Automated Machine-Learning Page Analysis for Credential Theft Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Credential stealing attacks occur due to users relying on visual and textual similarities of fake web pages that mimic legitimate brand pages, allowing attackers to steal sensitive information, with existing methods failing to effectively distinguish between legitimate and fake pages.

Innovation Solution

An automated machine-learning page examination engine analyzes web pages using brand and custom credential stealing page profiles, extracting features for comparison and classification to identify and distinguish between legitimate and fake pages, including visual, natural language, and source code analysis.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If users rely on visual and textual similarities to identify legitimate web pages, then ease of operation is improved, but reliability deteriorates as attackers can create convincing fake pages

Engineering Contradiction:
Improveuser ability to identify legitimate pagesVSAvoidaccuracy of page legitimacy identification
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces an automated machine-learning page examination engine as an intermediary between the user and the web page. This engine objectively analyzes visual, textual, and source code features to determine page legitimacy, replacing subjective human judgment with automated analysis that is not susceptible to visual deception by fake pages

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the mechanical human cognitive process of evaluating page legitimacy with an automated machine-learning system. The system uses supervised learning algorithms to analyze page features and make legitimacy determinations, eliminating the vulnerability of human reliance on visual similarities

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Measurement precision

If automated machine-learning analysis is implemented to detect credential stealing attacks, then detection accuracy is improved, but device complexity increases

Engineering Contradiction:
Improvedetection accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the detection system into distinct functional modules: a page examination engine that extracts features, a machine-learning classification system that analyzes features, and a profile management system that stores brand and credential stealing page profiles. This modular architecture manages complexity by organizing functions into independent, manageable components

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates simplified representations (profiles) of legitimate brand pages and credential stealing pages that capture essential visual, textual, and source code features. These profiles serve as reference models for comparison, reducing the complexity of analyzing entire web pages by focusing on key discriminative features

Inventive Principle:
Principle #26Copying

3Measurement precision

If comprehensive feature extraction and comparison is performed to distinguish legitimate and fake pages, then measurement precision is improved, but loss of time increases due to extensive analysis

Engineering Contradiction:
Improvedetection accuracyVSAvoidanalysis time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent extracts and compares only the most discriminative features from web pages, such as visual layout patterns, textual content characteristics, and source code structures. By focusing on partial but critical features rather than exhaustive analysis of all page elements, the system achieves high detection accuracy with reduced processing time

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The patent pre-processes and stores comprehensive profiles of legitimate brand pages and known credential stealing pages during an offline training phase. This preliminary action prepares reference data in advance, enabling rapid online comparison and classification without performing exhaustive analysis during real-time detection

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12418549B1Method and system for detecting credential stealing attacks
Publication Date: 2025.09.16 VARONIS SYSTEMS INC
  • US12418549B1 patent drawing
  • US12418549B1 patent drawing
  • US12418549B1 patent drawing

AI summary

An Active Vision detection method and system for detecting credential stealing attacks using an automated machine-learning page examination engine is provided that may be used to detect both brand-based and custom credential stealing attacks. The approach employs similarity analysis in a two-stage process that may be achieved through supervised or self-learning machine learning techniques and is comparable to human analysis. The Active Vision System is capable of self-learning; every new attack detected by the system becomes part of system's long-term memory making it incrementally more accurate in future predictions using its past experience.