Web Page Security Scanner for Phishing Protection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing web pages that require user authentication often lack secure protocols, making user data vulnerable to interception and compromising security.
Innovation Solution
A computer system is designed to scan web pages for user authentication elements and determine if secure protocols like SSL or TLS are implemented, displaying warnings if insecure protocols are used, thereby preventing the development, deployment, and access to such insecure web pages.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If web pages allow user authentication without verifying secure protocols, then ease of operation is improved, but security is worsened
Solution Approach 1:
The system performs preliminary verification of secure protocols (SSL/TLS) before allowing user authentication to proceed. The computer system checks whether the web page implements secure protocols before transmitting authentication credentials, preventing security compromises before they can occur.
Solution Approach 2:
The patent introduces an intermediary security verification layer between the user authentication process and the web page. This intermediary system actively scans and verifies secure protocol implementation, acting as a mediator that ensures security requirements are met before authentication can occur.
2Reliability
If the system scans and verifies secure protocols on all web pages, then security is improved, but device complexity is worsened
Solution Approach 1:
The computer system is designed with multi-functionality, serving both as a regular computing device and as a security scanning system. The same processor and software infrastructure are used for both general operations and security protocol verification, reducing the need for separate dedicated security hardware.
Solution Approach 2:
The system performs self-verification of secure protocols using its own computational resources. The computer system automatically scans and verifies secure protocol implementation on web pages it accesses, without requiring external verification services, thereby reducing overall system complexity.
3Reliability
If the system displays warnings for insecure web pages, then security is improved, but loss of information is worsened
Solution Approach 1:
The system takes preliminary anti-action by displaying security warnings before users can be compromised by insecure web pages. The warning is shown in advance, allowing users to take protective action (such as navigating away from the page) before authentication credentials could be transmitted insecurely.
Data Source
AI summary
Embodiments described herein are directed to preventing development of insecure web pages, preventing deployment of insecure web pages and to preventing access to insecure web pages. In one embodiment, a computer system accesses a web page that includes one or more web elements. The computer system then determines that the web page includes at least one element that requests user authentication and determines whether various specified secure protocols have been implemented on the web page. Then, if the specified secure protocols have not been implemented on the web page, the computer system displays a warning or error indicating that the web page is insecure.


