Method and system for verifying website provided to user

The website verification method and system address the challenge of identifying phishing websites by correlating URL and content with service providers, enhancing user safety and convenience through accurate phishing detection.

WO2025147025A1PCT designated stage expired Publication Date: 2025-07-10ATON INC
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
PCT/KR2024/021323
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-01-04
Filing Date
2024-12-27
Publication Date
2025-07-10

AI Technical Summary

Technical Problem

Users face difficulties in distinguishing between legitimate and phishing websites, particularly through smishing attacks, which can lead to personal information leakage and financial fraud.

Method used

A website verification method and system that analyzes URL information and content for correlation with a predetermined service provider, providing determinations of phishing, suspicious, or legitimate websites using correlation analysis and reference criteria.

Benefits of technology

Enhances user safety by accurately identifying phishing websites, reducing the risk of information leakage, while maintaining user convenience by selective verification and allowing continued use of mistakenly identified legitimate sites.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure KR2024021323_10072025_PF_FP_ABST
    Figure KR2024021323_10072025_PF_FP_ABST
Patent Text Reader

Abstract

The present disclosureprovides a method and system for verifying a website provided to a user. The method for verifying a website provided to a user may comprise the steps of: receiving, from a computing device associated with a service provider, uniform resource locator (URL) information of a first website and first content disclosed in the first website; receiving, from a user terminal, URL information of a second website and second content disclosed in the second website; and determining whether the service provider and the second website are associated with each other on the basis of the URL information of the first website, the URL information of the second website, the first content, and the second content.
Need to check novelty before this filing date? Find Prior Art

Description

Website verification method and system provided to users

[0001] The present disclosure relates to a website verification method and system, and more particularly, to a method and system for verifying a website provided to a user.

[0002]

[0003] As phishing techniques have diversified, it's become increasingly easy for internet users to access malicious, phishing websites impersonating financial institutions, public institutions, and other organizations through spam emails and various advertisements. Furthermore, the recent increase in smartphone penetration and advancements in smartphone technology have led to a rise in smartphone-based crimes. In particular, smishing, a combination of phishing and text messaging, has become increasingly prevalent. Smishing refers to a criminal method whereby text messages are sent to smartphone users to induce them to download and install viral applications or malware, thereby collecting personal information or facilitating mobile payments. Specifically, text messages often include URLs (Uniform Resource Locators) that direct users to phishing websites.

[0004] For example, if a URL is posted that misleads or confuses users with a financial institution or public agency, users must directly access the URL to verify its authenticity. It can be difficult to distinguish between legitimate websites like financial institutions and public agencies and phishing sites. Users may mistakenly believe the website is legitimate and enter personal information, or install malware or viral applications. In this case, users may fall victim to phishing attacks, potentially exposing them to the risk of financial and personal information leaks.

[0005]

[0006] The present disclosure provides a website verification method, a computer program stored in a recording medium, and a system (device) to solve the above-described problems.

[0007]

[0008] The present disclosure can be implemented in various ways, including a method, a device (system), and / or a computer program stored in a computer-readable storage medium, and a computer-readable storage medium having a computer program stored therein.

[0009] According to one embodiment of the present disclosure, a method for verifying a website provided to a user, performed by at least one processor, may include the steps of receiving Uniform Resource Locator (URL) information of a first website and first content disclosed in the first website from a computing device associated with a service provider, receiving URL information of a second website and second content disclosed in the second website from a user terminal, and determining whether there is an association between the service provider and the second website based on the URL information of the first website, the URL information of the second website, the first content, and the second content.

[0010] According to one embodiment of the present disclosure, the second content may include information identifying or characterizing the service provider, extracted from the second content.

[0011] According to one embodiment of the present disclosure, the step of determining whether there is a relationship between the service provider and the second website may include the steps of determining whether URL information of the first website matches URL information of the second website or determining whether URL information of the second website includes URL information of the first website, determining whether there is a relationship between the first content and information indicating or characterizing the service provider, and determining whether there is a relationship between the service provider and the second website based on the result of determining whether there is a relationship between the URL information and the result of determining whether there is a relationship between the information indicating or characterizing the service provider and the first content.

[0012] According to one embodiment of the present disclosure, the step of determining whether there is a correlation between the first content and the information indicating or characterizing the service provider may include the step of calculating a correlation between the first content and the information indicating or characterizing the service provider using correlation analysis, and the step of determining that the information indicating or characterizing the service provider and the first content are correlated if the correlation is greater than a predetermined first reference correlation.

[0013] According to one embodiment of the present disclosure, the step of determining whether the first content and the information indicating or characterizing the service provider are related may further include the step of determining that the information indicating or characterizing the service provider and the first content are not related if the relatedness is less than or equal to a predetermined second reference relatedness, and the step of providing URL information of a second website and the second content to the computing device if the relatedness is greater than the second reference relatedness and less than or equal to the first reference relatedness.

[0014] According to one embodiment of the present disclosure, in response to determining whether a service provider is related to a second website, information indicating one of a phishing website determination, a suspicious website determination, or a legitimate website determination may be provided to a user terminal.

[0015] According to one embodiment of the present disclosure, the step of providing information indicating one of a phishing website determination, a suspicious website determination, or a legitimate website determination to a user terminal may include providing information indicating one of a phishing website determination, a suspicious website determination, or a legitimate website determination and a calculated correlation to the user terminal.

[0016] According to one embodiment of the present disclosure, through a verification application of a user terminal, it is determined whether at least one of the URL information of a second website or the second content is associated with a predetermined service provider, and only when it is determined that at least one of the URL information of the second website or the second content is associated with the predetermined service provider, the URL information of the second website and the second content can be received from the user terminal.

[0017] A computer program stored in a computer-readable recording medium can be provided to execute a method according to one embodiment of the present disclosure on a computer.

[0018] According to one embodiment of the present disclosure, an information processing system comprises a communication module, a memory, and at least one processor connected to the memory and configured to execute at least one computer-readable program included in the memory, wherein the at least one program may include instructions for receiving URL information of a first website and first content disclosed in the first website from a computing device associated with a service provider, receiving URL information of a second website and second content disclosed in the second website from a user terminal, and determining whether there is an association between the service provider and the second website based on the URL information of the first website, the URL information of the second website, the first content, and the second content.

[0019]

[0020] According to some embodiments of the present disclosure, when accessing a website, the user can verify that the website is a phishing website by checking information indicating that the website is a phishing website. In other words, the user can avoid being phished by not mistaking the phishing website for a legitimate website.

[0021] According to some embodiments of the present disclosure, a website verification method can perform website verification only for a predetermined service provider, thereby allowing verification to be performed only on a portion of multiple websites accessed by a user. Specifically, website verification can be selectively performed only for the predetermined service providers requesting website verification. Furthermore, website verification can be prevented from being performed indiscriminately on all websites accessed by a user.

[0022] According to some embodiments of the present disclosure, a user can interrupt repetitive website verification by performing a certain input, and then examine websites identified as phishing websites in detail. Furthermore, even if a phishing website is identified incorrectly (e.g., a legitimate website is identified as a phishing website), the user can continue using the website. Thus, the website verification method according to the present disclosure can maintain user safety and security while simultaneously enhancing user convenience.

[0023] The effects of the present disclosure are not limited to the effects mentioned above, and other effects not mentioned can be clearly understood by a person having ordinary skill in the art to which the present disclosure belongs (referred to as “one skilled in the art”) from the description of the claims.

[0024]

[0025] Embodiments of the present disclosure will be described below with reference to the accompanying drawings, wherein like reference numerals represent similar elements, but are not limited thereto.

[0026] FIG. 1 is a drawing showing an example of how a website accessed from a user terminal is output according to one embodiment of the present disclosure.

[0027] FIG. 2 is a schematic diagram showing a configuration connected to enable communication between an information processing system and multiple user terminals for website verification according to one embodiment of the present disclosure.

[0028] FIG. 3 is a block diagram showing the internal configuration of a computing device according to one embodiment of the present disclosure.

[0029] FIG. 4 is a flowchart illustrating an example of a website verification method according to one embodiment of the present disclosure.

[0030] FIG. 5 is a flowchart of an example of a website verification method according to one embodiment of the present disclosure.

[0031] FIG. 6 is a diagram illustrating an example of an interface of a user terminal that receives information on a phishing website determination according to one embodiment of the present disclosure.

[0032] FIG. 7 is a flowchart illustrating an example of a website verification method according to one embodiment of the present disclosure.

[0033]

[0034] Hereinafter, specific details for implementing the present disclosure will be described in detail with reference to the attached drawings. However, in the following description, specific descriptions of widely known functions or configurations will be omitted if they may unnecessarily obscure the gist of the present disclosure.

[0035] In the attached drawings, identical or corresponding components are assigned the same reference numerals. Furthermore, in the description of the embodiments below, duplicate descriptions of identical or corresponding components may be omitted. However, even if a description of a component is omitted, it is not intended that such component is not included in any embodiment.

[0036] The advantages and features of the disclosed embodiments, and methods for achieving them, will become clearer with reference to the embodiments described below, along with the accompanying drawings. However, the present disclosure is not limited to the embodiments disclosed below and may be implemented in various different forms. These embodiments are provided solely to ensure the completeness of the disclosure and to fully inform those skilled in the art of the scope of the invention.

[0037] The terms used in this specification will be briefly explained, followed by a detailed description of the disclosed embodiments. The terms used in this specification have been selected from widely used, current terms, taking into account the functions of the present disclosure. However, these terms may vary depending on the intentions of engineers working in the relevant field, precedents, the emergence of new technologies, etc. Furthermore, in certain cases, terms may be arbitrarily selected by the applicant, and in such cases, their meanings will be described in detail in the relevant description of the invention. Therefore, the terms used in this disclosure should not be defined simply as names of terms, but rather based on their meanings and the overall content of the present disclosure.

[0038] In this specification, singular expressions include plural expressions unless the context clearly indicates otherwise. Furthermore, plural expressions include singular expressions unless the context clearly indicates otherwise. When a part of the specification is said to include a component, this does not exclude other components, but rather implies that other components may be included, unless otherwise specifically stated.

[0039] Also, the term 'module' or 'part' used in the specification means a software or hardware component, and the 'module' or 'part' performs certain roles. However, the 'module' or 'part' is not limited to software or hardware. The 'module' or 'part' may be configured to reside on an addressable storage medium and may be configured to execute one or more processors. Thus, as an example, the 'module' or 'part' may include at least one of components such as software components, object-oriented software components, class components, and task components, processes, functions, attributes, procedures, subroutines, segments of program code, drivers, firmware, microcode, circuitry, data, databases, data structures, tables, arrays, or variables. The functionality provided within the components and 'modules' or 'parts' may be combined into a smaller number of components and 'modules' or 'parts', or further separated into additional components and 'modules' or 'parts'.

[0040] According to one embodiment of the present disclosure, a 'module' or 'unit' may be implemented as a processor and a memory. 'Processor' should be broadly construed to include a general-purpose processor, a central processing unit (CPU), a microprocessor, a digital signal processor (DSP), a controller, a microcontroller, a state machine, and the like. In some circumstances, a 'processor' may also refer to an application-specific integrated circuit (ASIC), a programmable logic device (PLD), a field-programmable gate array (FPGA), and the like. A 'processor' may also refer to a combination of processing devices, such as, for example, a combination of a DSP and a microprocessor, a combination of multiple microprocessors, a combination of one or more microprocessors in conjunction with a DSP core, or any other such combination of configurations. In addition, 'memory' should be broadly construed to include any electronic component capable of storing electronic information. 'Memory' may refer to various types of processor-readable media, such as random access memory (RAM), read-only memory (ROM), non-volatile random access memory (NVRAM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable PROM (EEPROM), flash memory, magnetic or optical data storage, registers, etc. Memory is said to be in electronic communication with the processor if the processor can read information from, and / or write information to, the memory. Memory integrated in a processor is in electronic communication with the processor.

[0041] In addition, terms such as first, second, A, B, (a), (b), etc. used in the following embodiments are only used to distinguish certain components from other components, and the nature, order, or sequence of the components are not limited by the terms.

[0042] Additionally, in the embodiments below, when it is described that a component is 'connected', 'coupled' or 'connected' to another component, it should be understood that the component may be directly connected or connected to the other component, but another component may also be 'connected', 'coupled' or 'connected' between each component.

[0043] In the present disclosure, 'each of the plurality of As' may refer to each of all components included in the plurality of As, or may refer to each of some components included in the plurality of As.

[0044] Additionally, the terms 'comprises' and / or 'comprising' used in the following embodiments do not exclude the presence or addition of one or more other components, steps, operations and / or elements.

[0045] FIG. 1 is a diagram illustrating an example of how a website (130) accessed from a user terminal (120) according to one embodiment of the present disclosure is displayed. A user (110) can access the website (130) via the user terminal (120). In one embodiment, the website (130) may be a phishing website that impersonates a service provider (e.g., a financial institution, a public institution, etc.) to obtain certain information from the user unrelated to the provision of the service. For example, a user (110) may access the phishing website (130) via a smishing text message, a link shared on the Internet, etc.

[0046] In another embodiment, the accessed website (130) may be a legitimate website used by a service provider to provide services to the user (110). For example, the legitimate website may be a website actually used by a well-known company, financial institution, or public institution to provide services to the user (110). In other words, the website (130) accessed via the user terminal (120) may be a phishing website or a legitimate website.

[0047] The website (130) may include Uniform Resource Locator (URL) information. Here, the URL may refer to an address for accessing the website (130). Referring to FIG. 1, the URL of the website (130) may correspond to "www.Abank.xyz."

[0048] A website (130) can disclose content. For example, a legitimate website may disclose content related to various information about its services to provide services to users. In another example, a phishing website may disclose content related to a service provider to create confusion or misunderstanding that the website is provided by the service provider. Referring to Figure 1, a phishing website may disclose content such as information about banking services to make it appear as if it is provided by a bank, a financial service provider.

[0049] The content may include information (136) that identifies or characterizes the service provider. Here, the information (136) that identifies or characterizes the service provider may include information that identifies the service provider or, when combined with other information, may identify the service operator. For example, the information (136) that identifies or characterizes the service provider may include the name (or business name, brand name, etc.) of the service provider, the product name / service name / event name of the service provider, contact information associated with the service provider, an image that may identify the service provider (e.g., a trademark, emblem, QR code, etc.), and a sound that may identify the service provider (e.g., a sound repeatedly provided to a user or consumer when providing a service to the user or consumer, a sound provided each time a website is accessed, etc.).

[0050] In one embodiment, a phishing website may include a phishing object (134). Referring to FIG. 1, a user (110) may input phishing target information through the phishing object (134). For example, the user (110) may input his / her own personal contact information into the phishing object (134). However, the phishing website is not limited thereto, and may induce phishing of the user (110) in various forms. For example, the phishing website may include information requesting the input of a bank account number and password for the account. Alternatively, the phishing website may include a link to install a separate application capable of inducing phishing on the user terminal (120) and information requesting the installation.

[0051] The website verification system can receive URL information of a first website provided by the service provider and first content disclosed on the first website from a computing device associated with the service provider. Furthermore, the website verification system can receive URL information of a second website and second content disclosed on the second website from a user terminal (120). The second website may be a website (130) accessed via the user terminal (120). In this case, the user terminal (120) may have a website verification application installed, and the URL information of the second website and second content disclosed on the second website may be transmitted by the website verification application. Here, the website verification application may be provided as a separate application or may be included in an application provided by the service provider to provide the website verification service.

[0052] In one embodiment, the user terminal (120) may receive information regarding a predetermined service provider. Furthermore, the website verification application may extract information (136) identifying or characterizing the service provider from the content disclosed on the website (130). The website verification application may then use the information regarding the predetermined service provider to determine whether the predetermined service provider is associated with the URL information of a second website. Additionally or alternatively, the website verification application may use the information regarding the predetermined service provider to determine whether the predetermined service provider is associated with the content of the second website. In this case, the URL information of the second website and the second content may be transmitted to the website verification system only if at least one of the URL information of the second website or the second content is determined to be associated with the predetermined service provider. In this case, the extracted information (136) identifying or characterizing the service provider may be transmitted instead of the second content. In this case, the webpage verification system may verify the second webpage associated with the predetermined service provider by the webpage verification application.

[0053] The website verification system can use the first website to determine whether a second website and a service provider are related. Specifically, the website verification system can determine whether a service provider and the second website are related based on the URL information of the first website, the URL information of the second website, the first content, and the second content. The detailed process for determining whether a service provider and the second website are related is described with reference to FIGS. 4 and 5.

[0054] The website verification system, in response to determining whether a service provider is related to a second website, may provide information indicating one of a phishing website determination, a suspicious website determination, or a legitimate website determination to the user terminal (120). The information provided by the website verification system may be output through the user terminal (120) in various forms. For example, the user terminal (120) that has received the phishing website determination may provide a visual (e.g., a pop-up window, etc.), tactile (e.g., a vibration, etc.), or auditory (e.g., a warning sound) alarm indicating that the second website is a fake website. The appearance of the output on the user terminal (120) in response to the information provided by the website verification system is described with reference to FIG. 6. The output result of the received user terminal (120) is described in detail with reference to FIG. 6.

[0055] While Figure 1 illustrates a mobile website, this is not the only limitation. For example, website verification methods / services can also be implemented for PC websites. Specifically, for PCs, website verification can be performed using browser extensions or PC applications.

[0056] By this configuration, when a user (110) accesses a website (130), the user (110) can confirm that the website (130) he or she is currently accessing is a phishing website by checking information indicating that the website is a phishing website. In other words, the user (110) can avoid being phished by not mistaking a phishing website for a legitimate website.

[0057] Furthermore, the invention according to the present disclosure performs website verification only for pre-defined service providers, allowing website verification to be performed only on some of the multiple websites (130) accessed by a user (110). Specifically, website verification can be selectively performed only for pre-defined service providers requesting website verification. Furthermore, website verification may not be performed indiscriminately on all websites accessed by a user.

[0058] FIG. 2 is a schematic diagram illustrating a configuration in which communication is possible between an information processing system (230) and a plurality of user terminals (210_1, 210_2, 210_3) for website verification according to one embodiment of the present disclosure. As illustrated, the plurality of user terminals (210_1, 210_2, 210_3) may be connected to an information processing system (230) capable of providing website verification services via a network (220). Here, the plurality of user terminals (210_1, 210_2, 210_3) may include terminals of users who receive website verification services.

[0059] According to one embodiment, the information processing system (230) may include one or more server devices and / or databases capable of storing, providing, and executing computer executable programs (e.g., downloadable applications) and data related to providing website verification services, or one or more distributed computing devices and / or distributed databases based on cloud computing services.

[0060] The website verification service provided by the information processing system (230) may be provided to users through website verification service applications, web browsers, web browser extensions, etc. installed on each of a plurality of user terminals (210_1, 210_2, 210_3) and / or the information processing system (230). For example, the information processing system (230) may provide information corresponding to a message verification request received from the user terminals (210_1, 210_2, 210_3) and / or the information processing system (230) through the website verification service application, etc., or perform corresponding processing. For example, the information processing system (230) may correspond to the website verification system described with reference to FIG. 1.

[0061] A plurality of user terminals (210_1, 210_2, 210_3) can communicate with an information processing system (230) via a network (220). The network (220) can be configured to enable communication between the plurality of user terminals (210_1, 210_2, 210_3) and the information processing system (230). Depending on the installation environment, the network (220) can be configured as a wired network such as Ethernet, a wired home network (Power Line Communication), a telephone line communication device, and RS-serial communication, a mobile communication network, a wireless network such as WLAN (Wireless LAN), Wi-Fi, Bluetooth, and ZigBee, or a combination thereof. As another example, the network (220) can include a communication network configured by a communication company. At this time, the message and / or verification message can be communicated between the user terminals (210_1, 210_2, 210_3) and the information processing system (230) via the network (220). The communication method is not limited, and may include not only a communication method utilizing a communication network (e.g., a mobile communication network, wired Internet, wireless Internet, broadcasting network, satellite network, etc.) that the network (220) may include, but also short-range wireless communication between the user terminals (210_1, 210_2, 210_3).

[0062] In FIG. 2, a mobile phone terminal (210_1), a tablet terminal (210_2), and a PC terminal (210_3) are illustrated as examples of user terminals, but are not limited thereto, and the user terminals (210_1, 210_2, 210_3) may be any computing device capable of wired and / or wireless communication and capable of installing and executing a website verification application or web browser, etc. For example, the user terminal may include an AI speaker, a smartphone, a mobile phone, a navigation device, a computer, a laptop, a digital broadcasting terminal, a PDA (Personal Digital Assistants), a PMP (Portable Multimedia Player), a tablet PC, a game console, a wearable device, an IoT (Internet of Things) device, a VR (virtual reality) device, an AR (augmented reality) device, a set-top box, etc. In addition, although FIG. 2 illustrates three user terminals (210_1, 210_2, 210_3) communicating with the information processing system (230) via the network (220), this is not limited thereto, and a different number of user terminals may be configured to communicate with the information processing system (230) via the network (220).

[0063] In FIG. 2, a configuration in which a user's request is transmitted to an information processing system (230) through a user terminal (210_1, 210_2, 210_3) is exemplarily illustrated, but the present invention is not limited thereto. The user's request may be provided to the information processing system (230) through an input device associated with the information processing system (230) without passing through the user terminal (210_1, 210_2, 210_3), and the result of processing the user's request may be provided to the user through an output device (e.g., a display, etc.) associated with the information processing system (230).

[0064] FIG. 3 is a block diagram illustrating an internal configuration of a computing device (310) according to one embodiment of the present disclosure. The computing device (310) may include a memory (312), a processor (314), a communication module (316), and an input / output interface (318). As illustrated in FIG. 3, the computing device (310) may be configured to communicate information and / or data via a network using the communication module (316). In addition, each of the user terminal (210) and the information processing system (230) described above in FIG. 2 may correspond to one or more computing devices (310) or include one or more computing devices (310). In addition, a service provider may utilize the computing device (310) to provide / transmit a website (or URL information of the website, content disclosed on the website) to the information processing system (230) and / or the user terminal (210).

[0065] The memory (312) may include any non-transitory computer-readable recording medium. According to one embodiment, the memory (312) may include a non-permanent mass storage device such as a random access memory (RAM), a read only memory (ROM), a disk drive, a solid state drive (SSD), a flash memory, etc. As another example, a non-permanent mass storage device such as a ROM, an SSD, a flash memory, a disk drive, etc. may be included in the computing device (310) as a separate permanent storage device distinct from the memory. In addition, the memory (312) may store an operating system and at least one program code (e.g., code for generating a verification message, generating identification information, determining whether a first verification message and a second verification message match, extracting characteristic information of an operating entity, etc. that is installed and operated in the computing device (310).

[0066] These software components may be loaded from a computer-readable recording medium separate from the memory (312). This separate computer-readable recording medium may include a recording medium directly connectable to the computing device (310), for example, a computer-readable recording medium such as a floppy drive, a disk, a tape, a DVD / CD-ROM drive, a memory card, etc. As another example, the software components may be loaded into the memory (312) via a communication module (316) other than a computer-readable recording medium. For example, at least one program may be loaded into the memory (312) based on a computer program (e.g., a program for determining whether a service provider is related to a second website, extracting information that represents or characterizes a service provider, etc.) that is installed by files provided by developers or a file distribution system that distributes installation files of applications via the communication module (316).

[0067] The processor (314) may be configured to process instructions of a computer program by performing basic arithmetic, logic, and input / output operations. The instructions may be provided to a user terminal (not shown) or another external system via the memory (312) or the communication module (316). For example, the processor (314) may determine whether the first verification message and the second verification message match. In this case, in response to determining whether the first verification message and the second verification message match, the determination result may be provided to the user terminal.

[0068] The communication module (316) may provide a configuration or function for a user terminal (not shown) and a computing device (310) to communicate with each other via a network, and may provide a configuration or function for the computing device (310) to communicate with an external system (e.g., a separate cloud system, etc.). For example, control signals, commands, data, etc. provided under the control of the processor (314) of the computing device (310) may be transmitted to the user terminal and / or the external system via the communication module (316) and the network via the communication module of the user terminal and / or the external system.

[0069] Additionally, the input / output interface (318) of the computing device (310) may be a means for interfacing with a device (not shown) for input or output that is connected to the computing device (310) or that the computing device (310) may include. In FIG. 3, the input / output interface (318) is illustrated as an element configured separately from the processor (314), but is not limited thereto, and the input / output interface (318) may be configured to be included in the processor (314). The computing device (310) may include more components than those illustrated in FIG. 3. However, there is no need to explicitly illustrate most of the conventional components.

[0070] The processor (314) of the computing device (310) may be configured to manage, process, and / or store information and / or data received from multiple user terminals and / or multiple external systems. According to one embodiment, the processor (314) may receive a second verification message. Thereafter, the processor (314) may determine whether the first verification message stored in the memory (312) of the computing device (310) matches the second verification message.

[0071] FIG. 4 is a flowchart illustrating an example of a website verification method according to one embodiment of the present disclosure. The computing device (410) associated with the service provider may be a computing device utilized by the service provider. The computing device may correspond to or include the computing device (310) described with reference to FIG. 3 .

[0072] A computing device (410) associated with a service provider can generate a first website (S402). For example, the service provider can generate the first website by inputting information about the first website through the computing device (410) associated with the service provider. Alternatively, the computing device (410) associated with the service provider can receive information about the generated first website.

[0073] A computing device (410) associated with a service provider may transmit URL information of a first website and first content disclosed on the first website to an information processing system (420) (S410). Thereafter, the information processing system (420) may store the received URL information of the first website and the first content. Specifically, if multiple pairs of URL information of the first website and the first content are received, the information processing system (420) may classify and store the received information by service provider.

[0074] The user terminal (430) can access a second website (S412). For example, the second website may be a phishing website or a legitimate website. As another example, the second website may be a first website provided by a service provider. However, this is not limited to this, and the second website may be any website accessible via the user terminal (430).

[0075] In one embodiment, the website verification application on the user terminal (430) can determine whether a second website is associated with a predetermined service provider (S414). Here, the user terminal (430) can receive information regarding the predetermined service provider (e.g., the name, product name, brand name, etc. of the predetermined service provider). Specifically, the website verification application can determine whether at least one of the URL information of the second website or the second content disclosed on the second website is associated with the predetermined service provider. For example, if the URL of the second website includes the name of the predetermined service provider, it can be determined that the URL information of the second website and the predetermined service provider are associated. Furthermore, if the second content includes one or more names of the predetermined service provider, it can be determined that the second content and the predetermined service provider are associated. In another example, if the second content includes the product name, brand name, service name, etc. provided by the predetermined service provider, it can be determined that the second content and the predetermined service provider are associated. However, without limitation, it may be determined in various ways whether a second website is associated with a predetermined service provider.

[0076] In one embodiment, if the second website is determined to be associated with a predetermined service provider, the user terminal (430) may transmit URL information of the second website and second content to the information processing system (420) (S420). In another embodiment, the user terminal (430) may transmit URL information of the second website to the information processing system (420). Thereafter, the information processing system (420) may use the URL information of the second website to access the second website and obtain the second content disclosed on the second website.

[0077] The information processing system (420) can determine whether there is a connection between the service provider and the second website (S422). Thereafter, the information processing system (420) can transmit the result of determining whether there is a connection between the service provider and the second website to the user terminal (430). Specifically, the information processing system (420) can transmit information indicating one of the following: a phishing website determination, a suspicious website determination, or a legitimate website determination, in response to the determination result. The detailed process and determination results for determining whether there is a connection between the service provider and the second website are described with reference to FIGS. 5 and 6 .

[0078] Figure 5 is a flowchart illustrating an example of a website verification method according to one embodiment of the present disclosure. The information processing system (520) can determine whether there is a connection between a service provider and a second website. Specifically, the information processing system (520) can determine whether the URL information of the first website matches the URL information of the second website (S502). For example, the information processing system (520) can determine whether the domain address and / or path address in the URL information of the second website matches the domain address and / or path address in the URL information of the first website, or whether the URL information of the first website includes the domain address and / or path address.

[0079] Additionally or alternatively, the information processing system (520) may determine whether the URL information of the second website includes the URL information of the first website. For example, the URL information of the first website may be information corresponding to the host of the URL. In this case, it may be determined whether the URL information of the second website includes the URL information of the first website, which is information corresponding to the host.

[0080] The information processing system (520) can calculate the degree of association between the first content and information indicating or characterizing the service provider contained in and / or extracted from the second content (S504). At this time, the information indicating or characterizing the service provider may be information extracted and transmitted by the website verification application of the user terminal (530) or information extracted from the second content by the information processing system (520). Specifically, the information processing system (520) can calculate the degree of association between the first content and the information indicating or characterizing the service provider using association analysis. For example, the degree of association may include the degree of similarity between the first content and the information indicating or characterizing the service provider through natural language processing (NLP). In another example, the degree of association may include the textual similarity between the first content and the information indicating or characterizing the service provider using text embedding. In yet another example, the degree of association may include the degree of similarity between an image included in the first content and an image included in the information indicating or characterizing the service provider. However, without being limited thereto, various methods may be selected for the correlation analysis to indicate the degree to which information representing or characterizing the first content and the service provider are similar.

[0081] The information processing system (520) can determine whether the relevance is greater than (or equal to) a predetermined first reference relevance (S506). Here, a higher relevance value may indicate a higher degree of relevance. Specifically, if the relevance is determined to be greater than the predetermined first reference relevance, the information representing or characterizing the service provider and the first content may be determined to be related (S524).

[0082] If the information processing system (520) determines that the relevance is less than or equal to (or smaller than) a first predetermined reference relevance, the information processing system (520) can determine whether the relevance is greater than (or larger than or equal to) a second predetermined reference relevance (S508). In this case, the first reference relevance may be greater than the second reference relevance. Specifically, if the information processing system (520) determines that the relevance is greater than (or larger than or equal to) the second predetermined reference relevance, the information processing system (520) can transmit the URL information of the second website and the second content to a computing device (510) associated with the service provider (S510). If the information processing system (520) determines that the relevance is less than or equal to (or smaller than) the second predetermined reference relevance, the information processing system (520) can determine that the information indicating or characterizing the service provider and the first content are not related (S522).

[0083] In one embodiment, a computing device (510) associated with a service provider may review whether there is a connection between the service provider and the second website based on the received URL information of the second website and the second content. For example, the computing device (510) associated with the service provider may store detailed information about multiple websites that the service provider uses to provide services. In this case, the computing device (510) associated with the service provider may use the stored information to review in detail whether there is a connection between the service provider and the second website. Thereafter, the computing device (510) associated with the service provider may transmit the review result regarding the connection between the service provider and the second website (S520). Based on the review result regarding the connection between the service provider and the second website, the information processing system (520) may determine that there is no connection between the information indicating or characterizing the service provider and the first content (S522) or that there is a connection (S524).

[0084] In one embodiment, the information processing system (520) may determine whether the service provider is associated with the second website based on the result of determining whether the URL information generated by performing step S502 matches, and the result of determining whether the information indicating or characterizing the service provider is associated with the first content according to step S522 or S524. For example, if the URL information matches and the information indicating or characterizing the first content and the service provider are associated, the information processing system (520) may determine that the second website is associated with the service provider. As another example, if the URL information does not match and the information indicating or characterizing the first content and the service provider are associated, the information processing system (520) may determine that the second website is not associated with the service provider.

[0085] In one example, if the URL information does not match and the information indicating or characterizing the first content and the service provider is determined to be related, or if the URL information matches and the information indicating or characterizing the first content and the service provider is determined to be unrelated, the information processing system (520) may perform steps S510 and S520 to receive a review result on whether the service provider and the second website are related from the computing device (510) associated with the service provider. Thereafter, based on the received review result, the review result may be determined on whether the service provider and the second website are related.

[0086] In another example, if the URL information does not match and the information indicating or characterizing the first content and the service provider is determined to be related, or if the URL information matches and the information indicating or characterizing the first content and the service provider is determined to be unrelated, the information processing system (520) can determine whether the service provider and the second website are related based on the degree of relatedness. In this way, the information processing system (520) can determine whether the service provider and the second website are related in various ways based on the results of determining whether the URL information matches and the results of determining whether the information indicating or characterizing the service provider and the first content are related.

[0087] In one embodiment, the information processing system (520) may generate information indicating one of a phishing website determination, a suspicious website determination, or a legitimate website determination as a result of the determination regarding the association between the service provider and the second website. For example, if the information processing system (520) determines that the service provider and the second website are associated, a determination result indicating that the second website is a legitimate website may be generated. Furthermore, if the information processing system (520) determines that the service provider and the second website are associated, a determination result indicating that the second website is a phishing website may be generated. As another example, if the URL information does not match and the information indicating or characterizing the first content and the service provider is determined to be associated, or if the URL information matches and the information indicating or characterizing the first content and the service provider is determined to be unassociated, the information processing system (520) may generate a determination result indicating that the second website is a suspicious website presumed to be a phishing website. As another example, if the relevance is determined to be less than the first reference relevance and greater than the second reference relevance, the information processing system (520) may not perform steps S510 and S520, and a determination result may be generated that the second website is a suspicious website.

[0088] Alternatively, the information processing system (520) may not generate a judgment result indicating a suspicious website, but may only generate a judgment result indicating a phishing website or a legitimate website. Specifically, in the examples described above, if the information processing system (520) determines a suspicious website, the information processing system (520) may determine a phishing website or a legitimate website, rather than a judgment result indicating a suspicious website.

[0089] The information processing system (520) may provide the user terminal (530) with information indicating one of the following: a phishing website determination, a suspicious website determination, or a legitimate website determination, as a result of determining whether the service provider and the second website are related (S540). In one embodiment, the information processing system (520) may provide the user terminal (530) with a correlation score along with the website determination result. The user terminal (530) may output an analysis result for the second website based on the provided correlation score. The analysis result is described in detail with reference to FIG. 6.

[0090] If it is unclear whether the information processing system (520) determines whether a second website is related to a service provider, the information associated with the second website can be transmitted to a computing device (510) associated with the service provider to determine whether the second website is related to the service provider. In other words, the website verification method according to the present disclosure can precisely determine whether a second website is related to a service provider by utilizing a computing device (510) associated with the service provider.

[0091] Figure 6 is a diagram illustrating an example interface of a user terminal that receives information regarding a phishing website determination according to one embodiment of the present disclosure. In one example, the user terminal may receive information regarding the phishing website determination from an information processing system. The user terminal may then output a warning indicating that the website is a phishing website.

[0092] Referring to FIG. 6, the first example (600) may depict an interface in which a pop-up window (610) is displayed on a user terminal. The pop-up window (610) may include a warning indicating that the website being accessed on the user terminal is a phishing website. The user can confirm that the website being accessed is a phishing website through the pop-up window (610).

[0093] The user terminal can receive a correlation from the information processing system. Based on the correlation, the user terminal can output an analysis result (612) for the currently accessed website. For example, if the correlation is 100% when the first content disclosed on the first website and the content disclosed on the currently accessed website are completely identical, the user terminal can output a ratio corresponding to the received correlation as the analysis result (612).

[0094] The user terminal can output an object associated with the execution of the website verification service. Referring to FIG. 6, if the user terminal receives an input regarding the first object (614), a warning indicating that the website is a phishing website can be removed. In this case, if the user terminal accesses a site related to the website being accessed (e.g., a linked website accessible through a link disclosed on the website being accessed, a website with the same domain address as the website being accessed, etc.), the website verification method may not be executed for the newly accessed website. If the user terminal receives an input regarding the second object (616), a warning indicating that the website is a phishing website can be removed. In this case, if the user terminal accesses a website related to the website being accessed, the website verification method may be repeatedly executed for the newly accessed website.

[0095] Not limited to the method illustrated in Figure 6, warnings can be provided in various ways that allow users to identify a phishing website. For example, a user terminal may force-close a web browser in response to receiving information indicating a phishing website. As another example, a user terminal may output a warning sound in response to receiving information indicating a phishing website.

[0096] In one example, in response to receiving information indicating a suspicious website, the user terminal may output a warning identical to the warning indicating a phishing website. In another example, if the user terminal receives information indicating a legitimate website, the warning may not be output. In yet another example, if the user terminal receives information indicating a legitimate website, the user terminal may output information indicating the legitimate website (e.g., via a pop-up window) in response. However, this is not limited to this, and various methods may be used to enable the user to identify a phishing website, a suspicious website, or a legitimate website.

[0097] This configuration allows users to determine whether the website they are accessing on their terminal is a phishing website or a legitimate website. By performing a certain input, the user can interrupt repetitive website verification and then examine the website identified as a phishing website in detail. Furthermore, even if a phishing website is identified incorrectly (e.g., a legitimate website is identified as a phishing website), the user can continue using the website. Thus, the website verification method according to the present disclosure can maintain user safety and security while simultaneously enhancing user convenience.

[0098] FIG. 7 is a flowchart illustrating an example of a website verification method (700) according to one embodiment of the present disclosure. According to one embodiment, the website verification method (700) may be performed by at least one processor of a computing device associated with a user terminal, an information processing system, and a service provider. The website verification method (700) may be initiated by the processor receiving Uniform Resource Locator (URL) information of a first website and first content disclosed on the first website from a computing device associated with the service provider (S710).

[0099] In one embodiment, the processor may receive URL information for a second website and second content disclosed on the second website from the user terminal (S720). Here, the second content may include information identifying or characterizing the service provider, extracted from the second content.

[0100] In one embodiment, the processor may determine whether there is a connection between the service provider and the second website based on the URL information of the first website, the URL information of the second website, the first content, and the second content (S730). Additionally, the processor may determine whether the URL information of the first website matches the URL information of the second website, or whether the URL information of the second website includes the URL information of the first website. Furthermore, the processor may determine whether there is a connection between the first content and information indicating or characterizing the service provider. Thereafter, the processor may determine whether there is a connection between the service provider and the second website based on the result of determining whether there is a connection between the URL information and the result of determining whether there is a connection between the information indicating or characterizing the service provider and the first content.

[0101] Additionally, the processor may use association analysis to determine the association between the first content and information indicating or characterizing the service provider. Furthermore, the processor may determine that the first content and the information indicating or characterizing the service provider are related if the association is greater than a predetermined first reference association.

[0102] Specifically, the processor may determine that the information identifying or characterizing the service provider and the first content are not related if the relevance is less than or equal to a predetermined second criterion relevance. Furthermore, the processor may provide the computing device with the URL information of the second website and the second content if the relevance is greater than the second criterion relevance and less than or equal to the first criterion relevance.

[0103] In one embodiment, in response to determining whether a service provider is associated with a second website, the processor may provide the user terminal with information indicating one of a phishing website, a suspicious website, or a legitimate website. Additionally, the processor may provide the user terminal with information indicating one of a phishing website, a suspicious website, or a legitimate website, as well as the calculated association score.

[0104] In one embodiment, through a verification application of a user terminal, it is determined whether at least one of the URL information of a second website or the second content is associated with a predetermined service provider, and only when it is determined that at least one of the URL information of the second website or the second content is associated with the predetermined service provider, the URL information of the second website and the second content can be received from the user terminal.

[0105] The above-described method may be provided as a computer program stored on a computer-readable recording medium for execution on a computer. The medium may be one that continuously stores a computer-executable program or one that temporarily stores it for execution or download. In addition, the medium may be various recording means or storage means in the form of a single or multiple hardware combinations, and is not limited to a medium directly connected to a computer system, but may also be distributed over a network. Examples of the medium may include magnetic media such as hard disks, floppy disks, and magnetic tapes, optical recording media such as CD-ROMs and DVDs, magneto-optical media such as floptical disks, and those configured to store program instructions, including ROM, RAM, and flash memory. In addition, examples of other media may include recording or storage media managed by app stores that distribute applications, sites that supply or distribute various software, servers, etc.

[0106] The methods, operations, or techniques of the present disclosure may be implemented by various means. For example, these techniques may be implemented in hardware, firmware, software, or a combination thereof. Those skilled in the art will appreciate that the various exemplary logical blocks, modules, circuits, and algorithm steps described in connection with the disclosure herein may be implemented as electronic hardware, computer software, or a combination of both. To clearly illustrate this interchangeability of hardware and software, various exemplary components, blocks, modules, circuits, and steps have been described above generally in terms of their functionality. Whether such functionality is implemented as hardware or software will depend on the particular application and the design requirements imposed on the overall system. Those skilled in the art may implement the described functionality in various ways for each particular application, but such implementations should not be construed as departing from the scope of the present disclosure.

[0107] In a hardware implementation, the processing units used to perform the techniques may be implemented within one or more ASICs, DSPs, digital signal processing devices (DSPDs), programmable logic devices (PLDs), field programmable gate arrays (FPGAs), processors, controllers, microcontrollers, microprocessors, electronic devices, other electronic units designed to perform the functions described herein, a computer, or a combination thereof.

[0108] Accordingly, the various exemplary logical blocks, modules, and circuits described in connection with the present disclosure may be implemented or performed by any combination of a general-purpose processor, a DSP, an ASIC, an FPGA or other programmable logic device, discrete gate or transistor logic, discrete hardware components, or those designed to perform the functions described herein. A general-purpose processor may be a microprocessor, but in the alternative, the processor may be any conventional processor, controller, microcontroller, or state machine. A processor may also be implemented as a combination of computing devices, e.g., a combination of a DSP and a microprocessor, a plurality of microprocessors, one or more microprocessors in conjunction with a DSP core, or any other such configuration.

[0109] In a firmware and / or software implementation, the techniques may be implemented as instructions stored on a computer-readable medium, such as random access memory (RAM), read-only memory (ROM), non-volatile random access memory (NVRAM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable PROM (EEPROM), flash memory, a compact disc (CD), a magnetic or optical data storage device, etc. The instructions may be executable by one or more processors and may cause the processor(s) to perform certain aspects of the functionality described herein.

[0110] When implemented in software, the techniques described above may be stored on or transmitted as one or more instructions or code on a computer-readable medium. Computer-readable media includes both computer storage media and communication media, including any medium that facilitates transfer of a computer program from one place to another. Storage media may be any available media that can be accessed by a computer. By way of example, and not limitation, such computer-readable media can include RAM, ROM, EEPROM, CD-ROM or other optical disk storage, magnetic disk storage or other magnetic storage devices, or any other medium that can be used to carry or store desired program code in the form of instructions or data structures and that can be accessed by a computer. Also, any connection is properly termed a computer-readable medium.

[0111] For example, if the software is transmitted from a website, server, or other remote source using coaxial cable, fiber optic cable, twisted pair, digital subscriber line (DSL), or wireless technologies such as infrared, radio, and microwave, then the coaxial cable, fiber optic cable, twisted pair, digital subscriber line, or wireless technologies such as infrared, radio, and microwave are included within the definition of media. Disk and disc, as used herein, includes compact discs, laser discs, optical discs, digital versatile discs (DVDs), floppy disks, and Blu-ray discs, where disks usually reproduce data magnetically, whereas discs reproduce data optically using lasers. Combinations of the above should also be included within the scope of computer-readable media.

[0112] A software module may reside in RAM memory, flash memory, ROM memory, EPROM memory, EEPROM memory, registers, a hard disk, a removable disk, a CD-ROM, or any other form of storage medium known in the art. An exemplary storage medium may be coupled to the processor such that the processor can read information from, and write information to, the storage medium. Alternatively, the storage medium may be integral to the processor. The processor and the storage medium may reside in an ASIC. The ASIC may reside in a user terminal. Alternatively, the processor and the storage medium may reside as discrete components in the user terminal.

[0113] While the embodiments described above have been described as utilizing aspects of the presently disclosed subject matter in one or more standalone computer systems, the present disclosure is not limited thereto and may be implemented in conjunction with any computing environment, such as a network or distributed computing environment. Furthermore, aspects of the present disclosure may be implemented in multiple processing chips or devices, and storage may be similarly affected across multiple devices. Such devices may include personal computers, network servers, and portable devices.

[0114] While the present disclosure has been described in connection with certain embodiments herein, various modifications and variations may be made without departing from the scope of the present disclosure, which would be apparent to those skilled in the art. Furthermore, such modifications and variations are intended to fall within the scope of the claims appended to this specification.

Claims

1. A method for verifying a website provided to a user, performed by at least one processor, A step of receiving Uniform Resource Locator (URL) information of a first website and first content disclosed on the first website from a computing device associated with a service provider; A step of receiving URL information of a second website and second content disclosed on the second website from a user terminal; and A step of determining whether there is a connection between the service provider and the second website based on the URL information of the first website, the URL information of the second website, the first content, and the second content. , and website verification methods.

2. In paragraph 1, A method for verifying a website, wherein the second content includes information that identifies or characterizes the service provider, extracted from the second content.

3. In paragraph 2, The step of determining whether the above service provider is related to the above second website is: A step of determining whether the URL information of the first website matches the URL information of the second website or determining whether the URL information of the second website includes the URL information of the first website; A step of determining whether there is a relevance between the first content and information indicating or characterizing the service provider; and A step of determining whether the service provider is related to the second website based on the result of determining whether the URL information matches and the result of determining whether the information indicating or characterizing the service provider is related to the first content. A method of verifying a website, comprising:

4. In paragraph 3, The step of determining whether the first content above is related to information that represents or characterizes the service provider is as follows: A step of calculating the degree of association between the first content and information representing or characterizing the service provider using association analysis; and If the above relevance is greater than a predetermined first criterion relevance, a step of determining that the information indicating or characterizing the service provider and the first content are related A method of verifying a website, comprising:

5. In paragraph 4, The step of determining whether the first content above is related to information that represents or characterizes the service provider is as follows: If the above correlation is less than or equal to a predetermined second reference correlation, a step of determining that the information indicating or characterizing the service provider and the first content are not related; and If the above-mentioned degree of relevance is greater than the above-mentioned second reference degree of relevance and less than or equal to the above-mentioned first reference degree of relevance, a step of providing the URL information of the above-mentioned second website and the above-mentioned second content to the above-mentioned computing device. A method of website verification, further comprising:

6. In paragraph 1, In response to determining whether the service provider is related to the second website, a step of providing information indicating one of a phishing website determination, a suspicious website determination, or a legitimate website determination to the user terminal A method of website verification, further comprising:

7. In paragraph 6, The step of providing information indicating one of the above phishing website determination, suspicious website determination, or legitimate website determination to the user terminal. A step of providing information indicating one of the above phishing website judgment, suspicious website judgment or legitimate website judgment and the calculated correlation to the user terminal. A method of website verification, further comprising:

8. In paragraph 1, Through the verification application of the user terminal, it is determined whether at least one of the URL information of the second website or the second content is associated with a predetermined service provider, A website verification method, wherein the URL information of the second website and the second content are received from the user terminal only when at least one of the URL information of the second website or the second content is determined to be associated with the predetermined service provider.

9. A computer-readable, non-transitory recording medium recording commands for executing the method according to Article 1 on a computer.

10. As an information processing system, Communication module; memory; and At least one processor connected to said memory and configured to execute at least one computer-readable program contained in said memory Including, At least one of the above programs, Receiving URL information of a first website and first content disclosed on the first website from a computing device associated with a service provider, Receive URL information of a second website and second content disclosed on the second website from a user terminal, An information processing system including commands for determining whether there is a connection between the service provider and the second website based on URL information of the first website, URL information of the second website, the first content, and the second content.

Citation Information

Patent Citations

  • Forged site detection method and computer program

    JP2007233904A

  • Method for deterrence of personal information usingserver registration and apparatus thereof

    KR1020070059898A

  • Method on prevention of phishing through analysis of the internet site pattern

    KR1020070067651A

  • System and method for preventing phishing

    KR1020140017319A

  • Durable pot pedestals and their manufacture methods

    KR102080557B1