Phishing Website Screening Through Visual Element Hashing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing anti-phishing solutions are inefficient and insufficient in real-time or large-scale deployment scenarios due to high computational requirements and sensitivity to minor stylistic changes, failing to preemptively mitigate phishing threats effectively.

Innovation Solution

A cloud-based system using perceptual image hashing and genetic algorithms generates lookalike domains by analyzing visual similarity through lightweight image comparison techniques, enabling fast and scalable phishing detection by comparing visual elements in website screenshots.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If deep learning models or high-dimensional visual analysis techniques are used to compare website screenshots, then detection accuracy is improved, but computational requirements and device complexity increase significantly

Engineering Contradiction:
Improvedetection accuracyVSAvoidcomputational requirements
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the visual analysis process into multiple stages: first extracting key visual elements (logos, headers, navigation bars) from screenshots, then comparing only these extracted elements using perceptual hashing. This segmentation avoids processing entire high-resolution images, reducing computational complexity while maintaining detection accuracy for phishing sites that replicate specific visual components.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent extracts and isolates critical visual features (logos, text headers, navigation elements) from complete website screenshots for comparison. By taking out only the most discriminative visual elements rather than analyzing entire images, the system achieves accurate phishing detection with significantly reduced computational overhead compared to full-image deep learning approaches.

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If traditional image comparison techniques are used to detect phishing websites, then detection capability is improved, but scalability and processing speed deteriorate in large-scale deployment scenarios

Engineering Contradiction:
Improvedetection capabilityVSAvoidprocessing speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent replaces traditional mechanical image comparison methods (pixel-by-pixel analysis, template matching) with perceptual hashing techniques. This substitution transforms the comparison process into a more efficient computational operation that generates compact hash representations of visual elements, enabling rapid similarity assessment across large numbers of websites while maintaining reliable phishing detection capability.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent changes the parameter representation from high-dimensional image data to compact perceptual hash values. By transforming visual information into condensed hash representations that capture essential visual characteristics, the system achieves both reliable detection (through accurate hash comparison) and high productivity (through efficient processing of hash values compared to full images).

Inventive Principle:
Principle #35Parameter changes

3Ease of manufacture

If reactive measures such as blacklisting known phishing domains are used, then implementation simplicity is improved, but ability to preemptively mitigate evolving phishing threats deteriorates

Engineering Contradiction:
Improveimplementation simplicityVSAvoidability to detect new phishing threats
Core Design Contradiction:
Ease of manufactureVSAdaptability or versatility

Solution Approach 1:

The patent implements preliminary action by proactively generating lookalike domain names that mimic legitimate websites before phishing attacks occur. The system creates potential phishing domains using various deception techniques (character substitution, homograph attacks, domain extension variations) and prepares detection rules in advance, enabling preemptive blocking of phishing threats rather than reactive blacklisting after attacks are discovered.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent applies preliminary anti-action by pre-generating and pre-detecting potential phishing domains using visual similarity analysis. The system proactively identifies lookalike domains that could be used for phishing attacks and prepares detection mechanisms before actual phishing sites are deployed, countering evolving threats before they can harm users.

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentUS20250323943A1Detecting Phishing Websites Using Perceptual Image Hashing
Publication Date: 2025.10.16 ZSCALER INC
  • US20250323943A1 patent drawing
  • US20250323943A1 patent drawing
  • US20250323943A1 patent drawing

AI summary

Systems and methods for detecting phishing using image hashing include obtaining a plurality of images from different sources, generating a hash for each image, comparing at least one hash associated with a first image to one or more hashes associated with a second image, calculating a similarity score based on the comparing, and classifying the first image based on the similarity score.