Phishing Detection for Visually Similar Login Pages Using Screenshots
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing phishing detection systems are inefficient, unreliable, and slow in identifying phishing attempts, often failing to provide comprehensive protection for software applications, leading to significant damages.
Innovation Solution
An integrated phishing detection system that utilizes a trained phishing detection model, such as a deep neural network, to analyze screenshots and metadata of login pages, supplemented by visual comparison and metadata analysis, to accurately identify phishing attempts and generate alerts.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If heuristic-based approaches are used for phishing detection, then the system can operate with simpler architecture, but the detection reliability and accuracy deteriorate
Solution Approach 1:
The patent replaces traditional heuristic-based mechanical detection methods with a deep neural network model that processes visual features of login pages. The DNN model analyzes image data captured from login pages to detect phishing attempts, substituting rule-based heuristics with intelligent visual pattern recognition that achieves superior accuracy and reliability.
Solution Approach 2:
The patent transforms the detection approach by changing from textual/heuristic parameter analysis to visual parameter analysis. By capturing screenshots and converting them to image data, the system analyzes visual characteristics such as layout, branding elements, and visual consistency, which provides more reliable detection against evasive phishing techniques.
2Reliability
If third-party phishing detection solutions are used, then the system can benefit from external expertise, but the detection speed and responsiveness deteriorate
Solution Approach 1:
The patent merges the phishing detection functionality directly into the software application's security infrastructure. By integrating the DNN model and screenshot capture mechanism within the application itself, the system eliminates the need for external third-party services, achieving both high detection accuracy and rapid real-time response without communication delays.
Solution Approach 2:
The software application performs its own phishing detection using an embedded deep neural network model. The system captures screenshots of login pages, processes them through the integrated DNN, and makes detection decisions autonomously, eliminating dependency on external services and enabling immediate detection response.
3Productivity
If existing phishing detection systems are used, then the system can provide basic protection, but the comprehensive protection and robustness deteriorate
Solution Approach 1:
The patent adds a visual dimension to phishing detection by capturing and analyzing the graphical representation of login pages. The system converts web pages into image data and processes them through a deep neural network trained to recognize visual patterns of legitimate versus phishing pages, providing comprehensive protection that goes beyond traditional textual analysis.
Solution Approach 2:
The patent employs a composite detection approach that combines multiple techniques: screenshot capture, image processing, deep neural network analysis, and visual feature extraction. This multi-layered composite system integrates various detection mechanisms to achieve robust and comprehensive phishing protection that overcomes the limitations of single-method approaches.
Data Source
AI summary
This application is directed to systems and methods for detecting phishing attempts in a user application. In some embodiments, a disclosed method includes extracting from an incoming message a uniform resource identifier (URI) for identifying a resource on a computer network, generating a screenshot image of the resource identified by the URI, applying a phishing detection model to process the screenshot image and generate a phishing indicator representing a confidence level of determining that the resource would cause a phishing attack, and in accordance with a determination that the phishing indicator satisfies an alert condition, reporting via an alert message that the URI extracted from the incoming message corresponds to the phishing attack. In some embodiments, the alert condition includes a confidence threshold, and requires that the alert message be generated and reported in accordance with a determination that the phishing indicator is greater than the confidence threshold.


