Page Representation Matching for Subtle Phishing Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Phishing attacks are challenging to detect with high accuracy, particularly when they mimic legitimate pages with slight differences or translations, leading to potential financial and mental damages, and existing countermeasures like user training and out-of-band authentication are insufficient.

Innovation Solution

A method that involves recording representations of elements from legitimate pages and analyzing target pages for visual similarity, using domain name comparisons, and SSL certificate analysis to identify phishing attempts, with responsive actions to protect users.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Object-affected harmful factors

If phishing attacks mirror legitimate sites with slight differences or translations, then the attacker can successfully deceive users, but detection accuracy deteriorates

Engineering Contradiction:
Improvephishing attack successVSAvoiddetection accuracy
Core Design Contradiction:
Object-affected harmful factorsVSMeasurement precision

Solution Approach 1:

The patent segments the phishing detection task into multiple independent analysis dimensions: visual appearance analysis, domain name analysis, SSL certificate analysis, and content analysis. Each dimension examines specific aspects of the target page separately, allowing the system to detect phishing attempts even when individual aspects are subtly altered or translated, thereby maintaining high detection accuracy despite mirror-site variations.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces multiple analysis dimensions beyond simple visual comparison. It analyzes not only the visual appearance but also domain name characteristics, SSL certificate properties, and content features. This multi-dimensional approach enables detection of phishing attacks that use translations or slight visual modifications, as the attack would fail to pass all dimensional checks simultaneously.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If existing countermeasures like user training and out-of-band authentication are used, then some phishing protection is achieved, but they are insufficient against sophisticated attacks

Engineering Contradiction:
Improvephishing protectionVSAvoidcountermeasure effectiveness
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary automated analysis system that sits between the user and the phishing site. This system performs comprehensive automated checks on visual appearance, domain name, SSL certificate, and content before allowing user interaction. The intermediary layer handles the complexity of sophisticated attack detection, freeing users from needing to understand complex security concepts while providing robust protection.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs self-service analysis by automatically examining multiple aspects of target pages without requiring user intervention or complex security knowledge. The automated detection mechanism independently evaluates visual, domain, certificate, and content characteristics, providing sophisticated protection through self-executing analysis rather than relying on user training or complex manual procedures.

Inventive Principle:
Principle #25Self-service

3Measurement precision

If the system analyzes multiple aspects of pages (visual, domain, SSL, content), then detection accuracy improves, but system complexity increases

Engineering Contradiction:
Improvephishing detection accuracyVSAvoidanalysis system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent divides the complex analysis task into separate modular components: visual appearance analysis, domain name analysis, SSL certificate analysis, and content analysis. Each module operates independently and can be optimized separately, making the overall complex system more manageable. The segmented architecture allows high detection accuracy through comprehensive multi-aspect analysis while maintaining system maintainability through modular design.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20250337779A1Phishing detection using page representation matching
Publication Date: 2025.10.30 WALKME
  • US20250337779A1 patent drawing
  • US20250337779A1 patent drawing
  • US20250337779A1 patent drawing

AI summary

An apparatus, system, product and method comprising: obtaining a selection of page elements of a source page that are estimated to represent a visual appearance of the source page; generating respective representations of the page elements, wherein the representation is configured to be used for acquiring a page element in different pages; obtaining a target page, wherein a user is enabled to interact with the target page; determining a visual similarity measurement between the source page and the target page, wherein the visual similarity measurement is based on a successful acquisition in the target page, of the page elements, using the respective representations; classifying the target page as a phishing attack based on the visual similarity measurement, whereby detecting the phishing attack; and performing a responsive action in response to said detecting the phishing attack.