Phishing Detection via Dynamic Device Configuration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Phishing websites employ evasion techniques, such as cloaking, making it difficult for existing detection systems to accurately classify them as malicious, leading to false negatives and ineffective prevention of phishing attempts.

Innovation Solution

A phishing detection system dynamically configures a device to access malicious websites, analyzes programming code for evasion techniques, and modifies the webpage classification system to circumvent these techniques by mimicking device configurations and conditions, allowing accurate classification of phishing content.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Object-affected harmful factors

If evasion techniques (e.g., cloaking) are implemented in phishing websites, then the ability to trick users is improved, but the detectability by classification systems deteriorates

Engineering Contradiction:
Improvephishing effectivenessVSAvoidwebsite classification accuracy
Core Design Contradiction:
Object-affected harmful factorsVSDifficulty of detecting and measuring

Solution Approach 1:

The patent implements dynamic device configuration where the detection system modifies device parameters (geolocation, language, screen resolution, browser type) in real-time to access different versions of phishing websites. This dynamic approach allows the system to uncover cloaking mechanisms that serve different device types differently, thereby detecting evasion techniques that would remain hidden with static detection methods.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent introduces multiple device configuration dimensions (geolocation, language, screen resolution, browser type, operating system) to detect phishing websites. By examining the website across multiple dimensional configurations rather than a single static view, the system can identify cloaking behavior where the website presents different content based on device characteristics, thus resolving the detection difficulty.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Device complexity

If static device configuration is used to access websites, then the simplicity of detection is improved, but the ability to detect cloaking techniques deteriorates

Engineering Contradiction:
Improvedetection system complexityVSAvoidphishing detection accuracy
Core Design Contradiction:
Device complexityVSMeasurement precision

Solution Approach 1:

The patent performs preliminary analysis of the phishing website's source code to identify cloaking techniques and determine which device configurations would reveal the malicious content. This preliminary action allows the system to proactively configure the device appropriately before accessing the website, ensuring detection accuracy without requiring complex real-time adaptation during the access phase.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent creates virtual copies of different device configurations (geolocation, language, screen resolution, browser type, operating system) to access the phishing website from multiple perspectives. Rather than physically testing on numerous real devices, the system uses virtualized device profiles to simulate various user environments, maintaining simplicity while achieving comprehensive detection coverage.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS11233820B2Systems and methods for detecting phishing websites
Publication Date: 2022.01.25 PAYPAL INC
  • US11233820B2 patent drawing
  • US11233820B2 patent drawing
  • US11233820B2 patent drawing

AI summary

Methods and systems are presented for detecting malicious webpages based on dynamically configuring a device to circumvent one or more evasion techniques implemented within the malicious webpages. When a known malicious webpage is obtained, programming code of the known malicious webpage is analyzed to determine one or more evasion techniques implemented within the known malicious webpage. The one or more evasion techniques may cause a webpage classification engine to falsely classify the known malicious webpage as a non-malicious webpage. A software update is generated based on one or more feature parameters extracted from the one or more evasion techniques. The software update is used to for modify the webpage classification engine such that the webpage classification engine would correctly classify the known malicious webpage.