Machine Learning Engine for Credential Stealing Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Credential stealing attacks exploit human vulnerability by creating fake web pages that resemble legitimate brand pages, making it difficult to distinguish between authentic and fraudulent sites, especially in brand-based and custom credential stealing scenarios.
Innovation Solution
An automated machine-learning page examination engine is used to analyze candidate web pages by comparing identity and feature information with known brand profiles, determining if a page is a replica or custom credential stealing page through visual, natural language, and source code similarity analysis, and providing a graphical interface for displaying infection details if a threat is detected.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If users rely on visual and textual similarities to identify legitimate web pages, then ease of operation is improved, but reliability deteriorates because attackers can create convincing fake pages
Solution Approach 1:
The patent introduces an automated machine-learning page examination engine as an intermediary between the user and the web page. This engine independently analyzes the candidate page's visual features, text content, and source code, then compares them against stored brand profiles to determine legitimacy, thereby resolving the contradiction by providing reliable authentication without requiring users to manually verify technical indicators
Solution Approach 2:
The patent replaces the manual mechanical process of visual inspection and URL verification with an automated machine-learning system. The engine automatically extracts features, performs comparisons, and generates legitimacy determinations, substituting human cognitive processes with computational analysis that is both efficient and reliable
2Ease of operation
If users focus on visual appearance and text content of web pages, then ease of operation is improved, but measurement precision deteriorates because reliable indicators like URL and certificate are ignored
Solution Approach 1:
The patent segments the page analysis into multiple independent components: visual feature extraction, text content analysis, source code examination, and comparison against brand profiles. Each component evaluates specific aspects of the page, and their results are combined to form a comprehensive legitimacy determination, thereby achieving high measurement precision while maintaining ease of operation
Solution Approach 2:
The machine-learning page examination engine performs multiple functions simultaneously: it analyzes visual features, processes text content, examines source code, compares against multiple brand profiles, and determines legitimacy. This multi-functional approach ensures comprehensive evaluation without requiring separate manual processes
3Reliability
If automated analysis is implemented to detect credential stealing pages, then reliability is improved, but device complexity increases
Solution Approach 1:
The patent merges multiple analysis functions (visual feature extraction, text analysis, source code examination, brand profile comparison) into a single integrated machine-learning page examination engine. This consolidation improves reliability through comprehensive analysis while managing device complexity by providing a unified system architecture rather than separate independent components
4Measurement precision
If comprehensive feature comparison is performed to distinguish fake pages, then measurement precision is improved, but loss of time increases due to extensive analysis
Solution Approach 1:
The patent performs preliminary actions by pre-storing brand profile data including visual features, text content, and source code characteristics in a database. When a candidate page is analyzed, the system compares it against these pre-prepared profiles rather than creating profiles from scratch, significantly reducing analysis time while maintaining high measurement precision through comprehensive feature comparison
Data Source
AI summary
An Active Vision detection method and system for detecting credential stealing attacks using an automated machine-learning page examination engine is provided that may be used to detect both brand-based and custom credential stealing attacks. The approach employs similarity analysis in a two stage process that may be achieved through supervised or self learning machine learning techniques and is comparable to human analysis. The Active Vision System is capable of self-learning; every new attack detected by the system becomes part of system's long term memory making it incrementally more accurate in future predictions using its past experience.


