Phishing Detection via User Input Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for detecting phishing websites are ineffective against websites that modify their content by replacing keywords with images or display login interfaces using flash, allowing these sites to bypass detection.

Innovation Solution

A method and apparatus that detect phishing websites by monitoring user input information, determining the legitimacy of websites requiring private information, and generating warnings if the website is not legitimate, regardless of content modifications or display methods.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If text-based keyword detection is used to identify phishing websites, then detection simplicity is maintained, but detection effectiveness deteriorates because phishing sites replace keywords with images or flash

Engineering Contradiction:
Improvedetection simplicityVSAvoiddetection effectiveness
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent introduces an intermediary analysis layer that processes webpage elements between the surface content and the detection engine. Instead of directly analyzing text keywords or images, the system uses an intermediary representation that captures the functional purpose of elements (e.g., identifying that an image serves as a login button or that a form field collects credentials). This intermediary layer maintains detection simplicity while improving effectiveness by translating various phishing techniques into a common analysis framework.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the mechanical text-matching system with a more sophisticated detection mechanism that analyzes webpage structure, element relationships, and functional behavior. Instead of relying on simple keyword presence, the system examines how elements are organized, what data they collect, and how they interact, thereby detecting phishing attempts that use images or flash while maintaining ease of implementation through automated analysis.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If comprehensive webpage analysis is performed to detect phishing sites using images or flash, then detection effectiveness improves, but computational complexity increases

Engineering Contradiction:
Improvedetection effectivenessVSAvoidcomputational complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts only the essential and relevant features from webpages for analysis, rather than processing all content. It identifies and extracts key elements such as form fields, input boxes, credential collection points, and structural patterns that indicate phishing. By taking out only these critical features, the system achieves high detection effectiveness while reducing computational complexity by ignoring irrelevant webpage content.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent applies different analysis depths to different parts of the webpage based on their relevance to phishing detection. Critical areas such as login forms, credential input fields, and authentication-related elements receive detailed analysis, while other parts of the page receive minimal or no analysis. This local quality approach ensures high detection effectiveness for phishing indicators while reducing overall computational complexity by focusing resources where they are most needed.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS9712562B2Method, device and system for detecting potential phishing websites
Publication Date: 2017.07.18 TENCENT TECHNOLOGY (SHENZHEN) CO LTD
  • US9712562B2 patent drawing
  • US9712562B2 patent drawing
  • US9712562B2 patent drawing

AI summary

The present disclosure discloses a method and device for detecting a potential phishing website. In the method, a computing device having at least a processor obtains information input to a website and determines whether the website is legitimate through a server when the input information entered by the user has some private information. The computing device continues to access the website if the website is legitimate and generates a warning if the website is determined not to be legitimate.