Automated Machine-Learning Page Analysis for Credential Theft Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Credential stealing attacks occur due to users relying on visual and textual similarities of fake web pages that mimic legitimate brand pages, allowing attackers to steal sensitive information, with existing methods failing to effectively distinguish between legitimate and fake pages.
Innovation Solution
An automated machine-learning page examination engine analyzes web pages using brand and custom credential stealing page profiles, extracting features for comparison and classification to identify and distinguish between legitimate and fake pages, including visual, natural language, and source code analysis.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If users rely on visual and textual similarities to identify legitimate web pages, then ease of operation is improved, but reliability deteriorates as attackers can create convincing fake pages
Solution Approach 1:
The patent introduces an automated machine-learning page examination engine as an intermediary between the user and the web page. This engine objectively analyzes visual, textual, and source code features to determine page legitimacy, replacing subjective human judgment with automated analysis that is not susceptible to visual deception by fake pages
Solution Approach 2:
The patent replaces the mechanical human cognitive process of evaluating page legitimacy with an automated machine-learning system. The system uses supervised learning algorithms to analyze page features and make legitimacy determinations, eliminating the vulnerability of human reliance on visual similarities
2Measurement precision
If automated machine-learning analysis is implemented to detect credential stealing attacks, then detection accuracy is improved, but device complexity increases
Solution Approach 1:
The patent segments the detection system into distinct functional modules: a page examination engine that extracts features, a machine-learning classification system that analyzes features, and a profile management system that stores brand and credential stealing page profiles. This modular architecture manages complexity by organizing functions into independent, manageable components
Solution Approach 2:
The patent creates simplified representations (profiles) of legitimate brand pages and credential stealing pages that capture essential visual, textual, and source code features. These profiles serve as reference models for comparison, reducing the complexity of analyzing entire web pages by focusing on key discriminative features
3Measurement precision
If comprehensive feature extraction and comparison is performed to distinguish legitimate and fake pages, then measurement precision is improved, but loss of time increases due to extensive analysis
Solution Approach 1:
The patent extracts and compares only the most discriminative features from web pages, such as visual layout patterns, textual content characteristics, and source code structures. By focusing on partial but critical features rather than exhaustive analysis of all page elements, the system achieves high detection accuracy with reduced processing time
Solution Approach 2:
The patent pre-processes and stores comprehensive profiles of legitimate brand pages and known credential stealing pages during an offline training phase. This preliminary action prepares reference data in advance, enabling rapid online comparison and classification without performing exhaustive analysis during real-time detection
Data Source
AI summary
An Active Vision detection method and system for detecting credential stealing attacks using an automated machine-learning page examination engine is provided that may be used to detect both brand-based and custom credential stealing attacks. The approach employs similarity analysis in a two-stage process that may be achieved through supervised or self-learning machine learning techniques and is comparable to human analysis. The Active Vision System is capable of self-learning; every new attack detected by the system becomes part of system's long-term memory making it incrementally more accurate in future predictions using its past experience.


