Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

175 results about "Phishing" patented technology

Phishing is the fraudulent attempt to obtain sensitive information such as usernames, passwords and credit card details by disguising oneself as a trustworthy entity in an electronic communication. Typically carried out by email spoofing or instant messaging, it often directs users to enter personal information at a fake website which matches the look and feel of the legitimate site.

Ai-based cybersecurity system and method thereof

An AI-based Cybersecurity System and Method enable real-time detection, analysis, and mitigation of cyber threats within computing networks using adaptive artificial intelligence. The system continuously monitors network traffic, extracts behavioral and contextual attributes, and applies deep learning-based inference to identify anomalous activities indicating security breaches. The method integrates several computational units, including a network monitoring unit, feature extraction unit, artificial intelligence processor, contextual reasoning processor, and decision synthesis unit, to compute a composite risk index quantifying threat likelihood and severity. A classification processor categorizes detected threats into types such as ransomware, phishing, or unauthorized access, while a mitigation control processor initiates automated response actions to isolate compromised nodes and restore network integrity. An adaptive learning processor updates AI models using feedback from confirmed incidents. This provides a scalable, self-evolving cybersecurity framework that minimizes human intervention and enhances resilience against dynamic and zero-day threats.
Owner:PELL REDDY RAJENDER REDDY

Chatbot for Prevention of Online Fraud

In some embodiments, a fraud prevention system uses a chatbot agent to provide input to a threat analyzer. The chatbot agent converses with a user to identify a security need, guide the user into providing relevant data (e.g., a content of an email, a screenshot of a social media conversation), identify a target object for analysis, and indicate the target object to the threat analyzer. In turn, the threat analyzer applies a battery of tests to determine whether the target object is indicative of online fraud, such as a phishing attempt. The threat analyzer returns a verdict of the analysis to the chatbot agent for communication to the user.
Owner:BITDEFENDER IPR MANAGEMENT

Detection method and system for phishing mails

The invention discloses a detection method and system for a phishing mail, and relates to the technical field of mail security communication. The detection method for the phishing mail comprises the following steps of dual-stage screening, feature extraction and fusion, confrontation sample verification and detection model test and evaluation. According to the method, the mail sample is input into the phishing mail detection model to obtain the mail sample to be tested, the phishing mail double-stage screening is carried out to judge whether the mail sample is the phishing mail, and if the fine-grained mail screening is carried out, the total feature vector is obtained to carry out dynamic scoring to judge whether deep behavior analysis is carried out or not. The method comprises the following steps of: firstly, carrying out confrontation sample verification to output a test result, judging whether to carry out model parameter optimization, and finally, carrying out detection model test evaluation to feed back the test condition of the phishing mail detection model, thereby improving the accuracy of identifying the phishing mail by the phishing mail detection model. The problem that in the prior art, a phishing mail detection model is low in phishing mail recognition accuracy is solved.
Owner:张华

Detection of malicious domains

Disclosed are systems and methods that monitor for malicious and unauthorized behaviors, determine categories for detected malicious behaviors, determine why a domain is determined to be malicious, and provide information to users that identifies the categories and reasons as to why a domain is determined to be malicious. In some implementations, the disclosed systems and methods may be utilized to provide monitoring security to customers of a cloud service. For example, customers of a cloud service may maintain an account with the cloud service and the disclosed implementations may be utilized to protect those accounts from malicious attacks and cybercrimes such as, but not limited to, spam, phishing, malware, botnets, etc.
Owner:AMAZON TECH INC

Techniques for phishing-resistant enrollment and on-device authentication

Methods, systems, and devices for phishing-resistant authenticator enrollment are described. An authentication service may encrypt a token that is usable for an initial enrollment of a user in an authenticator application. The authentication service may transmit a first payload to the user. The first payload includes at least the encrypted token. An authenticator application may receive, from the user, a request to initiate the initial enrollment of the user on a device. The request may include the encrypted token. The authentication service may enroll the user in the authenticator application on the device based on decryption of the encrypted token using an encryption key on a near-field communication (NFC) device.
Owner:OKTA INC

Snapshot for activity detection and threat analysis

Embodiments of the technology described herein identify and mitigate phishing attempts by analyzing user input using a client-side proxy component and a proxy server. Embodiments disclosed herein provide systems, methods, and computer-storage media for employing proxy server capabilities in conjunction with a snapshot capturing an image or video recording of a target action input by a user into a software application. Certain embodiments disclosed herein employ proxy server capabilities to capture a snapshot and / or screen recording based on a user authorization or approval. For example, the proxy server proactively captures the snapshot or screen recording prior to, during, and after the user performing a target action. From the snapshot, certain embodiments extract snapshot features or determine enriched-contextual event data that is used to perform a mitigation action, generate a security mitigation score, or update an administrator portal activity log for an authorized administrator.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Detecting Phishing Websites Using Perceptual Image Hashing

Systems and methods for detecting phishing using image hashing include obtaining a plurality of images from different sources, generating a hash for each image, comparing at least one hash associated with a first image to one or more hashes associated with a second image, calculating a similarity score based on the comparing, and classifying the first image based on the similarity score.
Owner:ZSCALER INC

Transaction graph time sequence information and attention embedding fused Ethereum phishing node detection method

The invention relates to the field of block chain security, and discloses a detection method for phishing nodes in an Ethereum network. The method comprises the following steps: firstly, acquiring transaction data of a target node from an Ethereum network, and constructing a first-order transaction graph and a second-order transaction graph; wherein the first-order transaction graph retains an original transaction structure and time sequence information; and the second-order transaction graph combines a plurality of repeated transaction edges appearing between the same node pair, and adds the sum as the sum of a new transaction edge, so that the graph structure is simplified. Aiming at the first-order transaction graph, extracting time sequence characteristics of a transaction sequence through a gating loop unit (GRU); for embedding of a second-order transaction graph, a graph attention network (GAT) is utilized to introduce amount features. And finally, fusing the first-order time sequence features and the second-order structure features, inputting the fused features into a classification model, and judging whether the target node is a phishing node or not. According to the method, the accuracy and robustness of phishing node detection in the Ethereum network can be improved.
Owner:CHONGQING UNIV OF POSTS & TELECOMM

Large model-based phishing mail detection system and method

The invention discloses a phishing mail detection method and system based on a large model, and relates to the technical field of network security, the system comprises a real-time detection system and an offline analysis system, and a mail content analysis module receives real-time mail data to form structured data; the detection rule center matches the structured data with a detection rule, directly intercepts a mail hitting a high-confidence blacklist rule, and transmits the structured data of a mail hitting a low-confidence blacklist rule into a phishing mail detection agent; the phishing mail detection agent sequentially performs mail header suspicious feature analysis, mail body semantic analysis, mail body structure analysis and attachment content analysis on the structured data to obtain a mail intention, a link and an attachment file; and performing corresponding analysis by combining a detection tool, and judging whether the mail is a phishing mail or not according to an analysis result. A large-model-driven phishing mail detection intelligent agent is utilized, and a detection path is dynamically planned to cope with endless phishing mail attack means.
Owner:山东省大数据中心

Anti-phishing webpage detection system and method thereof

The invention discloses an anti-phishing webpage detection system and method. The anti-phishing webpage detection system comprises a webpage data capture module, a risk analysis module, a malicious webpage judgment module and a response decision module, relates to the technical field of anti-phishing webpage detection. According to the method, multi-dimensional data, including URL information, domain name information and webpage content information, of a webpage are extracted through the webpage data capturing module, a comprehensive original data basis is provided, and accurate support is provided for follow-up risk analysis; according to the method, comprehensive risk analysis is carried out by utilizing various webpage features including URL features, domain name features and content features, and potential phishing webpages can be effectively identified by calculating risk scores of the URL, the domain name and the webpage content; according to the method, the web pages are classified according to the comprehensive risk scores, the high-risk web pages are intercepted, the emergency response logs are generated, the low-risk web pages are continuously monitored, and safe browsing of a user is ensured.
Owner:HANGZHOU YIJIS DIGITAL TECHNOLOGY CO LTD

Systems and methods for threat detection and warning

The present disclosure relates generally to computer security, and, more particularly, to systems and methods for assisting a user in avoiding the accidental disclosure of confidential or sensitive information, as well as avoiding potential security breaches, including phishing and impersonation, malware, and security issues, particularly with respect to websites and electronic communications.
Owner:MIMECAST SERVICES LTD

Phishing website detection method and device, electronic equipment and medium

The embodiment of the invention discloses a phishing website detection method and device, electronic equipment and a medium, and the method comprises the steps: extracting a structural information feature vector and a content information feature vector of a first HTML document of a target website, and splicing the structural information feature vector and the content information feature vector to obtain a first feature vector of the target website; extracting a structural information feature vector and a content information feature vector of a second HTML document of the suspicious website, and splicing the structural information feature vector and the content information feature vector to obtain a second feature vector of the suspicious website; and according to the first feature vector and the second feature vector, detecting the phishing website through a pre-trained prediction model. Compared with the detection of the phishing website only depending on the content displayed in the website page, the method provided by the invention has the advantages that the feature vectors of the structure information and the content information of the HMTL document are respectively extracted and calculated, so that the model can comprehensively capture the overall features of the website, and the accuracy of the detection of the phishing website is improved.
Owner:CHINA TELECOM NETWORK SECURITY TECH CO LTD

Detection of Phishing Domains via Short Uniform Resource Locator (URL) Redirection Analysis

Systems and methods include receiving a customer domain from a user via a user device; parsing a plurality of candidate look-alike domains based on the customer domain; executing at least one detection technique selected from a plurality of short URL detection techniques to determine whether one or more short URLs redirect to one of the plurality of candidate look-alike domains; and in response to determining, by the at least one detection technique, that the one or more short URLs redirect to one of the plurality of candidate look-alike domains, classifying that candidate look-alike domain as a phishing attempt.
Owner:ZSCALER INC

Automated effective template generation

The systems and methods disclose an automated effective template generation and recommendation for selection. A semantic similarity of a plurality of messages may be identified that at least meets a similarity threshold, each of the plurality of messages reported by a plurality of users as a potentially malicious message. The plurality of messages may be indexed under a common template identifier. One or more messages of the plurality of messages indexed under the common template identifier may be determined to have a report-to-reach ratio less than a report-to-reach threshold. Responsive to the determination, the one or more messages may be identified to be used for generating one or more simulated phishing templates. A recommendation of the one or more templates may be provided to a system administrator and / or a security awareness and simulation training platform to create and deliver simulated phishing messages using the templates.
Owner:KNOWBE4 INC

Privacy-preserving labeling and classification of email

Emails or other communications are labeled with a category label such as “spam” or “good” without using confidential or Personally Identifiable Information (PII). The category label is based on features of the emails such as metadata that do not contain PII. Graphs of inferred relationships between email features and category labels are used to assign labels to emails and to features of the emails. The labeled emails are used as a training dataset for training a machine learning model (“MLM”). The MLM identifies unwanted emails such as spam, bulk email, phishing email, and emails that contain malware.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Positive reinforcement phishing identification simulations

A computerized platform for implementing a positive reinforcement-based educational campaign to increase awareness of indications of signs of unsafe e-mails is configured to perform a method utilizing an assignment-based approach to provide an assignment to a user in which the user is presented with a simulated e-mail including one or more indicators the user is instructed to determine as being more likely associated with a social engineering-containing e-mail or a safe e-mail. This method of phish testing simulations eliminates the possibility of false positive metrics tied to a company's cyber resiliency and thus improves the overall accuracy of cyber program measures and reporting designed to prevent the most prevalent and successful cyber-attack methods in use today-social engineering delivered through phishing e-mails.
Owner:CYBERHOOT LLC

Policy game and large language model-based phishing mail detection method, apparatus and device, and medium

The invention discloses a phishing mail detection method and device based on a strategy game and a large language model, equipment and a medium, and relates to the technical field of network security, and the method comprises the steps: obtaining a target detection mail; the target detection mail is input into a target phishing mail detection model for detection, a phishing mail detection result is obtained, the target phishing mail detection model is obtained through combined training of statistical features and semantic features, the statistical features are obtained through strategy gaming, and the semantic features are obtained through extraction of a large language model. According to the method, the key risk points of the phishing mail are accurately positioned through the statistical features extracted based on the strategy game, and the complex features of the phishing mail are comprehensively captured in combination with the semantic features extracted by the large language model, so that the limitation of traditional single-dimensional feature detection is avoided, and the detection precision is improved.
Owner:JINAN UNIVERSITY

Methods and Software For Training Users to Discern Electronic Phishing Messages and for Building Phishing Knowledgebases for Automated Electronic-Message Filtering

Computer-executed methods for training users to discern electronic phishing messages to reduce risk of threats to the integrity of computing systems and / or computing resources. In some embodiments, the methods involve gamifying the training to motivate users to participate in the training. In some embodiments, gamification includes instructing electronic-messaging-system users to forward suspected phishing messages for analysis. The analysis may include automatically determining one or more of a variety of factors for each forwarded suspected phishing message, such as whether or not the suspected phishing message is an actual phishing message, whether or not the reporting is an original reporting, and how quickly the user made the report. In some embodiments, points are awarded based on the analyzed factors. In some embodiments, the methods involve building phishing knowledgebases for automatic electronic-message filtering. Software for performing disclosed methods or one or more portions thereof.
Owner:TRUSTEES OF DARTMOUTH COLLEGE THE

Information processing system, information processing apparatus, program, and information processing method

To provide an information processing system or the like for enabling a manager to quickly and appropriately cope with phishing mail by facilitating post-coping of the phishing mail by the manager.SOLUTION: Report information indicating that phishing mail has been received is received from a given user belonging to an organization, and when the report information is received, given response processing is performed. For example, an information sharing area is generated, an administrator and a user are controlled to be able to access the information sharing area, information related to the phishing mail is shared in the information sharing area, and a degree of risk of specific information included in the phishing mail is determined.SELECTED DRAWING: Figure 3
Owner:HENNGE CO LTD

Multi-dimensional analysis-based phishing mail detection method, apparatus and device, and medium

The invention provides a phishing mail detection method and device based on multi-dimensional analysis, equipment and a medium. The method comprises the following steps: receiving a to-be-detected mail; performing keyword feature matching on the mail content, and if a threat keyword in a preset keyword library is matched, executing a secure forwarding operation; if the threat keyword in the preset keyword library is not matched, executing a threat library joint detection operation, and comprehensively outputting a first risk score; carrying out multi-modal semantic understanding analysis on the mail; generating a comprehensive threat judgment based on the first risk score and a semantic understanding analysis result; if the mail is judged to be a phishing mail, triggering an automatic response mechanism; otherwise, continuing to monitor the subsequent mails. The method has the beneficial effects that the problem of single feature dimension of a traditional method is solved by simultaneously extracting three types of core features of texts, URLs and attachments, and the recognition rate of phishing mails is obviously improved.
Owner:深圳市和讯华谷信息技术有限公司

Real-time ransom and security breach detection and prevention

The real-time ransom and security breach detection and prevention system empowers users and system administrators by providing real-time threat detection and prevention by detecting any phishing links, malicious executables and objects, and manipulation of authentication tokens that could potentially escalate a threat into ransom attacks, security breaches or other cyber attacks, and take immediate action by blocking and reporting the potential security breach before escalating into a real attack. The real-time ransom and security breach detection and prevention system generates a first hash of the link, executable, object, or authentication token. Utilizing this generated first hash, the real-time ransom and security breach detection and prevention system calculates a second hash upon user interaction or at runtime and compares the two unique hashes to determine if the link, executable, object, or authentication token is corrupt and terminates the gateway to prevent the cyber-threat from infecting the system.
Owner:IMPERVIOUS WORLD CORP

Ethereum phishing fraud detection method and system based on dynamic time chart comparative learning

The invention discloses an Ethereum phishing fraud detection method and system based on dynamic time graph comparative learning, and the method comprises the steps: obtaining a transaction record of an Ethereum transaction network, and constructing a time multilateral digraph which is used for representing multiple relationships between nodes and neighbor nodes in the Ethereum network; extracting statistical features from the time multilateral directed graph, executing feature mask and edge perturbation technologies, and generating graph embedding features with discriminability in combination with a graph contrast learning method; and fusing the statistical features with the graph embedded features to generate a final representation of each node. According to the method, the influence of the data imbalance problem on the model performance is effectively relieved through the combination of dynamic graph modeling and graph contrast learning, and the early-stage accurate recognition capability of the phishing nodes is improved.
Owner:HAINAN NORMAL UNIV

Electronic device with group action sharing of security filtering for third-party content

An electronic device, method and computer program product mitigate risks of presenting content that may include links to malware or phishing queries at secondary device(s) by learning from security-related user actions taken at trusted primary device(s). In response to receiving, via user interface component(s), a user input designating third-party content as violating a security policy at an electronic device assigned group level authorization to make security decisions for security policy sharing group of electronic devices, the controller updates a security policy module of the electronic device. The controller configures the electronic device to implement the updated security policy of the third-party content. The controller transmits a security policy update to each second device within the security policy sharing group to trigger an update of the respective security policy module to recognize and locally implement security measures against similar third-party content that is subsequently received.
Owner:MOTOROLA MOBILITY LLC

Method, device and equipment for identifying phishing mail attack, medium and product

The invention relates to the technical field of computers, and discloses a phishing mail attack identification method, device and equipment, a medium and a product. The method comprises the following steps: acquiring office system data, and screening out multiple pieces of target event data from the office system data based on a preset weak password feature; performing data structuring processing on the target event data to obtain a field value of each key feature field, and obtaining a high-risk account list according to the field value of each key feature field based on a preset abnormal behavior rule; obtaining mail system data, carrying out fishing behavior analysis according to the mail system data based on a preset fishing behavior rule, obtaining a candidate fishing mail account, and determining the candidate fishing mail account as a target fishing mail account when it is detected that the candidate fishing mail account exists in the high-risk account list, the recognition accuracy of the phishing mail attack can be improved, and the overall defense capability of the phishing mail attack can be improved.
Owner:BEIJING YOUTEJIE INFORMATION TECH

Threat sensing system based on active domain name generation and real-time malicious domain name detection

The invention discloses a threat sensing system based on active domain name generation and real-time malicious domain name detection, and belongs to the technical field of network security detection. The system comprises a historical threat sensing module, a real-time threat sensing module and a malicious detection module. In the historical threat sensing module, a domain name generation module constructs a similar domain name generation model by using an autoregression model based on Transform and generates a similar domain name list of a target enterprise, a risk assessment module detects whether similar domain names are registered or not, and if the similar domain names are registered and can be accessed, the similar domain names are added into a to-be-detected list; the real-time threat sensing module monitors newly registered domain names in real time, and adds the newly registered domain names into a suspicious domain name list if the similarity between the newly registered domain names and the target enterprise domain names is high; and the malicious detection module detects the list to be detected and the suspicious domain name list and identifies phishing websites. The domain name generated by the system can keep high similarity with the real domain name of an enterprise visually and semantically, and the potential domain name abuse risk can be quickly identified and evaluated.
Owner:BEIJING UNIV OF POSTS & TELECOMM

Method and system for detection of phishing emails and suspect malicious executable hyperlinks

Aspects of the subject disclosure may include, for example, receiving, at a device, a message over a communication network from a remote source, determining if the message includes executable code and initiating a virtual machine in an isolated portion of the memory of the device responsive to the determining the message include executable code. Aspects of the subject disclosure further include executing, by the virtual machine, the executable code within the isolated portion of the memory, monitoring, by an artificial intelligence module, activities of the executable code during the executing the executable code and determining if the executable code comprises malicious code responsive to the monitoring activities of the executable code. Aspects of the disclosure further include deleting the executable code from the device in response to a determination that the executable code comprises malicious code. Other embodiments are disclosed.
Owner:AT&T INTELLECTUAL PROPERTY I L P

Performing automated detection of phishing web sites using embedded tracking element

In some implementations, a method performed by data processing apparatuses includes serving a web page comprising an embedded markup image and a detection script. The detection script is configured to cause a client device to, in response to loading the embedded markup image, determine a current environment location indicative of a source of the web page, determine whether the current environment location matches a domain associated with a subject system, generate an obfuscated data payload based on the current environment location, and send a request to a predetermined endpoint in response to determining that the current environment location does not match the domain associated with the subject system. The request includes the obfuscated data payload.
Owner:TARGET BRANDS INC

Cybersecurity enforcement using synthetic phishing

In some implementations, a cybersecurity enforcement system may generate a synthetic phishing attempt targeting a user. The cybersecurity enforcement system may update, based at least in part on a mode of the synthetic phishing attempt, a risk profile specific to the user.
Owner:CAPITAL ONE SERVICES LLC

Phishing mail processing method, device, equipment and medium

The invention relates to the field of artificial intelligence, can be applied to business system platforms of finance, medical health and the like, and discloses a phishing mail processing method, device, equipment and medium, and the method comprises the following steps: obtaining mail information of an original mail in real time and extracting key fields in the mail information; according to key fields in the mail information, performing security filtering on all the original mails according to a preset filtering strategy to obtain to-be-detected mails after security filtering; obtaining an original sample of a to-be-detected mail, performing mail type detection on the original sample of the to-be-detected mail through a pre-constructed intelligent agent, and determining whether the to-be-detected mail is a phishing mail; and if yes, performing multi-stage response processing on the phishing mail according to the mail information of the phishing mail and a preset response strategy, and blocking and eliminating an attack path of the phishing mail. The phishing mails are processed through multi-stage response processing after the phishing mails are reliably identified through the intelligent agent, so that the processing completeness is ensured, and the risk caused by the phishing mails is effectively restrained in time.
Owner:PING AN TECH (SHENZHEN) CO LTD