System and method for evaluating uniform resource locator
The VAILS system with ML models and a distributed ledger effectively evaluates URL credibility by analyzing attributes like HTTPS, FQDN, and domain reputation, addressing the inadequacies of conventional security measures and enhancing URL security in telecommunication services.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2025-09-19
- Publication Date
- 2026-04-02
AI Technical Summary
Conventional security measures are inadequate in assessing the legitimacy of URLs, leading to potential security breaches due to the lack of a reliable and systematic approach to evaluate their credibility, which poses risks such as phishing attacks and malware distribution.
A system and method that evaluates URLs using a Vigilant Artificially Intelligent Linguistic System (VAILS) with a URL analyzer, incorporating Machine Learning (ML) models and a distributed ledger to analyze multiple attributes, assign a risk score, and determine credibility through conditions related to HTTPS, FQDN, URL length, domain reputation, and prohibited extensions.
Enhances the ability to distinguish between secure and insecure URLs by providing a comprehensive evaluation of credibility, reducing the risk of phishing attacks and enhancing security in telecommunication services.
Smart Images

Figure IN2025051527_02042026_PF_FP_ABST
Abstract
Description
SYSTEM AND METHOD FOR EVALUATING UNIFORM RESOURCELOCATORTECHNICAL FIELD
[0001] The embodiments of the present disclosure generally relate to the field of artificial intelligence based analytical systems. More particularly, the present disclosure relates to a system and a method for evaluating Uniform Resource Locators (URLs).BACKGROUND OF THE INVENTION
[0002] The subject matter disclosed in the background section should not be assumed or construed to be prior art merely due to its mention in the background section. Similarly, any problem statement mentioned in the background section or its association with the subject matter of the background section should not be assumed or construed to have been previously recognized in the prior art.
[0003] In today’s digital landscape, users frequently encounter Uniform Resource Locators (URLs) within messages, emails, and other forms of communication. In general, the URLs serve as essential gateways to information, however the URLs poses significant security risks such as Phishing attacks, malware distribution, and other malicious activities. These security risks exploit the URLs to deceive users into accessing harmful content.
[0004] Conventional security measures, such as firewalls and antivirus software, offer some protection but are not always sufficient to assess a legitimacy of a URL embedded within a message. Currently, the lack of a reliable and systematic approach to evaluate credibility of the URLs leads to potential security breaches. Conventional solutions are limited in their ability to analyze multiple attributes of the URLs which are critical for determining the trustworthiness of the URLs.
[0005] Therefore, there lies a need for a solution that can address the above discussed challenges by comprehensively scrutinizing the URLs to enable the users to distinguish between secure and insecure URLs effectively.SUMMARY
[0006] The following embodiments present a simplified summary in order to provide a basic understanding of some aspects of the disclosed invention. This summary is not an extensive overview, and it is not intended to identify key / critical elements or to delineate the scope thereof. Its sole purpose is to present some concepts in a simplified form as a prelude to the more detailed description that is presented later.
[0007] According to an embodiment, a method for evaluating a Uniform Resource Locator (URL) in a message is provided. The method includes extracting the URL from the message. The method further includes assigning a risk score to the URL. The risk score is a predefined initial value. Furthermore, the method includes determining whether at least one condition from a set of Internet Protocol (IP) conditions is satisfied for the URL. Furthermore, the method includes updating, based on the determination that the at least one IP condition from the set of IP conditions is satisfied, the risk score by adding phase values corresponding to each IP condition satisfied. Furthermore, the method includes determining whether at least one URL characteristic condition from a set of URL characteristic conditions is satisfied for the URL. Furthermore, the method includes updating, based on the determination that the at least one URL characteristic condition from the set of URL characteristic conditions is satisfied, the risk score by adding phase values corresponding to each URL characteristic condition satisfied. Furthermore, the method includes determining whether an entry corresponding to the risk score of the URL is present in a distributed ledger. Furthermore, the method includes updating the risk score by adding a phase value to the risk score based on the determination that the entry corresponding to the risk score of the URL is present in the distributed ledger, wherein the risk score is indicative of credibility of the URL.
[0008] In some aspects of the present disclosure, the set of IP conditions comprises first and second IP conditions. The first IP condition is met when the URL has at least one of Hyper Text Transfer Protocol Secure (HTTPS) component. The second IP condition when the URL has a Fully Qualified Domain Name (FQDN) component. Moreover, the set of URL characteristic conditions include first through third URL characteristic conditions. The first URL characteristic condition is met when a value of length of the URL being less than or equal to a predefined URL length value, in response to a determination that the URL does not have the FQDN component, or a prohibited extension is present in the URL. The second URL characteristic condition is met when the URL being associated with a reputed domain. The third URL characteristic condition is met when a mean value of the risk score for the URL being greater than or equal to an expected mean value of the risk score.
[0009] In some aspects of the present disclosure, prior to the determining whether the URL characteristic condition(s) are satisfied, the method includes determining, in response to a determination that the second IP condition is satisfied, whether the prohibited extension is present or absent in the URL. Moreover, the method includes updating the risk score by adding a phase value based on the determination that the prohibited extension is absent in the URL.
[0010] In some aspects of the present disclosure, the method further includes determining, in response to the determination that the entry corresponding to the risk score of the URL is present in the distributed ledger, a credibility percentage value for the URL by comparing the risk score with a select risk score.
[0011] In some aspects of the present disclosure, the method further includes determining, based on the determination that the prohibited extension is present in the URL, the credibility percentage value for the URL by comparing the risk score with the select risk score.
[0012] In some aspects of the present disclosure, the method further includes determining, through a Machine Learning (ML) model, a probability value ofcredibility for the URL based on the determination that the entry corresponding to the risk score of the URL is absent in the distributed ledger. Moreover, the method includes determining the credibility percentage value for the URL based on the probability value of credibility for the URL, wherein the ML model performs Natural Language Processing (NLP) on the URL to determine the probability value of credibility for the URL.
[0013] In some aspects of the present disclosure, an addition of a phase values to the risk score is associated with an increase in the credibility percentage of the URL when a corresponding condition is satisfied.
[0014] According to another aspect of the present disclosure, a system to analyze credibility of a Uniform Resource Locator (URL) is provided. The system includes a distributed ledger, a receiving unit, and a processing circuitry. The receiving unit is configured to receive the message and extract the URL from the message. The processing circuitry is configured to assign a risk score to the URL, wherein the risk score is a predefined initial value. Moreover, the processing circuitry is configured to determine whether at least one condition from a set of Internet Protocol (IP) conditions is satisfied for the URL. Furthermore, the processing circuitry is configured to update, based on the determination that the at least one condition from the set of URL characteristic conditions is satisfied, the risk score by adding phase values corresponding to each URL characteristic condition satisfied. Furthermore, the processing circuitry is configured to determine whether an entry corresponding to the risk score of the URL is present in the distributed ledger. Furthermore, the method includes update the risk score by adding a seventh phase value to the risk score based on the determination that the entry corresponding to the risk score of the URL is present in the distributed ledger. The risk score is indicative of credibility of the URL.BRIEF DESCRIPTION OF DRAWINGS
[0015] Various embodiments disclosed herein will become better understood from the following detailed description when read with the accompanying drawings. Theaccompanying drawings constitute a part of the present disclosure and illustrate certain non-limiting embodiments of inventive concepts. Further, components and elements shown in the drawings are not necessarily to scale, emphasis instead being placed upon clearly illustrating the principles of the present disclosure. For the purpose of consistency and ease of understanding, similar components and elements are annotated by reference numerals in the exemplary drawings.
[0016] FIG. 1 is a block diagram depicting a system to evaluate a Uniform Resource Locator (URL), in accordance with an example embodiment of the present disclosure.
[0017] FIG. 2 illustrates example components of a user device of the system to evaluate the URL, in accordance with an exemplary embodiment of the present disclosure.
[0018] FIG. 3 illustrates example components of a URL analyzer to evaluate the URL, in accordance with an exemplary embodiment of the present disclosure.
[0019] FIG. 4 illustrates a flowchart depicting a process for evaluating the URL, in accordance with an embodiment of the present disclosure.
[0020] FIG. 5 illustrates a flowchart depicting a method for evaluating the URL, in accordance with an embodiment of the present disclosure.LIST OF REFERENCE NUMERALS
[0021] The following list is provided for convenience and in support of the drawing figures and as part of the text of the specification, which describe innovations by reference to multiple items. Items not listed here may nonetheless be part of a given embodiment. For better legibility of the text, a given reference number is recited near some, but not all, recitations of the referenced item in the text. The same reference number may be used with reference to different examples or different instances of a given item. The list of reference numerals is as follows:100 - System101 - VAILS102 - User Device(s)104 - URL Analyzer106 - Network108 - Distributed Ledger112 - Processing Circuitry114 - Memory116 - Transceiver Unit118 - ML Model(s)202 - User Interface204 - Network Interface206 - Processing Unit208 - Application Console210 - Device Memory302 - Console Host306 - First Communication Bus310 - Protocol Checker312 - FQDN Observer314 - Extension Reviewer316 - Length Comparator318 - Reputed Domain Assessor320 - Mean Comparer322 - WOT analyzer324 - Score Updater326 - Second Communication Bus400 - Process402-450 - Operational blocks of the process 400500 - Method502-518 - Operational blocks of the method 500DETAILED DESCRIPTION OF THE INVENTION
[0022] Inventive concepts of the present disclosure will now be described more fully hereinafter with reference to the accompanying drawings, in which examples of one or more embodiments of inventive concepts are shown. Inventive concepts may, however, be embodied in different forms and should not be construed as limited to the embodiments set forth herein. Further, the one or more embodiments disclosed herein are provided to describe the inventive concept thoroughly and completely, and to fully convey the scope of each of the present inventive concepts to those skilled in the art. Furthermore, it should be noted that the embodiments disclosed herein are not mutually exclusive concepts. Accordingly, one or more components from one embodiment may be tacitly assumed to be present or used in any other embodiment.
[0023] The following description presents various embodiments of the present disclosure. The embodiments disclosed herein are presented as teaching examples and are not to be construed as limiting the scope of the present disclosure. The present disclosure should in no way be limited to the illustrative implementations, drawings, and techniques illustrated below, including the exemplary design and implementation illustrated and described herein, but may be modified, omitted, or expanded upon without departing from the scope of the present disclosure.
[0024] The following description contains specific information pertaining to embodiments in the present disclosure. The detailed description uses the phrases “in some embodiments” or “some implementations” which may each refer to one or more or all of the same or different embodiments or implementations. The term “some” as used herein is defined as “one, or more than one, or all.” Accordingly, the terms “one,” “more than one,” “more than one, but not all” or “all” would all fall under the definition of “some.” In view of the same, the terms, for example, “in an embodiment” or “in an implementation” refers to one embodiment or one implementation and the term, for example, “in one or more embodiments” refers to “at least one embodiment, or more than one embodiment, or all embodiments .”.Further, the term, for example, “in one or more implementations” refers to “at least one implementation, or more than one implementation, or all implementations.
[0025] The term “comprising,” when utilized, means “including, but not necessarily limited to;” it specifically indicates open-ended inclusion in the so-described one or more listed features, elements in a combination, unless otherwise stated with limiting language. Furthermore, to the extent that the terms “includes,” “has,” “have,” “contains,” and other similar words are used in either the detailed description, such terms are intended to be inclusive in a manner similar to the term “comprising.”
[0026] In the following description, for the purposes of explanation, various specific details are set forth in order to provide a thorough understanding of embodiments of the present disclosure. It will be apparent, however, that embodiments of the present disclosure may be practiced without these specific details. Several features described hereafter can each be used independently of one another or with any combination of other features.
[0027] The description provided herein discloses exemplary embodiments only and is not intended to limit the scope, applicability, or configuration of the present disclosure. Rather, the foregoing description of the exemplary embodiments will provide those skilled in the art with an enabling description for implementing any of the exemplary embodiments. Specific details are given in the following description to provide a thorough understanding of the embodiments. However, it may be understood by one of the ordinary skilled in the art that the embodiments disclosed herein may be practiced without these specific details.
[0028] The terminology used herein is for the purpose of describing particular embodiments only and is not intended to be limiting of the disclosure. As used herein the description, the singular forms "a", "an", and "the" include plural forms unless the context of the invention indicates otherwise.
[0029] The terminology and structure employed herein are for describing, teaching, and illuminating some embodiments and their specific features and elements and do not limit, restrict, or reduce the scope of the present disclosure. Accordingly, unless otherwise defined, all terms, and especially any technical and / or scientific terms, used herein may be taken to have the same meaning as commonly understood by one having ordinary skill in the art.
[0030] An object of the present disclosure is to provide a system and a method for evaluating a credibility and risk factor of a Uniform Resource Locator (URL) to identify whether the URL is trustable or insecure. Another object of the present disclosure is to provide a system and a method that can help in evaluating a legitimacy of a message on the basis of the URL to prevent phishing attacks.
[0031] The one or more embodiments herein mainly describes a system and a method that helps in analyzing and identifying legitimacy of messages by scrutinizing the URL included in the messages. The system corresponds to Vigilant Artificially Intelligent Linguistic System (VAILS). If any message contains any URL, then a URL analyzer of the VAILS extracts the URL from the message and performs a series of operations on the URL to evaluate how secure the URL is.
[0032] Embodiments of the present disclosure will be described below in detail with reference to the accompanying drawings. FIG. 1 and FIG. 2, discussed below, and the one or more embodiments used to describe the principles of the present disclosure are by way of illustration only and should not be construed in any way to limit the scope of the present disclosure. Those skilled in the art will understand that the principles of the present disclosure may be implemented in any suitably arranged system or device.
[0033] FIG. 1 illustrates a block diagram depicting a system 100 for evaluating the URL, in accordance with an embodiment of the present disclosure. The embodiments of the system 100 shown in FIG. 1 are for illustration only. Other embodiments of the system 100 may be used without departing from the scope of this disclosure.
[0034] The system 100 includes user device(s) 102, a URL analyzer 104 (i.e., a data processing server / microservice integrated to the VAILS), and a distributed ledger 108. The URL analyzer 104 may be supported by Machine Learning (ML) models 118 such as, but not limited to Natural Language Processing (NLP) models. The user device(s) 102, the URL analyzer 104, the distributed ledger 108 are communicatively coupled to each other by way of a network 106.
[0035] The user device(s) 102 may enable user(s) to provide input(s) to the URL analyzer 104. The user device may further present (or display) enable the user to view or display output(s) generated by the URL analyzer 104. More specifically, the output(s) may be associated with operation(s) performed by the system 100 for evaluating the legitimacy (or credibility) of the URL in the message received from the user device. In some aspects of the present disclosure, the user device 102 may further include an application console (shown as 208 later in FIG. 2) to run a computer-executable software application that may be stored in a device memory (shown later as 210 in FIG. 2) of the user device 102 and may enable the user to provide instruction(s) and retrieve result(s) from the URL analyzer 104. In some aspects of the present disclosure, the console may include suitable logic, instructions, and / or codes for executing various operations and may be controlled by the URL analyzer 104.
[0036] The URL analyzer 104 may be configured as a network of computers, a software framework, or a combination thereof, that may provide a generalized approach to create a server implementation. Examples of the URL analyzer 104 may include, but are not limited to, personal computers, laptops, mini -computers, mainframe computers, any non-transient and tangible machine that can execute a machine-readable code, cloud-based servers, distributed server networks, or a network of computer systems. The URL analyzer 104 may be realized through various web-based technologies such as, but not limited to, a Java web -framework, a .NET framework, a personal home page (PHP) framework, or any web-application framework. In other aspects of the present disclosure, the URL analyzer 104 may be configured to perform one or more data processing and / or storage operations toenable the evaluation of the credibility of the URL included in the message received from the user device 102.
[0037] The URL analyzer 104 may include processing circuitry 112, a server memory 114, and a transceiver unit 116. The processing circuitry 112 may include processor(s) (such as data processing engines) configured with suitable logic, instructions, circuitry, interfaces, and / or codes for executing one or more operations of various operations performed by the URL analyzer 104. Examples of the processing circuitry 112 may include, but are not limited to, an Application Specific integrated circuit (ASIC) processor, a Reduced Instruction Set Architecture (RISC) processor, a Complex Instruction Set Architecture (CISC) processor, a Field Programmable Gate Array (FPGA), and the like. In some embodiments disclosed herein, the processing circuitry 112 may include, but are not limited to, processor(s) configured to extract the URL from the message and determine a credibility (in terms of credibility percentage) of the URL.
[0038] The server memory 114 may be configured to store logic, instructions, circuitry, interfaces, and / or codes of the processing circuitry 112 for executing various operations. The server memory 114 may further be configured to store data including information associated with commonly used protocols, valid URLs, and the ledger of trusted entities, that may be utilized by various data processing engines (or processor(s)) of the processing circuitry 112 to evaluate the credibility and the legitimacy of the URL included in the message. Aspects of the present disclosure are intended to include and / or otherwise cover any type of the data associated with the URLs, without deviating from the scope of the present disclosure. Examples of the server memory 114 may include but are not limited to, a Read-Only Memory (ROM), a Random-Access Memory (RAM), a flash memory, a removable storage drive, a Hard Disc Drive (HDD), a solid-state memory, a magnetic storage drive, a Programmable Read-Only Memory (PROM), an Erasable Programmable Read- Only Memory (EPROM), and / or an Electrically Erasable Programmable Read-Only Memory EEPROM.
[0039] The transceiver unit 116 may be configured to enable the URL analyzer 104 to communicate with various entities (or operational components) of the system 100 via the network 106. Examples of the transceiver unit 116 may include, but are not limited to, a modem, a network interface such as an Ethernet card, a communication port, and / or a Personal Computer Memory Card International Association (PCMCIA) slot and card, an antenna, a radio frequency (RF) transceiver, amplifier(s), a tuner, oscillator(s), a digital signal processor, a coder-decoder (CODEC) chipset, a subscriber identity module (SIM) card, and a local buffer circuit. It will be apparent to a person of ordinary skill in the art that the transceiver unit 116 may include any device and / or apparatus capable of providing wireless or wired communications between the URL analyzer 104 and various other entities of the system 100.
[0040] The network 106 may include suitable logic, circuitry, and interfaces that may be configured to provide several network ports and several communication channels for transmission and reception of data related to operations of various entities of the system 100. Each network port may correspond to a virtual address (or a physical machine address) for transmission and reception of the communication data. For example, the virtual address may be an Internet Protocol Version 4 (IPV4) (or an IPV6 address) and the physical address may be a Media Access Control (MAC) address. The network 106 may be associated with an application layer for implementation of communication protocols based on one or more communication requests from the various entities of the system 100. The communication data may be transmitted or received via the communication protocols. Examples of the communication protocols may include, but are not limited to, Hypertext Transfer Protocol (HTTP), File Transfer Protocol (FTP), Simple Mail Transfer Protocol (SMTP), Domain Network System (DNS) protocol, Common Management Interface Protocol (CMIP), Transmission Control Protocol and Internet Protocol (TCP / IP), User Datagram Protocol (UDP), Long Term Evolution (LTE) communication protocols, or any combination thereof.
[0041] In some aspects of the present disclosure, the communication data may be transmitted or received via at least one communication channel of several communication channels in the network 106. Examples of the communication channels may include, but are not limited to, a wireless channel, a wired channel, a combination of wireless and wired channel thereof. The wireless or wired channel may be associated with a data standard which may be defined by one of a Local Area Network (LAN), a Personal Area Network (PAN), a Wireless Local Area Network (WLAN), a Wireless Sensor Network (WSN), Wireless Area Network (WAN), Wireless Wide Area Network (WWAN), a metropolitan area network (MAN), a satellite network, the Internet, an optical fibre network, a coaxial cable network, an infrared (IR) network, a radio frequency (RF) network, and a combination thereof. Aspects of the present disclosure are intended to include or otherwise cover any type of communication channel, including known, related art, and / or later developed technologies.
[0042] The distributed ledger 108 may include multiple data processing servers deployed in a distributed network (such as through blockchain technology) in a mesh topology. Each server may be configured to co-operatively operate for storing various types of data such as, but not limited to phone numbers, email addresses, website URLs, instant messaging IDs, and social media profile links associated with a plurality of users, in a distributed manner. The distributed ledger 108 may further be configured to perform computational operation(s) based on a set of predefined protocols to generate and / or store data in a distributed ledger based on a set of predefined protocols decided for the distributed ledger 108 using smart contract.
[0043] The ML model(s) 118 may be equipped with circuitry, logic, codes, and interfaces configured to perform task(s) pertaining to Artificial Intelligence (Al) such as, but not limited to, classification, contextual analysis, data generation, etc. In some aspects of the present disclosure, the ML model(s) may preferably be configured to perform Natural Language Processing (NLP) operations to support the URL analyzer in analysis of the credibility of the URL. In some aspects of the present disclosure, the ML model(s) may be trained through dataset(s) includinginformation of instances related to factors associated with determination of the credibility of the URL, such as but not limited to, domain specifications, configuration specifications, approved / restricted URL hosts, availability of the hosting domain, etc. Preferably, The ML model(s) 118 may be trained using a substantial size of training dataset for Natural Language Processing. In some aspects of the present disclosure, the ML model(s) 118 may be trained to support the URL analyzer in determining a probability of the URL being faulty (in terms of credibility percentage), based on which the credibility of the URL can be evaluated. In some aspects of the present disclosure, the ML model(s) 118 may be deployed in external datacenters whereas in some other aspects of the present disclosure, the ML model(s) 118 may be integrally embedded with the URL analyzer 104.
[0044] According to an exemplary embodiment, the URL analyzer 104 may be utilized in a variety of application areas such as, but not limited to, telecommunication. Trust serves as the glue and cornerstone of human society and emerges as a critical enabler of information and communications technologies (ICT). The system 100, by way of the URL analyzer 104, enables security and trust in telecommunication services. For example, the system 100 provides a solution to evaluate risk involved with any URL received through any type of message through a multi-tiered analysis of the URL on a variety of parameters. The system 100 may be integrated to a variety of telecom services (through an application installed on device(s) rendering the telecom services) and may provide information of credibility of a URL received by the device(s) such that user(s) of the device(s) may be informed in real-time about the credibility / trustworthiness of the URL received. In one implementation, the application may be hosted through the URL analyzer 104 implemented on a distant server and may require communication services (or communication channel) to assess the credibility of the received URL in an online mode. In another implementation, the application may utilize processing capabilities of the device and may work in an offline mode as well with limited / complete support.
[0045] In some aspects of the present disclosure, the system 100 can be integrated with a variety of telecommunication services such as, but not limited to Short Message Service Centre (SMSC) services, Value Added Services (VAS), Rich Communication Services (RCS), Multi-media Messaging Services (MMS), IP Multimedia Subsystems (IMS), and Application to Person (A2P) messaging platforms. The system 100, by way of the URL analyzer 104, may retrieve the URL from a message received through the telecommunication services, as mentioned hereinabove, and analyze the URL on a variety of credibility parameters. Based on the analysis, the system 100 may suggest whether or not the URL received from the message through the telecom platform is credible or not. In some aspects of the present disclosure, the system 100 may further identify factor(s) associated the credibility parameter(s) having low credibility confidence and may generate indicative notification(s) for the factor(s). For example, when the URL is identified associated with a prohibited source, the system 100 may generate indicative notification(s) in real-time about the URL being associated with the prohibited source and may be unsafe to access. In some other aspects of the present disclosure, the system 100 may further restrict (or block access) of the URLs when the credibility percentage is determined in a critical range. As may be apparent to a person of ordinary skill in the art, the examples are presented hereinabove are for illustration only and are non-limiting to the scope of the present disclosure. Various other exemplary embodiment s) and / or use-cases may also exist where the system 100 may be utilized to support the telecommunication services in enhancing credibility, trust, and security, without deviating from the scope of the present disclosure.
[0046] Although FIG. 1 illustrates one example of the system 100, various changes may be made to FIG. 1. Further, the system 100 may include any number of components in addition to the components shown in FIG. 1. Further, various components in FIG. 1 may be combined, further subdivided, or omitted and additional components may be added according to particular needs. The URLanalyzer 104 may retrieve message data from the user devices 102 periodically, continuously, or on instance basis.
[0047] FIG. 2 is a block diagram that illustrates example components of the user device 102, in accordance with an exemplary embodiment of the present disclosure. The user device 102 may include a user interface 202, a network interface 204, a processing unit 206, an application console 208, and a device memory 210.
[0048] The user interface 202 may include an input interface for receiving inputs from a user of the user device 102. Examples of the input interface of the user interface 202 may include, but are not limited to, a touch interface, a mouse, a keyboard, a motion recognition unit, a gesture recognition unit, a voice recognition unit, or the like. Aspects of the present disclosure are intended to include or otherwise cover any type of the input interface including known, related art, and / or later developed technologies. The user interface 202 may further include an output interface for displaying (or presenting) an output to the user. Examples of the output interface of the user interface 202 may include, but are not limited to, a digital display, an analog display, a touch screen display, a graphical user interface, a website, a webpage, a keyboard, a mouse, a light pen, an appearance of a desktop, and / or illuminated characters. Aspects of the present disclosure are intended to include or otherwise cover any type of the output interface including known, related art, and / or later developed technologies.
[0049] The network interface 204 may be configured to enable the user device 102 to communicate with the URL analyzer 104 through the network 106. Examples of the network interface 204 may include, but are not limited to, a modem, a network interface such as an Ethernet card, a communication port, and / or a Personal Computer Memory Card International Association (PCMCIA) slot and card, an antenna, a radio frequency (RF) transceiver, one or more amplifiers, a tuner, one or more oscillators, a digital signal processor, a coder-decoder (CODEC) chipset, a subscriber identity module (SIM) card, and a local buffer circuit. It will be apparent to a person of ordinary skill in the art that the network interface 204 may includeany device and / or apparatus capable of providing wireless or wired communications between the user device 102 and the URL analyzer 104 via the network 106.
[0050] The processing unit 206 may include suitable logic, instructions, circuitry, interfaces, and / or codes for executing various operations, such as the operations associated with the user device 102, or the like. In some aspects of the present disclosure, the processing unit 206 may utilize one or more processors such as Arduino or raspberry pi or the like. Further, the processing unit 206 may be configured to control one or more operations executed by the user device 102 in response to the input received at the user interface 202 from the user. In some aspects of the present disclosure, the user interface 202, the network interface 204, the application console 208, and the device memory 210 may be communicatively coupled to each other via the processing unit 206. Examples of the processing unit 206 may include, but are not limited to, an application-specific integrated circuit (ASIC) processor, a reduced instruction set computing (RISC) processor, a complex instruction set computing (CISC) processor, a field-programmable gate array (FPGA), a Programmable Logic Control unit (PLC), and the like. Some aspects of the present disclosure are intended to include or otherwise cover any type of the processing unit 206 including known, related art, and / or later developed processing units.
[0051] The application console 208 may be configured as the computer application, to be executed by the processing unit 206. The application console 208 may include suitable logic, instructions, and / or codes for executing various operations and may be controlled by the URL analyzer 104. In some aspects of the present disclosure, the computer application may be stored in the device memory 210. Examples of the computer application may include, but are not limited to, an audio application, a video application, a social media application, a navigation application, or the like. Preferably, the application console 208 may be configured to facilitates the user to send a message comprising a URL to the URL analyzer 104 and request the URL analyzer 104 to analyze / evaluate the credibility of the URL. The application console208 further enables a credibility analysis (i.e., received from the URL analyzer 104 for the URL) be rendered to the user.
[0052] The device memory 210 may be configured to store data, instructions, logic, codes for various operations performed by the user interface 202, the network interface 204, the processing unit 206, and the application console 208. Particularly, the device memory 210 may be configured to store data associated with the computer application that enables the computer application to run on the user device 102 through the application console 208. Examples of the device memory 210 may further include, but are not limited to, a Read-Only Memory (ROM), a Random- Access Memory (RAM), a flash memory, a removable storage drive, a hard disk drive (HDD), a solid-state memory, a magnetic storage drive, a Programmable Read Only Memory (PROM), an Erasable PROM (EPROM), and / or an Electrically EPROM (EEPROM).
[0053] Although FIG. 2 illustrates one example of the user device 102, various changes may be made to FIG. 2. For example, the user device 102 may include any number of components in addition to those shown in FIG. 2, without deviating from the scope of the present disclosure. Further, various components in FIG. 2 may be combined, further subdivided, or omitted and additional components may be added according to particular needs.
[0054] FIG. 3 illustrates example components of the URL analyzer 104 or VAILS, in accordance with an exemplary embodiment of the present disclosure. The URL analyzer 104 may include the processing circuitry 112, the server memory 114, and the transceiver unit 116 and a console host 302. Various components of the URL analyzer 104 may be communicatively coupled to each other by way of a first communication bus 306.
[0055] The console host 302 may include suitable logic, instructions, circuitry, interfaces, and / or codes for hosting the computer application installed on the user device 102 through the application console 208. The transceiver unit 116 may be configured to receive the message containing the URL and extract the URL fromthe message. Aspects of the present disclosure are intended to include, or otherwise cover any type of message that may be capable of carrying / including the URL, such as but not limited to, a text message, an E-mail, a link received by the user device 102 via a social media platform, a Bluetooth transferred file, a pop-up notification etc.
[0056] The processing circuitry 112 may include several engines / modules comprising suitable logic, instructions, circuitry, interfaces, and / or codes to perform tasks related to data processing and data transmission. Particularly, the processing circuitry 112 may be configured to assign a risk score (i.e., a predefined initial value) to the URL extracted from the message. The processing circuitry 112 may further be configured to determine whether at least one condition from a set of Internet Protocol (IP) conditions is satisfied for the URL. Preferably, the set of IP conditions include a first IP condition and a second IP condition. The first IP condition is met when the URL has at least one of Hyper Text Transfer Protocol Secure (HTTPS) component. The second IP condition is met when the URL has a Fully Qualified Domain Name (FQDN) component.
[0057] The processing circuitry 112 may also be configured to update, based on the determination that the at least one IP condition from the set of IP conditions is satisfied, the risk score by adding phase values corresponding to the IP condition satisfied. For example, when the first IP condition is met, the processing circuitry 112 may add the phase value corresponding to the first IP condition to the initial risk score of the URL. Similarly, when the second IP condition is met, the processing circuitry 112 may add the phase value corresponding to the second IP condition to the initial risk score of the URL. When both the IP conditions are met, the processing circuitry 112 may add the first and second phase values to the risk score.
[0058] The processing circuitry 112 may further be configured to determine whether at least one URL characteristic condition from a set of URL characteristic conditions is satisfied for the URL. The set of URL characteristic conditions comprise first through third URL characteristic conditions. The first URLcharacteristic condition is met / satisfied when a value of length of the URL being less than or equal to a predefined URL length value, in response to a determination that the URL does not have the FQDN component (or a prohibited extension) is present in the URL. The second URL characteristic condition is satisfied when the URL being associated with a reputed domain. The third URL characteristic condition is satisfied when a mean value of the risk score for the URL being greater than or equal to an expected mean value of the risk score. Preferably, the expected mean value of the risk score is indicative of the average risk value determined for a reliable URL. When the mean value of the risk score is higher than the expected mean value, such a URL is probably unreliable.
[0059] Preferably, prior to the determination whether the at least one URL characteristic conditions is satisfied, the processing circuitry is configured to determine, in response to a determination that the second IP condition is satisfied, whether the prohibited extension is present or absent in the URL. Moreover, the processing circuitry is also configured to update the risk score by adding a phase value based on the determination that the prohibited extension is absent in the URL.
[0060] The processing circuitry 112 may also configured to determine whether an entry corresponding to the risk score of the URL is present in the distributed ledger. Moreover, the processing circuitry 112 may be configured to update the risk score by adding a seventh phase value to the risk score based on the determination that the entry corresponding to the risk score of the URL is present in the distributed ledger. The risk score is indicative of credibility of the URL.
[0061] In some aspects of the present disclosure, in response to the determination that the entry corresponding to the risk score of the URL is present in the distributed ledger 108, the processing circuitry 112 may be configured to determine a credibility percentage value for the URL by comparing the risk score with a select risk score. Preferably, the select risk score may correspond to an ideal URL (reliable and credible URL). The comparison of the risk score of the URL with the select riskscore enables the determination of credibility (in terms of percentage) of the URL with respect to the reliable and credible URL.
[0062] In some aspects of the present disclosure, based on the determination that the prohibited extension is present in the URL, the processing circuitry 112 may be configured to determine the credibility percentage value for the URL by comparing the risk score with the select risk score.
[0063] In some aspects of the present disclosure, the ML model(s) 118 may enable the processing circuitry 112 to determine a probability value of credibility for the URL based on the determination that the entry corresponding to the risk score of the URL is absent in the distributed ledger 108. Moreover, the ML model(s) 118 may also support the processing circuitry 112 to determine the credibility percentage value for the URL based on the probability value of credibility for the URL. Preferably, the ML model(s) 118 may perform Natural Language Processing (NLP) on the URL to determine the probability value of credibility for the URL.
[0064] Specifically, the processing circuitry 112 evaluates the credibility of the URL at multiple phases through analysis of a variety of credibility parameters. For example, at different phases of analysis, the processing circuitry 112 analyzes whether the URL is associated with HTTPS domain, FQDN, whether the URL is associated with prohibited extension, or with reputed domain. Moreover, the processing circuitry 112 also compares the length and mean value of the URL with predefined values stored for credible URLs. Additionally, the processing circuitry 112 utilizes ML model(s) 118 (using NLP technology) and distributed ledger 108 (i.e., Web of Trust) at some phases. The phase value associated with each phase of verification enhances the credibility of the URL being associated with a condition predefined for secure URLs, and therefore adds to the risk score. A higher value of the risk score after a complete analysis of the URL at the multiple phases represents a high credibility (or high confidence) of the URL, whereas a low value of the risk score after a complete analysis of the URL at the multiple phases represents a low credibility (or low confidence) of the URL.
[0065] Specifically, the processing circuitry 112 may include a protocol checker 310, a FQDN observer 312, an extension reviewer 314, a length comparator 316, a reputed domain assessor 318, a mean comparer 320, a WOT analyzer 322, and a score updater 324. Various components of the processing circuitry 112 may be communicatively coupled to each other by way of a second communication bus 326.
[0066] The protocol checker 310 may be configured to check whether the URL is based on ‘https’. In such a scenario, when the URL is based on ‘https’ the protocol checker 310 may instruct the score updater 324 to update the risk score by adding the phase value associated with the presence of https in the URL.
[0067] The FQDN observer 312 may be configured to determine whether the URL is IP address-based or qualified domain name (FQDN)-based. When the FQDN observer 312 identifies that the URL is FQDN-based then the FQDN observer 312 may instruct the score updater 324 to update the risk score by adding the phase value associated with the FQDN-based URL.
[0068] The extension reviewer 314 may be configured to determine that when the URL is based on FQDN then it must have an extension. When the extension is not permitted or allowed by the VAILS then such URL will be prohibited and the probability for the URL does not change. When, the extension is allowed in the VAILS, then the extension reviewer 314 may instruct the score updater 324 to update the risk score by adding the phase value associated with non-prohibited extension.
[0069] The length comparator 316 may be configured to compare the length of the URL with the mean length of the URL (stored in the server memory 114 or on the VAILS). When the length comparator 316 determines that the length of the URL is less than or equal to the mean length of the URL, the length comparator 316 may instruct the score updater 324 to update the risk score by adding the phase value associated with URL length limitations.
[0070] The reputed domain assessor 318 may assess the URL in terms of domain reputation. Information of the reputation of the URL domains may be stored in the server memory 114 (or the VAILS). The reputed domain assessor 318 may assess whether the URL belongs to a reputed domain or not based on the information of the reputations of the URL domains. When the reputed domain assessor 318 determines that the URL belongs to a reputed domain, the reputed domain assessor 318 may instruct the score updater 324 to update the risk score by adding the phase value associated with URL reputation.
[0071] The mean comparer 320 may be configured to compare the mean value of the risk score with a predefined mean value of the risk score. When the mean value of the risk score is greater than or equal to the predefined mean value, the mean comparer 320 may instruct the score updater 324 to update the risk score by adding the phase value associated with the mean risk score condition.
[0072] The Web of Trust (WOT) analyzer 322 may be configured to keep all types of contacts such as phone numbers, email addresses, website URLs, instant messaging IDs, and social media profile links. When the URL is identified similar to any of the records of WOT then the risk score is updated and probability for the URL is secured Else, the WOT analyzer may pass the URL to the NLP pipeline 323.
[0073] The NLP pipeline 323 may utilize the ML model(s) 118 for evaluating the probability value of credibility for the URL based on the determination that the entry corresponding to the risk score of the URL is absent in the distributed ledger 108 (i.e., on the basis of the dataset the VAILS possess).
[0074] Various engines of the processing circuitry 112 are presented to illustrate the functionality driven by the URL analyzer 104. It will be apparent to a person having ordinary skill in the art that various engines in the processing circuitry 112 are for illustrative purposes and not limited to any specific combination of hardware circuitry and / or software.
[0075] The server memory 114 may be configured to store logic, instructions, circuitry, interfaces, and / or codes of the processing circuitry 112 for executing various operations of the URL analyzer 104. Aspects of the present disclosure are intended to include and / or otherwise cover any type of the data associated with the operations of various components of the URL analyzer 104 for determining various conditions associated with the URL credibility as presented hereinabove, without deviating from the scope of the present disclosure. Examples of the server memory 114 may include but are not limited to, a ROM, a RAM, a flash memory, a removable storage drive, a HDD, a solid-state memory, a magnetic storage drive, a PROM, an EPROM, and / or an EEPROM.
[0076] In some aspects of the present disclosure, the server memory 114 may be segregated into multiple repositories that may be configured to store a specific type of data. In the exemplary embodiment as presented through FIG. 3, the server memory 114 includes a data objects repository 328 comprising data objects of the URL analyzer 104 and an instructions repository 330 comprising instruction(s) to enable execution of operations of the various components of the URL analyzer 104. The data objects repository 328 may be configured to store data object(s) corresponding to various operations of the processing circuitry 112. The instructions repository 330 may be configured to store instructions and / or codes for operations performed by the various components of the URL analyzer 104.
[0077] In some embodiments of the present disclosure, the instructions repository 330 is configured to store computer program instructions and / or codes for operation(s) of various components of the processing circuitry 112. For example, the instructions repository 330 may be configured to store computer program instructions corresponding to the operation(s) performed by the processing circuitry 112 for analyzing the URL in the message for determining the credibility of the URL, as presented through the various engines in the processing circuitry 112. In an embodiment of the present disclosure, the instructions repository 330 may be configured as a non-transitory storage medium. Examples of the instructions repository 330 configured as the non-transitory storage medium includes harddrives, solid-state drives, flash drives, Compact Disk (CD), Digital Video Disk (DVD), and the like. Aspects of the present disclosure are intended to include or otherwise cover any type of non-transitory storage medium as the instructions repository 330, without deviating from the scope of the present disclosure. As will be appreciated, any such computer program instructions stored in the instructions repository 330 may be executed by one or more computer processors, including without limitation a general-purpose computer or special purpose computer, or other programmable processing apparatus to produce a machine, such that the computer program instructions which execute on the computer processor(s) or other programmable processing apparatus create means for implementing the function(s) specified.
[0078] It will be apparent to a person of ordinary skill in the art that the repositories in the server memory 114 are presented based on the functionality of the URL analyzer 104 and are not limited to those disclosed. The server memory 114 may have any configuration, combination and / or count of repositories without deviating from the scope of the present disclosure.
[0079] Although FIG. 3 illustrates one example of the URL analyzer 104, various changes may be made to FIG. 3, without deviating from the scope of the present disclosure. Further, the URL analyzer 104 may include any number of components in addition to those shown in FIG.3 without deviating from the scope of the present disclosure. Further, various components in FIG. 3 may be combined, further subdivided, or omitted and additional components may be added according to particular needs.
[0080] FIG. 4 illustrates a flowchart depicting a process 400 for evaluating the URL, in accordance with an embodiment of the present disclosure. The process 400 includes a series of operations described below with reference to blocks 402 through 450. The process begins at block 402.
[0081] At the block 402, the processing circuitry 112 receives, via an input interface, a message including the URL, and extracts the URL from the message. The processing circuity 112 may also calculate and initialize a risk score (hereinafter interchangeably referred to as ‘ V-score’) for the URL. In one or more embodiments, the risk score is calculated as given below in equation (1):Where, knis a constant value of each of the phase, and vnis a variable value of each phase.
[0082] At block 404, the processing circuitry 112 performs a protocol verification operation to verify whether a protocol of the URL is Hyper Text Transfer Protocol Secure (HTTPS). To verify whether the protocol of the URL is HTTPS, the processing circuitry 112 determines whether the URL includes the HTTPS component. If it is verified that the protocol of the URL is HTTPS, the process 400 proceeds to block 408. Alternatively, if the protocol of the URL is not HTTPS, the process 400 proceeds to block 406.
[0083] At the block 406, the processing circuitry 112 retains the risk score for the URL. The process 400 further proceeds to block 410.
[0084] At the block 408, the processing circuitry 112 updates the risk score for the URL by adding the first phase value to the risk score. The process 400 further proceeds to block 412.
[0085] At the block 410, the processing circuitry 112 performs domain assessment operation(s). Specifically, the processing circuitry 112 determines whether the URL is either an Internet Protocol (IP)-address based URL, or a Fully Qualified Domain Name (FQDN) based URL. Preferably, at block 412, the processing circuitry 112 determines whether the URL includes the FQDN component. When the processing circuitry 112 determines that the URL is the FDQN based URL, the process 400 proceeds to block 412. Alternatively, when the processing circuitry 112 determines1 that the URL is the IP-address based URL (i.e., the FQDN component is absent from the URL), the process 400 further proceeds to block 414.
[0086] At the block 412, the processing circuitry 112 updates the risk score for the URL by adding the second phase value to the risk score. The process 400 further proceeds to block 416.
[0087] At the block 414, the processing circuitry 112 retains the risk score for the URL. The process 400 further proceeds to block 422.
[0088] At the block 416, the processing circuitry 112 performs an extension review operation. Specifically, the processing circuitry 112 determines whether an extension associated with the FQDN based URL is permitted or not by the VAILS. Particularly, the processing circuitry 112 determines that the prohibited extension is present or absent in the URL. When the processing circuitry 112 determines that the extension associated with the FQDN based URL is not permitted (i.e., the prohibited extension is present), the process 400 proceeds to block 420. Alternatively, when the processing circuitry determines that the extension associated with the FQDN based URL is permitted (i.e., the prohibited extension is absent), the process 400 proceeds to block 418.
[0089] At the block 418, the processing circuitry 112 updates the risk score for the URL by adding the third phase value to the risk score. The process 400 further proceeds to the block 422.
[0090] At the block 420, the processing circuitry 112 retains the risk score for the URL. Moreover, the processing circuitry 112 determines the probability value for the credibility for the URL using the risk score. The process 400 further proceeds to block 421.
[0091] At the block 421, the processing circuitry 112 determines the probability value for credibility of the URL based on the risk score of the block 420 and amaximum value of the risk score (Vmax). The process 400 further proceeds to block 452.
[0092] At block 422, the processing circuitry 112 compares the value of length of the URL with the predefined mean length value of valid URLs. When the processing circuitry 112 determines that the length of the URL is greater than the mean length value of the valid URLs, the process 400 proceeds to block 424. Alternatively, when the processing circuitry 112 determined that the length of the URL is less or equal to the mean length of the valid URLs, the process 400 proceeds to block 426.
[0093] At block 424, the processing circuitry 112 retains the risk score for the URL.
[0094] At block 426, the processing circuitry 112 updates the risk score for the URL by adding the fourth phase value to the risk score. The process 400 further proceeds to block 428.
[0095] At block 428, the processing circuitry 112 determines whether the domain of the URL belongs to the reputed domains. When the processing circuitry 112 determines that the domain of the URL belongs to the reputed domains, the process 400 proceeds to block 430. Alternatively, when the processing circuitry 112 determines that the domain of the URL does not belong to the reputed domains, the process 400 proceeds to block 432.
[0096] At block 430, the processing circuitry 112 updates the risk score for the URL by adding the fifth phase value to the risk score. The process 400 further proceeds to block 434.
[0097] At block 432, the processing circuitry 112 retains the risk score for the URL. The process 400 further proceeds to block 434.
[0098] At block 434, the processing circuitry 112 determines whether the actual mean (x) of the URL is greater than or equal to the expected mean (p). When the processing circuitry 112 determines that the actual mean is greater than or equal to the expected mean, the process 400 proceeds to block 436. Alternatively, when theprocessing circuitry 112 determines that the actual mean is less than the expected mean, the process 400 proceeds to block 438.
[0099] At block 436, the processing circuitry 112 updates the risk score for the URL by adding the sixth phase value to the risk score. The process 400 proceeds to block 440.
[0100] At block 438, the processing circuitry 112 retains the risk score for the URL. The process 400 proceeds to block 440.
[0101] At block 440, the processing circuitry 112 determines whether the URL is similar to any of the records of the distributed ledger 108 (herein after interchangeably referred to as ‘Web of trust (WOT)’). Preferably, the processing circuitry 112 determines whether the entry corresponding to the risk score of the URL is present or absent in the distributed ledger 108. When the processing circuitry 112 determines that the entry corresponding to the risk score of the URL is present in the WOT, the process 400 proceeds to block 442. Alternatively, when the processing circuitry 112 determines that the entry corresponding to the risk score of the URL is absent in WOT, the process 400 proceeds to block 444.
[0102] At block 442, the processing circuitry 112 updates the risk score by adding the seventh phase value to the risk score. The process 400 further proceeds to block 446.
[0103] At block 444, the processing circuitry 112 evaluates the probability value of credibility for the URL using the risk score and the maximum value (Vmax) of the risk score. The process 400 now proceeds to block 450.
[0104] At block 446, the processing circuitry 112 evaluates the probability value of credibility for the URL using the ML model(s) 118 based on dataset(s) of the VAILS.
[0105] At block 448, the processing circuitry 112 adjusts the determined probability based on output data received from the ML model(s) 118. The process 400 further proceeds to block 450.
[0106] At block 450, the processing circuitry 112 calculates an output percentage of the credibility of the URL based on the probability of the URL determined at blocks 446 or 450, based on the finding of the processing circuitry 112.
[0107] In one or more embodiments disclosed herein, the constant and variable values are evaluated and added to the aggregate risk score at every phase of operations performed at the blocks 408, 412, 418, 424, 426, 430, 436, and 442. The ratio of the risk score and the Vmax is the probability for the URL to be secure.
[0108] In one or more embodiments disclosed herein, other parameters besides the risk score may also be utilized to evaluate the legitimacy of the URLs and may be calculated during the evaluation of the risk score. Such parameters may include, but are not limited to, the actual mean (x) of the corresponding operations performed at blocks 404, 410, 416, 422, 428, 434, and 440, the expected mean (p) of the corresponding operations, and the Vmax of the variable of the corresponding operations. The actual mean can be given as shown below in equation (2):-=Sf=1(fcn)(Vn) z2x nv
[0109] The expected mean can be given as shown below in equation (3): p = ^ ... (3)
[0110] FIG. 5 illustrates a flowchart depicting a method 500 for evaluating the URL, in accordance with an embodiment of the present disclosure. The method 500 includes a series of operations described below with reference to blocks 502 through 518. The method begins at block 502.
[0111] At block 502, the URL analyzer 104 may extract the URL from the message.
[0112] At block 504, the URL analyzer 104 may assign the risk score to the URL, where the risk score is a predefined initial value.
[0113] At block 506, the URL analyzer 104 may determine whether at least one condition from the set of Internet Protocol (IP) conditions is satisfied for the URL. When the URL analyzer 104 identifies the IP condition(s) being satisfied, the method 500 proceeds to block 508. Else, the method 500 proceeds to block 510.
[0114] At block 508, the URL analyzer 104 may update the risk score by adding phase values corresponding to each IP condition satisfied. The method 500 further proceeds to block 510.
[0115] At block 510, the URL analyzer 104 may determine whether at least one URL characteristic condition from the set of URL characteristic conditions is satisfied for the URL. When the URL analyzer 104 identifies the URL characteristic condition(s) being satisfied, the method 500 proceeds to block 512. Else, the method 500 proceeds to block 514.
[0116] In some aspects of the present disclosure, prior to determining whether the at least one URL characteristic conditions is satisfied, the URL analyzer 104 may determine in response to a determination that the second IP condition is satisfied, whether the prohibited extension is present or absent in the URL. Moreover, the URL analyzer 104 may update the risk score by adding a phase value based on the determination that the prohibited extension is absent in the URL.
[0117] In some aspects of the present disclosure, based on the determination that the prohibited extension is present in the URL, the URL analyzer 104 may determine the credibility percentage value for the URL by comparing the risk score with the select risk score.
[0118] At block 512, the URL analyzer 104 may update the risk score by adding phase value corresponding to each URL characteristic condition satisfied. The method 500 further proceeds to block 514.
[0119] At block 514, the URL analyzer 104 may determine whether an entry corresponding to the risk score of the URL is present in a distributed ledger 108.When the URL analyzer 104 identifies the entry corresponding to the risk score of the URL is present in a distributed ledger 108, the method 500 proceeds to block 516. Else, the method 500 proceeds to block 518.
[0120] At block 516, the URL analyzer 104 may update the risk score by adding a phase value to the risk score corresponding to the presence of the entry for the risk score of the URL in the distributed ledger 108.
[0121] In some aspects of the present disclosure, in response to the determination that the entry corresponding to the risk score of the URL is present in the distributed ledger 108, the URL analyzer 104 may determine the credibility percentage value for the URL by comparing the risk score with the select risk score.
[0122] At block 518, the URL analyzer 104 retains the risk score in response to the absence of the entry for the risk score of the URL in the distributed ledger 108.
[0123] In some aspects of the present disclosure, the ML model(s) 118 may support the URL analyzer 104 to determine the probability value of credibility for the URL based on the determination that the entry corresponding to the risk score of the URL is absent in the distributed ledger 108. Moreover, the ML model(s) 118 may determine the credibility percentage value for the URL based on the probability value of credibility for the URL. Preferably, the ML model 118 performs Natural Language Processing (NLP) on the URL to determine the probability value of credibility for the URL.
[0124] Particularly, the addition of a phase values to the risk score is associated with an increase in the credibility percentage of the URL when a corresponding condition is satisfied. Moreover, the URL analyzer 104 determines the credibility of the URL based on the final risk score, where the final risk score is indicative of the credibility of the URL.
[0125] Now, referring to the technical abilities and advantageous effect of the present disclosure, the embodiments disclosed herein provides a system and amethod that can help in identifying whether the URL is trustable or insecure by evaluating the credibility and risk factor of the URLs included in text messages, emails, and in other forms of communications. Such identification helps in avoiding insecure URLs. Another noteworthy advantage offered by the one or more embodiments of the present disclosure may include providing a system and a method that evaluates the legitimacy of the messages based on information contained in the URL. As a result, any type of phishing attacks can be easily prevented.
[0126] The present disclosure provides a solution (i.e., the URL analyzer 104) that analyzes the URL on a variety of parameters (i.e., at multiple phases). For example, the URL analyzer 104 analyzes the URL from the message for presence of secure indicators (i.e., by identifying conditions such as as presence / absence of HTTPS and / or FQDN, association with prohibited domain or reputed domain, assessing length and mean values of the URL, etc., and utilizing ML model(s) 118 and distributed ledger 108). Each indicator adds up to credibility percentage of the URL. Such a multi-tiered analysis at different phases makes the system more accurate and secure. As the system 100 provides accurate analysis of the credibility of the URL, such a system can be integrated with several application areas and provide several advantages. For example, the system 100 can provide data breach prevention, support business continuity, enable protection from financial fraud and legal penalties, and provide freedom to focus on the productivity of the application. Moreover, a tagged secure URL is more likely to be visited frequently, which results in enhanced traffic, eventually resulting in higher revenues.
[0127] Those skilled in the art will appreciate that the methodology described herein in the present disclosure may be carried out in other specific ways than those set forth herein in the above disclosed embodiments without departing from essential characteristics and features of the present invention. The above-described embodiments are therefore to be construed in all aspects as illustrative and not restrictive.
[0128] The drawings and the forgoing description give examples of embodiments. Those skilled in the art will appreciate that one or more of the described elements may well be combined into a single functional element. Alternatively, certain elements may be split into multiple functional elements. Elements from one embodiment may be added to another embodiment. For example, orders of processes described herein may be changed and are not limited to the manner described herein. Any combination of the above features and functionalities may be used in accordance with one or more embodiments.
[0129] In the present disclosure, each of the embodiments has been described with reference to numerous specific details which may vary from embodiment to embodiment. The foregoing description of the specific embodiments disclosed herein may reveal the general nature of the embodiments herein that others may, by applying current knowledge, readily modify and / or adapt for various applications such specific embodiments without departing from the generic concept, and, therefore, such adaptations and modifications are intended to be comprehended within the meaning of the disclosed embodiments. It is to be understood that the phraseology or terminology employed herein is for the purpose of description and is not limited in scope.
Claims
I / We claim:
1. A method (500) for evaluating a Uniform Resource Locator (URL) in a message, the method (500) comprising: extracting the URL from the message; assigning a risk score to the URL, wherein the risk score is a predefined initial value; determining whether at least one condition from a set of Internet Protocol (IP) conditions is satisfied for the URL; updating, based on the determination that the at least one IP condition from the set of IP conditions is satisfied, the risk score by adding phase values corresponding to each IP condition satisfied; determining whether at least one URL characteristic condition from a set of URL characteristic conditions is satisfied for the URL; updating, based on the determination that the at least one URL characteristic condition from the set of URL characteristic conditions is satisfied, the risk score by adding phase values corresponding to each URL characteristic condition satisfied; determining whether an entry corresponding to the risk score of the URL is present in a distributed ledger (108); and updating the risk score by adding a phase value to the risk score based on the determination that the entry corresponding to the risk score of the URL is present in the distributed ledger (108), wherein the risk score is indicative of credibility of the URL.
2. The method (500) as claimed in claim 1, wherein: the set of IP conditions comprises a first IP condition when the URL has at least one of Hyper Text Transfer Protocol Secure (HTTPS) component, and a second IP condition when the URL has a Fully Qualified Domain Name (FQDN) component; andthe set of URL characteristic conditions comprises a first URL characteristic condition when a value of length of the URL being less than or equal to a predefined URL length value, in response to a determination that the URL does not have the FQDN component or a prohibited extension is present in the URL, a second URL characteristic condition when the URL being associated with a reputed domain, and a third URL characteristic condition when a mean value of the risk score for the URL being greater than or equal to an expected mean value of the risk score.
3. The method (500) as claimed in claim 2, wherein prior to determining whether the at least one URL characteristic conditions is satisfied, the method (500) comprises: determining, in response to a determination that the second IP condition is satisfied, whether the prohibited extension is present or absent in the URL; and updating the risk score by adding a phase value based on the determination that the prohibited extension is absent in the URL.
4. The method (500) as claimed in claim 3, comprising determining, in response to the determination that the entry corresponding to the risk score of the URL is present in the distributed ledger (108), a credibility percentage value for the URL by comparing the risk score with a select risk score.
5. The method (500) as claimed in claim 4, comprising determining, based on the determination that the prohibited extension is present in the URL, the credibility percentage value for the URL by comparing the risk score with the select risk score.
6. The method (500) as claimed in claim 4, comprising:determining, through a Machine Learning (ML) model (118), a probability value of credibility for the URL based on the determination that the entry corresponding to the risk score of the URL is absent in the distributed ledger (108); and determining the credibility percentage value for the URL based on the probability value of credibility for the URL, wherein the ML model (118) performs Natural Language Processing (NLP) on the URL to determine the probability value of credibility for the URL.
7. The method (500) as claimed in claim 4, wherein an addition of a phase values to the risk score is associated with an increase in the credibility percentage of the URL when a corresponding condition is satisfied.
8. A system (100) to evaluate a Uniform Resource Locator (URL) in a message, the system (100) comprising: a distributed ledger (108); a transceiver unit (116) configured to receive the message and extract the URL from the message; and processing circuitry (112) communicatively coupled to the receiving unit and the distributed ledger (108), wherein the processing circuitry (112) is configured to: assign a risk score to the URL, wherein the risk score is a predefined initial value; determine whether at least one condition from a set of Internet Protocol (IP) conditions is satisfied for the URL; update, based on the determination that the at least one IP condition from the set of IP conditions is satisfied, the risk score by adding phase values corresponding to the IP condition satisfied; determine whether at least one URL characteristic condition from a set of URL characteristic conditions is satisfied for the URL;update, based on the determination that the at least one condition from the set of URL characteristic conditions is satisfied, the risk score by adding phase values corresponding to each URL characteristic condition satisfied; determine whether an entry corresponding to the risk score of the URL is present in the distributed ledger (108); and update the risk score by adding a seventh phase value to the risk score based on the determination that the entry corresponding to the risk score of the URL is present in the distributed ledger (108), wherein the risk score is indicative of credibility of the URL.
9. The system (100) as claimed in claim 8, wherein: the set of IP conditions comprises a first IP condition when the URL has at least one of Hyper Text Transfer Protocol Secure (HTTPS) component, and a second IP condition when the URL has a Fully Qualified Domain Name (FQDN) component; and the set of URL characteristic conditions comprises a first URL characteristic condition when a value of length of the URL being less than or equal to a predefined URL length value, in response to a determination that the URL does not have the FQDN component or a prohibited extension is present in the URL, a second URL characteristic condition when the URL being associated with a reputed domain, and a third URL characteristic condition when a mean value of the risk score for the URL being greater than or equal to an expected mean value of the risk score.
10. The system (100) as claimed in claim 9, wherein, prior to determining whether the at least one URL characteristic conditions is satisfied, the processing circuitry (112) is configured to:determine, in response to a determination that the second IP condition is satisfied, whether the prohibited extension is present or absent in the URL; and update the risk score by adding a phase value based on the determination that the prohibited extension is absent in the URL.
11. The system (100) as claimed in claim 10, wherein, in response to the determination that the entry corresponding to the risk score of the URL is present in the distributed ledger (108), the processing circuitry (112) is configured to determine a credibility percentage value for the URL by comparing the risk score with a select risk score.
12. The system (100) as claimed in claim 11, wherein, based on the determination that the prohibited extension is present in the URL, the processing circuitry (112) is configured to determine the credibility percentage value for the URL by comparing the risk score with the select risk score.
13. The system (100) as claimed in claim 11, further comprises a Machine Learning (ML) model (118), wherein the processing circuitry (112) is configured to: determine, through the ML model (118), a probability value of credibility for the URL based on the determination that the entry corresponding to the risk score of the URL is absent in the distributed ledger (108); and determine the credibility percentage value for the URL based on the probability value of credibility for the URL, wherein the ML model (118) performs Natural Language Processing (NLP) on the URL to determine the probability value of credibility for the URL.
14. The system (100) as claimed in claim 11, wherein an addition of a phase values to the risk score is associated with an increase in the credibility percentage of the URL when a corresponding condition is satisfied.
15. A computer-program product for evaluating a Uniform Resource Locator (URL) in a message, the computer program product comprising computerexecutable instructions that are stored on a non-transitory computer-readable medium and that, when executed by at least one processor performs operations comprising: extracting the URL from the message; assigning a risk score to the URL, wherein the risk score is a predefined initial value indicative of credibility of the URL; determining whether at least one condition from a set of Internet Protocol (IP) conditions is satisfied for the URL; updating, based on the determination that the at least one IP condition from the set of IP conditions is satisfied, the risk score by adding phase values corresponding to each IP condition satisfied; determining whether at least one URL characteristic condition from a set of URL characteristic conditions is satisfied for the URL; updating, based on the determination that the at least one URL characteristic condition from the set of URL characteristic conditions is satisfied, the risk score by adding phase values corresponding to each URL characteristic condition satisfied; determining whether an entry corresponding to the risk score of the URL is present in a distributed ledger (108); and updating the risk score by adding a phase value to the risk score based on the determination that the entry corresponding to the risk score of the URL is present in the distributed ledger (108), wherein the risk score is indicative of credibility of the URL.
Citation Information
Patent Citations
System and method for multi-layered rule learning in URL filtering
US11470044B1
URL pattern-based risk scoring and anomaly detection
US20230396649A1