Method for managing internet browsing on a terminal

The method enhances Internet browsing security by using predictive models to generate trust scores based on site metrics, enabling real-time protection against impersonation and phishing attacks without compromising user confidentiality.

WO2025103982A1PCT designated stage expired Publication Date: 2025-05-22ORANGE SA
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
PCT/EP2024/081957
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-11-15
Filing Date
2024-11-12
Publication Date
2025-05-22

AI Technical Summary

Technical Problem

Existing security measures for Internet browsing are not fully effective in preventing users from navigating to sites that impersonate legitimate sites, as they rely on centralized servers that can be slow to detect and block such sites, and may compromise user confidentiality.

Method used

A method for managing Internet browsing that involves obtaining metrics from a target site and using a predictive model, possibly hosted externally, to generate a trust score. This score is used to determine actions such as blocking navigation or warning the user, without requiring centralized lists of suspicious sites.

Benefits of technology

The method provides real-time protection against dangerous sites by analyzing site metrics at the time of access, reducing the risk of phishing and site impersonation, while maintaining user confidentiality by not revealing browsing history or site identities to external servers.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure EP2024081957_22052025_PF_FP_ABST
    Figure EP2024081957_22052025_PF_FP_ABST
Patent Text Reader

Abstract

The invention relates to a method for managing Internet browsing on a terminal implemented by a management entity (100), the method comprising the following steps: • obtaining metrics (FTR) for an Internet site, referred to as the target site (S1, S2, S3), to which access is requested by the terminal (DVC); • obtaining a trust score (SCR) relating to the target site (S1, S2, S3), wherein the trust score is at least partially obtained by a device (SVR) external to the terminal (DVC); • performing an action (ACT) relating to Internet browsing on the terminal (DVC) on the basis of the obtained trust score (SCR).
Need to check novelty before this filing date? Find Prior Art

Description

Method for managing Internet browsing on a terminal

[0001] The technical area is that of Internet navigation.

[0002] More specifically, the invention relates to a method for securing Internet browsing on a terminal. The terminal in question may be any terminal used to browse the Internet via an Internet browser. Possible terminals for browsing the Internet include computers, whether portable or desktop, but also smartphones, or larger terminals, such as touchscreen tablets or phablets, or smaller terminals, such as smartwatches or any other connected object. The terminal may also be the on-board computer of a vehicle, for example a connected car.The terminal can also be a games console, connected to the Internet via a home network, or an in-flight entertainment system offered to passengers of a vehicle such as an airplane, boat, train, coach, taxi or private car.

[0003] One of the most common attacks in the Internet browsing field is phishing users through an attacker's website that mimics a legitimate website. In this attack, a user will be led by any means, for example, an email containing a link, to connect to a website, called the attacker's site. For example, the email will contain a message stating that the reader has to pay a bill, or has won a gift, or some other enticing information, which will lead the user to click on the link contained in the email, which triggers the navigation of their Internet browser to the link contained in the email.The attacking site, which the user is encouraged to navigate, imitates the website of a legitimate organization, for example the website of a bank, a telecommunications operator, a commercial site or any other possible site. We can also speak of a trusted site, for the site of such a legitimate organization. Once on the attacking site, while believing he is browsing a trusted website, the user will provide information, for example a credit card number, believing he is providing it to the legitimate organization, whose website the attacking site imitates. The information thus provided can then be used directly by the attacker, for example to carry out banking transactions or identity theft, or will be traded on underground markets where this type of data is negotiated.Phishing attacks can also be used to trick a remote worker into thinking they are logging into their company's website remotely. The remote worker will then provide their credentials to the website, which impersonates their employer's website. The attacker can then use their credentials to log into the company's legitimate website, impersonating the remote worker, and carry out further attacks by gaining direct access to the company's information system. State of the art

[0004] The attack described above has seen the development of several forms of parry.

[0005] The first line of defense is to detect phishing messages. These messages, which encourage the user to connect to the attacking site, can be emails, or SMS messages (Short Message Service) received by mobile phones, or messages from email services such as Messenger, WhatsApp, Telegram or any other service. Detection tools present in the servers transmitting messages between terminals, or present in the terminals themselves, will then focus on detecting phishing messages. These messages will then be either deleted directly, or transmitted to their recipients with very visible warnings urging the user to be wary and not to follow the Internet browsing links present, unless they are sure of the legitimacy of the message.

[0006] Such phishing message detection systems are well established, but are not completely effective. Phishing messages may go undetected, or users may ignore warnings, or users may navigate to attacking sites that impersonate legitimate sites without having been lured to the attacking site by a phishing message. Therefore, there is a need to secure Internet browsing to prevent a user from navigating to a site that impersonates a legitimate site, regardless of protective measures aimed at reducing phishing messages.

[0007] Existing security measures for browsing generally rely on the processing of URLs (Uniform Resource Locators) used for browsing the Internet.

[0008] An attacker building a website that spoofs a legitimate site will start by obtaining an Internet address close enough to that of the legitimate site to fool users. For example, the French Social Security uses the domain name ameli.fr for its website. An attacker will seek the right to use the address amelii.fr to build a website that mimics the legitimate site, and then attract users to this site with phishing messages. Another attack technique will involve registering domain names that contain the spoofed name by surrounding it with other meaningful keywords. For example, also for the French Social Security, the domain payments-ameli.info could be created by attackers.

[0009] Regardless of the domain name chosen by the attacker, one measure to secure browsing is for Internet browsers to use lists of suspicious addresses. Centralized servers analyze suspicious websites, for example by identifying sites linked to by phishing messages, and thus create lists of suspicious sites. The analyses carried out by these servers can use several techniques, including machine learning techniques. These lists can be distributed to browsers, allowing browsers to block their users when they try to go to a suspicious site, or to warn them, depending on the browser's policy and the type of lists created by the server.

[0010] Analysis servers can also respond to a request from a browser, which submits a website address to a server, which can tell it whether the address in question belongs to an already established list, or which will launch a dedicated analysis of the website corresponding to the address submitted by the browser.

[0011] Security measures based on lists of suspicious addresses have several flaws. First, they are not responsive enough. When an attacker prepares a website impersonating a legitimate site, only a few hours will pass between reserving the domain name to obtain an address for the attacking site, deploying the attacking site, and sending the phishing messages. During this very short period, it is likely that the analysis servers, which are primarily looking to analyze all existing websites, will not have started browsing the new domain reserved by the attacker and then analyzing the site impersonating the legitimate site. A server that seeks to analyze suspicious sites and then distribute lists of addresses to browsers to block therefore risks being overtaken by attackers. Speed ​​can be improved if browsers themselves submit the addresses to be analyzed to servers.But this implies that the servers are informed of the Internet addresses to which the browser wishes to go. This poses a confidentiality problem: in fact, the user of the Internet browser may not wish to entrust a third-party server with the Internet address to which he wishes to navigate, even in exchange for information on the security of this address.

[0012] Additionally, when analysis is performed by a server, the server will need to interact with the analyzed site. Attackers who set up a site impersonating a legitimate site can learn to recognize analysis servers. When a site impersonating a legitimate site detects that an analysis server, known to the attackers, has started analyzing it, the impersonating site can implement countermeasures that will complicate the server's analysis work, for example by blocking its requests, delaying them, or presenting the server with a harmless version and not the version dedicated to standard browsers.

[0013] Finally, attackers can set up a seemingly benign site when they purchase a domain name. The analysis servers that will analyze this site will then be deceived. It is when the attackers launch their phishing campaign, by sending messages in large quantities, that they will replace the seemingly benign site with the real attacker's site. This delays the attackers' ability to detect the attack by analysis servers as much as possible.

[0014] The invention improves the situation.

[0015] According to a functional aspect, the invention relates to a method for managing the Internet browsing of a terminal, implemented by a management entity, comprising the following steps: Obtaining metrics of an Internet site, called the target site, to which access is requested by the terminal; Obtaining a trust score relating to the target site from the metrics, obtaining the trust score being at least partly carried out by a device external to the terminal; Action relating to the Internet browsing of the terminal according to the trust score obtained.

[0016] The term "metrics" used here can be translated into English by the term features.

[0017] According to a first mode of implementation, obtaining the confidence score includes an analysis by a predictive model.

[0018] According to another embodiment of the invention, which may be implemented alternatively or cumulatively with the previous embodiment, the management entity is included in an Internet browser executed by the terminal.

[0019] Thanks to the invention, the user of a terminal comprising an Internet browser has protection against dangerous Internet sites during his Internet browsing. This protection is obtained without a centralized server having to distribute lists of addresses of suspicious sites, lists which are then saved by the Internet browsers of the terminals, and used for example to block the user's browsing.

[0020] According to the invention, metrics are obtained from a website and then a trust score relating to the target site is obtained from the metrics. According to one embodiment, the metrics are analyzed by a predictive model in order to obtain the trust score. This model is derived from machine learning. For example, it may be an artificial neural network. Such a model has been learned from website metrics. The same metrics are obtained from a site, called the target site, to which access is requested, i.e. to which a user wishes to go, which results in a request from the user's terminal to this website. Since the prediction model has been trained from the same metrics, it will be able to immediately return a relevant score on the danger of the site to which the user wishes to navigate as soon as the obtained metrics are provided to it.This ensures the protection of the terminal user. Since the model has already learned the characteristics of dangerous websites, and since obtaining metrics is sufficiently fast, our invention has the necessary responsiveness to website spoofing attacks when compared to solutions based on maintaining and updating website addresses.

[0021] Thanks to our invention, the interaction with the website that may be an attacker site is done at the level of the terminal's Internet browser. The latter obtains the website's metrics by looking at its characteristics and performing calculations based on them. In this way, there is no direct interaction between an analysis server and a potentially dangerous site. The dangerous site cannot therefore detect that it is interacting with an analysis server and it will therefore not implement camouflage measures. Obtaining the trust score is at least partly carried out by a device external to the terminal, i.e. by an analysis server, but the interaction with the potentially dangerous site, which corresponds to obtaining metrics, is not done by this analysis server but by the terminal.

[0022] Furthermore, the analysis is performed at the precise moment when access is requested to the target site by the terminal, and not when an analysis server, which browses the Internet, requests it. The analysis is therefore performed at the moment when the user may have been led to request access to the attacking site by a phishing campaign. In the case where the attackers use a seemingly benign site to deceive the analysis servers, our invention resists this countermeasure by the attackers. Indeed, the site that is analyzed in our invention is indeed the one accessed by the user's terminal, and which is therefore potentially dangerous, and not a benign site used to deceive analysis servers before the attack is triggered.

[0023] The fact that obtaining the confidence score is at least partly carried out by a device external to the terminal has the advantage that the performance of our invention is improved. Indeed, a predictive model such as used in an embodiment of our invention cannot be maintained in an Internet browser given its size, and also the necessary frequency of its updating. The model or program making it possible to obtain a score from the metrics is therefore hosted in a remote server to which the management entity, which may itself be present in the Internet browser, will submit website metrics. In such an architecture, where a remote server analyzes websites to answer questions from Internet browsers on the safety or danger of websites, a problem is that of respecting the confidentiality of users' Internet browsing.Indeed, the server from which analyses are requested may be submitted addresses of sites to which users wish to browse, and such submissions may be intercepted by attackers, or the remote server may be hacked. Our solution does indeed use a remote server that will analyze a given website on demand to determine whether it is dangerous or not. But our invention allows this result to be achieved without the user having to provide the addresses of the sites they are browsing. Only the metrics of the target website are submitted to the server, and not the address of the target site itself. The confidentiality of the user's browsing is therefore well respected.

[0024] Another advantage of this distribution of analyses between a management entity included in a terminal's Internet browser and a predictive model (or any other program or part of a program allowing a confidence score to be obtained from the metrics) hosted in a server is to avoid direct interaction between an analysis server and dangerous sites. We have seen that managers of dangerous sites can identify that analysis servers make repeated requests to sites in order to analyze them. In this case, the dangerous sites are camouflaged to avoid being detected. In the architecture proposed in this embodiment, the server does not interact directly with the target site. It is a standard Internet browser that obtains the metrics of the target site by an interaction that cannot be distinguished from the interaction of a browser without analysis capabilities.Once the metrics are obtained, they are submitted to the predictive model hosted on a server. This means that the model does not have to interact directly with the target site, which may be a dangerous site.

[0025] The architecture of this embodiment therefore combines the advantages of centralization for the predictive model (or any other program or part of a program making it possible to obtain a confidence score from the metrics), which makes it possible to have a large model, taking into account a very large number of metrics, which can be updated easily and a decentralization of obtaining the metrics of the target sites, which is done at the level of the Internet browsers, during the standard navigation of the users, which makes it possible to avoid arousing the suspicions of the managers of dangerous sites and which shortens the calculation and obtaining times of the metrics.

[0026] The management entity will most often be included in an Internet browser present in the terminal. For example, it will be a module that uses an extension mechanism provided by the vast majority of available Internet browsers, such as Firefox and Chrome. But it is possible to imagine an architecture in which the management entity is a separate program, hosted in the terminal, and which interacts with the terminal's Internet browser in order to carry out the method of managing the terminal's Internet browsing according to the invention, which secures the Internet browsing of the terminal and its user.

[0027] According to another embodiment of the invention, which may be implemented cumulatively with the first embodiment, the analysis by the predictive model comprises an analysis carried out by a predictive model, called the first model, present in the terminal, and an analysis carried out by another predictive model, called the second model, transferred to a device external to the terminal, the analysis by the second model being carried out as a function of the result of the analysis by the first model.

[0028] In this embodiment, a first model, simpler and smaller, is present in the terminal and performs a first analysis. Depending on the result of this first analysis, a second analysis can be performed by querying a second model, more detailed than the first model and larger. This second model, given its size, is present in a device external to the terminal. The second analysis is performed for example when there is a suspicion that the analyzed site could be malicious, but without total guarantee. The second model, more detailed, then makes it possible to remove the ambiguity that remains after the first analysis.

[0029] With this embodiment, it is possible to combine the advantages of a decentralized mode, in which a small model is present in the terminal browsers, and a more centralized mode, in which a large model is present in a centralized server. The analysis carried out by the model present in the terminal browsers generally makes it possible to give a first rapid response of harmlessness or danger. It is when this first analysis does not make it possible to decide with sufficient certainty that a second analysis is carried out with the second model, transferred to a device external to the terminal.

[0030] According to another embodiment of the invention, which may be implemented alternatively or cumulatively with the previous embodiment, the action relating to Internet browsing of the terminal comprises a display on the terminal of a notice determined according to the data provided representative of a confidence score relating to the target site.

[0031] With this embodiment, a first protective measure consists of alerting the terminal user by displaying a notice relating to the danger of the website to which access is requested. The predictive model will provide a confidence score from the metrics obtained. This confidence score is dependent on the form of the predictive model. If the predictive model is a neural network, for example, it may provide a more or less large real number as a result. Such a real number cannot be presented in a raw form to the user. An opinion must be deduced from it, for example by defining confidence scales grouping score intervals. Opinions can range from "dangerous" to "harmless", possibly with qualifications such as "completely" or "rather". Colors or logos can be used to have a simple presentation of the opinion to the user.It is this notice on the site whose access is requested that the terminal, via the Internet browser, will present to the user so that he is warned of its possible danger or, on the contrary, reassured as to its harmlessness.

[0032] According to another embodiment of the invention, which may be implemented alternatively or cumulatively with the previous embodiments, the action relating to the user's navigation comprises blocking the terminal's Internet navigation.

[0033] With this implementation, the user of the Internet browser is protected during their browsing. This browsing is blocked if the trust score reaches a threshold such that blocking browsing is deemed necessary. In this way, the user is immediately protected from potentially dangerous websites.

[0034] According to another embodiment of the invention, which may be implemented alternatively or cumulatively with the previous embodiments, the target site comprises a form comprising at least one field to be completed and the action relating to Internet browsing of the terminal comprises the deletion of at least part of the form fields present in the target site.

[0035] With this embodiment, the user of the Internet browser is protected during his navigation. Obtaining the metrics of the target site takes a certain amount of time, as does the analysis of these by the predictive model. It is possible to envisage an embodiment of Internet navigation according to the invention in which users will only go to target sites once the analysis of these has been carried out. But the mode that will be most often carried out will consist of obtaining the metrics and analyzing them in parallel with the Internet navigation of the user's terminal. In this mode of analysis and navigation in parallel, it will happen that a user begins to fill in form fields, therefore begins to provide sensitive data, on a site whose analysis of the metrics will reveal that it is dangerous.The action taken by the management entity will then include deleting form fields in an attempt to prevent the user's private data from being provided to the dangerous site. This deletion action may be combined with blocking navigation and warning the user.

[0036] According to another embodiment of the invention, which may be implemented alternatively or cumulatively with the previous embodiments, the confidence score relating to the target site is supplemented by an indication of an Internet site distinct from the target site.

[0037] With this implementation, obtaining a score, potentially achieved by an analysis of the metrics, is supplemented by an analysis that seeks to determine which is the legitimate site that is being usurped when the analysis of the metrics shows that the target site is actually usurping a legitimate site. The proposal of the legitimate site will thus make it possible to redirect the user's navigation to the correct site. A site that is not necessarily the usurped site but a harmless site can be proposed in addition to the analysis even if it does not discover the legitimate site usurped by the target site.

[0038] According to another embodiment of the invention, which may be implemented alternatively or cumulatively with the previous embodiments, the analysis comprises a screenshot of a page of the target site, the extraction of images from the screenshot and the analysis of the extracted images by an image recognition algorithm.

[0039] Thanks to this embodiment, the determination of the usurped legitimate site is facilitated. This determination will be based on analyses of images extracted from the target site. In particular, one or more screenshots of the target site will then make it possible to extract images present in it. Among these extracted images, in the case of a site usurping the identity of a legitimate site, we will find images imitating or copying images such as logos present or expected on the legitimate site. An image recognition algorithm trained on a base of images present on legitimate sites, such as the logos of the institutions owning the sites in question for example, will then be able to recognize the images extracted from the screenshot(s) as copies or imitations of these logos. Once this recognition is successful, it is then easy to say which is the legitimate site usurped by the target site.The legitimate site can then be offered to the user to continue browsing to the site they actually want to access, even though they had been guided to an attacking site by a phishing message.

[0040] According to another embodiment of the invention, which may be implemented alternatively or cumulatively with the previous embodiments, the screenshot of a page of the target site is subject to a request for authorization from the user.

[0041] Transferring a screenshot of the target site can pose a privacy issue for the user's browsing that the transfer of metrics does not. With this implementation, this functionality is subject to user authorization in order to preserve this privacy or, at least, to ensure that the user is informed of this transfer.

[0042] According to another embodiment of the invention, which may be implemented alternatively or cumulatively with the preceding embodiments, at least one of the metrics is obtained from at least one piece of information among the following categories of information: Information relating to the Internet address of the target site; Information relating to the past navigation of the terminal; Information relating to the contents of the pages of the target site, before or after rendering and execution of code contained in the target site; Reputation information obtained from external services; Information relating to the cryptographic certificates used by the target site.

[0043] With this embodiment, all categories of information that can signal the dangerousness of a site are exploited. A large number of metrics can be obtained from the information in these categories. A predictive model, for example a neural network, can then be learned by a supervised learning method, for example, that is to say that the metrics corresponding to sites known to be dangerous are provided as input to the learning of the predictive model, with the additional information that these metrics are obtained from a dangerous site.

[0044] According to another embodiment of the invention, which may be implemented alternatively or cumulatively with the previous embodiments, the predictive model is enriched with metrics obtained and other information relating to the target site.

[0045] With this implementation, the predictive model is enriched by user browsing. Management entities present in Internet browsers can transmit to the predictive model the metrics they collect as they browse the Internet. Users can also be asked for opinions regarding the safety and danger of the websites they browse. All of this information, namely the site metrics and the associated opinions, can then enrich the predictive model and refine its opinions thanks to this large amount of data.

[0046] According to a first material aspect, the invention relates to a management entity capable of carrying out a method for managing the Internet browsing of a terminal comprising the following modules: Module for obtaining metrics of an Internet site, called the target site, to which access is requested by the terminal; Module for obtaining a confidence score relating to the target site from the metrics obtained, the obtaining of the confidence score being at least partly carried out by a device external to the terminal; Module for action relating to the Internet browsing of the terminal according to the confidence score obtained.

[0047] It should be noted that in this text, the terms "module" or "entity" can correspond to a software component as well as to a hardware component or to a set of hardware and software components, a software component itself corresponding to one or more computer programs or sub-programs or, more generally, to any element of a program capable of implementing a function or a set of functions as described for the modules concerned. In the same way, a hardware component corresponds to any element of a hardware assembly capable of implementing a function or a set of functions for the module concerned (integrated circuit, smart card, memory card, etc.).

[0048] The management entity comprises a module for obtaining a confidence score from the metrics of the target site. This obtaining is at least partly transferred to a device external to the terminal, in other words hosted by a remote server. In embodiments, obtaining the confidence score is carried out by an analysis using a predictive model, and this model is, at least in part, transferred to the remote server. In this case, the obtaining module included in the management entity will then at least carry out the transmission of the metrics and the reception of the confidence score. The rest of the analysis is then transferred to a device external to the terminal.

[0049] According to another material aspect, the invention relates to a terminal comprising a management entity according to the invention.

[0050] The terminal referred to here may be any type of terminal that includes an Internet browser. This may include computers, laptops or desktop computers, but also smartphones, or larger terminals, such as tablets or phablets, or smaller terminals, such as smartwatches or any other connected object. The terminal may also be the on-board computer of a vehicle, for example a connected car. The management entity may then be a component of the terminal's Internet browser, or a separate program that communicates with the Internet browser, inside the terminal, using, for example, a software bus or any other communication element of the terminal.

[0051] According to another material aspect, the invention relates to a computer program capable of being implemented by a terminal, the program comprising code instructions which, when executed by a processor, carry out the steps of the management method defined above.

[0052] Finally, according to another material aspect, the invention relates to a data medium on which is recorded a computer program comprising sequences of instructions for implementing the management method defined above.

[0053] The data carriers may be any entity or device capable of storing the programs. For example, the carriers may comprise a storage means, such as a ROM, for example a CD ROM or a microelectronic circuit ROM, or a magnetic recording means such as a hard disk. On the other hand, the carriers may be transmissible media such as an electrical or optical signal, which may be conveyed via an electrical or optical cable, by radio or by other means. The programs according to the invention may in particular be downloaded from a network such as the Internet. Alternatively, the information carrier may be an integrated circuit in which the program is incorporated, the circuit being adapted to execute or to be used in the execution of the method in question. Brief description of the figures

[0054] The invention will be better understood on reading the following description, given by way of example, and made with reference to the appended drawings in which:

[0055] represents a terminal and an Internet browser comprising a management entity according to the invention, used when a user browses the Internet.

[0056] illustrates an example of steps implemented within the framework of an embodiment of the invention.

[0057] represents a terminal and an Internet browser comprising a management entity according to the invention, having a different architecture than that of the. Detailed description

[0058] The figure represents an example of an embodiment of the invention among those possible.

[0059] In this example, a DVC terminal including a BWR Internet browser is described. The term "browser" is chosen as a translation of the English browser. The BWR browser itself includes a management entity 100. The management entity 100, in other embodiments, may be a program separate from the BWR browser, which communicates with it. It is also possible to imagine an embodiment in which the management entity 100 is not included in the DVC terminal, but receives the information necessary for executing the management method from the BWR browser. For example, a management entity 100 could be deployed in a home gateway and carry out the management method for all the DVC terminals present in the local network of the home gateway.

[0060] The management entity 100 itself comprises three modules: Module 101 is a module for obtaining website metrics. Module 102 is a module for obtaining a confidence score. In the example shown here, obtaining the confidence score is done by analyzing metrics using a predictive model. Obtaining the confidence score is partly carried out by an SVR device external to the DVC terminal. Module 103 is a module for performing an action relating to the navigation of the DVC terminal on a website.

[0061] This is an exemplary embodiment of the invention in which the management entity 100 is included in the BWR browser. Most browsers provide an extension mechanism that allows the basic functions of an Internet browser to be supplemented by other functionalities. The management entity 100 may be an extension of the BWR Internet browser and will then be included therein. In other embodiments, the management entity 100 is a program running in the DVC terminal and which communicates with the BWR Internet browser to carry out the steps of the method according to the invention. In other embodiments, the management entity 100 runs outside the DVC terminal and carries out the management method by communicating with it.

[0062] The DVC terminal has the hardware architecture of a conventional computer. It includes a processor, RAM and read-only memory such as Flash or ROM (memory not shown in the figure) as well as input-output devices such as keyboards and / or screens (not shown in the figure). The DVC terminal can be a desktop or laptop computer, a smartphone, a touchscreen tablet or a phablet, or a connected object such as a connected watch. The DVC terminal can also be the on-board computer of a motor vehicle, or a multimedia system embedded in a vehicle, i.e. an in-flight entertainment system for passengers, for example in a car, but also in an airplane, a coach, a train, or a ship.The DVC terminal can also be a game console or any other equipment that can perform functions similar to the equipment mentioned above.

[0063] In any case, the DVC terminal includes a BWR Internet browser. This is a program that allows the user of the DVC terminal to access a website and interact with it. The BWR browser displays to the user, via the screen of the DVC terminal, the content of a website. The user can then provide, via the input devices of the DVC terminal such as a keyboard or a touch screen with a virtual keyboard, or by voice commands picked up by a microphone of the terminal, data that is addressed to the website. The management entity 100 can be included in the BWR browser, for example by using an extension mechanism, or can be a program running in the DVC terminal in parallel with the BWR browser, or a program running outside the DVC terminal, managing the management process for several terminals in parallel.For example, the management entity 100 may be a program running in an access gateway and carrying out the method according to the invention for all the DVC terminals present in the local network created by the access gateway.

[0064] In the example shown in the figure, the DVC terminal can connect to a NET communication network. This NET communication network can be, for example, the Internet. It is via the NET communication network that the BWR Internet browser can interact with Internet sites. Three Internet sites S1, S2, S3 are shown in the figure. In general, the interaction of the BWR browser with the sites S1, S2, S3 is done using the HTTP protocol (acronym for Hypertext Transfer Protocol), but other protocols can also be used.

[0065] The management entity 100 interacts with an MDL predictive model. In the exemplary embodiment of the invention presented in the, the MDL predictive model is hosted by an SRV device external to the DVC terminal. The SRV device will for example be a computer server. In all cases, it will have the hardware architecture of a conventional computer. It may also be a virtual machine running in a cloud computing system or a set of one or more containers comprising the programs and data necessary to run the MDL predictive model. The management entity 100 can use the NET communication network to interact with the SRV device and thus with the MDL predictive model.The management entity 100 may also use a network separate from the NET network, for example a virtual private network (Virtual Private Network) in order to ensure better confidentiality and security for communications between the DVC terminal and the SVR device.

[0066] An advantage of the architecture presented in the is to be able to have a large MDL predictive model, and therefore able to take into account a large number of parameters. It would not be efficient for such a large MDL predictive model to be distributed in all the BWR Internet browsers comprising a management entity 100 carrying out the method according to the invention. By maintaining a centralized MDL predictive model, hosted in an SRV server, the question of the size of the MDL model does not have to be taken into account. In addition, the centralized architecture described makes it possible to avoid developing a mechanism for distributing the MDL predictive model as well as an update mechanism in order to ensure that it is always relevant.

[0067] In other exemplary embodiments, the MDL predictive model may be present in the DVC terminal. For example, the MDL model may be a module of the management entity 100. This solution has the advantage of facilitating the interrogation of the MDL predictive model by the management entity 100 in comparison to the architecture represented in which the MDL predictive model is hosted by an SRV server. In other exemplary embodiments, the management entity 100 uses several prediction models which may be present in the DVC terminal or in a separate SVR device.

[0068] The method according to the invention is carried out by the management entity 100 during Internet browsing by the user of the DVC terminal via the BWR browser included in the DVC terminal.

[0069] During this navigation, the BWR browser will interact with a website such as S1, S2, S3. This interaction allows the module 101 of the management entity 100 to obtain a whole set of FTR metrics (features) from a site that the user seems to want to visit. The FTR metrics are obtained from information relating to the interaction according to the http protocol with the sites S1, S2, S3. These FTR metrics will then be submitted to the MDL predictive model.

[0070] For example, FTR metrics are obtained from the address of the site S1, S2, S3, also called URL (acronym for Uniform Resource Locator). The FTR metrics obtained from the URL of the site S1, S2, S3 are for example the following: Total length of the URL; Average length of the different words in the URL; Presence or not of a subdomain in the URL; Depth, total length, average length of words, number of hyphens and number of digits present in the subdomain; Depth, total length, average length of words, number of hyphens and number of digits present in the domain; Presence of a path in the URL; Depth, total length, average length of words, number of hyphens and number of digits present in the path; Presence of parameters in the URL.

[0071] The skilled person will know the meanings of the terms domain, subdomain, path, and parameters in this context. To give an example, in the following URL:

[0072] http: / ventes.orange.fr / exemple / client?terminal=phone

[0073] the string "orange" is the domain; the string "fr" is the top-level domain (TLD); the string "sales" is the subdomain; the string "example / client" is the path; and the string "terminal=phone" indicates the presence of a "terminal" parameter that takes the value "phone".

[0074] Furthermore, the string "http" indicates that the protocol for interacting with the website is the HTTP protocol and not another protocol such as FTP (acronym for File Transfer Protocol) or HTTPS (encrypted version of the HTTP protocol).

[0075] FTR metrics obtained from the URL of the visited site are indicative of site addresses that are being circumvented, that seek to hide certain elements, or that seek to obtain unusual parameters, which is indicative of a phishing site seeking to impersonate a legitimate site.

[0076] Other FTR metrics can be obtained from the URL of the visited site than those presented above which are only non-limiting examples.

[0077] Other FTR metrics are obtained from data relating to the user's past navigation. For example, an FTR metric obtained is the number of redirects that led to the website S1, S2, S3 that will be analyzed. These redirects can be caused either by navigation using the HTTP protocol or by instructions in code hosted in the site(s) present on the navigation path. These codes will often be written in JavaScript, but any other language can be used. A high number of redirects can be indicative of concealment of the final addresses to which the user is led by an attacker site. Other FTR metrics obtained from the user's past navigation can be defined.

[0078] Other FTR metrics are obtained from information about the contents of the target site's pages, before or after rendering and execution of code (e.g., Javascript) contained in the target site. Examples of FTR metrics obtained from the contents of the target site's pages include: Presence or name of a TITLE tag, or title tag, in the page; Presence or name of H1 tags, indicating the highest section level, and therefore a title, in the page; Number of SCRIPT tags, i.e., indicating the presence of executable code; Number of SCRIPT tags including resources hosted by the same domain name; Number of SCRIPT tags including resources hosted by different domain names; Number of SCRIPT tags including code contained directly in the target site's page; Number of links to other pages contained in the target site's page; Number of links pointing to pages hosted by the same domain name;Number of links pointing to pages hosted by different domain names; Number of empty or inactive links; Number of IMG tags, i.e. indicating or containing images; Number of IMG tags displaying images hosted by the same domain name; Number of IMG tags displaying images hosted by different domain names; Number of IMG tags displaying images contained directly in the target site page (in base64 format).;

[0079] These metrics reveal the internal structure of the target site's pages S1, S2, and S3. They may indicate that dangerous elements are hidden within this structure, for example, in seemingly harmless images. References to external elements may also indicate a website impersonating a legitimate site, while the legitimate site would only reference elements present within the site itself.

[0080] Other FTR metrics can be obtained from the content of the pages of the visited sites and the FTR metrics defined above which are only possible examples.

[0081] Other FTR metrics are obtained from reputation information provided by external services. For example, services such as Google's search engine, which lists a very large proportion of existing websites and regularly crawls the Internet to detect the appearance of new sites, use algorithms to measure a site's good reputation based on the number of links leading to the site. The results of these measurement algorithms may be made public. This is the case, for example, with Open PageRank, a free service provided by the company DomCop, which provides a figure calculated using the same algorithm used by Google to rank the reputation of sites. Other figures provided by external services can be used as FTR metrics.

[0082] Other FTR metrics can be obtained from the cryptographic certificates used and displayed by the target site. Examples of FTR metrics include: Whether or not TLS encryption (Transport Layer Security, the standard encryption protocol used by websites) is present; Certificate issuer; Certificate age.

[0083] Such FTR metrics can reveal the reputation of the certificate issuer, as well as whether periods of certificate issuer hijacking may have been exploited by attackers to forge false certificates. The very lack of use of TLS is an important clue, as a legitimate site will tend to use a TLS certificate to guarantee its identity.

[0084] Other FTR metrics can be obtained from cryptographic certificates, such as a mismatch between a site address and the certificate present on the site.

[0085] Other types of FTR metrics can be obtained from the information accessible to the management entity 100, and in particular to the module 101 for obtaining FTR metrics, from the visited websites S1, S2, S3.

[0086] We recall that the interaction between the BWR browser and the websites S1, S2, S3 which provides access to this information and therefore makes it possible to obtain the FTR metrics is an interaction similar to that of any Internet browser with a website. This interaction therefore does not allow a potential attacking site among the sites S1, S2, S3 to detect that it is subject to analysis by the BWR browser and the management entity 100. A potential attacking site will therefore not implement concealment measures similar to those it can implement when it detects that a centralized site is carrying out a systematic analysis of the websites to detect attacking sites.

[0087] The 101 module for obtaining FTR metrics obtains FTR metrics either by performing simple calculations or processing from the information accessible from the S1, S2, S3 sites or by querying third-party services, such as Open PageRank or others.

[0088] Once the FTR metrics are obtained, they are provided to the FTR metrics analysis module 102 by an MDL predictive model.

[0089] In the embodiment shown in the, the MDL predictive model is hosted by an SRV device external to the DVC terminal. In other embodiments, the MDL model may be present in the management entity 100, for example as a component of the analysis module 102. In still other embodiments, the MDL predictive model may be a component of the BWR browser or of the DVC terminal. Finally, in other embodiments, the MDL predictive model may be separated into several components: a part of the MDL model may be present in the management entity 100 and perform a first processing of the FTR metrics, then a subsequent processing may be subsequently performed by a component of the MDL model hosted in a remote server. Finally, in other embodiments, several predictive models may be used, which may be present in the DVC terminal or in an SRV device external to the DVC terminal.

[0090] The advantages of these different architectures are as follows: In a centralized architecture, where the MDL model is hosted in the SRV device separate from the DVC terminal, the MDL predictive model can be of a very large size, which would not be manipulable by a component of the BWR browser. In addition, it can be updated easily, without having to set up a protocol for distributing the MDL model to all the DVC terminals or BWR browsers integrating a management entity 100 according to the invention. In a decentralized architecture, where the MDL model is hosted in whole or in part in the management entity 100, the interrogation of the MDL model by the analysis module 102 is done instantaneously. In addition, when the MDL model is hosted in the BWR browser, it is available even in the event of unavailability of the SVR device.

[0091] A possible architecture is to use a predictive MDL model integrated into an SVR device, but that the BWR browsers implementing the invention also have in the management entity 100 a copy of the MDL model which is updated less frequently than the MDL model hosted in the SVR device which can be a centralized server. This copy of the MDL model can then be used in the event of unavailability of the SVR server.

[0092] In all cases, the MDL predictive model is provided as input with the FTR metrics obtained by the module 101 and will provide as output an SCR data representative of a confidence score relating to the Internet site among the sites S1, S2, S3 for which the FTR metrics were obtained.

[0093] The MDL predictive model can be, for example, a neural network that has undergone supervised or unsupervised learning. In supervised learning, a training set is formed of FTR metrics obtained from websites that are known to be legitimate or attacking sites. The training will then make it possible to modify the parameters of the neural network so that, when submitted to it FTR metrics from a website, it can discriminate between those obtained from a legitimate site and those obtained from an attacking site. In unsupervised learning, the FTR metrics obtained from websites are used to train the MDL model without having a verdict on whether the website is safe or not. This makes it possible to include a large number of sites in the training set since a verdict does not have to be given for each site and its associated FTR metrics.These notions of supervised or unsupervised learning of a neural network are well known to neural network specialists and are not detailed further here.

[0094] When the MDL model is a neural network, it is possible to submit to it FTR metrics of the same type as those used for its training and it will be able to discriminate as to the site for which the FTR metrics were obtained. This discrimination results in an SCR confidence score which is then obtained by the analysis module 102.

[0095] The MDL predictive model can be of a different type than a neural network. The MDL model can be, for example, an expert system that uses a set of logical rules to derive the SCR data representative of a trust score for the website for which the FTR metrics were obtained. Such logical rules reflect the reasoning of an expert and must, in general, be created by a dedicated process. For example, such a rule could consist of saying that if, on the one hand, the analyzed website among the sites S1, S2, S3 displays words related to a banking activity, such as "bank", "credit card", "transfer", "payment", "invoice", and on the other hand, the analyzed website does not use any encryption, then the analyzed site is probably an attacker site and not at all the legitimate site of a bank.The FTR metrics to apply this rule would therefore be the presence of certain words in the site on the one hand and the presence of a cryptographic certificate on the other hand and the SCR data would then be a binary result on the dangerousness of the analyzed site.

[0096] It is also possible to use an MDL predictive model, which is a mathematical function calculated from FTR metrics. For example, a linear function may exist between the risk that a site is an attacker and one or more given FTR metrics, such as a reputation figure. Several functions can thus be combined to form the MDL predictive model.

[0097] In general, the MDL predictive model can be built using several techniques from the work of artificial intelligence and machine learning. For example, the MDL model can be formed by an artificial neural network supplemented by a set of rules from an expert system that ensure that particularly relevant information (a very poor reputation score, for example) will not be drowned in the set of FTR metrics used as input to the neural network forming the MDL model.

[0098] An important advantage of the invention is that the MDL predictive model only receives FTR metrics and not the identity of the site visited among the sites S1, S2, S3. Thus, the confidentiality of the user's Internet browsing is preserved even when the MDL predictive model is hosted by an SRV device which is a centralized server. The only information provided to the centralized SRV server is FTR metrics which do not allow the identity of the sites visited to be reconstructed but which still allow the MDL predictive model to provide a diagnosis as to the dangerousness of the site visited.

[0099] The MDL predictive model can be enriched throughout the use of the method according to the invention by the FTR metrics submitted to it associated with other information relating to the site visited among the sites S1, S2, S3.

[0100] Once the analysis module 102 has produced SCR data representative of a confidence score relating to the visited website, the action module 103 will carry out an ACT action relating to Internet browsing to protect the user from a website detected as dangerous.

[0101] The ACT action relating to navigation can be of several types. First of all, in the general case, the SCR data representing a confidence score is such that the action module 103 can deduce therefrom that the site visited among the sites S1, S2, S3 is harmless and, in this case, the ACT action will consist of letting the user's terminal continue its navigation without intervention from the action module 103.

[0102] Another possible ACT action is to display to the user information deduced from the SCR data relating to the confidence score. The MDL predictive model will provide an SCR confidence score from the FTR metrics obtained. This confidence score, or the SCR data representative of this score, depends on the form of the MDL predictive model. If the MDL predictive model is a neural network, for example, it may provide a more or less large real number as a result. Such a real number cannot be presented in a raw form to the user. An opinion must be deduced from it, for example by defining confidence scales grouping score intervals. Opinions can range from "dangerous" to "harmless", possibly with qualifications such as "completely" or "rather". Colors or logos can be used to have a simple presentation of the opinion to the user.It is this notice on the site whose access is requested that the DVC terminal, for example via the BWR Internet browser, will present to the user so that he is warned of its possible danger or, on the contrary, reassured as to its harmlessness.

[0103] Another ACT action possibility is to block the user's navigation. If the SCR data representing the confidence score is sufficiently strong so that the diagnosis of danger of the site among the sites S1, S2, S3 is almost certain, the action module 103 will block navigation on the dangerous site in order to protect the user and prevent them from revealing sensitive data or the DVC terminal from being infected by software downloaded from the dangerous site.

[0104] Another possibility of ACT action is to delete the form fields present on the site among the sites S1, S2, S3 on which the user is currently browsing. Obtaining the FTR metrics of the target site takes a certain amount of time, as does the analysis of these by the MDL predictive model. It is possible to envisage an embodiment of the Internet navigation according to the invention in which the users will only go to target sites S1, S2, S3 once the analysis of these has been carried out. But the mode that will be most often carried out will consist of obtaining the FTR metrics and analyzing them in parallel with the user's Internet navigation. In this mode of analysis and navigation in parallel, it will happen that a user begins to fill in form fields, therefore begins to provide sensitive data, on a site whose analysis of the FTR metrics reveals that it is dangerous.The ACT action carried out by the module 103 of the management entity 100 will then include the deletion of at least some of the fields of the forms in order to attempt to prevent the provision of the user's private data to the dangerous site among the sites S1, S2, S3. This ACT deletion action may be combined with an ACT action of blocking Internet browsing and warning given to the user.

[0105] In certain embodiments, the analysis module 102, in addition to providing SCR data representative of a trust score relating to a given target site, will also provide an indication of a website distinct from the target site. The objective is, when the analysis of the FTR metrics by the MDL predictive model indicates that the target site is probably a site usurping the identity of a legitimate site, to seek to identify the legitimate site whose identity is usurped. When carrying out the ACT action, the module 103 will thus be able to either directly direct the user's navigation to the legitimate site or indicate to the user that the site on which he is browsing has been detected as usurping the identity of a legitimate site and will suggest that he continue his navigation on the legitimate site.

[0106] One way to carry out this operation may be as follows. The analysis step performed by the analysis module 102 may comprise a screenshot of one or more pages of the target site among the sites S1, S2, S3. This screenshot may then be processed according to known image processing algorithms to extract the images that correspond to logos present on the target website. These extracted images may then be subjected to an image recognition algorithm that has a database of images such as logos present on a set of legitimate sites such as sites of financial organizations, companies, administrations that may be usurped by attacker sites. A conventional image recognition algorithm may then indicate that the images extracted from the target site are identical or very close to the images present on a given legitimate site.This result will be a clear indication that the target site is indeed trying to usurp the identity of a legitimate site, and, moreover, the identity of the legitimate site will thus be known. The analysis module 102 will then be able to provide this identity to the module 103 which will carry out an action ACT relating to the user's navigation by taking into account the legitimate site whose identity is usurped by an attacking site.

[0107] The analysis relating to the images displayed by the target site may either use an image recognition algorithm and an image database that will be hosted in a remote server, which server may be the same SVR device that hosts the MDL predictive model or another server, or a virtual machine or a container running in a cloud computing architecture, or may be carried out directly in the management entity 100 which may embed the image recognition algorithm in the analysis module 102 as well as an image database.The advantages of these respective choices are similar to those relating to the choice of architecture made for hosting the MDL model, namely on the one hand the ease of updating and the possibility of handling a larger image base in the case of hosting by an SVR device external to the DVC terminal and on the other hand the faster response time and greater availability in the case of hosting directly by the management entity 100.

[0108] It may be noted that the transfer of an image capture from the target site to an SVR server, unlike the transfer of FTR metrics, may involve a breach of the confidentiality of the Internet browsing of the user of the DVC terminal via the BWR browser. To overcome this drawback, the transfer of captured images may be subject to authorization requested from the user in certain embodiments.

[0109] The, for its part, presents an example of steps implemented within the framework of an embodiment of the invention.

[0110] The BWR browser, when the DVC terminal and its user are browsing the Internet, will request REQ from websites, here in this case firstly the site S1. This provides, via the HTTP protocol, data such as texts, images, contained in a page written in the HTML language (acronym for Hyper-Text Markup Language). This data allows the BWR browser to display the website S1 to the user. In parallel, or prior to the display of the site to the user, the management entity 100 present in the BWR browser, and more precisely the module 101, will obtain a whole series of FTR metrics. These FTR metrics are obtained from elements present in the page(s) of the site S1 which are known to the BWR browser thanks to the REQ request. The analysis module 102 submits these FTR metrics to the MDL predictive model which will provide in response SCR data representative of a confidence score relating to the Internet site S1.The management entity 100 will take a decision based on this SCR score which results in the performance of an ACT action. In this case, the BWR browser stops browsing the site S1, because the SCR data indicates that this site is not trustworthy. An additional ACT action may be the deletion or attempted deletion of data that may have already been provided by the user to the site S1 via the BWR browser. The method according to the invention then continues with the user browsing the site S2, for which the BWR browser makes a REQ request in order to obtain HTML data. FTR metrics are extracted from this new HTML data, FTR metrics submitted to the MDL predictive model. The latter provides in response an SCR data item representative of a trust score to be given to the site S2.This SCR confidence score does not indicate a dangerous site, so the BWR browser continues to navigate to the S2 site with a new REQ request that will obtain a new HTML page. The method according to the invention thus takes place throughout the user's navigation on the Internet.

[0111] The, for its part, presents another embodiment of the invention according to an architecture different from that already presented.

[0112] In this exemplary embodiment, the DVC terminal comprises a predictive model MDL1, called the first model. This model MDL1 can be included, for example, in the BWR browser, for example in the analysis module 102 of the management entity 100. When the module 101 for obtaining the FTR metrics obtains the FTR metrics of a site S1, S2, S3, these can be immediately subjected to an analysis carried out by the analysis module 102 using the first predictive model MDL1. This first analysis may, depending on its results, be supplemented by an analysis carried out with another predictive model MDL2, called the second model MDL2, which is hosted in an SVR server separate from the DVC terminal. The first predictive model MDL1 can be a small model, easy to deploy in all the DVC terminals that implement the invention.The result of the analysis by this first MDL1 model can then be obtained quickly, especially since the first MDL1 model is present in the DVC terminal and therefore easy to access. The second MDL2 model, on the other hand, is much larger than the first MDL1 model and therefore cannot be deployed in all DVC terminals. It is hosted in an SVR server separate from the DVC terminals.

[0113] The analysis by the second MDL2 model will therefore not always be carried out in this example, which is indicated by a dotted arrow in the. In all cases, the analysis module 102 produces SCR data representative of a confidence score. This SCR data can be obtained directly from the analysis carried out by the first predictive model MDL1. If an analysis is also carried out by the second predictive model MDL2, the SCR data representative of a confidence score can be that obtained by the analysis carried out by the second MDL2 model or obtained by combining the results of the analyses carried out by the first predictive model MDL1 and the second MDL2 model.

[0114] The management entity 100 will be able to continue carrying out the management method by carrying out an action ACT relating to the Internet browsing of the DVC terminal as a function of the SCR data representing a confidence score relating to the target site S1, S2, S3 which will have been obtained after analysis by the first predictive model MDL1 and possibly by the second model MDL2.

[0115] This example of implementation has the advantage of presenting an architecture that is both decentralized, with a first small-sized predictive model MDL1, easy to distribute, which is found in the DVC terminals as close as possible to the analyses to be carried out, and a second predictive model MDL2, a priori much more detailed than the first predictive model MDL1, and therefore much more difficult to distribute and update, but which will provide more detailed analyses if those provided by the first MDL1 model are insufficient.

Claims

Method for managing the Internet browsing of a terminal (DVC), implemented by a management entity (100), comprising the following steps: Obtaining metrics (FTR) of an Internet site, called target site (S1, S2, S3), to which access is requested by the terminal (DVC); Obtaining a confidence score (SCR) relating to the target site (S1, S2, S3) from the metrics (FTR), obtaining the confidence score being at least partly carried out by a device (SVR) external to the terminal (DVC); Action (ACT) relating to the Internet browsing of the terminal (DVC) as a function of the confidence score (SCR) obtained. Management method according to claim 1, characterized in that obtaining the confidence score (SCR) comprises an analysis by a predictive model (MDL). Management method according to claim 2, characterized in that the analysis by the predictive model (MDL) comprises an analysis carried out by a predictive model (MDL1), called the first model, present in the terminal (DVC), and an analysis carried out by another predictive model (MDL2), called the second model, transferred to a device (SVR) external to the terminal (DVC), the analysis by the second model (MDL2) being carried out according to the result of the analysis by the first model (MDL1). Management method according to one of claims 1 to 3, characterized in that the target site (S1, S2, S3) comprises a form comprising at least one field to be completed, and in that the action (ACT) relating to Internet browsing of the terminal (DVC) comprises the deletion of at least part of the form fields present in the target site (S1, S2, S3). Management method according to one of claims 1 to 4, characterized in that the confidence score (SCR) relating to the target site (S1, S2, S3) is supplemented by an indication of an Internet site distinct from the target site (S1, S2, S3). Management method according to one of claims 2 to 5, characterized in that the predictive model (MDL) is enriched with the metrics (FTR) obtained and other information relating to the target site (S1, S2, S3). Management entity (100) capable of carrying out a method for managing the Internet browsing of a terminal (DVC) comprising the following modules: Module (101) for obtaining metrics (FTR) of an Internet site (S1, S2, S3), called target site, to which access is requested by the terminal (DVC); Module (102) for obtaining a confidence score (SCR) relating to the target site (S1, S2, S3) from the metrics (FTR), obtaining the confidence score being at least partly carried out by a device (SVR) external to the terminal (DVC); Module (103) for action (ACT) relating to the Internet browsing of the terminal (DVC) as a function of the confidence score (SCR) obtained. Terminal (DVC) comprising a management entity (100) according to claim 7. A computer program capable of being implemented by a management entity (100) according to claim 7, the program comprising code instructions which, when executed by a processor, performs the steps of the management method according to claim 1. Data carrier on which is recorded a computer program according to claim 9 comprising sequences of instructions for implementing the management method according to claim 1.

Citation Information

Patent Citations

  • Security level determination of websites

    US20120017281A1

  • Utilizing machine learning models to process low-results web queries and generate web item deficiency predictions and corresponding user interfaces

    US20230350968A1