Machine Learning Engine for Credential Stealing Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Credential stealing attacks exploit human vulnerability by creating fake web pages that resemble legitimate brand pages, making it difficult to distinguish between authentic and fraudulent sites, especially in brand-based and custom credential stealing scenarios.

Innovation Solution

An automated machine-learning page examination engine is used to analyze candidate web pages by comparing identity and feature information with known brand profiles, determining if a page is a replica or custom credential stealing page through visual, natural language, and source code similarity analysis, and providing a graphical interface for displaying infection details if a threat is detected.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If users rely on visual and textual similarities to identify legitimate web pages, then ease of operation is improved, but reliability deteriorates because attackers can create convincing fake pages

Engineering Contradiction:
Improveuser ability to identify legitimate pagesVSAvoidaccuracy of page authentication
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces an automated machine-learning page examination engine as an intermediary between the user and the web page. This engine independently analyzes the candidate page's visual features, text content, and source code, then compares them against stored brand profiles to determine legitimacy, thereby resolving the contradiction by providing reliable authentication without requiring users to manually verify technical indicators

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the manual mechanical process of visual inspection and URL verification with an automated machine-learning system. The engine automatically extracts features, performs comparisons, and generates legitimacy determinations, substituting human cognitive processes with computational analysis that is both efficient and reliable

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Ease of operation

If users focus on visual appearance and text content of web pages, then ease of operation is improved, but measurement precision deteriorates because reliable indicators like URL and certificate are ignored

Engineering Contradiction:
Improveuser page evaluation processVSAvoidaccuracy of page identification
Core Design Contradiction:
Ease of operationVSMeasurement precision

Solution Approach 1:

The patent segments the page analysis into multiple independent components: visual feature extraction, text content analysis, source code examination, and comparison against brand profiles. Each component evaluates specific aspects of the page, and their results are combined to form a comprehensive legitimacy determination, thereby achieving high measurement precision while maintaining ease of operation

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The machine-learning page examination engine performs multiple functions simultaneously: it analyzes visual features, processes text content, examines source code, compares against multiple brand profiles, and determines legitimacy. This multi-functional approach ensures comprehensive evaluation without requiring separate manual processes

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If automated analysis is implemented to detect credential stealing pages, then reliability is improved, but device complexity increases

Engineering Contradiction:
Improvedetection accuracyVSAvoidsystem structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple analysis functions (visual feature extraction, text analysis, source code examination, brand profile comparison) into a single integrated machine-learning page examination engine. This consolidation improves reliability through comprehensive analysis while managing device complexity by providing a unified system architecture rather than separate independent components

Inventive Principle:
Principle #5Merging (Combining)

4Measurement precision

If comprehensive feature comparison is performed to distinguish fake pages, then measurement precision is improved, but loss of time increases due to extensive analysis

Engineering Contradiction:
Improvedetection accuracyVSAvoidanalysis duration
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent performs preliminary actions by pre-storing brand profile data including visual features, text content, and source code characteristics in a database. When a candidate page is analyzed, the system compares it against these pre-prepared profiles rather than creating profiles from scratch, significantly reducing analysis time while maintaining high measurement precision through comprehensive feature comparison

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11165793B2Method and system for detecting credential stealing attacks
Publication Date: 2021.11.02 VARONIS SYSTEMS INC
  • US11165793B2 patent drawing
  • US11165793B2 patent drawing
  • US11165793B2 patent drawing

AI summary

An Active Vision detection method and system for detecting credential stealing attacks using an automated machine-learning page examination engine is provided that may be used to detect both brand-based and custom credential stealing attacks. The approach employs similarity analysis in a two stage process that may be achieved through supervised or self learning machine learning techniques and is comparable to human analysis. The Active Vision System is capable of self-learning; every new attack detected by the system becomes part of system's long term memory making it incrementally more accurate in future predictions using its past experience.