Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

109 results about "Phishing" patented technology

Phishing is the fraudulent attempt to obtain sensitive information such as usernames, passwords and credit card details by disguising oneself as a trustworthy entity in an electronic communication. Typically carried out by email spoofing or instant messaging, it often directs users to enter personal information at a fake website which matches the look and feel of the legitimate site.

Ai-based cybersecurity system and method thereof

An AI-based Cybersecurity System and Method enable real-time detection, analysis, and mitigation of cyber threats within computing networks using adaptive artificial intelligence. The system continuously monitors network traffic, extracts behavioral and contextual attributes, and applies deep learning-based inference to identify anomalous activities indicating security breaches. The method integrates several computational units, including a network monitoring unit, feature extraction unit, artificial intelligence processor, contextual reasoning processor, and decision synthesis unit, to compute a composite risk index quantifying threat likelihood and severity. A classification processor categorizes detected threats into types such as ransomware, phishing, or unauthorized access, while a mitigation control processor initiates automated response actions to isolate compromised nodes and restore network integrity. An adaptive learning processor updates AI models using feedback from confirmed incidents. This provides a scalable, self-evolving cybersecurity framework that minimizes human intervention and enhances resilience against dynamic and zero-day threats.
Owner:PELL REDDY RAJENDER REDDY

Detection method and system for phishing mails

The invention discloses a detection method and system for a phishing mail, and relates to the technical field of mail security communication. The detection method for the phishing mail comprises the following steps of dual-stage screening, feature extraction and fusion, confrontation sample verification and detection model test and evaluation. According to the method, the mail sample is input into the phishing mail detection model to obtain the mail sample to be tested, the phishing mail double-stage screening is carried out to judge whether the mail sample is the phishing mail, and if the fine-grained mail screening is carried out, the total feature vector is obtained to carry out dynamic scoring to judge whether deep behavior analysis is carried out or not. The method comprises the following steps of: firstly, carrying out confrontation sample verification to output a test result, judging whether to carry out model parameter optimization, and finally, carrying out detection model test evaluation to feed back the test condition of the phishing mail detection model, thereby improving the accuracy of identifying the phishing mail by the phishing mail detection model. The problem that in the prior art, a phishing mail detection model is low in phishing mail recognition accuracy is solved.
Owner:张华

Detection of malicious domains

Disclosed are systems and methods that monitor for malicious and unauthorized behaviors, determine categories for detected malicious behaviors, determine why a domain is determined to be malicious, and provide information to users that identifies the categories and reasons as to why a domain is determined to be malicious. In some implementations, the disclosed systems and methods may be utilized to provide monitoring security to customers of a cloud service. For example, customers of a cloud service may maintain an account with the cloud service and the disclosed implementations may be utilized to protect those accounts from malicious attacks and cybercrimes such as, but not limited to, spam, phishing, malware, botnets, etc.
Owner:AMAZON TECH INC

Detecting Phishing Websites Using Perceptual Image Hashing

Systems and methods for detecting phishing using image hashing include obtaining a plurality of images from different sources, generating a hash for each image, comparing at least one hash associated with a first image to one or more hashes associated with a second image, calculating a similarity score based on the comparing, and classifying the first image based on the similarity score.
Owner:ZSCALER INC

Large model-based phishing mail detection system and method

The invention discloses a phishing mail detection method and system based on a large model, and relates to the technical field of network security, the system comprises a real-time detection system and an offline analysis system, and a mail content analysis module receives real-time mail data to form structured data; the detection rule center matches the structured data with a detection rule, directly intercepts a mail hitting a high-confidence blacklist rule, and transmits the structured data of a mail hitting a low-confidence blacklist rule into a phishing mail detection agent; the phishing mail detection agent sequentially performs mail header suspicious feature analysis, mail body semantic analysis, mail body structure analysis and attachment content analysis on the structured data to obtain a mail intention, a link and an attachment file; and performing corresponding analysis by combining a detection tool, and judging whether the mail is a phishing mail or not according to an analysis result. A large-model-driven phishing mail detection intelligent agent is utilized, and a detection path is dynamically planned to cope with endless phishing mail attack means.
Owner:山东省大数据中心

Systems and methods for threat detection and warning

The present disclosure relates generally to computer security, and, more particularly, to systems and methods for assisting a user in avoiding the accidental disclosure of confidential or sensitive information, as well as avoiding potential security breaches, including phishing and impersonation, malware, and security issues, particularly with respect to websites and electronic communications.
Owner:MIMECAST SERVICES LTD

Detection of Phishing Domains via Short Uniform Resource Locator (URL) Redirection Analysis

Systems and methods include receiving a customer domain from a user via a user device; parsing a plurality of candidate look-alike domains based on the customer domain; executing at least one detection technique selected from a plurality of short URL detection techniques to determine whether one or more short URLs redirect to one of the plurality of candidate look-alike domains; and in response to determining, by the at least one detection technique, that the one or more short URLs redirect to one of the plurality of candidate look-alike domains, classifying that candidate look-alike domain as a phishing attempt.
Owner:ZSCALER INC

Policy game and large language model-based phishing mail detection method, apparatus and device, and medium

The invention discloses a phishing mail detection method and device based on a strategy game and a large language model, equipment and a medium, and relates to the technical field of network security, and the method comprises the steps: obtaining a target detection mail; the target detection mail is input into a target phishing mail detection model for detection, a phishing mail detection result is obtained, the target phishing mail detection model is obtained through combined training of statistical features and semantic features, the statistical features are obtained through strategy gaming, and the semantic features are obtained through extraction of a large language model. According to the method, the key risk points of the phishing mail are accurately positioned through the statistical features extracted based on the strategy game, and the complex features of the phishing mail are comprehensively captured in combination with the semantic features extracted by the large language model, so that the limitation of traditional single-dimensional feature detection is avoided, and the detection precision is improved.
Owner:JINAN UNIVERSITY

Multi-dimensional analysis-based phishing mail detection method, apparatus and device, and medium

The invention provides a phishing mail detection method and device based on multi-dimensional analysis, equipment and a medium. The method comprises the following steps: receiving a to-be-detected mail; performing keyword feature matching on the mail content, and if a threat keyword in a preset keyword library is matched, executing a secure forwarding operation; if the threat keyword in the preset keyword library is not matched, executing a threat library joint detection operation, and comprehensively outputting a first risk score; carrying out multi-modal semantic understanding analysis on the mail; generating a comprehensive threat judgment based on the first risk score and a semantic understanding analysis result; if the mail is judged to be a phishing mail, triggering an automatic response mechanism; otherwise, continuing to monitor the subsequent mails. The method has the beneficial effects that the problem of single feature dimension of a traditional method is solved by simultaneously extracting three types of core features of texts, URLs and attachments, and the recognition rate of phishing mails is obviously improved.
Owner:深圳市和讯华谷信息技术有限公司

Real-time ransom and security breach detection and prevention

The real-time ransom and security breach detection and prevention system empowers users and system administrators by providing real-time threat detection and prevention by detecting any phishing links, malicious executables and objects, and manipulation of authentication tokens that could potentially escalate a threat into ransom attacks, security breaches or other cyber attacks, and take immediate action by blocking and reporting the potential security breach before escalating into a real attack. The real-time ransom and security breach detection and prevention system generates a first hash of the link, executable, object, or authentication token. Utilizing this generated first hash, the real-time ransom and security breach detection and prevention system calculates a second hash upon user interaction or at runtime and compares the two unique hashes to determine if the link, executable, object, or authentication token is corrupt and terminates the gateway to prevent the cyber-threat from infecting the system.
Owner:IMPERVIOUS WORLD CORP

Electronic device with group action sharing of security filtering for third-party content

An electronic device, method and computer program product mitigate risks of presenting content that may include links to malware or phishing queries at secondary device(s) by learning from security-related user actions taken at trusted primary device(s). In response to receiving, via user interface component(s), a user input designating third-party content as violating a security policy at an electronic device assigned group level authorization to make security decisions for security policy sharing group of electronic devices, the controller updates a security policy module of the electronic device. The controller configures the electronic device to implement the updated security policy of the third-party content. The controller transmits a security policy update to each second device within the security policy sharing group to trigger an update of the respective security policy module to recognize and locally implement security measures against similar third-party content that is subsequently received.
Owner:MOTOROLA MOBILITY LLC

Phishing mail processing method, device, equipment and medium

The invention relates to the field of artificial intelligence, can be applied to business system platforms of finance, medical health and the like, and discloses a phishing mail processing method, device, equipment and medium, and the method comprises the following steps: obtaining mail information of an original mail in real time and extracting key fields in the mail information; according to key fields in the mail information, performing security filtering on all the original mails according to a preset filtering strategy to obtain to-be-detected mails after security filtering; obtaining an original sample of a to-be-detected mail, performing mail type detection on the original sample of the to-be-detected mail through a pre-constructed intelligent agent, and determining whether the to-be-detected mail is a phishing mail; and if yes, performing multi-stage response processing on the phishing mail according to the mail information of the phishing mail and a preset response strategy, and blocking and eliminating an attack path of the phishing mail. The phishing mails are processed through multi-stage response processing after the phishing mails are reliably identified through the intelligent agent, so that the processing completeness is ensured, and the risk caused by the phishing mails is effectively restrained in time.
Owner:PING AN TECH (SHENZHEN) CO LTD

Real-time ransom and security breach detection and prevention

The real-time ransom and security breach detection and prevention system empowers users and system administrators by providing real-time threat detection and prevention by detecting any phishing links, malicious executables and objects, and manipulation of authentication tokens that could potentially escalate a threat into ransom attacks, security breaches or other cyber attacks, and take immediate action by blocking and reporting the potential security breach before escalating into a real attack. The real-time ransom and security breach detection and prevention system generates a first hash of the link, executable, object, or authentication token. Utilizing this generated first hash, the real-time ransom and security breach detection and prevention system calculates a second hash upon user interaction or at runtime and compares the two unique hashes to determine if the link, executable, object, or authentication token is corrupt and terminates the gateway to prevent the cyber-threat from infecting the system.
Owner:IMPERVIOUS WORLD CORP

Systems and methods for aida campaign controller intelligent records

Systems and methods, disclosed herein, of a campaign controller that stores information to a database about execution of multiple simulated phishing campaigns for multiple users, where each of the simulated phishing campaigns use one or more models for communicating simulated phishing communications. Based on this information, the campaign controller may determine a rate of success of the model, in causing a user to interact with a link in one of the simulated phishing campaigns, and may display the model's rate of success via a user interface.
Owner:KNOWBE4 INC

A timing risk memory fusion real-time detection method for Ethereum phishing address detection

PendingCN122660926APositive sampleRisk Control
The application discloses a timing risk memory fusion real-time detection method for Ethereum phishing address detection, and belongs to the technical field of blockchain security and machine learning risk identification. The method obtains on-chain account transaction data and constructs an account-level transaction sequence, divides a recent transaction window and a historical transaction window for a to-be-detected account, adopts a shared transaction timing encoder to generate a recent behavior representation and a historical risk memory representation, combines window intervals to form time decay information, and outputs a phishing risk score and an alarm result through a historical risk fusion network. The method can be optimized in combination with positive sample weighted training, teacher fusion and knowledge distillation, solves the problems that only relying on recent transactions is easy to lose historical risk context, complete historical recalculation has high overhead, and a few phishing address identification is difficult, and is suitable for on-chain real-time risk control scenes.
Owner:CHONGQING UNIV OF POSTS & TELECOMM

Lookalike Domain Risk Score Determination

PendingUS20260197338A1Domain nameWeb site
A systems and methods for determining a risk score for lookalike domains are disclosed. A plurality of candidate domains are generated from a seed domain using a genetic algorithm that applies deception techniques. Registered candidate domains are analyzed by multiple independent scoring engines that produce an internal deception score, a reputation score, a visual similarity score based on rendered webpage analysis, and a favicon similarity score. The individual scores are dynamically weighted and combined using conditional logic to calculate a final risk score. The weighting adapts based on signal strength, including prioritizing visual cloning indicators or malicious infrastructure signals. Unregistered domains are assigned reduced priority. When the final risk score exceeds a predefined threshold, an alert is generated. The disclosed approach integrates lexical, infrastructure, and content-based signals to reduce false positives and improve detection of sophisticated phishing domains.
Owner:ZSCALER INC

Phishing Site Identification and Security Remedy

Embodiments are related to determining if an unverified web page is a phishing site of a verified web page. In one or more embodiments, a computing server detects a style sheet element of an unverified web page accessed by a user using a web browser extension. The computing server checks if the detected style sheet element contains a copy of a part of a style sheet element present in the verified web page. If the style sheet element of the unverified web page contains a copy of the part of a style sheet element of the verified web page, indicating that the unverified web page is a phishing site, the computing server takes a security action. In some embodiments, the computing server may check if the unverified web page is a known web page.
Owner:RAMP BUSINESS CORP

Phishing avoidance assistance

In one aspect, an apparatus may include a processor system (24) and storage (28) accessible to the processor system. The storage may include instructions executable by the processor system to access (400) an email received at a recipient email account and to parse (410) data related to the email. Based on the parsing of the data, the instructions may be executable to determine (420) whether to take at least one action to help avoid a potential phishing instance based on bogus or look-alike email addresses. Based on a determination to take at least one action to help avoid the potential phishing instance, the instructions may be executable to take (440) at least a first action to help avoid the potential phishing instance. Thus, various techniques may be implemented to help avoid phishing attempts from email addresses that would look legitimate to an unsuspecting user, helping to prevent fraud, cybertheft, and other malicious phishing outcomes.
Owner:SONY GROUP CORP

Training method for domain-name generation model, phishing website detection method, and related apparatus

Provided in the embodiments of the present application are a training method for a domain-name generation model, a phishing website detection method, and a related apparatus. The training method comprises: matching serial numbers for a top-level domain name of a phishing website domain name and for characters of a second-level domain name thereof, so as to generate domain-name vectors; extracting semantic features of the domain-name vectors; on the basis of the top-level domain name and the characters of the second-level domain name, performing clustering to obtain common features; and by means of a generative adversarial network, performing training on the basis of a target domain-name vector, domain-name semantic feature vectors and the common features, and by means of the common features, guiding a generator to generate a potential phishing website domain name on the basis of the target domain-name vector and the domain-name semantic feature vectors. Reliable a priori knowledge is provided by means of combining domain-name similarity and domain-name semantic feature vectors; and by means of clustering, common features covering the similarities of real phishing website domain names in terms of structure, grammar and semantics are obtained, and the common features are used to guide a generative adversarial network to generate a similar domain name. Therefore, the present application has the advantages of a wide detection range, high timeliness and high practicability.
Owner:PENG CHENG LAB

Machine learning based system and method using URL feature hashing, HTML encoding, and content page embedded images to detect phishing websites

A phishing classifier is disclosed for classifying URLs and content pages as phishing or not, comprising a URL feature hasher that parses and hashes URLs into feature hashes, and a headless browser that visits and internally renders the pages of the URLs, extracts HTML tokens, and captures an image of the rendering. Also disclosed is a phishing classifier for classifying URLs and content pages accessed via the URLs as phishing or not, comprising a URL feature hasher that parses and hashes URLs into feature hashes, and a headless browser that visits and internally renders the pages of the URLs, extracts words from the rendering, and captures an image of the pages. Classifying URLs and content pages accessed via the URLs as phishing or not is further disclosed. In addition to one or more of the disclosures, there is a phishing classification layer, a URL embedder, and an HTML encoder.
Owner:NETSKOPE INC

Information processing device, phishing site detection method, and program

Provided are an information processing device and the like that can contribute to efficiently discovering phishing sites without preparing information relating to legitimate sites in advance. This information processing device is provided with: an information acquisition unit configured to acquire suspicious site information; an element extraction unit configured to extract prescribed elements in the suspicious site information; and a degree-of-similarity determination unit configured to calculate the degree of character string similarity between a prescribed URL domain in a prescribed element and a prescribed URL domain in the suspicious site information, or the degree of character string similarity between all or some of the prescribed elements, and determine whether or not the site relating to the suspicious site information is a phishing site on the basis of whether or not the calculated degree of similarity is within a preset numerical range.
Owner:NEC CORP

A high-precision ethereum phishing account detection method based on high-order topology

This application belongs to the field of Ethereum transaction technology, and particularly relates to a high-precision Ethereum phishing account detection method based on high-order topology. The detection method includes: acquiring transaction information containing historical phishing nodes, and then cleaning it to obtain several qualified transaction records; constructing a training node graph based on the qualified transaction records; constructing a corresponding multi-order graph based on the training node graph; the multi-order graph includes a bipartite graph and a classic pairwise graph, the bipartite graph containing the edge relationships between the simplex nodes corresponding to each maximal clique in the training node graph and the original nodes; the classic pairwise graph containing the edge relationships between the original nodes; obtaining the optimal influence score of the current classification model based on the multi-order graph; calculating the spliced ​​feature matrix of the current actual Ethereum node graph based on the optimal influence score; and the current classification model predicting phishing nodes based on the current actual Ethereum node graph and the corresponding spliced ​​feature matrix. This application can accurately detect phishing nodes.
Owner:UNIV OF SCI & TECH OF CHINA

Displaying representations of a virtual card within a virtual wallet application to enhance authentication security and to provide anti-phishing methods

Systems and methods are described herein for updating a representation of a virtual payment card in response to a virtual transaction between a first device (e.g., a user device) and a second device (e.g., a merchant point-of-sale device). The systems and methods may be used to authenticate user identity with an additional layer of security and / or combat phishing attempts intended to dupe users into disclosing confidential profile information. In response to a completed transaction, the second device delivers interactivity data (e.g., animation data, card image data, contextual data, notification sound data, etc.) to the first device, which actuates a distinct representation (e.g., an animation, a graphic image, a notification sound, etc.) of the card image of the virtual payment card used in the completed transaction.
Owner:ADEIA GUIDES INC

Cyber security phishing campaign

Embodiments describe herein relate to the automatic generation of personalised phishing communications for a target user within an organization. The content of a phishing communication is generated based on a generative artificial intelligence algorithm. In certain embodiments, data associated with the target user is as a part of a prompt to the generative artificial intelligence algorithm, enabling personalised content to be created. In further embodiments, we describe the use of templates associated with various parameters to be used as part of the prompt, which allows the content of the phishing communication to be customised according to the training requirements of a target user with minimal administrative input.
Owner:OUTTHINK LTD

Multi-modal phishing mail detection and interpretation generation method and system based on large model

The invention relates to a multi-modal phishing mail detection and interpretation generation method and system based on a large model, and the method comprises the steps: carrying out the preprocessing of an input original mail, extracting the multi-modal data in the original mail, and enabling the multi-modal data to comprise a text, an image and an attachment; the multi-modal data is analyzed, a mail analysis abstract is generated, and the analysis processing process comprises text processing, image detection, attachment detection and URL link detection; and combining the mail analysis abstract with a preset cue word, inputting the combined mail analysis abstract and the preset cue word into a large model, executing a phishing mail detection task through the large model, and synchronously generating a natural language text for explaining a detection result. Compared with the prior art, high-precision identification of novel and complex phishing mails is realized, a user is effectively warned and the security protection awareness of the user is improved through instant and credible explanation of a detection result, and an active defense system integrating detection, early warning and education is formed.
Owner:STATE GRID INFORMATION & TELECOMM BRANCH +1

Method and device for generating phishing mail for testing, equipment and medium

The invention relates to a generation method and device of a phishing mail for testing, equipment and a medium. The method comprises the following steps: acquiring initial information of a receiving object, the initial information being obtained by sampling based on respective object information of each object; performing feature reasoning based on the initial information and at least one object feature in an object feature database through a large language model to obtain object feature information of the receiving object; determining a target phishing strategy used for describing a phishing test scene and a target phishing mode used for describing a mail interaction mode; according to the initial information, the object feature information, the target phishing strategy and the target phishing mode, obtaining a mail generation prompt word; and generating a phishing mail for a phishing security test based on the mail generation cue word through a mail generation model. By adopting the method, diversified and targeted phishing mails can be generated, so that the security test effect is improved.
Owner:CHINA TELECOM CLOUD TECH CO LTD

A phishing website detection method and system based on a capsule neural network

The application discloses a phishing website detection method and system based on a capsule neural network. Different components of a website URL are segmented, character-level word segmentation, truncation padding and coding are implemented to realize fine-grained feature discrimination of different components, component-level and URL overall features are extracted, the overall space structure is learned by using a capsule network, and normal and phishing URLs are distinguished by a joint classification network. In the method and system, an adversarial training mechanism is introduced, independent adversarial training is performed on multiple embedding layers, the accuracy, F1-Score of the model is improved, and the false positive rate is reduced, so that the robustness and generalization ability of the model are enhanced. Experimental results show that the technology disclosed by the application surpasses the prior art on a million-level sample data set, and effectively improves the recognition performance of phishing URLs.
Owner:JIANGSU COLLEGE OF FINANCE & ACCOUNTING

Authentication processing device, authentication processing method, and program

This provides a new online authentication method that does not rely on traditional passwords or authentication codes and cannot be breached by real-time phishing scams. [Solution] The authentication processing device stores a first identifier of the user terminal included in the authentication application information received from the user terminal, and sends an authentication URL for launching the application provided to the user terminal via SMS to the user terminal. The authentication processing device determines whether the first identifier matches a second identifier of the user terminal included in the authentication processing information received from the user terminal, and if they match, provides the user terminal with a message indicating that the authentication process has been successfully completed. The authentication processing device determines whether the first session ID included in the authentication application information matches a second session ID included in the authentication processing information, and if they match, provides the user terminal with a message indicating that the authentication process has been successfully completed.
Owner:SUMITOMO MITSUI CARD

Method and apparatus for detecting phishing behavior

The embodiment of the present application provides a kind of phishing behavior detection method and device, it is related to network security technical field, wherein method includes: when receiving current log data, current log data is converted into current graph data;Current graph data is stored in graph database;When determining that current log data is the log data of including IP access behavior, at least one graph included in graph database is matched with the graph to be detected based on graph query statement rule, and matching result is obtained;The graph to be detected is composed of the graph data corresponding to each log data between the last log data of including IP access behavior and current log data and current graph data;When matching result is matching success, it is determined that the log data corresponding to the graph to be detected is network fishing behavior data.The present application realizes the detection of network fishing behavior based on the real-time triggering of graph query statement rule to external IP behavior, improves the accuracy of network fishing behavior detection.
Owner:QI-ANXIN LEGENDSEC INFORMATION TECH (BEIJING) INC +1