Web Resource Login Element Detection for Phishing Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security measures are inadequate in preventing access to phishing websites, as they are resource-intensive and struggle to keep up with the rapid creation of new phishing sites, especially in geolocation-specific attacks where security services may have limited visibility.

Innovation Solution

A method and apparatus that analyze communication messages for hyperlinks and block access to web resources containing login elements, while utilizing a reputation system to assess the safety of URLs and allowing access only to trusted sites, with the option to whitelist suspicious but necessary URLs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If current security applications and reputation systems are used to evaluate webpages, then user protection from malicious attacks is improved, but the system cannot keep up-to-date with the huge amount of new phishing websites established continuously

Engineering Contradiction:
Improveprotection effectivenessVSAvoidupdate speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system performs preliminary analysis of web resources by examining communication messages for hyperlinks before users access them. The processor analyzes web resource data to find logging in elements in advance, blocking potential phishing sites before they can compromise users. This proactive approach allows the system to protect users without needing to continuously update reputation databases for every new phishing site.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The invention extracts and analyzes specific critical elements (hyperlinks and logging in elements) from communication messages and web resources, rather than evaluating entire webpages through resource-intensive reputation systems. By focusing only on the presence of logging in elements in hyperlinked web resources, the system achieves effective phishing detection with minimal computational overhead and without requiring continuous updates of comprehensive security databases.

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If security services monitor and block phishing websites, then user security is improved, but geolocation-specific phishing in countries where security services have no visibility remains a problem

Engineering Contradiction:
Improvesecurity coverageVSAvoidgeolocation coverage
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system enables each user device to independently analyze web resource data for logging in elements without relying on external security services or centralized reputation databases. The processor locally evaluates hyperlinked web resources and makes blocking decisions autonomously, allowing the system to protect users in any geolocation without requiring local security service infrastructure. This decentralized approach eliminates geolocation-specific vulnerabilities.

Inventive Principle:
Principle #25Self-service

3Measurement precision

If comprehensive analysis of all webpages is performed to detect phishing sites, then detection accuracy is improved, but computational resources and time consumption increase significantly

Engineering Contradiction:
Improvephishing detection accuracyVSAvoidcomputational resource consumption
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The system extracts and analyzes only the critical logging in elements from web resource data associated with hyperlinks in communication messages, rather than performing comprehensive analysis of entire webpages. This selective extraction approach maintains high detection accuracy for phishing sites while significantly reducing computational resource consumption and processing time.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The invention applies partial analysis by focusing exclusively on the presence of logging in elements in hyperlinked web resources, which is sufficient to detect phishing attempts. This partial action approach provides adequate protection without the excessive computational resources required for complete webpage evaluation, achieving the right balance between detection accuracy and resource efficiency.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS10474810B2Controlling access to web resources
Publication Date: 2019.11.12 WITHSECURE CORP (A K A WITHSECURE OYJ)
  • US10474810B2 patent drawing
  • US10474810B2 patent drawing
  • US10474810B2 patent drawing

AI summary

The invention relates to a method including at a user device: receiving a communication message over the Internet or other network; analysing web resource data related to one or more web resource hyperlinks included in the received communication message to find any user logging in elements by detecting functions for verifying the validity of inputs, the logging in element being used to control user access by identifying and authenticating the user through credentials inputted by the user; and in the event that any logging in elements are found, blocking access to the related web resource having the logging in element.