Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

43 results about "Phishing detection" patented technology

Visual deep learning for inline phishing detection

Techniques for visual deep learning for inline phishing detection are disclosed. In some embodiments, a system / process / computer program product for visual deep learning for inline phishing detection includes extracting a logo from a screenshot of a web page; detecting phishing based on a match to at least one of a plurality of reference logos using a visual deep learning model and that a domain associated with the web page is not associated with an entity that matches the logo extracted from the web page; and performing a remedial action in response to determining that the web page is associated with phishing.
Owner:PALO ALTO NETWORKS INC

Advanced Cybersecurity System for Real-Time Phishing Detection, Account Takeover Fraud Prevention, and Software Repository Optimization Using Machine Learning Techniques

Systems and processes are disclosed for enhancing cybersecurity and optimizing software repositories through integration of web crawling, web scraping, feature engineering, and advanced machine learning algorithms to detect phishing attempts, prevent account takeover fraud, and identify unused code in repositories. The system collects and refines data from various sources, including transaction logs, customer databases, device details, external data sources, and historical fraud data, to build comprehensive datasets. Feature engineering creates new, meaningful features from the refined data, which are used to train and evaluate machine learning models. The best-performing models are deployed in production to monitor incoming communications and transactions in real-time, flagging suspicious activities and optimizing codebases. This processing ensures timely detection and prevention of security threats while maintaining efficient software development processes. Robust protection is provided against evolving cyber threats and enhances software performance and security through continuous learning and adaptation.
Owner:BANK OF AMERICA CORP

Lookalike Domain Phishing Detection

The present disclosure enhances domain lookalike detection by integrating a phishing risk assessment score into a multi-layered evaluation framework. The method systematically generates lookalike domains through genetic algorithms. Registered domains undergo advanced phishing analysis, incorporating domain and URL checks, technical infrastructure assessments, content inspections, and reputation-based intelligence to calculate a dynamic phishing score. A comprehensive risk score is then determined by merging phishing likelihood with business attributes, graphical / contextual similarity metrics, and domain registration patterns. Domains are categorized into predefined risk levels including phishing, registered, preventative, company-owned, or watchlist, with specific action recommendations provided for each category. The system generates prioritized alerts for high-risk domains, offering customers actionable intelligence to mitigate threats. By combining phishing-specific indicators with contextual evaluations, this solution improves detection accuracy, reduces false positives, and enables organizations to respond effectively to domain-based threats in real time, addressing evolving cybersecurity challenges.
Owner:ZSCALER INC

Method for evaluating and discovering phishing attempts in an email

PCT designated stageWO2025226915A1Securing communicationElectronic mailPhishing detection
A method of rating a phishing email's human phishing detection difficulty includes identifying cues in content of the email tending to indicate that the email is a phishing email; assigning weights to identified cues; assessing a relative severity based on the weighted cues; determining an overall human detection difficulty of the email based on the relative severity of the weighted cues and a total number of the identified cues determining a target audience for the phishing email; determining a plurality of sub-groups of the target audience; and determining a plurality of respective premise alignments of the email by characterizing respective pertinences of a message premise of the email with respect to each respective sub-group of the target audience; wherein the step of determining an overall human detection difficulty of the email is additionally based on the respective premise alignments of the email.
Owner:THE GOVERNMENT OF THE UNITED STATES OF AMERICA AS REPRESENTED BY THE SECRETARY DEPARTMENT OF HEALTH & HUMAN SERVICES

Phishing detection using page representation matching

An apparatus, system, product and method comprising: obtaining a selection of page elements of a source page that are estimated to represent a visual appearance of the source page; generating respective representations of the page elements, wherein the representation is configured to be used for acquiring a page element in different pages; obtaining a target page, wherein a user is enabled to interact with the target page; determining a visual similarity measurement between the source page and the target page, wherein the visual similarity measurement is based on a successful acquisition in the target page, of the page elements, using the respective representations; classifying the target page as a phishing attack based on the visual similarity measurement, whereby detecting the phishing attack; and performing a responsive action in response to said detecting the phishing attack.
Owner:WALKME

Systems and Methods for Detection of Phishing Webpages Through Autoencoder Techniques

One implementation is directed to a phishing detection methodology including operations of obtaining an image of a candidate phishing webpage having a login screen component, where encoder is deployed on the image resulting in the generation of a latent representation corresponding to the login screen component. The login screen component may then be classified as one of a defined set of classes by deploying a machine learning model taking the latent representation as input. Further, an additional operation may include obtaining allow / deny lists of account authentication providers for the domain of the URL of the candidate phishing webpage. Finally, a determination may be made as to whether the candidate phishing webpage is a phishing webpage when the login class assigned by the classifying machine learning model does not appear on the allow list.
Owner:CISCO TECHNOLOGY INC

Visual deep learning for inline phishing detection

Techniques for visual deep learning for inline phishing detection are disclosed. In some embodiments, a system / process / computer program product for visual deep learning for inline phishing detection includes extracting a logo from a screenshot of a web page; detecting phishing based on a match to at least one of a plurality of reference logos using a visual deep learning model and that a domain associated with the web page is not associated with an entity that matches the logo extracted from the web page; and performing a remedial action in response to determining that the web page is associated with phishing.
Owner:PALO ALTO NETWORKS INC

Systems and methods for detection of phishing webpages through autoencoder techniques

One implementation is directed to a phishing detection methodology including operations of obtaining an image of a candidate phishing webpage having a login screen component, where encoder is deployed on the image resulting in the generation of a latent representation corresponding to the login screen component. The login screen component may then be classified as one of a defined set of classes by deploying a machine learning model taking the latent representation as input. Further, an additional operation may include obtaining allow / deny lists of account authentication providers for the domain of the URL of the candidate phishing webpage. Finally, a determination may be made as to whether the candidate phishing webpage is a phishing webpage when the login class assigned by the classifying machine learning model does not appear on the allow list.
Owner:CISCO TECHNOLOGY INC

Device for recognizing context of voice phishing in real time during call and operating method thereof

The present invention relates to a real-time voice phishing detection technology utilizing an artificial intelligence-based model. The real-time voice phishing recognition device according to an embodiment may include: a voice signal collection unit for collecting a voice signal transmitted to a communication terminal in real time after setting a call; a text information extraction unit for converting the collected voice signal into text to extract text information; a voice feature information extraction unit for extracting voice feature information for the voice signal in parallel with the extraction of the text information; a risk degree calculation unit for calculating, by using a voice phishing detection model, a risk degree on the basis of the extracted text information and the extracted voice feature information; and a voice phishing detection unit for detecting voice phishing on the basis of the calculated risk degree.
Owner:SOONCHUNYANG UNIV IND ACAD COOP FOUND

Systems and methods to perform phishing detection and device attestation via browser extension

In an embodiment, a browser extension for a browser is installed at the first compute device. A first log indicating activities tracked by the browser extension as being performed at a software as a service (SaaS) application via the browser and by the user is generated. A representation of the first log is sent to a second compute device to cause the second compute device to perform cyber attestation by comparing (1) the first log and (2) a second log (a) sent to the second compute device via a third compute device associated with the SaaS application and (b) representing activities determined by the third compute device as being performed at the SaaS application via the browser and by the user.
Owner:OBSIDIAN SECURITY INC

Systems and methods to perform phishing detection and device attestation via browser extension

In an embodiment, a browser extension for a browser is installed at the first compute device. A first log indicating activities tracked by the browser extension as being performed at a software as a service (SaaS) application via the browser and by the user is generated. A representation of the first log is sent to a second compute device to cause the second compute device to perform cyber attestation by comparing (1) the first log and (2) a second log (a) sent to the second compute device via a third compute device associated with the SaaS application and (b) representing activities determined by the third compute device as being performed at the SaaS application via the browser and by the user.
Owner:OBSIDIAN SECURITY INC

Anti-phishing detection method and system based on insurance company recruitment

The invention provides an anti-phishing detection method and system based on recruitment of an insurance company, and aims to solve the problems of flooding of phishing recruitment and false recruitment information, long manual troubleshooting time, low accuracy and high labor cost in the current insurance industry. Internet multi-platform recruitment information is automatically collected, preliminarily screened and then directionally pushed to administrators of all cities through WeChat, and false information is disposed after offline verification and confirmation. According to the invention, the semi-automatic process of recruitment information from collection to disposal is realized, the anti-phishing detection efficiency and accuracy are greatly improved, the manpower consumption of enterprises is reduced, and the brand reputation of insurance companies and the rights and interests of job seekers are effectively protected.
Owner:CHINA LIFE INSURANCE CO LTD

Ethereum phishing account detection method, device and equipment

The invention provides an Ethereum phishing account detection method, device and equipment. The method comprises the following steps: carrying out effective time sequence sampling on an Ethereum transaction network by utilizing dynamic random walk; representing the sampled data as a discrete dynamic weighted directed multiple graph; image signal processing is carried out on the discrete dynamic weighted directed multiple graphs, graph signals of all the time snapshots are determined, and the graph signals comprise different dimension features of all nodes in the time snapshots; the discrete dynamic weighted directed multi-graph and the graph signal of each time snapshot are input into a pre-trained detection network for phishing detection, the phishing score of each node is determined, and the phishing score represents the probability that the corresponding node is a phishing account; and determining a phishing account in the transaction network based on the phishing score of each node. According to the Ethereum network phishing account detection method provided by the invention, the phishing account can be effectively and accurately identified and determined.
Owner:NAT UNIV OF DEFENSE TECH

An efficient cascading multi-stage adaptive threshold phishing detection method

The application discloses a kind of high-efficiency cascade multi-stage adaptive threshold phishing detection methods, for the problem of insufficient anti-robustness in existing phishing detection technology, insufficient multi-modal cooperation, detection efficiency and precision imbalance, etc., cascade multi-stage adaptive threshold phishing detection framework is proposed.The first stage is realized by light single-mode detection model to achieve millisecond-level preliminary screening, and more than 80% low-level threats are intercepted;The second stage adopts a multi-modal fusion model with strong anti-interference capability, combines frequency domain feature enhancement and dynamic noise injection technology to improve anti-robustness, and excavates deep correlation features through cross-modal attention mechanism to realize accurate identification of complex phishing attacks.Online learning module is integrated at the same time, so that the system can continuously adapt to new attack patterns, and finally achieve high-precision, low-latency, strong anti-interference detection capability.
Owner:SOUTHWEST PETROLEUM UNIV

System

To provide an environment in which a user can safely perform online activities by providing a real-time phishing fraud detection and warning system using a generative model.SOLUTION: The phishing fraud detection system includes means for analyzing the received digital information using a generative model trained using knowledge of security experts and training data obtained from specialized information sources to detect characteristics of the fraudulent activity, means for generating an alert based on the analysis, and means for providing specific safety action advice to the user.SELECTED DRAWING: Figure 1
Owner:SOFTBANK GROUP CORP

Phishing detection via grammatical artifacts

There is disclosed a method of mitigating phishing, including extracting text from a website under analysis; using a spell check algorithm to compare extracted words or phrases to a language dictionary of words or phrases selected from web pages known to be phishing targets, and using a spell counter to count misspell hits from the spell check algorithm; comparing the extracted words or phrases to a case-sensitive usage reference, and using a usage counter to count mismatched usage hits from the case-sensitive usage reference; combining the spell counter and the usage counter into a combined counter; and using the combined counter to identify the website under analysis as a suspected phishing website and taking a phishing mitigation action.
Owner:MCAFEE LLC

Phishing website detection method and system, terminal and storage medium

The invention provides a phishing website detection method and system, a terminal and a storage medium, and the method comprises the steps: carrying out the feature extraction of website sample data, and obtaining sample local features; performing context information extraction on the sample local features to obtain sample context features, and performing sparse attention mechanism calculation on the sample context features to obtain attention sample features; constructing a meta-feature matrix according to the attention sample features and a base learner; performing dynamic attention weighting on the meta-feature matrix to obtain a meta-weighted matrix, and inputting the meta-weighted matrix into a meta-learner for training until the meta-learner converges; and inputting to-be-detected website data into the converged meta-learner for phishing detection to obtain a phishing website detection result. According to the embodiment of the invention, the dynamic attention weighting is carried out on the meta-feature matrix, so that the extraction of key features in the meta-feature matrix by the meta-learner is improved, the accuracy of the meta-learner is improved, and the accuracy of phishing website detection is further improved.
Owner:NANCHANG UNIV

Two-dimensional code phishing detection method and device

The invention discloses a two-dimensional code phishing detection method and device, relates to the technical field of network security, and mainly aims to reduce the hysteresis of two-dimensional code phishing detection. According to the main technical scheme, the method comprises the following steps: performing feature extraction processing on a data object carrying a two-dimensional code to obtain at least one type of intention feature data related to the intention of the data object; performing intention analysis based on the at least one intention feature data to obtain intention data of the data object, the intention data being related to an induction degree of the data object to induce a user to scan a two-dimensional code; feature extraction processing is carried out on a target object pointed by the two-dimensional code to obtain object feature data of the target object, and the object feature data is related to the malicious degree of the target object; and detecting whether the two-dimensional code is a phishing two-dimensional code for phishing attack based on the intention data and the object feature data.
Owner:QI AN XIN TECHNOLOGY GROUP INC

Systems and methods for detecting a phishing domain in a domain name system (DNS) record set

This document describes a system and method for detecting phishing domains used by cyber attackers to conduct phishing attacks in a Domain Name System (DNS) record set, the system including a homograph phishing domain detection module, a typosquatting phishing domain detection module, a general phishing domain detection module, and an alert module. These modules are configured to use a combination of homograph, typosquatting, and general phishing domain techniques to collaboratively detect and identify phishing domains from a DNS record set. Subsequently, the alert module can be used to correlate alerts from the various phishing detection modules to discover phishing activity occurring in DNS network data.
Owner:ENSIGN INFOSECURITY PTE LTD

Snapshot phishing detection and threat analysis

Embodiments of the technology described herein identify and mitigate phishing attempts by analyzing user input received at the operating system level. Initially, a credential, such as a username or password, is registered with the threat detection system. The technology described herein intercepts user input at the operating system level, generates a hash of the input, and compares it with a hash of a credential being monitored. The technology described herein will perform a threat assessment when a secret entry is detected. The threat assessment may use the application context and the network context as inputs to the assessment. When the threat assessment results in an unknown classification or when the snapshot is otherwise requested, a snapshot is captured to supplement the threat assessment. Based on user settings, the snapshot is consumed by a snapshot phishing machine learning model. Various mitigation actions may be taken when a threat is detected.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Detection of site phishing using neural network-enabled site image analysis leveraging few-shot learning

Website phishing detection is enabled using a siamese neural network. One twin receives a query image associated with a website page. The other twin receives a subset of a set of reference website images together with positive (phishing) examples that were used to train the networks, the subset of reference website images having been determined by applying an identifier associated with a brand of interest. The operation of applying the identifier significantly reduces the relevant search space for the inferencing task. If the inferencing determines a sufficient likelihood that the website page is a phishing page, control signaling is generated to control a system to take a given mitigation action.
Owner:AKAMAI TECHNOLOGIES INC

Phishing detection of visually similar login pages

This application is directed to systems and methods for detecting phishing attempts in a user application. In some embodiments, a disclosed method includes extracting from an incoming message a uniform resource identifier (URI) for identifying a resource on a computer network, generating a screenshot image of the resource identified by the URI, applying a phishing detection model to process the screenshot image and generate a phishing indicator representing a confidence level of determining that the resource would cause a phishing attack, and in accordance with a determination that the phishing indicator satisfies an alert condition, reporting via an alert message that the URI extracted from the incoming message corresponds to the phishing attack. In some embodiments, the alert condition includes a confidence threshold, and requires that the alert message be generated and reported in accordance with a determination that the phishing indicator is greater than the confidence threshold.
Owner:WALMART APOLLO LLC

Content-based deep learning for inline phishing detection

An inline and offline machine learning pipeline for detection of phishing attacks with a holistic, easily upgradeable framework is presented herein. A packet analyzer records capture logs of network traffic between an endpoint device and a firewall. A parser extracts inputs from the capture logs inline that it communicates to one of an inline model and an offline model for phishing detection. The inline model and offline model are neural networks with parallelizable network architectures that do not depend on handcrafted inputs. The inline model operates inline with the packet analyzer and parser and makes fast phishing attack classifications based on inputs generated from capture logs. The offline model uses additional inputs such as inputs generated from network logs to make phishing attack classifications.
Owner:PALO ALTO NETWORKS INC

Phishing mail detection method and device, storage medium and equipment

The invention discloses a phishing mail detection method and device, a storage medium and equipment, and relates to the field of network security, and the method comprises the steps: obtaining a mail file uploaded by authorized security gateway equipment, forwarding the mail file to a phishing mail detection model for phishing mail detection, and obtaining a phishing detection result of the phishing mail detection model; if the phishing detection result represents that a phishing mail risk exists, performing mail protection operation on a phishing mail and a corresponding target security gateway device according to the risk level of the phishing mail risk; and synchronizing the risk indication information of the phishing mail risk to a security local library of all authorized security gateway devices so as to call a device security program to delete risk data related to the phishing mail. According to the invention, the security protection capability of the mail system can be enhanced, and sharing and collaborative protection of security information are realized.
Owner:SANGFOR TECH INC

Phishing detection method and device, computer device and storage medium

The application discloses a fishing detection method and device, computer equipment and a storage medium, and the method comprises the following steps: obtaining a target detection frame comprising a pedestrian and a fishing rod; performing fishing behavior identification on the target detection frame through a fishing behavior detection model, and outputting a first result of an identification result being "fishing behavior"; performing fishing behavior identification on the target detection frame through a human body fishing rod key point detection model, and outputting a second result of the identification result being "fishing behavior"; and voting the first result and the second result to output a final identification result. The fishing detection method provided by the application can detect and manage the behavior of stealing a fishing rod in a day and night scene for 24 hours a day, can greatly save labor costs, can identify illegal fishing behavior in a large water area for 24 hours a day at low cost, improves the management level of water areas where fishing is prohibited, and improves the detection accuracy by voting the mean value of the first result and the second result to output the final identification result.
Owner:SHENZHEN INTELLIFUSION TECHNOLOGIES CO LTD

Phishing detection of uncategorized URLs using heuristics and scanning

Systems and methods include obtaining a Uniform Resource Locator (URL) for a site on the Internet; analyzing the URL with a Machine Learning (ML) model to determine whether or not the site is suspicious for phishing; responsive to the URL being suspicious for phishing, loading the site to determine whether or not an associated brand of the site is legitimate or not; and, responsive to the site being not legitimate for the brand, categorizing the URL for phishing and performing a first action based thereon. The systems and methods can further include, responsive to the URL being not suspicious for phishing or the site being legitimate for the brand, categorizing the URL as legitimate and performing a second action based thereon.
Owner:ZSCALER INC

Real-time detection of site phishing using Message Passing Neural Networks (MPNN) on directed graphs

Website phishing detection is enabled using a Message Passing Neural Network (MPNN) that scores requested HTML with a likelihood of being a phishing website. The technique leverages the assumption that the HTML in a phishing website often presents anomalous structure or features when compared with an analogous benign website. Once a phishing site is detected, a given mitigation action is then taken.
Owner:AKAMAI TECHNOLOGIES INC

Quick-response code phishing detection with in-browser remediation

A web browser quick-response (QR) code filter (QR code filter) intercepts and scans Hypertext Transfer Protocol (HTTP) responses corresponding to web pages that are intended for a web browser. The QR code filter scans the HTTP responses for QR codes, and for each detected QR code, decodes the QR code to identify a uniform resource locator (URL) for the web page to which the QR code redirects. A rendering engine renders the web page corresponding to the URL in an isolated environment. The QR code filter then analyzes the rendering and additional characteristics of the QR code to determine whether the QR code is malicious and, for malicious QR codes, determines remediation actions to perform.
Owner:PALO ALTO NETWORKS INC