Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

53 results about "Phishing attack" patented technology

Phishing is a type of security attack that attempts to trick or coerce targets into divulging sensitive/valuable information. Sometimes referred to as a “phishing scam,” attackers target users’ login credentials, financial information (such as credit cards or bank accounts), company data, and anything that could potentially be of value.

Integrated security for cloud applications

Provided herein are systems and methods for detecting a phishing attack. The method comprises: processing an original message to determine whether the original message is suspicious or benign, upon determining the original message is suspicious, generating multiple copies of the original message for detecting a phishing attack, where the multiple copies are varied from the original message in least one of tones, formats, and writing styles, and the multiple copies are generated to be similar to a training dataset that is utilized to train a phishing attack detection engine; and processing the multiple copies and the original message by the phishing attack detection engine to determine whether the original message is malicious or benign. One or more copies from the multiple copies that are not identified as malicious are utilized to further train the phishing attack detection engine automatically.
Owner:VARONIS SYSTEMS INC

Methods and systems for identifying phishing attacks

Provided are systems, software, and methods for phishing analysis and detection. The provided systems, software, and methods may comprise interfaces configured to capture and scan network session activity in real-time to detect a phishing attack using a set of trained machine learning classifiers, detect a phishing attach, classify the attack into one or more phishing classes, block the phishing attack and provide a safe preview of the blocked phishing attack. The machine learning classifiers may be deployed remotely. The systems, software, and methods may further comprise a web application programing interface configured to integrate the one or more analysis interfaces into at least one external software or application.
Owner:VARONIS SYSTEMS INC

Defending against phishing attacks by conversation modeling

In an example, a method for detecting phishing attacks includes: receiving textual representation of a portion of a conversation between two or more parties; determining one or more dialog turns; classifying, using a first ML model, each of the one or more dialog turns into a plurality of conversational intent classes to generate a first classification; classifying, using a second ML model, each of the one or more dialog turns into a plurality of PII request classes to generate a second classification; generating, based on the first classification and the second classification, a corresponding risk score for each of the one or more dialog turns; generating, based on the corresponding risk score, an accumulated risk score for the portion of the conversation; and triggering, based on determining that the generated accumulated risk score satisfies a predefined threshold value, an indication of a potential disclosure of PII.
Owner:SRI INTERNATIONAL

Phishing avoidance assistance

System and method for anti-phishing emails based on link domain name and user feedback The invention provides a system and a method for anti-phishing emails based on link domain name and user feedback. The system comprises an email receiving device, an email pre-processing device, an email property judging device, an outputting device and a feedback processing device. The method comprises the following steps: analyzing characteristics of the link domain name in the email, combining with a controlled network user feedback strategy, and identifying phishing emails and doubtful phishing emails. The Invention has advantages of high identification efficiency, low resource consumption and no error rate. The Invention can be configured to email servers, gateway servers and the like that require high real-time performance, protect the controlled network user against cheating by the phishing emails, resist the interference from the spiteful user in the controlled network, and can be widely applied to the application fields of network email filtering management, anti-phishing attack and the like.
Owner:SONY GROUP CORP

Web analyzer engine for identifying security-related threats

Techniques are described for providing a threat analysis platform capable of automating actions performed to analyze security-related threats affecting IT environments. Users or applications can submit objects (e.g., URLs, files, etc.) for analysis by the threat analysis platform. Once submitted, the threat analysis platform routes the objects to dedicated engines that can perform static and dynamic analysis processes to determine a likelihood that an object is associated with malicious activity such as phishing attacks, malware, or other types of security threats. The automated actions performed by the threat analysis platform can include, for example, navigating to submitted URLs and recording activity related to accessing the corresponding resource, analyzing files and documents by extracting text and metadata, extracting and emulating execution of embedded macro source code, performing optical character recognition (OCR) and other types of image analysis, submitting objects to third-party security services for analysis, among many other possible actions.
Owner:CISCO TECHNOLOGY INC

Automated attack chain following by a threat analysis platform

Techniques are described for providing a threat analysis platform capable of automating actions performed to analyze security-related threats affecting IT environments. Users or applications can submit objects (e.g., URLs, files, etc.) for analysis by the threat analysis platform. Once submitted, the threat analysis platform routes the objects to dedicated engines that can perform static and dynamic analysis processes to determine a likelihood that an object is associated with malicious activity such as phishing attacks, malware, or other types of security threats. The automated actions performed by the threat analysis platform can include, for example, navigating to submitted URLs and recording activity related to accessing the corresponding resource, analyzing files and documents by extracting text and metadata, extracting and emulating execution of embedded macro source code, performing optical character recognition (OCR) and other types of image analysis, submitting objects to third-party security services for analysis, among many other possible actions.
Owner:CISCO TECHNOLOGY INC

A deep spoofing detection and tracing system for network phishing attacks

PendingCN122394861APathPingAttack
The application discloses a kind of deep fake detection and tracing systems for network phishing attack, including the following steps: multi-source data acquisition module is used to form pre-processing multi-source data;Feature extraction module is used to form associated feature data;Association graph generation module is used to build fake content association layer and phishing propagation association layer, form unified attack association graph;Path screening construction module is used to identify effective relationship section, and build calculation path set;Similarity calculation backwrite module is used to perform PathSim similarity calculation, form the unified attack association graph after state update;Iterative calculation update module is used to re-execute PathSim similarity calculation, form candidate association result;Back-checking analysis output module is used to verify based on fake evidence and propagation evidence, and convert the candidate association result after verification into attack analysis result.The application improves the accuracy of deep fake content identification in network phishing attack scenario.
Owner:NINGXIA PUSHI INFORMATION TECH SERVICE CO LTD

Method and device for identifying phishing attack in mailbox

The invention belongs to the technical field of network security, and particularly provides a method and device for identifying a phishing attack of a mailbox, and the method comprises the steps: S1, collecting mail data, carrying out the cleaning, labeling and multi-carrier mail preprocessing of the mail data, and obtaining a mail sample; s2, extracting a mail head feature, a text feature, a link feature, an attachment feature and a two-dimensional code feature from the mail sample; s3, performing risk assessment on the mails by utilizing a machine learning classification model, and judging whether the mails are phishing mails or not; s4, performing automatic isolation, early warning or prompting on the phishing mail; and S5, collecting user feedback and system false alarm / missing report conditions, and continuously optimizing and training the machine learning classification model. According to the method, data quality is guaranteed through multivariate data integration and fine processing, risks are accurately evaluated by combining multi-dimensional feature extraction with an advanced machine learning classification model, the recognition accuracy is effectively improved, false and missing reports are reduced, mails can be flexibly processed according to the risks, the model is continuously optimized to adapt to a new attack technique, and the efficiency is improved. And a lasting guarantee is provided for enterprise and user information security.
Owner:CHINA LIFE INSURANCE CO LTD HEBEI BRANCH

Internal email filtering

Systems and methods for internal email filtering are provided. Various embodiments of the present technology provide systems and methods for improved email filtering including a dedicated internal email filtering process designed to intercept all emails exchanged within the organization and detect whether the email is internal or external. The system scans each internal email to detect potential threats, such as viruses, malware, or phishing attempts, and immediately quarantines any identified threats, preventing the email from being delivered to the intended recipient. The system also targets harmful attachments, isolating them to ensure they do not reach users, and safeguards against malicious links by identifying and safeguarding them (e.g., blocking, wrapping, checking, etc.) before they can be clicked. If an email is deemed not to be a security threat, it is safely delivered to the intended recipient, ensuring seamless and secure internal communication.
Owner:OPEN TEXT CORPORATION

Network security system driven by artificial intelligence

The invention discloses a network security system driven by artificial intelligence. The network security system is designed to detect, analyze and relieve wide network threats in real time. The network security system comprises a data receiving module which is responsible for gathering diversified data types, including images from various sources, text content and URLs (Uniform Resource Locator). The AI analysis module processes the received data using image recognition, optical character recognition, and semantic analysis, and identifies potential threats, such as phishing attacks, fraud, and propagation of malicious content. And a link analysis module evaluates the security of the URL through the dynamic white list and black list, and performs AI-based evaluation on unknown links. The audio interface expands threat detection to audio-based communication, integrates voice-to-text and text-to-voice functions, and enables the system to analyze fraud or malicious intentions that may exist in a telephone call.
Owner:ECCOM INTELLIGENCE CO LTD +1

A machine learning architecture for malicious domain detection and phishing prevention

Presented are apparatus, systems and methods for more secure online interactions from computing devices, including protections of sensitive identity, personal, employer, membership, financial and payments information; from the increasing waves of hacking, and relentless bombardment of phishing attacks; with ever more sophisticated social-engineering, which are increasingly indistinguishable from interactions with a genuine online connection. In one example, the computing device can store a data structure in a first application, the data structure comprising a set of sensitive-attribute data, and an identification of a plurality of predefined or otherwise known hosts, from a list of known remote hosts. The computing-device / local-host can execute a second application to locally render a remote internet resource, such as a web page, which may additionally request the input of one or more sensitive-attribute data entry fields. Responsive to receiving a uniform resource identifier (URI) (from an eMail, Text, scanned QR code, Hyperlink, Browser App or other), the computing device executes a first application to identify and analyze the URI, generate a plurality of first features comprising an identity of a remote host of the web-site page, compare the identity of the remote host to the identification of the plurality of known remote hosts, execute a heuristic algorithm or machine learning model, on the local host, to generate a source and content risk-score, of the remote host and the web page it conveys. The execution therebefore described can thus aid the computing device to more intelligently decide to: permit, restrict, or modify data generation methods in an auto-population entry of the one or more sensitive-attribute data entry fields, including but not limited to: selecting a payment information generation method for such data fields, based on risk analysis of said uniform resource identifier. This embodiment of the present disclosure can improve the ability of said computing device and said device user to more-immediately and objectively: identify, avoid, or manage; phishing and hacking attacks, versus those from legitimate or reputationally-sound remote hosts.
Owner:CARDWARE INC

Defensive multi-factor authentication against phishing

Techniques are disclosed that relate to detecting and preventing phishing attacks (e.g., man-in-the-middle attacks) related to multi-factor authentication (MFA) or two-factor authentication (2FA) processes. A system is described that determines whether to allow or deny a subsequent authentication step based on a trust level determined between a computing device that made an initial authentication request to a service computer system and a computing device (e.g., a mobile device) that is required to perform the subsequent authentication step (e.g., a 2FA authentication step). The computing device associated with the subsequent authentication step evaluates the trust between the devices and determines whether to allow or deny the subsequent authentication step. The techniques of the present disclosure enhance the security of computer systems against phishing attacks while maintaining a satisfactory user experience for legitimate users.
Owner:PAYPAL INC

Method for detecting a vulnerability to a phishing attack in a computer system.

The present invention relates to a method for detecting a vulnerability to a phishing attack in a computer system, characterized in that it comprises the implementation, by data processing means (11) of a server (1) of said computer system, of the steps of: Obtaining at least a first computer message of a phishing attempt, said first computer message comprising original personalization data; Generation of a second computer message corresponding to the first computer message in which said original personalization data has been anonymized;Generation of a third computer message corresponding to the second computer message in which new personalization data has been introduced for at least one user of said computer system, said target user, based on targeting data of said computer system, stored in data storage means (12) of said server (1); Issuance of said third computer message to said target user so as to simulate a phishing attack; Detection of at least one reaction to said third computer message implemented by said target user in said computer system [Fig. 1];
Owner:AAIS - ARMAGEDDON ARTIFICIAL INTELLIGENCE SECURITY

Machine learning architecture for malicious domain detection and phishing prevention

Presented are apparatus, systems and methods for more secure online interactions from computing devices, including protections of sensitive identity, personal, employer, membership, financial and payments information; from the increasing waves of hacking, and relentless bombardment of phishing attacks; with ever more sophisticated social-engineering, which are increasingly indistinguishable from interactions with a genuine online connection.In one example, the computing device can store a data structure in a first application, the data structure comprising a set of sensitive-attribute data, and an identification of a plurality of predefined or otherwise known hosts, from a list of known remote hosts. The computing-device / local-host can execute a second application to locally render a remote internet resource, such as a web page, which may additionally request the input of one or more sensitive-attribute data entry fields.Responsive to receiving a uniform resource identifier (URI) (from an eMail, Text, scanned QR code, Hyperlink, Browser App or other), the computing device executes a first application to identify and analyze the URI, generate a plurality of first features comprising an identity of a remote host of the web-site page, compare the identity of the remote host to the identification of the plurality of known remote hosts, execute a heuristic algorithm or machine learning model, on the local host, to generate a source and content risk-score, of the remote host and the web page it conveys. The execution therebefore described can thus aid the computing device to more intelligently decide to: permit, restrict, or modify data generation methods in an auto-population entry of the one or more sensitive-attribute data entry fields, including but not limited to: selecting a payment information generation method for such data fields, based on risk analysis of said uniform resource identifier. This embodiment of the present disclosure can improve the ability of said computing device and said device user to more-immediately and objectively: identify, avoid, or manage; phishing and hacking attacks, versus those from legitimate or reputationally-sound remote hosts.
Owner:CARDWARE INC

Systems and methods for detecting a phishing domain in a domain name system (DNS) record set

This document describes a system and method for detecting phishing domains used by cyber attackers to conduct phishing attacks in a Domain Name System (DNS) record set, the system including a homograph phishing domain detection module, a typosquatting phishing domain detection module, a general phishing domain detection module, and an alert module. These modules are configured to use a combination of homograph, typosquatting, and general phishing domain techniques to collaboratively detect and identify phishing domains from a DNS record set. Subsequently, the alert module can be used to correlate alerts from the various phishing detection modules to discover phishing activity occurring in DNS network data.
Owner:ENSIGN INFOSECURITY PTE LTD

Systems, devices, articles, and methods for protection from phishing attacks

Embodiments of the present disclosure relate to systems, devices, articles, and methods providing protection against phishing and thereby protecting sensitive information of a user or organization. The system receives a user request and document object model from a user interface device comprising details of the webpages. The system checks if the webpage contains a first part characterized by an input field to enter sensitive information and obscures the first part on the webpage if present. The system renders or displays the remaining part of the webpage.
Owner:STINGRAY SECURITY LTD

Phishing document deobfuscation and feature extraction method and its application in attack detection

The application discloses a method for de-obfuscation and feature extraction of phishing documents and application thereof in attack detection, wherein the de-obfuscation comprises obtaining obfuscated macro code of the phishing document, constructing a hint engineering template by using a pre-trained language model, analyzing an obfuscated logic structure and generating de-obfuscation rules and restoration strategies; the obfuscated macro code is structured into an abstract syntax tree by using an analysis tool, typical obfuscated patterns are matched based on a regular expression, function execution simulation and cell reference analysis are combined, preliminary restoration of the structure, restoration of control flow semantics and operation path construction are realized; according to the de-obfuscation rules and the abstract syntax tree, the obfuscated structure is converted into readable macro statements, a macro code instruction sequence without obfuscated semantics is generated, and a semantic sequence after de-obfuscation is output. The feature extraction comprises extraction of word features, Token features, abstract syntax tree features and relationship features. The application breaks through the bottleneck of traditional phishing attack detection and difficulty in identification of obfuscated documents, and improves the detection accuracy of phishing document attacks.
Owner:GUIZHOU UNIV

Prevention of man-in-the-middle phishing

Techniques for prevention of man-in-the-middle phishing are disclosed. In some embodiments, a system / process / computer program product for prevention of man-in-the-middle (MitM) phishing includes monitoring a session, wherein the session includes a request to access a website; evaluating a payload associated with the request to access the website using a MitM phishing profile to determine that the request to access the website matches at least in part the MitM phishing profile; and performing a remedial action in response to determining that the payload is associated with MitM phishing activity.
Owner:PALO ALTO NETWORKS INC

Methods and systems for identifying potentially harmful misdirection by URLS to thwart malicious phishing attacks

PCT designated stageWO2025259908A1Character and pattern recognitionSecuring communicationWeb siteInternet users
Methods and systems for identifying potentially harmful misdirection to a malicious URL to thwart a malicious phishing attack. The methods and systems capture an image of a target URL of a high-risk website and analyze the captured image to compare the apparent meaning of the captured image to a set of known URLs. Differences between the captured image and the known URLs are calculated based on a zone of familiarity for an Internet user calculated on prior computer activity of the user and a departure of the target URL from the zone of familiarity. The method and system identify whether the target URL is a potentially malicious URL based on the calculated difference. A warning is generated if the target URL is identified as a potentially malicious URL.
Owner:THE TRUSTEES OF INDIANA UNIV

Snapshot for activity detection and threat analysis

Embodiments of the technology described herein identify and mitigate phishing attempts by analyzing user input using a client-side proxy component and a proxy server. Embodiments disclosed herein provide systems, methods, and computer-storage media for employing proxy server capabilities in conjunction with a snapshot capturing an image or video recording of a target action input by a user into a software application. Certain embodiments disclosed herein employ proxy server capabilities to capture a snapshot and / or screen recording based on a user authorization or approval. For example, the proxy server proactively captures the snapshot or screen recording prior to, during, and after the user performing a target action. From the snapshot, certain embodiments extract snapshot features or determine enriched-contextual event data that is used to perform a mitigation action, generate a security mitigation score, or update an administrator portal activity log for an authorized administrator.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Content-based deep learning for inline phishing detection

An inline and offline machine learning pipeline for detection of phishing attacks with a holistic, easily upgradeable framework is presented herein. A packet analyzer records capture logs of network traffic between an endpoint device and a firewall. A parser extracts inputs from the capture logs inline that it communicates to one of an inline model and an offline model for phishing detection. The inline model and offline model are neural networks with parallelizable network architectures that do not depend on handcrafted inputs. The inline model operates inline with the packet analyzer and parser and makes fast phishing attack classifications based on inputs generated from capture logs. The offline model uses additional inputs such as inputs generated from network logs to make phishing attack classifications.
Owner:PALO ALTO NETWORKS INC

Phishing detection of uncategorized URLs using heuristics and scanning

Systems and methods include obtaining a Uniform Resource Locator (URL) for a site on the Internet; analyzing the URL with a Machine Learning (ML) model to determine whether or not the site is suspicious for phishing; responsive to the URL being suspicious for phishing, loading the site to determine whether or not an associated brand of the site is legitimate or not; and, responsive to the site being not legitimate for the brand, categorizing the URL for phishing and performing a first action based thereon. The systems and methods can further include, responsive to the URL being not suspicious for phishing or the site being legitimate for the brand, categorizing the URL as legitimate and performing a second action based thereon.
Owner:ZSCALER INC

Systems and methods for preventing phishing attacks

Embodiments of the present disclosure provide systems and methods to classify webpages according to phishing risk. Embodiments combine generative AI with a knowledgebase of anti-phishing questions. To classify a webpage, the generative AI processes details from the webpage to answer the anti-phishing questions. The webpage is classified at least in part based on the results generated by the generative AI.
Owner:OPEN TEXT CORPORATION

Incremental phishing defense method based on two-dimensional code decoding and multi-modal deep learning

The invention discloses an incremental phishing defense method based on two-dimensional code decoding and multi-modal deep learning, and the method achieves the efficient decoding of batch two-dimensional codes through a two-dimensional code decoding module, employs a multi-thread processing, image preprocessing and redundant double decoding engines, guarantees the obtaining of an accurate URL in a complex scene, and achieves the high-efficiency decoding of the two-dimensional codes. The method comprises the steps that firstly, a URL obtained through decoding is input into a multi-modal deep learning detection model, the model comprises a URL input processing layer, a BERT semantic coding layer, a CNN branch, a BiLSTM branch and a feature fusion and classification layer, semantic information and a structure dependency relationship can be extracted at the same time, and finally, the semantic information and the structure dependency relationship can be extracted through an incremental learning mechanism by freezing a pre-trained BERT trunk, fine tuning a top network and combining a data playback strategy. And continuous updating and dynamic adaptation of the model are realized, so that the detection accuracy and robustness are remarkably improved. The method can be widely applied to the scenes of mail security, payment code scanning security and the like, and two-dimensional code phishing attacks are effectively defended.
Owner:ANHUI UNIV

Systems and methods for preventing phishing attacks

Embodiments of the present disclosure provide systems and methods to classify webpages according to phishing risk. Embodiments combine generative AI with a knowledgebase of anti-phishing questions. To classify a webpage, the generative AI processes details from the webpage to answer the anti-phishing questions. The webpage is classified at least in part based on the results generated by the generative AI.
Owner:OPEN TEXT CORPORATION

Systems and methods for preventing one-time password phishing

Systems and methods for preventing phishing attacks are provided. For example, the computer system includes at least one processor that is configured to recognize a uniform resource locator (URL) to which a web browser is navigating as a URL associated with a website for which phishing protection is to be provided, the recognition based on an absence of the URL from a history of visited URLs for which a user has previously visited, monitor user input into one or more data fields associated with the website, determine whether the user input into the one or more data fields includes automatically generated one-time password (OTP) information by comparing the user input against one or more OTP information characteristics, and perform a security action in response to determining user entry of OTP information.
Owner:CITRIX SYSTEMS INC

Short message service (SMS) firewall monitoring and protection systems targeting fraudulent SMS phishing attacks across telecommunication networks

Systems and methods receive a message screening subscription request to screen SMS messages from potentially fraudulent sources to reduce SMS phishing attacks, the messages to be screened by a telecommunications network via a SMS firewall protocol for a plurality of recipient telephone numbers. It is ascertained that a message is being routed to at least one telephone number of the plurality of recipient telephone numbers, and data of a transmitting source of a message is compared, using the SMS firewall protocol, to stored data of potentially fraudulent sources. Based on the source of the message matching a potentially fraudulent source of the potentially fraudulent sources, a screening action is performed for the message.
Owner:TRUIST BANK

System, device and method for protecting users against phishing email attacks

A method to protect an email user against a phishing attack is described. The method includes detecting a mouse click or a mouse hovering, from a computer mouse of the email user, of an email item on a computer desktop, determining, based on a threat intelligence data source, that the email item is associated with the phishing attack, sending, in response to said determining, a phishing indicator detection signal to a signaling mechanism attached to the computer mouse, and generating, by the signaling mechanism in response to the phishing indicator detection signal, an alert signal to the email user, wherein the email user performs a mitigation action in response to the alert signal.
Owner:SAUDI ARABIAN OIL CO

System, device and method for protecting users against phishing email attacks

A method to protect an email user against a phishing attack is described. The method includes detecting a mouse click or a mouse hovering, from a computer mouse of the email user, of an email item on a computer desktop, determining, based on a threat intelligence data source, that the email item is associated with the phishing attack, sending, in response to said determining, a phishing indicator detection signal to a signaling mechanism attached to the computer mouse, and generating, by the signaling mechanism in response to the phishing indicator detection signal, an alert signal to the email user, wherein the email user performs a mitigation action in response to the alert signal.
Owner:SAUDI ARABIAN OIL CO