Phishing Detection via User Input Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for detecting phishing websites are ineffective against websites that modify their content by replacing keywords with images or display login interfaces using flash, allowing these sites to bypass detection.
Innovation Solution
A method and apparatus that detect phishing websites by monitoring user input information, determining the legitimacy of websites requiring private information, and generating warnings if the website is not legitimate, regardless of content modifications or display methods.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of manufacture
If text-based keyword detection is used to identify phishing websites, then detection simplicity is maintained, but detection effectiveness deteriorates because phishing sites replace keywords with images or flash
Solution Approach 1:
The patent introduces an intermediary analysis layer that processes webpage elements between the surface content and the detection engine. Instead of directly analyzing text keywords or images, the system uses an intermediary representation that captures the functional purpose of elements (e.g., identifying that an image serves as a login button or that a form field collects credentials). This intermediary layer maintains detection simplicity while improving effectiveness by translating various phishing techniques into a common analysis framework.
Solution Approach 2:
The patent replaces the mechanical text-matching system with a more sophisticated detection mechanism that analyzes webpage structure, element relationships, and functional behavior. Instead of relying on simple keyword presence, the system examines how elements are organized, what data they collect, and how they interact, thereby detecting phishing attempts that use images or flash while maintaining ease of implementation through automated analysis.
2Reliability
If comprehensive webpage analysis is performed to detect phishing sites using images or flash, then detection effectiveness improves, but computational complexity increases
Solution Approach 1:
The patent extracts only the essential and relevant features from webpages for analysis, rather than processing all content. It identifies and extracts key elements such as form fields, input boxes, credential collection points, and structural patterns that indicate phishing. By taking out only these critical features, the system achieves high detection effectiveness while reducing computational complexity by ignoring irrelevant webpage content.
Solution Approach 2:
The patent applies different analysis depths to different parts of the webpage based on their relevance to phishing detection. Critical areas such as login forms, credential input fields, and authentication-related elements receive detailed analysis, while other parts of the page receive minimal or no analysis. This local quality approach ensures high detection effectiveness for phishing indicators while reducing overall computational complexity by focusing resources where they are most needed.
Data Source
AI summary
The present disclosure discloses a method and device for detecting a potential phishing website. In the method, a computing device having at least a processor obtains information input to a website and determines whether the website is legitimate through a server when the input information entered by the user has some private information. The computing device continues to access the website if the website is legitimate and generates a warning if the website is determined not to be legitimate.


