Visual-Guided URL Pattern Discovery for Phishing Classification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional malware detection methods struggle to keep pace with the rapid evolution of malicious software, particularly in phishing campaigns, leading to ineffective classification and increased false negatives and false positives.

Innovation Solution

A visual-guided campaign auto-discovery (VisCAD) service that leverages image-based grouping techniques, including image hashing and encoding, to identify patterns in URLs and HTMLs, enabling efficient clustering and pattern extraction for improved phishing detection and benign categorization.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional signature-based detection methods are used, then detection simplicity is maintained, but detection effectiveness deteriorates against evolving malware

Engineering Contradiction:
Improvedetection effectivenessVSAvoiddetection system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces conventional mechanical signature-based detection with a visual-guided machine learning system that uses image hashing, encoding, and clustering algorithms to detect malware patterns, enabling adaptive detection against evolving threats

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system transforms detection parameters from static signatures to dynamic visual features through image hashing and encoding, allowing the detection system to adapt to varying malware implementations while maintaining consistent pattern recognition

Inventive Principle:
Principle #35Parameter changes

2Measurement precision

If machine learning techniques are implemented, then pattern recognition capability is improved, but processing time increases

Engineering Contradiction:
Improvepattern recognition accuracyVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary image hashing and encoding of malware samples to create visual fingerprints and feature representations, which are then stored and used for rapid pattern matching during detection, reducing real-time processing requirements

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent creates visual copies of malware samples through image hashing and encoding, generating compressed representations that capture essential patterns while reducing data size for faster processing and comparison

Inventive Principle:
Principle #26Copying

3Adaptability or versatility

If visual-guided campaign auto-discovery is implemented, then phishing detection coverage is improved, but system complexity increases

Engineering Contradiction:
Improvephishing detection coverageVSAvoidsystem architecture complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system employs a universal visual-guided framework that handles multiple detection tasks including phishing detection, pattern recognition, and campaign identification through a single integrated architecture using image hashing, encoding, and clustering

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent implements self-service automation where the system automatically discovers phishing campaigns, extracts patterns, and updates detection rules without human intervention, reducing operational complexity while expanding detection coverage

Inventive Principle:
Principle #25Self-service

4Reliability

If image-based grouping is used, then false positives are reduced, but computational resources are consumed

Engineering Contradiction:
Improvefalse positive rateVSAvoidcomputational resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The system extracts key visual features from malware samples through image hashing and encoding, separating essential pattern information from redundant data, which reduces the computational burden during pattern matching while maintaining detection accuracy

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS20250373626A1Viscad: visual-guided campaign auto-discovery
Publication Date: 2025.12.04 PALO ALTO NETWORKS INC
  • US20250373626A1 patent drawing
  • US20250373626A1 patent drawing
  • US20250373626A1 patent drawing

AI summary

The present application discloses a method, system, and computer system for classifying samples. The method includes (a) grouping a plurality of images associated with a plurality of samples to obtain a set of image groups, wherein the plurality of images are grouped based at least in part on visual similarities, (b) determining one or more patterns from URLs for samples associated with images comprised in a particular image group, and (c) generating a signature for each of the determined one or more patterns form the URLs.