Phishing Detection via Network Traffic Sequence Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional methods for detecting phishing websites are costly, cumbersome, and inefficient, and existing automated solutions often rely solely on URL analysis or visual features, which are insufficient in accurately identifying phishing attempts, especially as phishing attacks become more sophisticated.

Innovation Solution

A phishing detection system that combines multiple detection methods, including network traffic monitoring and analysis of URL patterns, feature extraction, and comparison with known legitimate websites, to identify potential phishing sites by analyzing network traffic patterns and extracting salient features from websites, even in the absence of knowledge about target websites.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional methods for detecting phishing websites are used, then detection capability is provided, but the system becomes costly and cumbersome

Engineering Contradiction:
Improvephishing detection capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The detection system is divided into multiple independent modules: URL pattern analysis module, visual feature extraction module, and network traffic analysis module. Each module performs a specific detection function and can operate independently, reducing overall system complexity while maintaining comprehensive detection capability

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system employs a unified detection framework that can handle multiple phishing detection approaches (URL-based, visual-based, network-based) through a single integrated platform, eliminating the need for separate detection systems and reducing operational complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Extent of automation

If automated solutions relying solely on URL analysis or visual features are used, then automation is achieved, but detection accuracy is insufficient

Engineering Contradiction:
Improveautomation levelVSAvoidphishing identification accuracy
Core Design Contradiction:
Extent of automationVSMeasurement precision

Solution Approach 1:

The patent combines three different detection approaches (URL pattern analysis, visual feature extraction, and network traffic analysis) into a unified detection system. By merging these complementary methods, the system achieves both automation and high accuracy, as each method compensates for the limitations of the others

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system transitions from single-dimension detection (either URL-based or visual-based) to multi-dimension detection by incorporating network traffic analysis as a third dimension. This dimensional expansion enables the system to detect phishing attempts that would be missed by any single method alone, thereby improving accuracy while maintaining automation

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Measurement precision

If multiple detection methods are combined to improve accuracy, then detection precision is improved, but system complexity increases

Engineering Contradiction:
Improvephishing detection accuracyVSAvoiddetection system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The detection system is divided into multiple independent modules: URL pattern analysis module, visual feature extraction module, and network traffic analysis module. Each module performs a specific detection function and can operate independently, reducing overall system complexity while maintaining comprehensive detection capability

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system incorporates a feedback mechanism where detection results from different modules are aggregated and cross-validated. The system learns from detected phishing patterns and updates its detection criteria, improving accuracy over time while managing complexity through intelligent result synthesis

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20200396252A1Systems and methods for identifying phishing websites
Publication Date: 2020.12.17 SWISSCOM AG
  • US20200396252A1 patent drawing
  • US20200396252A1 patent drawing

AI summary

Systems and methods are provided for automatically detecting phishing attacks. A sequence of network traffic events may be detecting within network traffic, the sequence including an initial communication from a network address to a first other network address, a first subsequent communication from the first other network address at a first time, and a second subsequent communication from the network address to a second other network address at a second time subsequent to the first time. The first other network address may be classified as a potential phishing website based on determining that the second other network address is not related to the first other network address, and that a time difference between the second time and the first time meets predefined criteria. Protective measures may be taken in response to the classifying, with the protective measures including at least blocking the first other network address.