methods based solely on the caller ID have a structural limitation in that they cannot adequately respond to the latest evolved phishing techniques.

[0007] Second, phishing detection technologies based on call voice analysis or keyword recognition have the problem that it is difficult to ensure analysis accuracy and struggle to detect new conversation patterns or sophisticated speech patterns that are not predefined.

[0008] Third, technologies that analyze links or files transmitted via text messages or messengers often operate after a call has ended or only recognize the risk after the user has already downloaded or executed the file, so there are limitations in preventing damage caused by phishing in advance.

[0009] Recently, voice phishing has emerged as a type of phishing crime. This is a new type of phishing crime in which malicious files, such as executable files, are transmitted to a user's device during a phone call. By inducing the call to continue until the malicious file is fully executed, the user's device is turned into a "zombie phone" that can be remotely controlled. Subsequently, personal information is leaked from the zombie phone to illegally withdraw money from the user's financial accounts or obtain fraudulent loans.

[0010] In particular, in voice phishing, since the communication connection between the user's terminal and the phishing criminal's terminal must be maintained until the malicious file is fully executed on the user's terminal, it is very important to block communication before or during file execution to prevent voice phishing crimes.

[0011] However, conventional technology has not sufficiently proposed a technique to fundamentally block phishing activities by linking phone call status with file transfer activities for real-time detection, assessing the risk of files transmitted during a call, and immediately forcibly terminating the call. In other words, a technical configuration that integrates call detection, file transfer detection, file risk assessment, and communication blocking into a single continuous control flow is difficult to find in conventional technology.

[0012] Another type of phishing crime is smishing. Smishing is a new type of phishing crime in which a text message containing a link is sent to an acquaintance's phone number; when the user clicks the link, their device is redirected to a phishing website, where a malicious file is planted to turn the device into a "zombie phone" that can be remotely controlled. Once the device becomes a zombie phone, personal information is leaked to illegally withdraw money from the user's financial accounts or obtain fraudulent loans.

[0013] Therefore, it is necessary to develop new technology that can prevent users' smartphones from being exploited for phishing crimes such as voice phishing or smishing.

[0014] The present invention aims to solve the aforementioned problems and address the need for such solutions by proposing a technology that prevents damage caused by phishing. This technology detects whether a file is being transferred from an external terminal to a user terminal during a call between the user terminal and an external terminal; if the file transferred during the call is suspected of being a phishing file, it forcibly terminates the call with the external terminal; and if the link information included in a text message received by the user terminal is a phishing link, it blocks access to the internet site corresponding to that link, thereby preventing the user terminal from being used for phishing crimes. The following are prior art related to this. Prior art literature

[0016] 1. Korean Patent Publication No. 10-1779696 2. Korean Patent Publication No. 10-2001157 3. Korean Patent Publication No. 10-2198333 4. Korean Patent Publication No. 10-2625864

[0017] 1. A Study on Voice Phishing Prevention Techniques through Voice Keyword Analysis (Korea Education and Research Information Service, 2019) 2. A Study on the Dynamic Evaluation Method of Smishing Blocking Apps with Detection Setting Functions (Service Science Society, 2015 vol.5, no.2) The problem to be solved

[0018] The present invention aims to prevent a user terminal from becoming a phishing zombie phone by detecting whether a file is transmitted from an external terminal to a user terminal during a call between the user terminal and an external terminal, forcibly terminating the call with the external terminal if the file transmitted during the call is suspected of being a phishing file, and blocking access to an internet site corresponding to a link if the link information included in a text message received by the user terminal is a phishing link. means of solving the problem

[0020] The phishing prevention method using the phishing prevention app of the present invention for solving the above problem is,

[0021] A first step (S100) in which a phishing prevention app (1) is installed on a user terminal (2);

[0022] A second step (S200) in which a phishing prevention app (1) checks whether the user terminal (2) is in a call with an external terminal (3) with a phone number other than the phone number stored in the user terminal (2) or whether a text message has been received on the user terminal (2) with the phone number stored in the user terminal (2);

[0023] A third step (S300) in which, if the result of the check through the second step (S200) is that the phishing prevention app (1) checks whether there is a file transfer from an external terminal (3) during the call, and if a text message is received, the phishing prevention app (1) checks whether the received text message contains link information;

[0024] The method is characterized by including a fourth step (S400) in which, if there is a file transmission from an external terminal (3) as a result of checking through the third step (S300), the phishing prevention app (1) checks whether the transmitted file is a suspected phishing file, and if it is a suspected phishing file, immediately forcibly terminates the call with the external terminal (3), and if the received text message contains link information, the phishing prevention app (1) prevents the user terminal (2) from accessing the internet site corresponding to the link even if the user selects the link, and then, once the safety of the link is confirmed, the blocking of access to the internet site corresponding to the link is lifted.

[0026] In addition, the phishing prevention application stored in the storage medium of the user terminal of the present invention for solving the above problem is,

[0027] A first detection unit (100) that checks whether the user terminal (2) is in a call with an external terminal (3) of a phone number other than the phone number stored in the user terminal (2), and if in a call, provides a call detection signal to the file transmission detection unit (200), and checks whether a text message has been received at the user terminal (2) with the phone number stored in the user terminal (2), and if received, provides a text message reception signal to the file transmission detection unit (200);

[0028] A second detection unit (200) that checks whether there is a file transmission from an external terminal (3) during a call when a call detection signal is provided from the first detection unit (100), and if there is a file transmission, provides the transmitted file information to the phishing prevention unit (300), and when a text message reception signal is provided from the first detection unit (100), checks whether the received text message contains link information, and if there is link information, provides the corresponding link information to the phishing prevention unit (300);

[0029] The invention is characterized by including a phishing prevention unit (300) that checks whether a file provided by the second detection unit (200) is a suspected phishing file, and if it is a suspected phishing file, immediately forcibly terminates the call with the external terminal (3), prevents the user terminal (2) from connecting to the internet site corresponding to the link even if the user selects the link information provided by the second detection unit (200), and then, when the safety of the link is confirmed, releases the blocking of access to the internet site corresponding to the link. Effects of the invention

[0031] The present invention detects whether a file is being transferred from an external terminal to a user terminal during a call between a user terminal and an external terminal; if the file transferred during the call is suspected to be a phishing file, it forcibly terminates the call with the external terminal; and if the link information included in a text message received by the user terminal is a phishing link, it blocks access to the internet site corresponding to that link, thereby preventing the user terminal from becoming a phishing zombie phone. This not only allows for the fundamental prevention of phishing crimes but also provides the effect of protecting information-vulnerable groups, such as the elderly or people with disabilities who are unfamiliar with smartphone usage, from phishing crimes without requiring any separate operation. Brief explanation of the drawing

[0033] FIG. 1 is an overall flowchart of the first embodiment of the present invention. FIG. 2 is a detailed explanatory diagram of a first embodiment of the present invention. FIG. 3 is a detailed configuration diagram of a second embodiment of the present invention. Specific details for implementing the invention

[0034] Embodiments of the present invention will be described in detail with reference to the attached drawings.

[0035] The present invention detects whether a file is being transferred from an external terminal to a user terminal during a call between a user terminal and an external terminal, forcibly terminates the call with the external terminal if the file transferred during the call is suspected of being a phishing file, and blocks access to the internet site corresponding to the link if the link information included in a text message received by the user terminal is a phishing link, thereby preventing the user terminal from becoming a phishing zombie phone. This invention not only enables the fundamental prevention of phishing crimes but also provides the effect of protecting information-vulnerable groups, such as the elderly or people with disabilities who are unfamiliar with smartphone usage, from phishing crimes without any separate operation.

[0036] Accordingly, the present invention may be classified into a phishing prevention method (hereinafter, first embodiment) and a phishing prevention application (hereinafter, second embodiment) depending on the embodiment.

[0038] Specifically, the phishing prevention method of the first embodiment of the present invention, as illustrated in FIG. 1,

[0039] A first step (S100) in which a phishing prevention app (1) is installed on a user terminal (2);

[0040] A second step (S200) in which a phishing prevention app (1) checks whether the user terminal (2) is in a call with an external terminal (3) with a phone number other than the phone number stored in the user terminal (2) or whether a text message has been received on the user terminal (2) with the phone number stored in the user terminal (2);

[0041] A third step (S300) in which, if the result of the check through the second step (S200) is that the phishing prevention app (1) checks whether there is a file transfer from an external terminal (3) during the call, and if a text message is received, the phishing prevention app (1) checks whether the received text message contains link information;

[0042] The method is characterized by including a fourth step (S400) in which, if there is a file transmission from an external terminal (3) as a result of checking through the third step (S300), the phishing prevention app (1) checks whether the transmitted file is a suspected phishing file, and if it is a suspected phishing file, immediately forcibly terminates the call with the external terminal (3), and if the received text message contains link information, the phishing prevention app (1) prevents the user terminal (2) from accessing the internet site corresponding to the link even if the user selects the link, and then, once the safety of the link is confirmed, the blocking of access to the internet site corresponding to the link is lifted.

[0044] As illustrated in FIG. 2, the first step (S100) is a step in which a phishing prevention app (1) is installed on a user terminal (2), and the user installs the phishing prevention app (1) on their terminal, and the installed phishing prevention app (1) is always kept in an active state.

[0046] As illustrated in FIG. 2, the second step (S200) is a step in which the anti-phishing app (1) checks whether the user terminal (2) is in a call with an external terminal (3) with a phone number other than the phone number stored in the user terminal (2), or whether a text message has been received on the user terminal (2) with a phone number stored in the user terminal (2).

[0047] In the case of voice phishing crimes, the phishing criminal makes a call with the phishing target user, and the phishing prevention app (1) monitors the call status information of the user terminal (2) and checks whether the user terminal (2) is in a call with an external terminal (3) of a phone number other than the phone number stored in the user terminal (2).

[0048] At this time, the call between the user terminal (2) and the external terminal (3) may be a call made by the user via an outgoing call from the user terminal (2) made by a text message (a message containing the phone number of the external terminal) transmitted by the external terminal (3), or a call made via an outgoing call from the external terminal (3).

[0049] In addition, the call between the user terminal (2) and the external terminal (3) is a call with the external terminal (3) of a phone number other than the stored phone number. As described below, during a call with the external terminal (3), if the external terminal (3) transmits an executable file (~.exe), the call is forcibly terminated because the transmitted file is suspected to be a phishing file. This causes inconvenience when the call with an acquaintance is forcibly terminated even when the acquaintance normally sends the executable file.

[0050] Accordingly, the anti-phishing app (1) does not proceed to the subsequent third step (S300) if the call of the user terminal (2) is a call to an external terminal (3) with a phone number stored in the user terminal (2), and proceeds to the subsequent third step (S300) if the call is a call to an external terminal (3) with a phone number not stored in the user terminal (2), thereby resolving the inconvenience of the call with an acquaintance being forcibly terminated.

[0051] For voice phishing, the phishing criminal sends a text message containing a phone number to the target user's terminal (2) to induce the target user to call the phishing criminal, or the phishing criminal directly calls the target user to attempt a call. In other words, since the user terminal (2) and the external terminal (3) must be in a call state for voice phishing to occur, the phishing prevention app (1) monitors the call status information of the user terminal (2) to determine whether the user terminal (2) is in a call with the external terminal (3) of a phone number other than the one stored in the user terminal (2).

[0052] In the case of smishing, another type of phishing crime, the phishing criminal sends a text message containing phishing link information (e.g., a death notice text message) to the phone number of an acquaintance of the phishing target user, and the anti-phishing app (1) monitors the reception of text messages on the user terminal (2) and checks whether a text message has been received on the phone number (acquaintance's phone number) stored on the user terminal (2).

[0054] As illustrated in FIG. 2, the third step (S300) is a step in which, based on the result of the check through the second step (S200), if a call is in progress, the phishing prevention app (1) checks whether there is a file transfer from an external terminal (3) during the call, and if a text message is received, the phishing prevention app (1) checks whether the received text message contains link information.

[0055] In the case of voice phishing crimes, the phishing criminal transmits a phishing file to the user terminal (2) that can turn the user terminal (2) into a zombie phone while in a call with the target user, and the phishing prevention app (1) checks whether there is a file transmission to the user terminal (2) that is in a call with an external terminal (3). Of course, if the external terminal (3) is not the phishing criminal's terminal, the file transmitted by the external terminal (3) will be a normal file rather than a malicious file, but whether the file transmitted by the external terminal (3) is a malicious phishing file is determined in the fourth step (S400) described later, and first, in the third step (S300), the phishing prevention app (1) only checks whether there is a file transmission from the external terminal (3) while in a call with an external terminal (3) that has a phone number other than the phone number stored in the user terminal (2).

[0056] In the case of smishing crime, the phishing criminal does not make a phone call to the target user, but sends a text message (e.g., a death notice text message) to the user terminal (2) using a phone number of the target user's acquaintance that was illegally obtained. The text message contains link information, and when the link is selected, the user terminal (2) is automatically connected to a phishing internet site, and a malicious phishing file is automatically transmitted from the phishing internet site to the user terminal (2), so that the user terminal (2) becomes a zombie phone that can be remotely controlled by the phishing criminal.

[0057] The user selects the link information included in the text message without thinking because it is a text message received from an acquaintance's phone number, and as a result, the user terminal (2) becomes a zombie phone that can be remotely controlled by a phishing criminal.

[0058] Therefore, the phishing prevention app (1) checks whether link information is included in the received text message of the phone number stored in the user terminal (2). Of course, the link information included in the received text message may be normal link information rather than phishing link information (link information actually sent by an acquaintance), but whether the link information included in the received text message is a malicious phishing link is determined in the fourth step (S400) described later. First, in the third step (S300), the phishing prevention app (1) only checks whether link information is included in the text message received from the phone number stored in the user terminal (2).

[0060] Meanwhile, deepfake voice phishing is one type of voice phishing crime. Deepfake voice phishing is a phishing crime that does not turn the target user's device into a zombie phone, but rather uses the deepfake modified voice of the target user's acquaintance, for example, a child (e.g., a deepfake voice of a child in danger), during a call to paralyze the target user's reason and then induce them to transfer money.

[0061] In order to prevent such deepfake voice phishing, the target user must be able to judge their current situation as rationally as possible; however, it is very difficult for the target user to judge their current situation rationally after hearing a deepfake modified voice of a child (e.g., a deepfake voice of a child in danger).

[0062] Therefore, it is necessary to enable a third party to objectively and rationally assess the current situation on behalf of the user who is in a deepfake voice phishing crime situation.

[0063] To this end, the above third step (S300) is,

[0064] The method further includes the step of checking through the second step (S200), and if a call is in progress, the phishing prevention app (1) displays an emergency button icon on the screen of the user terminal (2); if the emergency button icon is selected while the call is in progress, the phishing prevention app (1) converts the voice call content between the user terminal (2) and the external terminal (3) into text in real time and sends the text message in real time to the terminal of the pre-registered phone number, and displays the text message sent by the terminal to which the text message was sent on the screen of the user terminal (2).

[0065] When a user is on a call with a phishing criminal and feels something is off during the call, they select the emergency button icon displayed on their terminal screen. When the emergency button icon is selected, the anti-phishing app (1) converts the voice call content between the user terminal (2) and the external terminal (3) into text in real time and sends the text in real time to the terminal of a pre-registered phone number.

[0066] The above-mentioned pre-registered phone numbers are the phone numbers of acquaintances that the user has previously registered in the phishing prevention app (1), and it is preferable that there be multiple numbers. For example, when the emergency button icon is selected while the user has previously registered the phone numbers of their children, spouse, and friends in the phishing prevention app (1), the phishing prevention app (1) converts the voice call content between the user terminal (2) and the external terminal (3) into text in real time and sends the text simultaneously in real time to the terminals of the children, spouse, and friends who are the pre-registered phone numbers.

[0067] An acquaintance (child, spouse, friend, etc.) who receives a real-time text message regarding a user's conversation with a phishing criminal makes a rational and objective assessment of the current situation and sends a text message regarding the situation (e.g., "I think this call is a voice phishing call") to the user's device. In addition, the acquaintance who receives the real-time text message reports the voice phishing crime to investigative agencies along with sending the text message, enabling the agencies to promptly investigate the crime.

[0068] A text message sent by an acquaintance (child, spouse, friend, etc.) (e.g., "I think this call is a voice phishing call") is displayed on the user's terminal screen, and if the user determines through the text message that the current situation is a voice phishing situation, the user immediately ends the call with the external terminal (3) to prevent financial loss from occurring due to deepfake voice phishing.

[0070] As illustrated in FIG. 2, the fourth step (S400) is a step in which, if there is a file transmission from an external terminal (3) as a result of the check through the third step (S300), the phishing prevention app (1) checks whether the transmitted file is a suspected phishing file, and if it is a suspected phishing file, immediately forcibly terminates the call with the external terminal (3), and if the received text message contains link information, the phishing prevention app (1) prevents the user terminal (2) from accessing the internet site corresponding to the link even if the user selects the link, and then, if the safety of the link is confirmed, the blocking of access to the internet site corresponding to the link is lifted.

[0072] As a result of the check in the third step (S300), if there is a file transmission from the external terminal (3), the phishing prevention app (1) checks whether the transmitted file is a suspected phishing file, and if it is a suspected phishing file, immediately forcibly terminates the call with the external terminal (3). At this time, if the file transmitted from the external terminal (3) is an executable file (~.exe), the phishing prevention app (1) determines that the transmitted file is a suspected phishing file.

[0073] In the case of voice phishing crimes, the phishing criminal transmits a malicious file capable of turning the user terminal (2) into a zombie phone to the user terminal (2) of the target user. The malicious file capable of turning the user terminal (2) into a zombie phone has the format of an executable file (~.exe).

[0074] The file transmitted by the external terminal (3) of a phone number other than the phone number stored in the user terminal (2) may be a regular file (e.g., image file) or an executable file (~.exe) that is not an executable file (~.exe).

[0075] A normal file transmitted by an external terminal (3) cannot be a malicious executable file (~.exe) for phishing that can turn the user terminal (2) into a zombie phone, but an executable file (~.exe) transmitted by an external terminal (3) may be a malicious executable file (~.exe) for phishing or a normal executable file (~.exe).

[0076] Since the maliciousness of an executable file (~.exe) transmitted by an external terminal (3) is determined through precise analysis, it is difficult to immediately determine whether the executable file (~.exe) transmitted by the external terminal (3) is a malicious file during a short call with the external terminal (3). Therefore, in preparation for the case where the executable file (~.exe) transmitted by the external terminal (3) is a malicious phishing file capable of turning the user terminal (2) into a zombie phone, the phishing prevention app (1) considers the transmitted file as a suspected phishing file if the file transmitted from the external terminal (3) is an executable file (~.exe).

[0077] That is, if the transmitted file is an executable file (~.exe), the phishing prevention app (1) immediately terminates the call with the external terminal (3) by considering the transmitted file as a suspected phishing file. Of course, the transmitted executable file (~.exe) may not be a malicious phishing file, but the call with the external terminal (3) is terminated in case the executable file (~.exe) transmitted by the external terminal (3) turns out to be a malicious file.

[0078] In voice phishing crimes, a zombie phone refers to a phone in which a malicious executable file (~.exe) is installed on a user terminal (2), and the user terminal (2) is placed under the control of an external terminal (3) used by a phishing criminal. When the user terminal (2) becomes a zombie phone, the phishing criminal remotely controls the user terminal (2) that has become a zombie phone to illegally obtain various personal information of the user from the user terminal (2) and illegally withdraw money from the user's financial account or use it for fraudulent loans.

[0079] After the phishing criminal transmits an executable file (~.exe), which is a malicious file capable of turning the user terminal (2) into a zombie phone, to the user terminal (2) of the target user, the criminal induces the user terminal (2) and the phishing criminal's own terminal (external terminal (3)) to remain in a call state until the executable file (~.exe) is fully installed on the user terminal (2).

[0080] In other words, the phishing criminal maintains the call status by citing various reasons to prevent the target user from hanging up the phone until the phishing executable file (~.exe) is fully installed on the user terminal (2). This is to stall for time until the phishing executable file (~.exe) is fully installed on the user terminal (2), as the user terminal (2) cannot be turned into a zombie phone if the call is disconnected while the phishing executable file (~.exe) is being installed on the user terminal (2).

[0081] Therefore, if the transmitted file is an executable file (~.exe), the executable file (~.exe) is initially considered a suspected phishing file, and the phishing prevention app (1) immediately forcibly terminates the call with the external terminal (3) to prevent the transmitted executable file (~.exe) from being fully installed on the user terminal (2). In other words, the communication connection is blocked before the installation of the executable file (~.exe) is complete, thereby preventing the user terminal (2) from becoming a zombie phone.

[0083] Additionally, if the received text message contains link information as a result of the check in the third step (S300), the phishing prevention app (1) prevents the user terminal (2) from accessing the internet site corresponding to the link even if the user selects the link, and then, once the safety of the link is confirmed, it lifts the blocking of access to the internet site corresponding to the link.

[0084] In the case of smishing crime, the phishing criminal steals the phone number of an acquaintance of the target user and sends a text message containing link information (e.g., a obituary text message) to the user terminal (2). When the link information included in the text message is selected, the user terminal (2) is automatically connected to a phishing internet site, and a malicious phishing file is automatically transmitted from the phishing internet site to the user terminal (2), so that the user terminal (2) becomes a zombie phone that can be remotely controlled by the phishing criminal.

[0085] The user selects the link information included in the text message without thinking because it is a text message received from an acquaintance's phone number, and as a result, the user terminal (2) becomes a zombie phone that can be remotely controlled by a phishing criminal.

[0086] The link information included in the received text message may or may not be a malicious link intended for phishing. In this case, since the maliciousness of the link information is determined through a detailed analysis that takes time, it is difficult to determine immediately upon receiving the text message. Therefore, in preparation for the case where the link information included in the received text message is a malicious link intended for phishing that can turn the user terminal (2) into a zombie phone, the phishing prevention app (1) prevents the user terminal (2) from connecting to the internet site corresponding to the link, even if the user has selected the link, if the received text message contains link information.

[0087] After preventing the user terminal (2) from accessing the internet site corresponding to the link, once the safety of the link is confirmed, the blocking of access to the internet site corresponding to the link is lifted so that the user can access the internet site corresponding to the link through the link information and obtain necessary information.

[0088] Specifically, the anti-phishing app (1) prevents the user terminal (2) from accessing the internet site corresponding to the link, then provides the link information to an external security diagnostic agency to diagnose the safety of the link, and if the diagnosis result indicates that the link is safe, it displays a notification message on the screen indicating that the link is safe and simultaneously lifts the blocking of access to the internet site corresponding to the link so that the user can access the internet site corresponding to the link through the link information to obtain necessary information, and if the diagnosis result indicates that the link is not safe (if the link is a malicious link for phishing), it displays a notification message on the screen indicating that the link is unsafe and simultaneously maintains the blocking of access to the internet site corresponding to the link so that even if the user selects the link again in the future, the user terminal (2) will not access the internet site corresponding to the link, thereby preventing the user terminal (2) from becoming a zombie phone.

[0090] Meanwhile, even if the above-mentioned anti-phishing app (1) forcibly terminates the call with the external terminal (3) through the above-mentioned fourth step (S500), there may be cases where a phishing criminal attempts to make a call again for phishing purposes. If the external terminal (3) whose call was forcibly terminated attempts to make a call again for phishing purposes, it is necessary to block the user from receiving the incoming call at the source.

[0091] Additionally, the call with the external terminal (3) is forcibly terminated, and the transmitted executable file (~.exe) may not be executed on the user terminal (2) but may remain in an unexecuted state in the terminal storage space. In this case, since there is a risk of phishing damage occurring if the user carelessly executes the file later, even though the executable file (~.exe) remaining in an unexecuted state is a malicious executable file for phishing, it is necessary to warn the user about executing the file.

[0092] To this end, the present invention is characterized by further including a fifth step (S500) in which, after the forced termination of a call with an external terminal (3) through the fourth step (S400) as illustrated in FIG. 1, the anti-phishing app (1) blocks a call from the same external terminal (3) that forcibly terminated the call for a certain period of time, diagnoses whether a suspected phishing file transmitted during the blocking time is malicious, and if the diagnosis result indicates that the suspected phishing file is a malicious file for phishing, it displays a warning message prohibiting the execution of the file transmitted on the screen of the user terminal (2) and maintains the blocking of the call from the external terminal (3) that forcibly terminated the call, and if the diagnosis result indicates that the suspected phishing file is not a malicious file for phishing, it releases the blocking of the call from the external terminal (3) that forcibly terminated the call.

[0094] Specifically, the anti-phishing app (1) forcibly terminates a call with an external terminal (3), remembers the phone number of the external terminal (3) from which the call was forcibly terminated, and, as shown in FIG. 2, blocks incoming calls from the external terminal (3) with the remembered phone number for a certain period of time (e.g., 5 minutes).

[0095] At this time, the phishing prevention app (1) diagnoses whether the suspected phishing executable file (~.exe) is malicious during the blocking time. The phishing prevention app (1) of the present invention has a diagnostic function capable of diagnosing whether the executable file (~.exe) is a malicious phishing file. Therefore, after the call with the external terminal (3) is forcibly terminated, the phishing prevention app (1) diagnoses whether the suspected phishing executable file (~.exe) is malicious during the blocking time.

[0096] If, as a result of diagnosis, the suspected phishing executable file (~.exe) is a malicious file for phishing, a warning message prohibiting the execution of the file transmitted to the user terminal (2) screen is displayed as shown in FIG. 2 to prevent the user from carelessly executing the executable file, thereby preventing phishing damage caused by careless file execution, and at the same time, the call blocking from the external terminal (3) that forcibly terminated the call is maintained to prevent phishing attempts from the external terminal (3) that forcibly terminated the call.

[0097] Meanwhile, if the diagnosis result indicates that the suspected phishing executable file (~.exe) is not a malicious phishing file, the call blocking from the external terminal (3) that forcibly terminated the call is released. Since the fact that the suspected phishing executable file (~.exe) is not a malicious phishing file means that the user of the external terminal (3) that forcibly terminated the call is not a phishing criminal, the call blocking from the external terminal (3) is released so that normal calls with the external terminal (3) can be made thereafter.

[0100] Through the phishing prevention method using the phishing prevention app of the first embodiment of the present invention described above, not only is it possible to prevent damage caused by phishing crimes by blocking the user's smartphone from becoming a zombie phone through voice phishing or smishing by phishing criminals, but also to automatically protect vulnerable groups unfamiliar with smartphone usage, such as the elderly or people with disabilities, from phishing crimes without any separate operation or judgment.

[0102] Hereinafter, a phishing prevention application stored in a storage medium of a user terminal for execution on a user terminal, which is a second embodiment of the present invention, will be described.

[0103] A phishing prevention application stored in a storage medium of a user terminal according to a second embodiment of the present invention is, as illustrated in FIG. 3,

[0104] A first detection unit (100) that checks whether the user terminal (2) is in a call with an external terminal (3) of a phone number other than the phone number stored in the user terminal (2), and if in a call, provides a call detection signal to the file transmission detection unit (200), and checks whether a text message has been received at the user terminal (2) with the phone number stored in the user terminal (2), and if received, provides a text message reception signal to the file transmission detection unit (200);

[0105] A second detection unit (200) that checks whether there is a file transmission from an external terminal (3) during a call when a call detection signal is provided from the first detection unit (100), and if there is a file transmission, provides the transmitted file information to the phishing prevention unit (300), and when a text message reception signal is provided from the first detection unit (100), checks whether the received text message contains link information, and if there is link information, provides the corresponding link information to the phishing prevention unit (300);

[0106] The invention is characterized by including a phishing prevention unit (300) that checks whether a file provided by the second detection unit (200) is a suspected phishing file, and if it is a suspected phishing file, immediately forcibly terminates the call with the external terminal (3), prevents the user terminal (2) from connecting to the internet site corresponding to the link even if the user selects the link information provided by the second detection unit (200), and then, when the safety of the link is confirmed, releases the blocking of access to the internet site corresponding to the link.

[0108] The above phishing prevention unit (300) is characterized by determining that if the file provided by the file transfer detection unit (200) is an executable file (~.exe), the file is a suspected phishing file.

[0110] The above phishing prevention unit (300) is characterized by preventing the user terminal (2) from accessing the internet site corresponding to the link, providing the link information to an external security diagnostic agency to diagnose the safety of the link, and if the diagnosis result is a safe link, displaying a notification message on the screen that the link is safe and simultaneously lifting the blocking of access to the internet site corresponding to the link, and if the diagnosis result is not a safe link, displaying a notification message on the screen that the link is not safe and simultaneously maintaining the blocking of access to the internet site corresponding to the link.

[0112] The above phishing prevention unit (300) is characterized by blocking call calls from the same external terminal (3) that forcibly terminated the call after forcibly terminating a call with the external terminal (3) for a certain period of time, and during the blocking time, diagnosing whether the transmitted suspected phishing file is malicious, and if the diagnosis result indicates that the suspected phishing file is a malicious file for phishing, displaying a warning message prohibiting the execution of the transmitted file on the screen of the user terminal (2) and maintaining the blocking of call calls from the external terminal (3) that forcibly terminated the call, and if the diagnosis result indicates that the suspected phishing file is not a malicious file for phishing, releasing the blocking of call calls from the external terminal (3) that forcibly terminated the call.

[0114] The second detection unit (200) displays an emergency button icon on the screen of the user terminal (2) when a call detection signal is provided from the first detection unit (100), and when the emergency button icon is selected during a call, provides an emergency detection signal to the phishing prevention unit (300). The phishing prevention unit (300) is characterized by converting the voice call content between the user terminal (2) and the external terminal (3) into text in real time and sending the text message in real time to the terminal of the pre-registered phone number when the voice call content text is provided from the second detection unit (200), and displaying the text message sent by the terminal to which the text message was sent on the screen of the user terminal (2).

[0116] The functional features of the phishing prevention application, which is the second embodiment of the present invention and comprises the first detection unit (100), the second detection unit (200), and the phishing prevention unit (300), are identical to the functional features of the phishing prevention app (1) described in the first embodiment of the present invention.

[0117] Accordingly, as the description of the functional features of the first detection unit (100), the second detection unit (200), and the phishing prevention unit (300) has already been described in the first embodiment of the present invention, the detailed description of the functional features of the first detection unit (100), the second detection unit (200), and the phishing prevention unit (300) is omitted.

[0119] Although the technical concept of the present invention has been described above together with the accompanying drawings, this is merely an illustrative description of preferred embodiments of the present invention and is not intended to limit the invention. It is obvious that the scope of the rights of the present invention is not limited to the embodiments but includes modifications made by those skilled in the art within the scope of the technical concept of the present invention. Explanation of the symbols

[0121] 1 : Anti-phishing app 2 : User terminal 3 : External terminal 100 : First detection unit 200 : Second detection unit 300 : Anti-phishing section

Claims

Claim 1 A method for preventing phishing using a phishing prevention app, comprising: a first step (S100) in which a phishing prevention app (1) is installed on a user terminal (2); a second step (S200) in which the phishing prevention app (1) checks whether the user terminal (2) is in a call with an external terminal (3) with a phone number other than the phone number stored in the user terminal (2) or whether a text message has been received on the user terminal (2) with a phone number stored in the user terminal (2); a third step (S300) in which, if the result of the check through the second step (S200) indicates that the user is in a call, the phishing prevention app (1) checks whether there is a file transmission from the external terminal (3) during the call, and if a text message has been received, the phishing prevention app (1) checks whether the received text message contains link information; and, if the result of the check through the third step (S300) indicates that there is a file transmission from the external terminal (3), the phishing prevention app (1) checks whether the transmitted file is a suspected phishing file, and if it is a suspected phishing file, immediately with the external terminal (3) A fourth step (S400) of forcibly terminating a call, and if the received text message contains link information, preventing the user terminal (2) from accessing the internet site corresponding to the link even if the user selects the link, and then, once the safety of the link is confirmed, lifting the blocking of access to the internet site corresponding to the link;A phishing prevention method characterized by including a fifth step (S500) in which, after forcibly terminating a call with an external terminal (3) through the fourth step (S400), the phishing prevention app (1) blocks a call from the same external terminal (3) that forcibly terminated the call for a certain period of time, diagnoses whether a suspected phishing file transmitted during the blocking period is malicious, and if the diagnosis result indicates that the suspected phishing file is a malicious phishing file, it displays a warning message prohibiting the execution of the transmitted file on the screen of the user terminal (2) and simultaneously maintains the blocking of call calls from the external terminal (3) that forcibly terminated the call, and if the diagnosis result indicates that the suspected phishing file is not a malicious phishing file, it releases the blocking of call calls from the external terminal (3) that forcibly terminated the call. Claim 2 A phishing prevention method according to claim 1, wherein in the fourth step (S400), the phishing prevention app (1) determines that the transmitted file is a suspected phishing file if the transmitted file is an executable file (~.exe). Claim 3 A method for preventing phishing according to claim 1, wherein in the fourth step (S400), the phishing prevention app (1) prevents the user terminal (2) from accessing the internet site corresponding to the link, provides the link information to an external security diagnostic agency to diagnose the safety of the link, and if the diagnosis result is a safe link, displays a notification message on the screen indicating that the link is safe and simultaneously lifts the blocking of access to the internet site corresponding to the link, and if the diagnosis result is not a safe link, displays a notification message on the screen indicating that the link is not safe and simultaneously maintains the blocking of access to the internet site corresponding to the link. Claim 4 delete Claim 5 A phishing prevention method according to claim 1, wherein the third step (S300) further comprises the step of, if the result of the check through the second step (S200) is that a call is in progress, the phishing prevention app (1) displays an emergency button icon on the screen of the user terminal (2), and if the emergency button icon is selected while the call is in progress, the phishing prevention app (1) converts the voice call content between the user terminal (2) and the external terminal (3) into text in real time and transmits the text message in real time to the terminal of a pre-registered phone number, and displays the text message transmitted by the terminal to which the text of the voice call content was transmitted on the screen of the user terminal (2). Claim 6 In a phishing prevention application stored on a storage medium of a user terminal, the first detection unit (100) checks whether the user terminal (2) is in a call with an external terminal (3) with a phone number other than the phone number stored in the user terminal (2), and if in a call, provides a call detection signal to a file transmission detection unit (200), and checks whether a text message has been received by the user terminal (2) with the phone number stored in the user terminal (2), and if received, provides a text message reception signal to a file transmission detection unit (200); and when a call detection signal is provided from the first detection unit (100), checks whether there is a file transmission from the external terminal (3) during the call, and if there is a file transmission, provides transmitted file information to a phishing prevention unit (300), and when a text message reception signal is provided from the first detection unit (100), checks whether the received text message contains link information, and if there is link information, provides the corresponding link information to a phishing prevention unit (300).The second detection unit (200) checks whether the file provided is a suspected phishing file, and if it is a suspected phishing file, immediately forcibly terminates the call with the external terminal (3), and prevents the user terminal (2) from accessing the internet site corresponding to the link even if the user selects the link in the link information provided by the second detection unit (200), and then, when the safety of the link is confirmed, releases the blocking of access to the internet site corresponding to the link. The phishing prevention unit (300) is characterized by, after forcibly terminating the call with the external terminal (3), blocking a call from the same external terminal (3) that forcibly terminated the call for a certain period of time, and during the blocking time, diagnosing whether the transmitted suspected phishing file is malicious, and if the diagnosis result indicates that the suspected phishing file is a malicious file for phishing, displaying a warning message prohibiting the execution of the transmitted file on the screen of the user terminal (2) and simultaneously maintaining the blocking of the call from the external terminal (3) that forcibly terminated the call, and if the diagnosis result indicates that the suspected phishing file is not a malicious file for phishing, releasing the blocking of the call from the external terminal (3) that forcibly terminated the call. An anti-phishing application stored on a storage medium of a user terminal. Claim 7 An application for preventing phishing stored on a storage medium of a user terminal, wherein, in claim 6, the phishing prevention unit (300) determines that the file provided by the file transmission detection unit (200) is an executable file (~.exe) and that the file is a suspected phishing file. Claim 8 In claim 6, the phishing prevention unit (300) prevents the user terminal (2) from accessing the internet site corresponding to the link, then provides the link information to an external security diagnostic agency to diagnose the safety of the link, and if the diagnosis result is a safe link, displays a notification message on the screen indicating that the link is safe and simultaneously lifts the blocking of access to the internet site corresponding to the link, and if the diagnosis result is not a safe link, displays a notification message on the screen indicating that the link is not safe and simultaneously maintains the blocking of access to the internet site corresponding to the link. This describes a phishing prevention application stored in a storage medium of a user terminal. Claim 9 delete Claim 10 An application for preventing phishing stored in a storage medium of a user terminal, wherein, in claim 6, the second detection unit (200) displays an emergency button icon on the screen of the user terminal (2) when a call detection signal is provided from the first detection unit (100), and when the emergency button icon is selected during a call, provides an emergency detection signal to the phishing prevention unit (300), and when an emergency detection signal is provided from the second detection unit (200), the phishing prevention unit (300) converts the voice call content between the user terminal (2) and the external terminal (3) into text in real time and transmits the text in real time to a terminal of a pre-registered phone number, and displays the text message transmitted by the terminal to which the text of the voice call content was transmitted on the screen of the user terminal (2).

Citation Information

Patent Citations

  • A system and method for protecting from hacking of mobile terminal

    KR1020150084218A

  • Smishing message monitoring method and smishing level determination method

    KR1020210127117A

  • Voice phishing preventing mehtod and voice phishing preventing apparatus

    KR1020220056018A

  • Method for preventing voice phishing

    KR1020240120887A