Web Application Phishing Detection via Referrer Inspection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security measures for web applications are inadequate in preventing phishing and leeching attacks, as they often rely on generic models that fail to address the unique vulnerabilities of each application, leading to increased risks of data breaches and brand damage.

Innovation Solution

Implementing a behavior-based security model that detects phishing and leeching activity by inspecting HTTP referrer headers and identifying phishing vulnerabilities through redirect parameter validation, allowing for responsive actions to be taken to secure web servers and protect against external threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If generic security models are used to protect web applications, then implementation is simple and quick, but they fail to address unique vulnerabilities of each application leading to security breaches

Engineering Contradiction:
Improvesecurity effectivenessVSAvoidsecurity model complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the security approach by creating application-specific security models tailored to each web application's unique characteristics, vulnerabilities, and architecture rather than using a generic one-size-fits-all model. This segmentation allows the security system to address specific vulnerabilities of each application while maintaining manageable complexity through modular, targeted security configurations.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by customizing security measures to match the specific needs, vulnerabilities, and characteristics of each individual web application. Each application receives a tailored security model that addresses its unique risk profile, rather than applying uniform security controls across all applications. This ensures optimal security effectiveness for each application while maintaining overall system manageability.

Inventive Principle:
Principle #3Local quality

2Measurement precision

If comprehensive security inspection of HTTP referrer headers is performed, then phishing and leeching detection accuracy improves, but processing time and system resource consumption increase

Engineering Contradiction:
Improvephishing detection accuracyVSAvoidrequest processing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent implements preliminary action by pre-configuring security rules, patterns, and validation criteria for HTTP referrer header inspection before actual security checks are performed. The system pre-loads security policies, maintains updated lists of known malicious patterns, and prepares validation logic in advance. This allows the system to perform comprehensive security inspections with high accuracy while minimizing processing time during actual request handling, as the heavy lifting of security rule preparation is done beforehand.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If redirect parameters are validated to identify phishing vulnerabilities, then security coverage is improved, but false positive rate may increase requiring manual investigation

Engineering Contradiction:
Improvesecurity coverageVSAvoidinvestigation workflow complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements feedback mechanisms that allow the security system to learn from manual investigations and administrative decisions. When administrators investigate false positives or confirm phishing attempts, this feedback is used to refine and adjust the redirect parameter validation rules and patterns. The system continuously improves its detection accuracy by incorporating feedback from real-world cases, reducing false positives over time while maintaining comprehensive security coverage. This feedback loop minimizes the need for manual investigation by making the system progressively more accurate.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS8429751B2Method and apparatus for phishing and leeching vulnerability detection
Publication Date: 2013.04.23 TRUSTWAVE HOLDINGS INC
  • US8429751B2 patent drawing
  • US8429751B2 patent drawing
  • US8429751B2 patent drawing

AI summary

A system and method for protection of Web based applications are described. Anomalous traffic can be identified by comparing the traffic to a profile of acceptable user traffic when interacting with the application. Phishing and leeching are one type of anomalous traffic that is detected. The anomalous traffic, or security events, identified at the individual computer networks are communicated to a central security manager. Various responsive actions may be taken in response to detection of phishing or leeching.