Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

74 results about "Phishing" patented technology

Phishing is the fraudulent attempt to obtain sensitive information such as usernames, passwords and credit card details by disguising oneself as a trustworthy entity in an electronic communication. Typically carried out by email spoofing or instant messaging, it often directs users to enter personal information at a fake website which matches the look and feel of the legitimate site.

Ai-based cybersecurity system and method thereof

An AI-based Cybersecurity System and Method enable real-time detection, analysis, and mitigation of cyber threats within computing networks using adaptive artificial intelligence. The system continuously monitors network traffic, extracts behavioral and contextual attributes, and applies deep learning-based inference to identify anomalous activities indicating security breaches. The method integrates several computational units, including a network monitoring unit, feature extraction unit, artificial intelligence processor, contextual reasoning processor, and decision synthesis unit, to compute a composite risk index quantifying threat likelihood and severity. A classification processor categorizes detected threats into types such as ransomware, phishing, or unauthorized access, while a mitigation control processor initiates automated response actions to isolate compromised nodes and restore network integrity. An adaptive learning processor updates AI models using feedback from confirmed incidents. This provides a scalable, self-evolving cybersecurity framework that minimizes human intervention and enhances resilience against dynamic and zero-day threats.
Owner:PELL REDDY RAJENDER REDDY

Real-time ransom and security breach detection and prevention

The real-time ransom and security breach detection and prevention system empowers users and system administrators by providing real-time threat detection and prevention by detecting any phishing links, malicious executables and objects, and manipulation of authentication tokens that could potentially escalate a threat into ransom attacks, security breaches or other cyber attacks, and take immediate action by blocking and reporting the potential security breach before escalating into a real attack. The real-time ransom and security breach detection and prevention system generates a first hash of the link, executable, object, or authentication token. Utilizing this generated first hash, the real-time ransom and security breach detection and prevention system calculates a second hash upon user interaction or at runtime and compares the two unique hashes to determine if the link, executable, object, or authentication token is corrupt and terminates the gateway to prevent the cyber-threat from infecting the system.
Owner:IMPERVIOUS WORLD CORP

Systems and methods for aida campaign controller intelligent records

Systems and methods, disclosed herein, of a campaign controller that stores information to a database about execution of multiple simulated phishing campaigns for multiple users, where each of the simulated phishing campaigns use one or more models for communicating simulated phishing communications. Based on this information, the campaign controller may determine a rate of success of the model, in causing a user to interact with a link in one of the simulated phishing campaigns, and may display the model's rate of success via a user interface.
Owner:KNOWBE4 INC

A timing risk memory fusion real-time detection method for Ethereum phishing address detection

PendingCN122660926APositive sampleRisk Control
The application discloses a timing risk memory fusion real-time detection method for Ethereum phishing address detection, and belongs to the technical field of blockchain security and machine learning risk identification. The method obtains on-chain account transaction data and constructs an account-level transaction sequence, divides a recent transaction window and a historical transaction window for a to-be-detected account, adopts a shared transaction timing encoder to generate a recent behavior representation and a historical risk memory representation, combines window intervals to form time decay information, and outputs a phishing risk score and an alarm result through a historical risk fusion network. The method can be optimized in combination with positive sample weighted training, teacher fusion and knowledge distillation, solves the problems that only relying on recent transactions is easy to lose historical risk context, complete historical recalculation has high overhead, and a few phishing address identification is difficult, and is suitable for on-chain real-time risk control scenes.
Owner:CHONGQING UNIV OF POSTS & TELECOMM

Lookalike Domain Risk Score Determination

PendingUS20260197338A1Domain nameWeb site
A systems and methods for determining a risk score for lookalike domains are disclosed. A plurality of candidate domains are generated from a seed domain using a genetic algorithm that applies deception techniques. Registered candidate domains are analyzed by multiple independent scoring engines that produce an internal deception score, a reputation score, a visual similarity score based on rendered webpage analysis, and a favicon similarity score. The individual scores are dynamically weighted and combined using conditional logic to calculate a final risk score. The weighting adapts based on signal strength, including prioritizing visual cloning indicators or malicious infrastructure signals. Unregistered domains are assigned reduced priority. When the final risk score exceeds a predefined threshold, an alert is generated. The disclosed approach integrates lexical, infrastructure, and content-based signals to reduce false positives and improve detection of sophisticated phishing domains.
Owner:ZSCALER INC

Phishing Site Identification and Security Remedy

Embodiments are related to determining if an unverified web page is a phishing site of a verified web page. In one or more embodiments, a computing server detects a style sheet element of an unverified web page accessed by a user using a web browser extension. The computing server checks if the detected style sheet element contains a copy of a part of a style sheet element present in the verified web page. If the style sheet element of the unverified web page contains a copy of the part of a style sheet element of the verified web page, indicating that the unverified web page is a phishing site, the computing server takes a security action. In some embodiments, the computing server may check if the unverified web page is a known web page.
Owner:RAMP BUSINESS CORP

Phishing avoidance assistance

In one aspect, an apparatus may include a processor system (24) and storage (28) accessible to the processor system. The storage may include instructions executable by the processor system to access (400) an email received at a recipient email account and to parse (410) data related to the email. Based on the parsing of the data, the instructions may be executable to determine (420) whether to take at least one action to help avoid a potential phishing instance based on bogus or look-alike email addresses. Based on a determination to take at least one action to help avoid the potential phishing instance, the instructions may be executable to take (440) at least a first action to help avoid the potential phishing instance. Thus, various techniques may be implemented to help avoid phishing attempts from email addresses that would look legitimate to an unsuspecting user, helping to prevent fraud, cybertheft, and other malicious phishing outcomes.
Owner:SONY GROUP CORP

A high-precision ethereum phishing account detection method based on high-order topology

This application belongs to the field of Ethereum transaction technology, and particularly relates to a high-precision Ethereum phishing account detection method based on high-order topology. The detection method includes: acquiring transaction information containing historical phishing nodes, and then cleaning it to obtain several qualified transaction records; constructing a training node graph based on the qualified transaction records; constructing a corresponding multi-order graph based on the training node graph; the multi-order graph includes a bipartite graph and a classic pairwise graph, the bipartite graph containing the edge relationships between the simplex nodes corresponding to each maximal clique in the training node graph and the original nodes; the classic pairwise graph containing the edge relationships between the original nodes; obtaining the optimal influence score of the current classification model based on the multi-order graph; calculating the spliced ​​feature matrix of the current actual Ethereum node graph based on the optimal influence score; and the current classification model predicting phishing nodes based on the current actual Ethereum node graph and the corresponding spliced ​​feature matrix. This application can accurately detect phishing nodes.
Owner:UNIV OF SCI & TECH OF CHINA

Displaying representations of a virtual card within a virtual wallet application to enhance authentication security and to provide anti-phishing methods

Systems and methods are described herein for updating a representation of a virtual payment card in response to a virtual transaction between a first device (e.g., a user device) and a second device (e.g., a merchant point-of-sale device). The systems and methods may be used to authenticate user identity with an additional layer of security and / or combat phishing attempts intended to dupe users into disclosing confidential profile information. In response to a completed transaction, the second device delivers interactivity data (e.g., animation data, card image data, contextual data, notification sound data, etc.) to the first device, which actuates a distinct representation (e.g., an animation, a graphic image, a notification sound, etc.) of the card image of the virtual payment card used in the completed transaction.
Owner:ADEIA GUIDES INC

Cyber security phishing campaign

Embodiments describe herein relate to the automatic generation of personalised phishing communications for a target user within an organization. The content of a phishing communication is generated based on a generative artificial intelligence algorithm. In certain embodiments, data associated with the target user is as a part of a prompt to the generative artificial intelligence algorithm, enabling personalised content to be created. In further embodiments, we describe the use of templates associated with various parameters to be used as part of the prompt, which allows the content of the phishing communication to be customised according to the training requirements of a target user with minimal administrative input.
Owner:OUTTHINK LTD

Multi-modal phishing mail detection and interpretation generation method and system based on large model

The invention relates to a multi-modal phishing mail detection and interpretation generation method and system based on a large model, and the method comprises the steps: carrying out the preprocessing of an input original mail, extracting the multi-modal data in the original mail, and enabling the multi-modal data to comprise a text, an image and an attachment; the multi-modal data is analyzed, a mail analysis abstract is generated, and the analysis processing process comprises text processing, image detection, attachment detection and URL link detection; and combining the mail analysis abstract with a preset cue word, inputting the combined mail analysis abstract and the preset cue word into a large model, executing a phishing mail detection task through the large model, and synchronously generating a natural language text for explaining a detection result. Compared with the prior art, high-precision identification of novel and complex phishing mails is realized, a user is effectively warned and the security protection awareness of the user is improved through instant and credible explanation of a detection result, and an active defense system integrating detection, early warning and education is formed.
Owner:STATE GRID INFORMATION & TELECOMM BRANCH +1

Method and device for generating phishing mail for testing, equipment and medium

The invention relates to a generation method and device of a phishing mail for testing, equipment and a medium. The method comprises the following steps: acquiring initial information of a receiving object, the initial information being obtained by sampling based on respective object information of each object; performing feature reasoning based on the initial information and at least one object feature in an object feature database through a large language model to obtain object feature information of the receiving object; determining a target phishing strategy used for describing a phishing test scene and a target phishing mode used for describing a mail interaction mode; according to the initial information, the object feature information, the target phishing strategy and the target phishing mode, obtaining a mail generation prompt word; and generating a phishing mail for a phishing security test based on the mail generation cue word through a mail generation model. By adopting the method, diversified and targeted phishing mails can be generated, so that the security test effect is improved.
Owner:CHINA TELECOM CLOUD TECH CO LTD

A phishing website detection method and system based on a capsule neural network

The application discloses a phishing website detection method and system based on a capsule neural network. Different components of a website URL are segmented, character-level word segmentation, truncation padding and coding are implemented to realize fine-grained feature discrimination of different components, component-level and URL overall features are extracted, the overall space structure is learned by using a capsule network, and normal and phishing URLs are distinguished by a joint classification network. In the method and system, an adversarial training mechanism is introduced, independent adversarial training is performed on multiple embedding layers, the accuracy, F1-Score of the model is improved, and the false positive rate is reduced, so that the robustness and generalization ability of the model are enhanced. Experimental results show that the technology disclosed by the application surpasses the prior art on a million-level sample data set, and effectively improves the recognition performance of phishing URLs.
Owner:JIANGSU COLLEGE OF FINANCE & ACCOUNTING

Authentication processing device, authentication processing method, and program

This provides a new online authentication method that does not rely on traditional passwords or authentication codes and cannot be breached by real-time phishing scams. [Solution] The authentication processing device stores a first identifier of the user terminal included in the authentication application information received from the user terminal, and sends an authentication URL for launching the application provided to the user terminal via SMS to the user terminal. The authentication processing device determines whether the first identifier matches a second identifier of the user terminal included in the authentication processing information received from the user terminal, and if they match, provides the user terminal with a message indicating that the authentication process has been successfully completed. The authentication processing device determines whether the first session ID included in the authentication application information matches a second session ID included in the authentication processing information, and if they match, provides the user terminal with a message indicating that the authentication process has been successfully completed.
Owner:SUMITOMO MITSUI CARD

Systems and methods for threat detection and warning

The present disclosure relates generally to computer security, and, more particularly, to systems and methods for assisting a user in avoiding the accidental disclosure of confidential or sensitive information, as well as avoiding potential security breaches, including phishing and impersonation, malware, and security issues, particularly with respect to websites and electronic communications.
Owner:MIMECAST SERVICES LTD

Zero shot detection of LLM generated phishing emails

A pipeline for classifying malicious communications as AI generated or human generated has been created. The pipeline uses a first prompt template that directs a first LLM to parse a phishing e-mail and extract information from the phishing e-mail. The pipeline searches publicly available information to obtain current information based on keywords in the information extracted from the phishing e-mail. The pipeline then uses a second LLM to compose an e-mail. With a different prompt template, the pipeline directs the second LLM to compose an e-mail based on the obtained, current information and a recipient and sender extracted from the phishing e-mail. With another prompt, the pipeline directs the second LLM to determine whether the phishing e-mail is similar to the LLM composed e-mail. If the second LLM responds that the phishing e-mail is similar to the composed e-mail, then the phishing e-mail is classified as AI generated.
Owner:PALO ALTO NETWORKS INC

Method for detecting vulnerability to a phishing-type attack in a computer system

The present invention relates to a method for detecting vulnerability to a phishing-type attack in a computer system, the method being characterised in that it comprises carrying out, by data processing means (11) of a server (1) of the computer system, the steps of: (a) obtaining at least a first computer message relating to a phishing attempt, the first computer message comprising original personalisation data; (b) generating a second computer message corresponding to the first computer message, wherein the original personalisation data have been anonymised; (c) generating a third computer message corresponding to the second computer message to which new personalisation data have been added for at least one user of the computer system, referred to as the target user, according to targeting data of the computer system stored in data storage means (12) of the server (1); (d) transmitting the third computer message to the target user so as to simulate a phishing-type attack; (e) detecting at least one reaction to the third computer message carried out by the target user in the computer system.
Owner:AAIS - ARMAGEDDON ARTIFICIAL INTELLIGENCE SECURITY

GenAI Driven Personalized Education Platform

A generative artificial intelligence (GenAI) driven education platform provides personalized learning experiences by leveraging large language models (LLMs) and secure data storage. The platform refines training objectives, generates context-aware scenarios, and adjusts difficulty based on user performance. User data—such as past performance, roles, and preferences—remains on-premises for privacy, supporting dynamic content adaptation without exposing sensitive information to external servers. Contextual materials, including news articles or internal documents, enhance scenario realism. Real-time feedback pinpoints knowledge gaps, while iterative updates to test cases continually evolve training modules. Applications include phishing simulations, compliance training, professional exam preparation, and more. Interactive components, such as multimedia quizzes and immersive simulations, are rendered through a customizable interface. This hyper-personalized approach boosts engagement, retention, and relevance by incorporating granular user data and ongoing performance metrics. Ultimately, organizations gain a robust, adaptive framework to deliver secure, high-impact learning across academic, corporate, and professional environments.
Owner:GEN DIGITAL INC

Large model-based phishing mail identification method, apparatus and device, and medium

The invention discloses a fishing mail recognition method, device and equipment based on a large model and a medium, and relates to the technical field of artificial intelligence, and the method comprises the steps: obtaining a to-be-analyzed target mail, extracting initial mail information corresponding to the target mail, and carrying out the standardization processing of the initial mail information, and obtaining the target mail information; inputting the target mail information into a target large model, determining an identification target corresponding to the target mail information based on the source of the target mail information by using the target large model, and generating semantic feature information corresponding to the target mail information based on the identification target; the identification target is phishing mail detection or phishing mail re-checking; and performing weighted calculation on the semantic feature information and the security evaluation information of the target mail information to obtain a risk score, and generating a phishing mail recognition result corresponding to the target mail based on the risk score and the recognition target so as to process the target mail based on the phishing mail recognition result. According to the invention, the accuracy and efficiency of phishing mail identification can be improved.
Owner:HANGZHOU DBAPPSECURITY CO LTD

Phishing account detection model training method, detection method and device

According to the phishing account detection model training method, the phishing account detection method and the phishing account detection device, a second-order transaction network is independently constructed for each account, a local transaction structure of each account is completely reserved, and the bottleneck of feature dilution and excessive smoothness caused by traditional global large graph training is broken through; address similarity features are introduced, high-frequency transaction object tail number similarity deliberately constructed by an attacker is accurately captured, and the visual confusion type fishing behavior is effectively recognized. A random walk restart algorithm is adopted to generate double local subgraphs, center node self-pairing is used as a positive sample, a cross-subgraph non-center node is used as a negative sample, node-level comparison loss is constructed, and the discrimination capability of a model on phishing nodes and normal neighbors is enhanced; through joint classification loss end-to-end training, the graph neural network can be incrementally updated without re-training a global graph, and lightweight deployment is realized. According to the method, in a block chain transaction scene with extremely unbalanced data, the risk of misjudgment of the phishing account can be remarkably reduced, and high sensitivity and real-time performance are both achieved.
Owner:BEIJING UNIV OF POSTS & TELECOMM

Phishing email detection method and device based on strategy game and large language model, equipment and medium

The application discloses a phishing email detection method and device based on strategy game and large language model, equipment and medium, relates to the technical field of network security, and the method comprises the steps that a target detection email is acquired; the target detection email is input into a target phishing email detection model for detection to obtain a phishing email detection result, wherein the target phishing email detection model is obtained by joint training of statistical characteristics and semantic characteristics, the statistical characteristics are obtained by strategy game, and the semantic characteristics are obtained by extraction of a large language model. The application accurately locates the key risk points of the phishing email through the statistical characteristics extracted based on the strategy game, comprehensively captures the complex characteristics of the phishing email in combination with the semantic characteristics extracted by the large language model, thereby avoiding the limitations of traditional single-dimensional feature detection, and improving the detection precision.
Owner:JINAN UNIVERSITY

Phishing page testing method and device, electronic equipment and storage medium

Embodiments of the present application provide a phishing page testing method and device, electronic equipment and storage medium, the method comprises: constructing a corresponding pseudo phishing page based on a source phishing page; determining the target field of the constructed pseudo phishing page, the target field is a sensitive field in the data submitted through the pseudo phishing page; shielding the target field to perform phishing testing on the pseudo phishing page after shielding. According to the technical scheme in the embodiments of the present application, in the phishing drill process in the company, the sensitive fields in the pseudo phishing page can be shielded, the data in the pseudo phishing page can be selectively submitted to the phishing server, the risk of data leakage is reduced, and the security of private data is improved.
Owner:BEIJING HONGTENG INTELLIGENT TECH CO LTD

Email threat perception system

PendingCN122179195ASecuring communicationSpammingPerception system
The application provides an email threat perception system, belonging to the field of network security and email protection, and researches and practices email security threat perception technology, utilizes an email behavior detection model and a machine learning model to perform multi-dimensional and multi-level deep analysis on emails, so as to identify abnormal email behaviors, discover phishing links and sensitive contents, etc. On this basis, an active and low false alarm rate email security threat perception system is realized, which detects and filters spam emails, phishing emails and emails containing sensitive contents, and improves the security of email applications.
Owner:GUILIN UNIV OF ELECTRONIC TECH

Model for Detecting Phishing URLS

Methods, storage systems and computer program products implement embodiments of the present invention for protecting a computing device. These embodiments include detecting that a digital communication is received by the computing device, the digital communication including a Uniform Resource Locator (URL) for a web page in a first domain. The web page is retrieved from the domain, and a set of keywords are extracted from the retrieved web page. A query included the set of keywords is submitted to a search engine, and a response to the query is received from the search engine, the response indicating a set of second domains and their respective rankings. An alert is generated if it is determined that a ranking associated with a second domain corresponding to the first domain does not satisfy a specified ranking threshold
Owner:PALO ALTO NETWORKS INC

A method, apparatus, device and storage medium for adjusting a sending rate

The application discloses a mail sending rate adjusting method and device, equipment and storage medium, relates to the network security technical field, and includes the following steps: calling a preset Open API interface to create a mail sending task for each phishing email; determining whether the current time has reached the scheduled sending time; if yes, the mail sending task is sent to the master management service through the Open API interface, and the mail sending task is distributed to multiple agent nodes according to the distribution strategy of the mail sending task; the task execution mode of the mail sending task is obtained through the agent node, and the phishing email is sent to the target practice object according to the task execution mode; the mail sending rate is detected through the master management service, and it is determined whether the mail sending rate is greater than the preset rate threshold; if not, a new agent node is created to send the phishing email to be sent. The application can realize dynamic mail sending efficiency adjustment and achieve good phishing email practice effect.
Owner:HANGZHOU DBAPPSECURITY CO LTD

Mail protection method and detection method

The invention relates to the technical field of mail detection and protection, in particular to a mail protection method and a mail detection method. The mail protection method comprises the following steps: acquiring a to-be-detected mail, judging whether the to-be-detected mail contains a compressed attachment, judging whether the compressed attachment is an encrypted attachment when the to-be-detected mail contains the compressed attachment, judging whether the encrypted attachment can be decrypted according to an agreement when the compressed attachment is the encrypted attachment, and if the encrypted attachment can be decrypted according to the agreement, judging whether the to-be-detected mail contains the compressed attachment. And if the encrypted attachment is decrypted according to the agreement, determining that the to-be-tested mail is a normal mail and sending the to-be-tested mail to a recipient according to the recipient email address of the to-be-tested mail, and if the encrypted attachment cannot be decrypted according to the agreement, determining that the to-be-tested mail is a suspicious mail and performing isolation operation on the suspicious mail. On one hand, mail receiving and sending are carried out through agreed attachment encryption, receiving of phishing mails can be avoided, the mail protection effect is improved, and on the other hand, the mail protection effect can be further improved by isolating suspicious mails.
Owner:SHUHE TECHNOLOGY (SHENZHEN) CO LTD

Phishing webpage intelligent detection system and method based on proxy AI

The invention provides a proxy AI-based phishing webpage intelligent detection system and method, and the system is characterized in that the system comprises a link input module which is used for receiving a to-be-detected URL, and carrying out the preliminary filtering; the headless browser control module is used for controlling a headless browser to load a page and managing the life cycle of the page; the page content extraction module is used for extracting page information from the headless browser; manual analysis requirements are reduced through automatic interaction, the detection efficiency is improved, and the method is suitable for large-scale mail security scanning scenes; an interaction path and a decision process can be recorded, a transparent log is provided for security analysis, and subsequent optimization and auditing are facilitated.
Owner:BEIJING DIRECTION BIAO INFORMATION TECHNOLOGY CO LTD

System and method of for detecting phishing sites using DOM hashes and a machine learning classifier

Disclosed herein are systems and methods for detecting phishing sites using Document Object Model (DOM) hashes and a machine learning (ML) classifier. In one aspect, an exemplary method comprises: parsing at least one webpage of a website to generate a DOM tree of the webpage; generating at least one string of DOM tree elements according to one of more predetermined patterns; generating a hash of at least one string; checking if the hash is found in a database of hashes of known fishing websites; when the hash is not in the database, analyzing the associated webpage using a ML-based classifier trained to identify phishing websites; and determining if the webpage is a phishing or not based on the output of the classifier.
Owner:AO KASPERSKY LAB

A phishing website feature recognition and interception method introducing AI

PendingCN122640226ADomain namePathPing
The application provides a phishing website feature recognition and interception method introducing AI, which comprises the following steps: an edge computing node receives an access request initiated by a user to a website to be accessed, collects domain name structure, uniform resource locator path, page text, form field, certificate information, jump link, page screenshot and historical access behavior, and generates an initial feature set; a real access session and a plurality of identity gradient shadow sessions are established based on the initial feature set, identity gradient simulation parameters are determined by using a fruit fly algorithm, and page explicit response data are generated; the initial feature set and the page explicit response data are input into an artificial intelligence recognition model, page explicit mutation features are recognized, and a phishing page explicit risk result is generated; a synthetic identity probe is generated according to the phishing page explicit risk result, sensitive form fields are injected into an isolated session, and relay echo data are generated.
Owner:SHANGHAI DISAI INFORMATION TECHNOLOGY CO LTD