Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

31 results about "Phishing detection" patented technology

Visual deep learning for inline phishing detection

Techniques for visual deep learning for inline phishing detection are disclosed. In some embodiments, a system / process / computer program product for visual deep learning for inline phishing detection includes extracting a logo from a screenshot of a web page; detecting phishing based on a match to at least one of a plurality of reference logos using a visual deep learning model and that a domain associated with the web page is not associated with an entity that matches the logo extracted from the web page; and performing a remedial action in response to determining that the web page is associated with phishing.
Owner:PALO ALTO NETWORKS INC

Advanced Cybersecurity System for Real-Time Phishing Detection, Account Takeover Fraud Prevention, and Software Repository Optimization Using Machine Learning Techniques

Systems and processes are disclosed for enhancing cybersecurity and optimizing software repositories through integration of web crawling, web scraping, feature engineering, and advanced machine learning algorithms to detect phishing attempts, prevent account takeover fraud, and identify unused code in repositories. The system collects and refines data from various sources, including transaction logs, customer databases, device details, external data sources, and historical fraud data, to build comprehensive datasets. Feature engineering creates new, meaningful features from the refined data, which are used to train and evaluate machine learning models. The best-performing models are deployed in production to monitor incoming communications and transactions in real-time, flagging suspicious activities and optimizing codebases. This processing ensures timely detection and prevention of security threats while maintaining efficient software development processes. Robust protection is provided against evolving cyber threats and enhances software performance and security through continuous learning and adaptation.
Owner:BANK OF AMERICA CORP

Lookalike Domain Phishing Detection

The present disclosure enhances domain lookalike detection by integrating a phishing risk assessment score into a multi-layered evaluation framework. The method systematically generates lookalike domains through genetic algorithms. Registered domains undergo advanced phishing analysis, incorporating domain and URL checks, technical infrastructure assessments, content inspections, and reputation-based intelligence to calculate a dynamic phishing score. A comprehensive risk score is then determined by merging phishing likelihood with business attributes, graphical / contextual similarity metrics, and domain registration patterns. Domains are categorized into predefined risk levels including phishing, registered, preventative, company-owned, or watchlist, with specific action recommendations provided for each category. The system generates prioritized alerts for high-risk domains, offering customers actionable intelligence to mitigate threats. By combining phishing-specific indicators with contextual evaluations, this solution improves detection accuracy, reduces false positives, and enables organizations to respond effectively to domain-based threats in real time, addressing evolving cybersecurity challenges.
Owner:ZSCALER INC

Method for evaluating and discovering phishing attempts in an email

PCT designated stageWO2025226915A1Securing communicationElectronic mailPhishing detection
A method of rating a phishing email's human phishing detection difficulty includes identifying cues in content of the email tending to indicate that the email is a phishing email; assigning weights to identified cues; assessing a relative severity based on the weighted cues; determining an overall human detection difficulty of the email based on the relative severity of the weighted cues and a total number of the identified cues determining a target audience for the phishing email; determining a plurality of sub-groups of the target audience; and determining a plurality of respective premise alignments of the email by characterizing respective pertinences of a message premise of the email with respect to each respective sub-group of the target audience; wherein the step of determining an overall human detection difficulty of the email is additionally based on the respective premise alignments of the email.
Owner:THE GOVERNMENT OF THE UNITED STATES OF AMERICA AS REPRESENTED BY THE SECRETARY DEPARTMENT OF HEALTH & HUMAN SERVICES

Phishing detection using page representation matching

An apparatus, system, product and method comprising: obtaining a selection of page elements of a source page that are estimated to represent a visual appearance of the source page; generating respective representations of the page elements, wherein the representation is configured to be used for acquiring a page element in different pages; obtaining a target page, wherein a user is enabled to interact with the target page; determining a visual similarity measurement between the source page and the target page, wherein the visual similarity measurement is based on a successful acquisition in the target page, of the page elements, using the respective representations; classifying the target page as a phishing attack based on the visual similarity measurement, whereby detecting the phishing attack; and performing a responsive action in response to said detecting the phishing attack.
Owner:WALKME

Systems and Methods for Detection of Phishing Webpages Through Autoencoder Techniques

One implementation is directed to a phishing detection methodology including operations of obtaining an image of a candidate phishing webpage having a login screen component, where encoder is deployed on the image resulting in the generation of a latent representation corresponding to the login screen component. The login screen component may then be classified as one of a defined set of classes by deploying a machine learning model taking the latent representation as input. Further, an additional operation may include obtaining allow / deny lists of account authentication providers for the domain of the URL of the candidate phishing webpage. Finally, a determination may be made as to whether the candidate phishing webpage is a phishing webpage when the login class assigned by the classifying machine learning model does not appear on the allow list.
Owner:CISCO TECHNOLOGY INC

Visual deep learning for inline phishing detection

Techniques for visual deep learning for inline phishing detection are disclosed. In some embodiments, a system / process / computer program product for visual deep learning for inline phishing detection includes extracting a logo from a screenshot of a web page; detecting phishing based on a match to at least one of a plurality of reference logos using a visual deep learning model and that a domain associated with the web page is not associated with an entity that matches the logo extracted from the web page; and performing a remedial action in response to determining that the web page is associated with phishing.
Owner:PALO ALTO NETWORKS INC

Systems and methods for detection of phishing webpages through autoencoder techniques

One implementation is directed to a phishing detection methodology including operations of obtaining an image of a candidate phishing webpage having a login screen component, where encoder is deployed on the image resulting in the generation of a latent representation corresponding to the login screen component. The login screen component may then be classified as one of a defined set of classes by deploying a machine learning model taking the latent representation as input. Further, an additional operation may include obtaining allow / deny lists of account authentication providers for the domain of the URL of the candidate phishing webpage. Finally, a determination may be made as to whether the candidate phishing webpage is a phishing webpage when the login class assigned by the classifying machine learning model does not appear on the allow list.
Owner:CISCO TECHNOLOGY INC

Systems and methods to perform phishing detection and device attestation via browser extension

In an embodiment, a browser extension for a browser is installed at the first compute device. A first log indicating activities tracked by the browser extension as being performed at a software as a service (SaaS) application via the browser and by the user is generated. A representation of the first log is sent to a second compute device to cause the second compute device to perform cyber attestation by comparing (1) the first log and (2) a second log (a) sent to the second compute device via a third compute device associated with the SaaS application and (b) representing activities determined by the third compute device as being performed at the SaaS application via the browser and by the user.
Owner:OBSIDIAN SECURITY INC

Anti-phishing detection method and system based on insurance company recruitment

The invention provides an anti-phishing detection method and system based on recruitment of an insurance company, and aims to solve the problems of flooding of phishing recruitment and false recruitment information, long manual troubleshooting time, low accuracy and high labor cost in the current insurance industry. Internet multi-platform recruitment information is automatically collected, preliminarily screened and then directionally pushed to administrators of all cities through WeChat, and false information is disposed after offline verification and confirmation. According to the invention, the semi-automatic process of recruitment information from collection to disposal is realized, the anti-phishing detection efficiency and accuracy are greatly improved, the manpower consumption of enterprises is reduced, and the brand reputation of insurance companies and the rights and interests of job seekers are effectively protected.
Owner:CHINA LIFE INSURANCE CO LTD

An efficient cascading multi-stage adaptive threshold phishing detection method

The application discloses a kind of high-efficiency cascade multi-stage adaptive threshold phishing detection methods, for the problem of insufficient anti-robustness in existing phishing detection technology, insufficient multi-modal cooperation, detection efficiency and precision imbalance, etc., cascade multi-stage adaptive threshold phishing detection framework is proposed.The first stage is realized by light single-mode detection model to achieve millisecond-level preliminary screening, and more than 80% low-level threats are intercepted;The second stage adopts a multi-modal fusion model with strong anti-interference capability, combines frequency domain feature enhancement and dynamic noise injection technology to improve anti-robustness, and excavates deep correlation features through cross-modal attention mechanism to realize accurate identification of complex phishing attacks.Online learning module is integrated at the same time, so that the system can continuously adapt to new attack patterns, and finally achieve high-precision, low-latency, strong anti-interference detection capability.
Owner:SOUTHWEST PETROLEUM UNIV

System

To provide an environment in which a user can safely perform online activities by providing a real-time phishing fraud detection and warning system using a generative model.SOLUTION: The phishing fraud detection system includes means for analyzing the received digital information using a generative model trained using knowledge of security experts and training data obtained from specialized information sources to detect characteristics of the fraudulent activity, means for generating an alert based on the analysis, and means for providing specific safety action advice to the user.SELECTED DRAWING: Figure 1
Owner:SOFTBANK GROUP CORP

Systems and methods for detecting a phishing domain in a domain name system (DNS) record set

This document describes a system and method for detecting phishing domains used by cyber attackers to conduct phishing attacks in a Domain Name System (DNS) record set, the system including a homograph phishing domain detection module, a typosquatting phishing domain detection module, a general phishing domain detection module, and an alert module. These modules are configured to use a combination of homograph, typosquatting, and general phishing domain techniques to collaboratively detect and identify phishing domains from a DNS record set. Subsequently, the alert module can be used to correlate alerts from the various phishing detection modules to discover phishing activity occurring in DNS network data.
Owner:ENSIGN INFOSECURITY PTE LTD

Content-based deep learning for inline phishing detection

An inline and offline machine learning pipeline for detection of phishing attacks with a holistic, easily upgradeable framework is presented herein. A packet analyzer records capture logs of network traffic between an endpoint device and a firewall. A parser extracts inputs from the capture logs inline that it communicates to one of an inline model and an offline model for phishing detection. The inline model and offline model are neural networks with parallelizable network architectures that do not depend on handcrafted inputs. The inline model operates inline with the packet analyzer and parser and makes fast phishing attack classifications based on inputs generated from capture logs. The offline model uses additional inputs such as inputs generated from network logs to make phishing attack classifications.
Owner:PALO ALTO NETWORKS INC

Phishing mail detection method and device, storage medium and equipment

The invention discloses a phishing mail detection method and device, a storage medium and equipment, and relates to the field of network security, and the method comprises the steps: obtaining a mail file uploaded by authorized security gateway equipment, forwarding the mail file to a phishing mail detection model for phishing mail detection, and obtaining a phishing detection result of the phishing mail detection model; if the phishing detection result represents that a phishing mail risk exists, performing mail protection operation on a phishing mail and a corresponding target security gateway device according to the risk level of the phishing mail risk; and synchronizing the risk indication information of the phishing mail risk to a security local library of all authorized security gateway devices so as to call a device security program to delete risk data related to the phishing mail. According to the invention, the security protection capability of the mail system can be enhanced, and sharing and collaborative protection of security information are realized.
Owner:SANGFOR TECH INC

Phishing detection of uncategorized URLs using heuristics and scanning

Systems and methods include obtaining a Uniform Resource Locator (URL) for a site on the Internet; analyzing the URL with a Machine Learning (ML) model to determine whether or not the site is suspicious for phishing; responsive to the URL being suspicious for phishing, loading the site to determine whether or not an associated brand of the site is legitimate or not; and, responsive to the site being not legitimate for the brand, categorizing the URL for phishing and performing a first action based thereon. The systems and methods can further include, responsive to the URL being not suspicious for phishing or the site being legitimate for the brand, categorizing the URL as legitimate and performing a second action based thereon.
Owner:ZSCALER INC

Real-time detection of site phishing using Message Passing Neural Networks (MPNN) on directed graphs

Website phishing detection is enabled using a Message Passing Neural Network (MPNN) that scores requested HTML with a likelihood of being a phishing website. The technique leverages the assumption that the HTML in a phishing website often presents anomalous structure or features when compared with an analogous benign website. Once a phishing site is detected, a given mitigation action is then taken.
Owner:AKAMAI TECHNOLOGIES INC

Quick-response code phishing detection with in-browser remediation

A web browser quick-response (QR) code filter (QR code filter) intercepts and scans Hypertext Transfer Protocol (HTTP) responses corresponding to web pages that are intended for a web browser. The QR code filter scans the HTTP responses for QR codes, and for each detected QR code, decodes the QR code to identify a uniform resource locator (URL) for the web page to which the QR code redirects. A rendering engine renders the web page corresponding to the URL in an isolated environment. The QR code filter then analyzes the rendering and additional characteristics of the QR code to determine whether the QR code is malicious and, for malicious QR codes, determines remediation actions to perform.
Owner:PALO ALTO NETWORKS INC

Technology for phishing awareness and phishing detection

PendingUS20260154420A1Hardware monitoringDigital data authenticationSpear phishingData set
The present disclosure is directed to training email users to enhance awareness of attempted spear phishing by attackers observing user actions to build a model of user susceptibilities using a trained LLM. A service in an intrusion prevention system can receive from one or more accounts linked to an enterprise and provide a message, along with a prompt to the LLM, stimulating the generation of one or more variants of the received messages that exhibit similar content characteristics. The LLM can produce a set of variant messages encompassing these content characteristics, purposefully including one or more phishing traits identified during training with the prelabeled dataset. These variant messages are then transmitted to the relevant accounts to assess interactions with the set. Based on the interactions observed across the accounts, an interaction score is generated to evaluate the efficacy of the user's training to avoid phishing attempts within the enterprise environment.
Owner:CISCO TECHNOLOGY INC

Phishing detection of visually similar login pages

This application is directed to systems and methods for detecting phishing attempts in a user application. In some embodiments, a disclosed method includes extracting from an incoming message a uniform resource identifier (URI) for identifying a resource on a computer network, generating a screenshot image of the resource identified by the URI, applying a phishing detection model to process the screenshot image and generate a phishing indicator representing a confidence level of determining that the resource would cause a phishing attack, and in accordance with a determination that the phishing indicator satisfies an alert condition, reporting via an alert message that the URI extracted from the incoming message corresponds to the phishing attack. In some embodiments, the alert condition includes a confidence threshold, and requires that the alert message be generated and reported in accordance with a determination that the phishing indicator is greater than the confidence threshold.
Owner:WALMART APOLLO LLC

Systems and methods for detection of phishing webpages through autoencoder techniques

One implementation is directed to a phishing detection methodology including operations of obtaining an image of a candidate phishing webpage having a login screen component, where encoder is deployed on the image resulting in the generation of a latent representation corresponding to the login screen component. The login screen component may then be classified as one of a defined set of classes by deploying a machine learning model taking the latent representation as input. Further, an additional operation may include obtaining allow / deny lists of account authentication providers for the domain of the URL of the candidate phishing webpage. Finally, a determination may be made as to whether the candidate phishing webpage is a phishing webpage when the login class assigned by the classifying machine learning model does not appear on the allow list.
Owner:CISCO TECHNOLOGY INC

Advanced cybersecurity system for real-time phishing detection, account takeover fraud prevention, and software repository optimization using machine learning techniques

Systems and processes are disclosed for enhancing cybersecurity and optimizing software repositories through integration of web crawling, web scraping, feature engineering, and advanced machine learning algorithms to detect phishing attempts, prevent account takeover fraud, and identify unused code in repositories. The system collects and refines data from various sources, including transaction logs, customer databases, device details, external data sources, and historical fraud data, to build comprehensive datasets. Feature engineering creates new, meaningful features from the refined data, which are used to train and evaluate machine learning models. The best-performing models are deployed in production to monitor incoming communications and transactions in real-time, flagging suspicious activities and optimizing codebases. This processing ensures timely detection and prevention of security threats while maintaining efficient software development processes. Robust protection is provided against evolving cyber threats and enhances software performance and security through continuous learning and adaptation.
Owner:BANK OF AMERICA CORP

Application identification for phishing detection

Techniques for application identification for phishing detection are disclosed. In some embodiments, a system / process / computer program product for application identification for phishing detection includes monitoring network activities associated with a session, detecting a request to access a site, determining an advanced application identification associated with the site, and identifying the site as a phishing site based on the advanced application identification.
Owner:PALO ALTO NETWORKS INC

Adaptive AI-Driven Phishing Detection Device with Linguistic Deception and Voice-Spoof Analysis

ActiveGB6489944SAcousticsSpeech sound
Adaptive AI-Driven Phishing Detection Device with Linguistic Deception and Voice-Spoof Analysis
Owner:HAMED TAHERDOOST +1

Technology for phishing awareness and phishing detection

The present disclosure is directed to training email users to enhance awareness of attempted spear phishing by attackers observing user actions to build a model of user susceptibilities using a trained LLM. A service in an intrusion prevention system can receive from one or more accounts linked to an enterprise and provide a message, along with a prompt to the LLM, stimulating the generation of one or more variants of the received messages that exhibit similar content characteristics. The LLM can produce a set of variant messages encompassing these content characteristics, purposefully including one or more phishing traits identified during training with the prelabeled dataset. These variant messages are then transmitted to the relevant accounts to assess interactions with the set. Based on the interactions observed across the accounts, an interaction score is generated to evaluate the efficacy of the user's training to avoid phishing attempts within the enterprise environment.
Owner:CISCO TECHNOLOGY INC

Detection method and system for mobile terminal-oriented customized deceptive phishing website

The invention provides a detection method and system for a mobile terminal customized deceptive phishing website, and relates to the technical field of network security and mobile terminal artificial intelligence. The method comprises the following steps: segmenting to-be-detected URL data obtained in real time by adopting a word segmentation and structure combination embedding representation method, and performing structure marking to obtain a URL embedding matrix; performing real-time detection on the URL embedding matrix through a customized fraudulent phishing detection model obtained through multi-branch semi-supervised integrated distillation strategy training to obtain a phishing detection result of the to-be-detected URL data; based on a concept drift detection mechanism, if a phishing detection result is suspicious, the result is fed back to a cloud data pool, a detection model is updated according to the drift degree and is redeployed locally, and thus the reliability and stability of the detection result are maintained. The method aims at solving the problems that an existing phishing website detection technology is poor in adaptability, insufficient in detection precision, difficult in mobile terminal deployment, unstable in model and the like.
Owner:NORTHEASTERN UNIV CHINA

An Ethereum network phishing detection method, system, electronic device and medium

The application provides an Ethereum network phishing detection method, system, electronic equipment and medium, and belongs to the field of network security.The Ethereum network phishing detection method comprises the following steps: obtaining transaction records in an Ethereum; each transaction record comprises an account and a transaction relationship between accounts; a transaction graph is constructed according to the transaction records, with account nodes and transaction relationships as edges; initial features of each node in the transaction graph are extracted; final features of each node in the transaction graph are determined based on a feature learning model according to the transaction graph and the initial features of each node; the feature learning model comprises a first graph convolutional network, a conditional random field and a second graph convolutional network connected in sequence; the categories of each node are determined based on a classification model according to the final features of each node; and the category of each node is a phishing account or a non-phishing account. By combining a graph convolutional network and a conditional random field, a network phishing account on the Ethereum can be effectively identified.
Owner:INNER MONGOLIA UNIVERSITY