Phishing Detection via LSTM URL Pattern Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional phishing detection systems face challenges in identifying and blocking phishing URLs in real-time, as they often rely on blacklists that are not updated quickly enough, and webpage content analysis can be time-consuming, allowing phishing attacks to go undetected until after they have completed.

Innovation Solution

The use of a machine learning process, specifically a long short-term memory (LSTM) network-based phishing system that generates synthetic phishing URLs and adjusts detection systems to recognize patterns that allow phishing URLs to bypass traditional detection, enhancing both phishing attacks and detection capabilities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If conventional phishing detection systems use blacklists and webpage content analysis, then they can identify phishing URLs, but the detection process is too slow and allows phishing attacks to complete before detection

Engineering Contradiction:
Improvephishing detection accuracyVSAvoiddetection time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent extracts and analyzes only the URL string itself without requiring full webpage content analysis. By focusing detection on URL patterns, characteristics, and components rather than complete webpage rendering and analysis, the system achieves fast detection while maintaining accuracy in identifying phishing attempts

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system performs preliminary analysis of URL patterns and characteristics before phishing attacks can complete. By pre-establishing detection rules and analyzing URL structures in advance, the system can quickly identify and block phishing attempts before they cause harm, rather than waiting for attack completion

Inventive Principle:
Principle #10Preliminary action

2Reliability

If phishing detection systems analyze webpage content in real-time, then they can detect phishing attempts, but the evaluation time is too long allowing attacks to go undetected

Engineering Contradiction:
Improvephishing detection reliabilityVSAvoidURL evaluation speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent extracts only the essential URL components for analysis rather than evaluating complete webpage content. This extraction approach maintains detection reliability by focusing on critical URL patterns while dramatically improving evaluation speed by avoiding full webpage rendering and content analysis

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system segments the phishing detection process into distinct phases: URL pattern analysis, characteristic identification, and threat assessment. This segmentation allows parallel processing of different URL components, improving overall evaluation speed while maintaining comprehensive detection reliability through multi-faceted analysis

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10944789B2Phishing detection enhanced through machine learning techniques
Publication Date: 2021.03.09 EASY SOLUTIONS ENTERPRISES CORP
  • US10944789B2 patent drawing
  • US10944789B2 patent drawing
  • US10944789B2 patent drawing

AI summary

Phishing enhancement and phishing detection enhancement technologies. The technologies can include determinations of an effectiveness rate of one or more phishing threat actors. The technologies can also include selection of effective URLs from at least one effective phishing threat actor. The technologies can also include generation or adjustment of a phishing system using a machine learning process to identify patterns in the selected effective URLs that enable the selected effective URLs to avoid detection by the phishing detection system. The technologies can also include generation of synthetic phishing URLs using the phishing system and the identified patterns. The technologies can also include adjustments or training of the phishing system or the phishing detection system according to the synthetic phishing URLs to enhance the systems.