Phishing Detection for Visually Similar Login Pages Using Screenshots

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing phishing detection systems are inefficient, unreliable, and slow in identifying phishing attempts, often failing to provide comprehensive protection for software applications, leading to significant damages.

Innovation Solution

An integrated phishing detection system that utilizes a trained phishing detection model, such as a deep neural network, to analyze screenshots and metadata of login pages, supplemented by visual comparison and metadata analysis, to accurately identify phishing attempts and generate alerts.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If heuristic-based approaches are used for phishing detection, then the system can operate with simpler architecture, but the detection reliability and accuracy deteriorate

Engineering Contradiction:
Improvedetection system architectureVSAvoidphishing detection reliability
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent replaces traditional heuristic-based mechanical detection methods with a deep neural network model that processes visual features of login pages. The DNN model analyzes image data captured from login pages to detect phishing attempts, substituting rule-based heuristics with intelligent visual pattern recognition that achieves superior accuracy and reliability.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent transforms the detection approach by changing from textual/heuristic parameter analysis to visual parameter analysis. By capturing screenshots and converting them to image data, the system analyzes visual characteristics such as layout, branding elements, and visual consistency, which provides more reliable detection against evasive phishing techniques.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If third-party phishing detection solutions are used, then the system can benefit from external expertise, but the detection speed and responsiveness deteriorate

Engineering Contradiction:
Improvedetection accuracyVSAvoiddetection response time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent merges the phishing detection functionality directly into the software application's security infrastructure. By integrating the DNN model and screenshot capture mechanism within the application itself, the system eliminates the need for external third-party services, achieving both high detection accuracy and rapid real-time response without communication delays.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The software application performs its own phishing detection using an embedded deep neural network model. The system captures screenshots of login pages, processes them through the integrated DNN, and makes detection decisions autonomously, eliminating dependency on external services and enabling immediate detection response.

Inventive Principle:
Principle #25Self-service

3Productivity

If existing phishing detection systems are used, then the system can provide basic protection, but the comprehensive protection and robustness deteriorate

Engineering Contradiction:
Improvedetection efficiencyVSAvoidcomprehensive security protection
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent adds a visual dimension to phishing detection by capturing and analyzing the graphical representation of login pages. The system converts web pages into image data and processes them through a deep neural network trained to recognize visual patterns of legitimate versus phishing pages, providing comprehensive protection that goes beyond traditional textual analysis.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The patent employs a composite detection approach that combines multiple techniques: screenshot capture, image processing, deep neural network analysis, and visual feature extraction. This multi-layered composite system integrates various detection mechanisms to achieve robust and comprehensive phishing protection that overcomes the limitations of single-method approaches.

Inventive Principle:
Principle #40Composite materials

Data Source

PatentUS20250247424A1Phishing detection of visually similar login pages
Publication Date: 2025.07.31 WALMART APOLLO LLC
  • US20250247424A1 patent drawing
  • US20250247424A1 patent drawing
  • US20250247424A1 patent drawing

AI summary

This application is directed to systems and methods for detecting phishing attempts in a user application. In some embodiments, a disclosed method includes extracting from an incoming message a uniform resource identifier (URI) for identifying a resource on a computer network, generating a screenshot image of the resource identified by the URI, applying a phishing detection model to process the screenshot image and generate a phishing indicator representing a confidence level of determining that the resource would cause a phishing attack, and in accordance with a determination that the phishing indicator satisfies an alert condition, reporting via an alert message that the URI extracted from the incoming message corresponds to the phishing attack. In some embodiments, the alert condition includes a confidence threshold, and requires that the alert message be generated and reported in accordance with a determination that the phishing indicator is greater than the confidence threshold.