Method for preventing digital fraud, and corresponding electronic device, system, computer program product and medium
The digital fraud prevention process analyzes audiovisual content from user interfaces and correlates it with trusted data sources to detect phishing and other scams, addressing the limitations of existing cybersecurity solutions by identifying risks beyond the immediate application interface and rendering timely alerts.
Patent Information
- Application Number
- PCT/EP2025/063784
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-05-23
- Filing Date
- 2025-05-20
- Publication Date
- 2025-11-27
Smart Images

Figure EP2025063784_27112025_PF_FP_ABST
Abstract
Description
[0001] DESCRIPTION
[0002] Title of the invention: Method for preventing digital fraud and corresponding electronic device, system, computer program product and media
[0003] 1. Technical field
[0004] This application relates to the field of telecommunications and more specifically to the protection of users of telecommunications systems against cyberattacks. It concerns, in particular, a method for preventing digital fraud, implemented by one or more electronic devices, as well as the electronic device(s), computer program products, and corresponding recording media.
[0005] 2. State of the art
[0006] Nowadays, system and telecommunications users are increasingly targeted by cyberattacks. The techniques employed in these cyberattacks, or digital frauds, are becoming increasingly sophisticated and varied, and are sometimes very difficult for a targeted user to detect. Furthermore, a single attacker can rapidly change the form of their attacks (for example, by creating multiple ephemeral websites).
[0007] Among the most widespread attacks, phishing attacks stand out, where a malicious third party adopts a false identity (often that of a trusted third party) to deceive a user and / or induce them to provide sensitive information (personal data, banking data, etc.) and / or to perform actions such as making a payment (by bank transfer, for example).
[0008] Numerous solutions have been developed to combat cybercrime, particularly phishing. However, existing market solutions are unable to eradicate all forms of cybercrime.
[0009] Therefore, there is a need for a solution that improves upon existing cybersecurity solutions on the market.
[0010] 3. Description of the invention
[0011] This application aims to improve the situation through the use of a digital fraud prevention process.
[0012] According to this application, the digital fraud prevention process includes,
[0013] - a conditional rendering of an alert message on a user interface of an electronic device, said conditional rendering taking into account the presence in information rendered by a computer application on a user interface of said device of at least one initial element of content encouraging contact with a third party other than via said computer application. Thus, according to at least one embodiment, the digital fraud prevention process comprises:
[0014] Obtaining audiovisual content from the capture of information rendered by a computer application on a user interface of an electronic device; conditional rendering of an alert message on said user interface taking into account the presence in said audiovisual content obtained of at least one first element of content encouraging contact with a third party other than via said computer application.
[0015] Audiovisual content is defined as content having at least one audio, video and / or textual component, such as an image or a video for example.
[0016] Depending on the implementation methods, it can be "fixed" content (already recorded), or dynamic content (flow).
[0017] According to at least one embodiment, said information is a web page or a message received via email.
[0018] According to at least one embodiment, the first content element belongs to a type of content element representing at least one of the following items: a telephone number; a physical location.
[0019] According to at least one embodiment, the first content element is obtained by a contextual and / or semantic analysis of the audiovisual content.
[0020] According to at least one embodiment, said conditional rendering takes into account a consistency between said first content element and at least one associated data in a data source, certified reliable by a trusted third party, to a second content element obtained during said analysis.
[0021] In at least one embodiment, the method comprises accessing a first data structure associating reliable data sources with descriptions of the types of data accessible via said reliable data sources; selecting said data source taking into account a similarity between:
[0022] • on the one hand, a type of said first element of the content and a first type of data included in a description associated with said data source in said first data structure,
[0023] • and on the other hand, a second type of data included in said description and a type of said second content element.
[0024] In at least one embodiment, if an inconsistency is detected between the first piece of content and at least one piece of data, the method includes recording that other data in a first set of content elements associated with a risk of digital fraud. In at least one embodiment, the second piece of content belongs to a group comprising:
[0025] - a logo of an organization;
[0026] - an identifier of an organization;
[0027] -a label from an organization;
[0028] - a combination of at least two of the above content elements.
[0029] According to at least one embodiment, said conditional rendering takes into account the membership of said first content element in a second set of content elements certified as reliable by a trusted third party.
[0030] In at least one embodiment, the conditional rendering takes into account the membership of the first content element in a third set of content elements already associated in a data structure with a digital fraud risk. This third set of content elements may, for example, be the same set of content elements as the first set of content elements associated with a digital fraud risk introduced above.
[0031] The characteristics, presented in isolation in this application in connection with certain embodiments of at least one of the methods of obtaining and / or rendering of this application may be combined with each other according to other embodiments of this method.
[0032] In another aspect, the present application also relates to an electronic device adapted to implement at least one of the methods of obtaining and / or rendering the present application in any of its embodiments.
[0033] For example, this application relates to an electronic device comprising at least one processor configured to implement digital fraud prevention, including:
[0034] - a conditional rendering of an alert message on a user interface of said electronic device, said conditional rendering taking into account the presence in information rendered by a computer application on a user interface of said device of at least one first element of content encouraging contact with a third party other than via said computer application.
[0035] For example, this application relates to an electronic device comprising at least one processor configured to implement digital fraud prevention, including:
[0036] Obtaining audiovisual content from the capture of information rendered by a computer application on a user interface of an electronic device; conditional rendering of an alert message on said user interface taking into account the presence in said audiovisual content obtained of at least one first element of content encouraging contact with a third party other than via said computer application.
[0037] According to another aspect, the present application also relates to a telecommunications system comprising at least one electronic device suitable for implementing the prevention method of the present application in any of its embodiments.
[0038] Thus, the present application relates, for example, to a telecommunications system comprising at least one electronic device including at least one processor configured to implement digital fraud prevention, including
[0039] Obtaining audiovisual content from the capture of information rendered by a computer application on a user interface of an electronic device; conditional rendering of an alert message on said user interface taking into account the presence in said audiovisual content obtained of at least one first element of content encouraging contact with a third party other than via said computer application.
[0040] This application also relates to a computer program comprising instructions for implementing the various embodiments of the above prevention method, when the program is executed by a processor and a recording medium readable by an electronic device and on which the computer program and the corresponding information medium are recorded.
[0041] For example, this application relates to a computer program comprising instructions for implementing, when the program is executed by a processor of an electronic device, a digital fraud prevention method comprising:
[0042] - a conditional rendering of an alert message on a user interface of an electronic device, said conditional rendering taking into account the presence in information rendered by a computer application on a user interface of said device of at least one first element of content encouraging contact with a third party other than via said computer application.
[0043] For example, this application relates to a computer program comprising instructions for implementing, when the program is executed by a processor of an electronic device, a digital fraud prevention method comprising:
[0044] Obtaining audiovisual content from the capture of information rendered by a computer application on a user interface of an electronic device; conditional rendering of an alert message on said user interface taking into account the presence in said audiovisual content obtained of at least one first element of content encouraging contact with a third party other than via said computer application.
[0045] For example, the present application thus relates to an information carrier readable by a processor of an electronic device and on which is recorded a computer program comprising instructions for the implementation, when the program is executed by the processor, of a digital fraud prevention process comprising, - a conditional rendering of an alert message on a user interface of an electronic device, said conditional rendering taking into account the presence in information rendered by a computer application on a user interface of said device of at least one first element of content encouraging contact with a third party other than via said computer application.
[0046] For example, the present application also relates to a data carrier readable by a processor of an electronic device and on which is recorded a computer program including instructions for the implementation, when the program is executed by the processor, of a digital fraud prevention process comprising: Obtaining audiovisual content from a capture of information rendered by a computer application on a user interface of an electronic device; a conditional rendering of an alert message on said user interface taking into account the presence in said audiovisual content obtained of at least one first element of content encouraging contact with a third party other than via said computer application.
[0047] The programs mentioned above may use any programming language, and be in the form of source code, object code, or code intermediate between source code and object code, such as in a partially compiled form, or in any other desirable form.
[0048] The information (or recording) media referred to in this application may be any entity or device capable of storing the program. For example, a medium may include a storage means, such as a ROM, for example a CD-ROM or a microelectronic circuit ROM, or a magnetic recording means.
[0049] Such a storage medium could be, for example, a hard drive, flash memory, etc. Furthermore, an information carrier could be a transmissible medium such as an electrical or optical signal, which can be transmitted via an electrical or optical cable, by radio, or by other means. A program according to the invention can, in particular, be downloaded from a network such as the Internet.
[0050] Alternatively, an information (or recording) medium may be an integrated circuit in which a program is incorporated, the circuit being adapted to execute or to be used in the execution of any of the embodiments of the process which is the subject of this patent application.
[0051] In general, obtaining an element means in this application, for example, receiving that element from a communication network, acquiring that element (via, for example, user interface elements or sensors), creating that element by various processing means such as copying, encoding, decoding, transformation, etc., and / or accessing that element from a local or remote storage medium accessible to at least one device implementing, at least partially, that obtaining.
[0052] 4. Brief description of the drawings
[0053] Other features and advantages of the invention will become clearer upon reading the following description of particular embodiments, given by way of simple illustrative and non-limiting examples, and the accompanying drawings, among which:
[0054] Figure 1 presents a simplified view of a system, cited as an example, in which at least some embodiments of the process of the present application can be implemented.
[0055] Figure 2 presents a simplified view of a device adapted to implement at least some embodiments of the process described in this application.
[0056] Figure 3 presents an overview of the process of this application, in some of its embodiments.
[0057] Figure 4 presents, on the one hand, an example of a fraudulent web page and, on the other hand, of an alert message, rendered on a user interface of a device such as device 200 in Figure 2, implementing the process of the present application, in some of its embodiments.
[0058] 5. Description of the implementation methods
[0059] This application proposes a digital fraud detection solution based on capturing information rendered by a computer application on a user interface of an electronic device and correlating it with data from at least one other data source (for example, from various sources).
[0060] The proposed solution is an "Over The Top" (OTT) solution, meaning it operates "above" (or on top of) the applications running on the electronic device and can run regardless of the application currently running on the terminal. Such a solution offers the advantage, at least in some embodiments, of being independent of the operating system of the device on which the prevention method is implemented and of the applications running on that device.
[0061] Data from various sources refers to data related to contextual information constructed in relation to the user's activity. This can include structured data stored internally on the electronic device or externally (for example, structured data stored on a database or a third-party server).
[0062] These data sources can vary depending on the user's activity (web browsing, etc.), as well as the information displayed on the device's user interface. For example, when the displayed information relates to a company, one of the data sources could be a registry listing all companies created in a geographical area (such as a country), like the "infogreffe" website in France.
[0063] The solution focuses in particular on identifying, within the information displayed on the application interface, elements that could entice a user to contact a malicious third party without using that application interface. These elements could include, for example, a phone number to call, an email address to use, and / or a physical address to visit or to whom to send paper documents.
[0064] The proposed solution can thus help detect cyberattacks that might go unnoticed by solutions (such as some prior art solutions) focusing on the "immediate" means of action provided by the software application that generated the rendering, to a user via its application interface (displaying the rendered information). The inventors ingeniously observed that a cyberattack could be merely the prelude to a scam unfolding through a channel other than the application interface in question (during a phone call or a face-to-face meeting, for example). Monitoring interactions via the application interface will therefore not be sufficient in such a situation.
[0065] Thus, for example, a very simple web page presenting a company's activities, without containing a link (or "Uniform Resource Locator" (URL) to another page, or any graphical element for data entry, will be considered harmless from the outset by some prior art solutions because it does not directly allow the provision of confidential information and cannot redirect the user to a potentially malicious site. Therefore, these prior art solutions will not analyze it. Conversely, the solution described in this application will analyze other elements present on the page to detect, by correlation with at least one data source, any potentially malicious and / or fraudulent context.
[0066] The present request is now described in more detail in relation to the figures presented.
[0067] Figure 1 represents a telecommunications system 100 in which certain embodiments of the invention can be implemented. The system 100 comprises one or more electronic devices, at least some of which can communicate with each other via one or more communication networks 160, possibly interconnected (for example, via an interconnection device 140 (also called a gateway), such as a local area network (LAN) and / or a wide area network (WAN). Examples of networks may include a corporate or home LAN and / or a WAN such as the internet, cellular, GSM (Global System for Mobile Communications), UMTS (Universal Mobile Telecommunications System), Wi-Fi, etc.
[0068] As illustrated in Figure 1, the system 100 may also include one or more electronic devices, such as a terminal 110, 112 (like a laptop, smartphone, and / or tablet), an augmented, mixed, or virtual reality headset, a connected object, and / or a server 130, for example, an application server, or a storage device 150, 152. The system may also include network management and / or interconnection elements (not shown). These electronic devices may be associated with at least one user 120 (for example, via a user account accessible by login), and several of the electronic devices 110, 112 may be associated with the same user. At least one computer application 170 may run, at least partially, on at least one of the devices and, in particular, provide an application interface to a user 120 of a terminal 110, 112 of the system.
[0069] Figure 2 illustrates a simplified structure of an electronic device 200 of the system 100, for example the device 110, 112, 130 or 140 of Figure 1, adapted to implement the principles of this application. Depending on the embodiment, it may be a server, a gateway and / or a terminal.
[0070] Device 200 includes, in particular, at least one memory M 210. Device 200 may include, in particular, a buffer memory, volatile memory (e.g., RAM, for "Random Access Memory"), and / or non-volatile memory (e.g., ROM, for "Read Only Memory"). Device 200 may also include a processing unit UT 220, equipped, for example, with at least one processor P 222, and driven by a computer program PG 212 stored in memory M 210. At initialization, the code instructions of the computer program PG are, for example, loaded into RAM before being executed by the processor P.Said at least one processor P 222 of the processing unit UT 220 may in particular implement, individually or collectively, any one of the embodiments of at least one of the prevention methods of this application (described in particular in relation to Figure 3), according to the instructions of the computer program PG.
[0071] The device may also include, or be coupled to, at least one I / O module 230, such as a communication module, enabling, for example, the device 200 to communicate with other devices in the system 100 via wired or wireless communication interfaces, and / or such as a user interface module for the device (also referred to more simply in this application as a "user interface"). A user interface of the device is understood to mean, for example, an interface integrated into the device 200, or a part of a third-party device coupled to this device by wired or wireless communication means. For example, this could be a secondary display of the device, a camera (enabling the acquisition of gesture commands from an operator, for example), or a set of speakers connected wirelessly to the device.
[0072] A user interface can notably be an "output" user interface adapted for rendering (or controlling rendering) an output element of a computer application used by the device 200 (such as a web page), for example an application running at least partially on the device 200 or an "online" application running at least partially remotely, for example on the server 130 of the system 100. Examples of output user interfaces of the device include one or more screens, including at least one graphics screen (touchscreen for example), one or more speakers, a connected headset (including an augmented, mixed or virtual reality headset).
[0073] By output, we mean a presentation (or "output" in English terminology) on at least one user interface, in any form, for example, including text, audio, and / or video components, or a combination of such components. Furthermore, a user interface can be an "input" user interface, adapted for receiving a command from a user of device 200 or for entering information by a user of device 200. This could include an action (command, input, etc.) to be performed in relation to an item rendered by device 200 and transmitted to a computer application running at least partially on device 200 or to an "online" application running at least partially remotely, for example, on a server (not shown) of system 100.Examples of input user interfaces for device 200 include a sensor, an audio and / or video acquisition means (e.g., a microphone, a camera (webcam), a control acquisition means (key(s), e.g., a keyboard, button, mouse, touchscreen actuator), etc.
[0074] Some user interfaces (such as a touchscreen) can be input / output user interfaces, allowing both information rendering and user actions.
[0075] Here, "application interface" refers to the application elements rendered by an application via an output (or input / output) user interface of the device 200 and the elements of interaction with the application presented on this output interface (including input forms, clickable links, etc.) and actionable via an input (or input / output) interface of the device (keyboard, mouse, touch screen, etc.).
[0076] Said at least one microprocessor of device 200 can in particular be adapted to implement the process of the present application.
[0077] Thus, at least one microprocessor of device 200 can be adapted, in particular, to implement digital fraud prevention, including:
[0078] - a conditional rendering of an alert message on a user interface of said device, said conditional rendering taking into account the presence in information rendered by a computer application on a user interface of said device of at least one first element of content encouraging contact with a third party other than via said computer application.
[0079] Thus, at least one microprocessor of device 200 can be adapted, in particular, to implement digital fraud prevention, including:
[0080] Obtaining audiovisual content derived from the capture of information rendered by a computer application on the user interface of an electronic device; conditionally displaying an alert message on said user interface, taking into account the presence in said audiovisual content of at least one initial element of content prompting contact with a third party other than via said computer application. For example, device 200 may include (or be coupled with) at least one communication module adapted for receiving audiovisual content and / or sending an alert to or from a third-party device.
[0081] It is noted that according to the embodiments, the device can be the device 110, 112 on which the application interface to be evaluated is rendered or a device "supervising" a device 110,112 on which the application interface to be evaluated is rendered.
[0082] Thus, in certain embodiments, the device 200 may include (or be coupled to) at least one module for capturing audiovisual content rendered on a user output interface (of the device 200 or a third-party device). Such a capture module may, for example, correspond to audiovisual stream acquisition equipment (hardware module) (such as smart glasses, an augmented or virtual reality headset, a camera, a microphone, etc.) or to a software module such as an application probe, internal to the device 200, capable of detecting (capturing) and collecting information rendered to a user on an output interface of the device 200. For example, in the case of an email rendered on a screen of the device 200, a camera of the device may acquire an image of the rendered email, and an application probe may capture an HTML description of the email.An application probe can sometimes prove more reliable than certain character recognition techniques, for example OCR (Optical Character Recognition), since it directly captures the data, unlike character recognition techniques which obtain this data by interpreting the acquired elements, with the associated risk of error.
[0083] This image or the description of this image can then be processed by one or more modules of the device 200 (for example modules of the program P loaded by the processing unit of the device 200).
[0084] For the sake of simplicity, in the rest of the request we will equate the audiovisual content (image and / or audio) and its description (for example in html format).
[0085] For example, the P program of device 200 may include a management module (detection, recognition) for events related to the activity of the user of said device 200. For example, when device 200 is a computer or a smartphone, the detection module may detect a change in active windows, determine the name of an active application, capture audiovisual content (or its description), such as an audio and / or video stream if device 200 is an AR / VR headset. The P program may also include a context management module, responsible for performing a contextual analysis of the obtained audiovisual content, and a module responsible for verifying the consistency of the elements resulting from the contextual analysis to detect potential fraud.
[0086] Some of the above input / output modules are optional and may therefore be absent from device 200 in certain embodiments. In particular, if the process is implemented locally by device 200, communication modules adapted for receiving audiovisual content and / or sending an alert message from / to another device may be optional in certain embodiments.
[0087] On the contrary, in some of its embodiments, the process can be implemented in a distributed manner between at least two devices 110, 112, 130, 140, 150, 152 of the system 100.
[0088] The terms "module," "component," or "element" of the device refer to a hardware element, particularly a wired one, a software element, or a combination of at least one hardware element and at least one software element. The method according to the invention can therefore be implemented in various ways, including in wired and / or software form.
[0089] We now present in more detail certain implementation methods of prevention process 300 of this application.
[0090] As shown in Figure 3, the process 300 can include obtaining 310 audiovisual content rendered on an application interface. For example, this could be an image, such as an image of a video-type audiovisual stream acquired or received in real time (via a capture or communication module of the device 200, depending on the embodiment) and representative of the rendering on a graphic screen of the device 200 of an application 170. It could also be voice content in certain embodiments. In addition, or alternatively, the process can include obtaining a description of the rendered audiovisual content. The description could, for example, be generated by an application probe. It could, in particular, be a representation in a computer language using tags to describe the elements of digital content (web page, email, etc.) (nature, size, color, positioning, labels, structure, etc.).and the links between these elements, or between these elements and external elements. Examples of such languages are HTML (HyperText Markup Language), CSS (Cascading Style Sheets), and / or JavaScript. An example of an HTML description is provided in Appendix 1.
[0091] As illustrated, the process may include an analysis of the obtained content and / or the description obtained of that content (or its description), for example, to identify the displayed data. For instance, the analysis may include the extraction of informative elements from the obtained audiovisual content (and / or its description). For example, in the case of obtained content with a visual component, this may involve using image analysis techniques to detect image fragments likely to correspond to objects of interest (logo, text, etc.), precisely "outlining" these objects of interest, and, when they are likely to contain text, applying character recognition techniques (for example, "optical character recognition" or OCR) to these image fragments to extract textual elements (words or strings of characters).Image analysis can also provide 322 positioning information for these objects of interest (text, logo, etc.) in the audiovisual content.
[0092] In the case of audiovisual content including a voice sequence, audio analysis techniques can for example be applied to enable word recognition in this sequence (including speech-to-text conversion techniques (or "Speech To Text" according to English terminology), to which positioning information in the sequence can also be associated.
[0093] As mentioned above, the analysis can also include an analysis of a description obtained from the audiovisual content. This analysis can, for example, detect (and extract) informative elements from the description similar to those detected through image analysis (logos, text, etc.). However, analyzing a description can sometimes detect text and other elements present in the content with greater reliability, since these are explicitly indicated in the description and not "deduced" from image processing, which is subject to potential errors or inaccuracies. Furthermore, an analysis based on application probes can prove simpler, and therefore less demanding in terms of memory and processing resources, than an analysis using image processing.
[0094] An analysis of a content description can also allow, at least in some embodiments, the detection and extraction of informative elements not detectable visually or by audio analysis on the content, such as an internet access present in the content but appearing (visually) on the content with a label different from the actual address of this access, or a url present in the content but hidden (visually) from a user.
[0095] As illustrated, process 300 can also include obtaining the "fraud" context of the content, that is, a corpus of data on which the assessment of the fraud risk associated with the content will be based. This obtaining may involve searching the extracted information from the content and / or its description for elements relevant to a fraud context (such as logos, meaningful words, and / or named entities that may be important for predicting (detecting) fraudulent content (i.e., for assessing the risk that the content is fraudulent). For example, such named entities might include a company name, a telephone number, an internet address, an email address, a web address (or URL, for Uniform Resource Locator), etc. All this data forms the "context" of the content to be assessed.
[0096] As illustrated, process 300 may include an assessment 330 of the (fraud) context obtained.
[0097] Optionally, this evaluation 330 may include a check 331 that at least one context element of a certain type (internet address, domain name, telephone number, etc.) belongs to at least one set (for example, one or more lists) of elements of the same type already classified as reliable; and / or, conversely, a check 332 that such context element(s) belong to at least one set (for example, one or more lists) of elements of the same type already classified as representative of a cyberattack. These checks may be optional in certain embodiments.
[0098] The fraud context assessment 330 may also include, for example, a consistency check 337 between at least two elements of the content's fraud context. For example, the process may include a consistency check 337 between at least one first element of a first type of context and at least one associated element, external to the context, of at least one second element of the context, this associated element being the second element of a type corresponding to the first type of this first element. This element may be associated with the second element in at least one data source accessible (locally or remotely) to the device 200 and considered reliable.Put more simply, if the fraud context includes a first element and a second element, the process may include a check 337 of the consistency of the first element of the context with an element external to the context, of the same type (or a similar type) as the first context element, and obtained from the second element. More precisely, the process may include obtaining 333 at least one first data structure describing and providing access to at least one reliable data source (capable of providing this external element in our example above). Alternatively, the process may include obtaining a path to such a first data structure.
[0099] The first data structure can for example be obtained 333 by accessing a configuration file prior to the execution, or initialization, of the process 300. It can also be built dynamically by a supervisor operator and received prior to or during the execution of the process 300 (for example during each evolution of this data structure).
[0100] The first data structure can, for example, be obtained (by accessing at least one local or remote file) each time audiovisual content is retrieved, or alternatively, each time content is analyzed (for example, just before, during, or just after the content is retrieved or analyzed). In some embodiments, the first data structure can also be obtained via a configuration file prior to the execution and / or initialization of process 300.
[0101] Note that the first data structure can evolve over time, so it may be possible to add new data sources and associated descriptions to the first data structure, to modify them (access path and / or description) or to delete them.
[0102] As illustrated, the process may include a 334 (read) access to the first obtained data structure 333.
[0103] The first data structure may include an identifier and / or a path to at least one data source considered reliable. It may also include, in association with the identifier and / or path of this source, a description of the types of data accessible through this reliable data source.
[0104] The first data structure can, for example, take the form of a list, a database, or a lookup table.
[0105] Examples of reliable data sources include government data sources (such as business registers) or private data sources (such as telephone number directories) verified by a trusted third party. It could also be one or more data sources maintained by the same entity implementing the process described in this application (for example, a data source such as a telephone network subscriber list managed internally by a telephone operator, like the applicant). A data source could take the form of, for example, one or more files, at least one database, a web service (such as an online application), etc.
[0106] A data source can, for example, provide access to secondary data structures that link certain data together. For example, the first data structure may contain an address (or access link (URL for example)) of a first data source, corresponding to a government business register, to which is associated, in the first structure, a description listing the information accessible via this first data source (i.e. the description of the "second" data structure that this data source contains (Company name, company address, Company ID, code and / or label of the company activity, etc.).Similarly, in this example, the first data structure can also contain an address of a second data source, corresponding to a register of postal addresses, telephone numbers and / or company websites, to which is associated, in the first structure, a description listing the information accessible via this second data source (Company name, Company ID, date of creation of the company, company address, URL of the company website, main telephone number, etc.).
[0107] Similarly, in this example, the first data structure can also contain an address of a third data source, corresponding to a register of company trademarks, to which is associated, in the first structure, a description listing the information accessible via this third data source (Company name, current logo, former logos, sound motif ("jingle" according to English terminology) specific to the company, etc.).
[0108] Note that, as this example shows, a data source can provide access to data other than textual data, such as image or audio data.
[0109] According to a first example, the first data structure can be represented as a lookup table associating the address of a data source with an n-tuple describing the different types of data accessible via that source.
[0110] Thus, the example above can be represented in the form of the following table ("table 1"):
[0111] [Table 1]
[0112] According to a second example, the first data structure can be represented in the form of the following table ("table 2"), listing the possible data types (descriptors) of the sources and associating, for each source and each possible data type, a boolean value indicating whether the source actually leads to data of the type concerned, (a boolean value "True" being indicated below, for example, by an "X", and a boolean value "False" by an absence of an "X").
[0113] [Table 2] ni
[0114] "T
[0115] Associating a data source address with a tuple describing the different data types accessible through that source (as in Table 1) can facilitate the evolution of the initial data structure (for example, to integrate sources providing access to "new" data types not previously present in the initial data structure). Associating a data source address with a set of Boolean values (as in Table 2) indicating the data types accessible through the source can, in certain embodiments, allow for faster determination of a source's data types than associating a data source address with a tuple describing the source's data types, thus offering advantages in terms of processing time and / or complexity.
[0116] As illustrated in Figure 3, process 300 may, in certain embodiments, include a selection 335 of at least one data source from the first data structure, taking into account a similarity between:
[0117] - on the one hand, the type of at least one first element of the context (which is to be checked) and a data type included in the description associated with the data source in the first data structure, and - on the other hand, another data type included in the description associated with the data source in the first data structure and the type of at least one second element of the context (through which the check can be carried out).
[0118] Depending on the embodiment and the types of context elements, similarity is understood to mean either identical types (for example, a first element of type "telephone number" versus the presence of the data type "telephone number" in the description of a source), or types corresponding to at least partially identical data (for example, a first element of type "email" versus the presence of the data type "domain name" in the description of a source, the email associated with a company logically including the company's domain name). The process 300 may include accessing at least one selected data source to obtain at least one element external to the fraud context and associated, in the data source, with the second context element, and verifying the consistency between this external element and the first context element whose consistency is being verified.
[0119] Consistency checking can be performed iteratively on several context elements (to be checked). For example, in some embodiments, it can be performed for each context element originating from the application interface. In particular, the process may include checking the consistency of seemingly innocuous context elements that do not allow online data entry or access to another webpage / website, such as a company registration number in an official national register listing business creations, for example.
[0120] Depending on the embodiment, a variable number of data sources can be selected to verify the consistency of a first context element. Increasing the number of selected data sources can improve the reliability of the prevention process in certain embodiments (for example, by guarding against the potential corruption of a data source that was otherwise considered reliable). Limiting the number of data sources selected to verify the consistency of the same context element can help reduce the processing time and / or complexity of the consistency check (for example, by avoiding duplication of certain checks when multiple data sources provide access to external elements of the same type as the first element to be verified).
[0121] In some embodiments, data sources can be used in a cascading fashion, enabling consistency checks between multiple elements of the fraud context through the use of intermediate data sources containing complementary data types. For example, if the fraud context includes an element of type Type-1 and a second element of type Type-2, a cascading approach can be used: access to a first data source whose description includes data of Type-1, Type-3, then access to a second data source containing data of type Type-3, Type-4, Type-5, and finally access to a third data source containing data of type Type-5, Type-6, Type-2.
[0122] The process may include processing the evaluation result. This processing may include generating a message informing the user of the consistency check result. Depending on the embodiment, the message may be rendered and / or stored locally and / or transmitted to another device (for example, via another user device or to a monitoring device).
[0123] This message may be optional when consistency check 337 did not detect any inconsistency.
[0124] This message may correspond to an alert when the consistency check 337 has resulted in the detection of at least one inconsistency for at least one element of the context. If the consistency check 337 has resulted in the detection of at least one inconsistency for at least one element of the context, the process may include adding at least one identifying piece of information relating to the checked application interface, and / or the inconsistent context element, to a data structure containing data identified as representative of a cyberattack. Such a data structure may be used subsequently within the process of this application (for example, step 332) or by any other process (for example, another fraud prevention process of the applicant).
[0125] An example of the implementation of the procedure described in this application is presented below, in conjunction with Figure 4. In our example, a user of an electronic terminal searches the internet for a firewood supplier. They access one of the websites suggested by their terminal's search engine. The website they access displays the 410 error page shown in Figure 4.
[0126] The 300 process is initiated by the display of the 410 homepage (or alternatively by activating the link presented by the search engine and giving access to this 410 homepage).
[0127] According to the process, a capture (310) of the content displayed on the homepage (410) is performed. The captured content is then analyzed (320) to extract keywords and obtain the context of the fraud, and a contextual evaluation (330) is performed. This evaluation results in the detection of an inconsistency between the company name and the telephone number displayed on the homepage. An alert is generated. In the illustrated example, this alert generation includes displaying an informational message (420) on the electronic terminal screen. In the illustrated example, the process may also include saving all homepage elements detected as inconsistent (element types, values, etc.) to a remote server. The alert may also include sending a message to a third-party supervisor.In our example, this involves a third party managing a data structure that lists fraudster phone numbers and offers an alert service to its users (such as the plaintiff's "Orange Telephone" service). The fraudulent phone number is added to the supervisory third party's data structure so that users of the service can be alerted to the fraud risk associated with that phone number.
[0128] Appendix 1
[0129] {
[0130] {
[0131] "kind": {
[0132] "value": "web_navigator",
[0133] "conf: 0.86
[0134] },
[0135] "thrilled": [
[0136] {
[0137] "area_type": {
[0138] "value": "web_site_url",
[0139] "conf": 0.86
[0140] },
[0141] "bbox": [{"x":1, "y": 1, "w": 923, "h": 60}],
[0142] "data": [
[0143] {
[0144] "type": "web_site_url",
[0145] "mimetype":"text / x-uri",
[0146] "bbox": [{"x":1 , "y": 1 , "w": 323, "h": 12}], "value":"http: / / i nfo-edf.com / we2345", "conf": 0.98
[0147] }
[0148] },
[0149] {
[0150] "area_type": {
[0151] "value": "organizationjnfo",
[0152] "conf": 0.76
[0153] },
[0154] "bbox": [{"x":1 , "y": 70, "w": 723, "h": 300}],
[0155] "data": [
[0156] {
[0157] "type": "logo",
[0158] "mimetype":"image / jpg",
[0159] "bbox": [{"x":12, "y": 23, "w": 123, "h": 123}], "value":"EDF", "conf": 0.78
[0160] },
[0161] {
[0162] "type": "Organization",
[0163] "mimetype":"text / *",
[0164] "bbox": [{"x":123, "y": 330, "w": 223, "h": 12}], "value":"EDF",
[0165] "conf": 0.98
[0166] },
[0167] {
[0168] "type": "mail",
[0169] "mimetype":"text / plain",
[0170] "bbox": [{"x":123, "y": 400, "w": 183, "h": 12}], "value":"contact@edf.com",
[0171] "hidden_value": "contact@info-edf.com", "conf": 0.78
[0172] },
[0173] {
[0174] "type": "phone", "mimetype":"text / plain",
[0175] "bbox": [{"x":123, "y": 450, "w": 120, "h": 12}],
[0176] "value":"09.98.33.21.42",
[0177] "conf": 0.97
[0178] } ]
[0179] },
[0180] }
Claims
DEMANDS 1. A method for preventing digital fraud comprising, - a conditional rendering of an alert message on a user interface of an electronic device, said conditional rendering taking into account the presence in information rendered by a computer application on a user interface of said device of at least one first element of content encouraging contact with a third party other than via said computer application.
2. Prevention method according to claim 1 wherein said information is a web page or a message received via email.
3. A prevention method according to claim 1 or 2 wherein the first content element belongs to a type of content element representing at least one of the following items: - a telephone number; - a physical location.
4. Prevention method according to any one of claims 1 to 3 wherein the first content element is obtained by a contextual and / or semantic analysis of the audiovisual content.
5. Prevention method according to claim 4 wherein said conditional rendering takes into account a consistency between said first content element and at least one associated data in a data source, certified reliable by a trusted third party, to a second content element obtained during said analysis.
6. A prevention method according to claim 5, wherein the method comprises - access to an initial data structure associating reliable data sources with descriptions of the types of data accessible via said reliable data sources; - a selection of said data source taking into account a similarity between: • on the one hand, a type of said first element of the content and a first type of data included in a description associated with said data source in said first data structure, • and on the other hand, a second type of data included in said description and a type of said second content element.
7. Prevention method according to claim 5 or 6 wherein in the event of detection of an inconsistency between said first content element and said at least one data point, the method comprises a recording of said first element in a first set of content elements associated with a risk of digital fraud.
8. A prevention method according to any one of claims 5 to 7, wherein said second content element belongs to a group comprising: - a logo of an organization; - an identifier of an organization; -a label from an organization; - a combination of at least two of the above content elements.
9. A prevention method according to any one of claims 1 to 8 wherein said conditional rendering takes into account a membership of said first content element in a second set of content elements certified as reliable by a trusted third party.
10. Prevention method according to any one of claims 1 to 9 wherein said conditional rendering takes into account a membership of said first content element in a third set of content elements already associated in a data structure with a risk of digital fraud.
11. Electronic device comprising at least one processor configured to implement digital fraud prevention, including: - a conditional rendering of an alert message on a user interface of said electronic device, said conditional rendering taking into account the presence in information rendered by a computer application on a user interface of said device of at least one first element of content encouraging contact with a third party other than via said computer application.
12. Product computer program comprising instructions for the implementation, when said program is executed by a processor, of a digital fraud prevention method according to at least one of claims 1 to 10.
13. Information carrier readable by a processor of an electronic device and on which is recorded a computer program comprising instructions for the implementation, when said program is executed by said processor, of a digital fraud prevention method according to any one of claims 1 to 10.
Citation Information
Patent Citations
Phishing website identification method and system
CN108566399A
Method and apparatus for image recognition services
EP3239919A1
Anti-phishing system and method using computer vision to match identifiable key information
US10999322B1
Detecting and Protecting Against Employee Targeted Phishing Attacks
US20230188564A1