US2008163369A1PendingUtilityA1

Dynamic phishing detection methods and apparatus

Assignee: CHANG MING-TAI ALLENPriority: Dec 28, 2006Filed: Dec 28, 2006Published: Jul 3, 2008
Est. expiryDec 28, 2026(~0.4 yrs left)· nominal 20-yr term from priority
H04L 63/1483H04L 63/1416G06F 21/51G06F 21/55G06F 2221/2119
48
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A computer-implemented method for detecting a phishing attempt by a given website is provided. The method includes receiving a webpage from the given website, which includes computer-readable code for the webpage. The method also includes ascertaining hyperlink references in the computer-readable code. Each hyperlink reference refers to at least a component of another webpage. The method further includes performing linking relationship analysis on at least a subset of websites identified to be referenced by the hyperlink references, which includes determining whether a first website is in a bi-directional/uni-directional linking relationship with the given website. The first website is one of the subset of websites. The method yet also includes, if the first website is in the bi-directional linking relationship, designating the given website a non-phishing website. The method yet further includes, if the first website is in the uni-directional linking relationship, performing anti-phishing measures with respect to the given website.

Claims

exact text as granted — not AI-modified
1 . A computer-implemented method for detecting a phishing attempt by a given website, comprising:
 receiving a webpage from said given website, including computer-readable code for said webpage;   ascertaining a set of hyperlink references in said computer-readable code, each hyperlink reference in said set of hyperlink references referencing at least a component of another webpage that is associated with said given website or a website different from said given website;   performing linking relationship analysis on at least a subset of websites identified to be referenced by said set of hyperlink references, including determining whether a first website that is associated with a webpage referenced by a first one of said set of hyperlink references is in a bi-directional linking relationship with said given website or in a uni-directional linking relationship with said given website, said first website being one of said subset of websites;   if said first website is in said bi-directional linking relationship with said given website, designating said given website a non-phishing website; and   if said first website is in said uni-directional linking relationship with said given website, performing anti-phishing measures with respect to said given website.   
   
   
       2 . The method of  claim 1  wherein said first one of said set of hyperlink references has a first type, said first type being a member of a predefined set of triggering hyperlink reference types. 
   
   
       3 . The method of  claim 2  wherein said subset of websites represents websites associated with hyperlink references whose types belong to said predefined set of triggering hyperlink reference types, said performing said linking relationship analysis is performed only on said subset of websites. 
   
   
       4 . The method of  claim 3  wherein said predefined set of triggering hyperlink reference types includes an anchor hyperlink reference type. 
   
   
       5 . The method of  claim 1  wherein said subset of websites represents or more website identified to be most relevant. 
   
   
       6 . A computer-implemented method for detecting a phishing attempt by a given website, comprising:
 receiving a webpage from said given website, including computer-readable code for said webpage;   obtaining from said computer readable code a transaction destination URL, said transaction destination URL representing a destination URL for transaction information requested by said webpage;   ascertaining a set of hyperlink references in said computer-readable code, each hyperlink reference in said set of hyperlink references referencing at least a component of another webpage that is associated with given website or a website different from said given website;   performing transaction destination analysis on at least a subset of websites identified to be referenced by said set of hyperlink references, including ascertaining a first transaction destination URL specified by a transaction page in a first website that is associated with a webpage referenced by a first one of said set of hyperlink references, said first transaction destination URL representing a destination URL for transaction information requested by said transaction page in said first website; and   if said transaction destination URL obtained from said computer readable code for said webpage from said given website is different from said first transaction destination URL, performing anti-phishing measures with respect to said given website.   
   
   
       7 . The method of  claim 6  wherein said transaction information requested by said webpage pertains to at least one of user authentication information and user financial information. 
   
   
       8 . The method of  claim 6  wherein said first one of said set of hyperlink references has a first type, said first type being a member of a predefined set of triggering hyperlink reference types. 
   
   
       9 . The method of  claim 8  wherein said subset of websites represents websites associated with hyperlink references whose types belong to said predefined set of triggering hyperlink reference types, said performing said linking relationship analysis is performed only on said subset of websites. 
   
   
       10 . The method of  claim 9  wherein said predefined set of triggering hyperlink reference types includes an anchor hyperlink reference type. 
   
   
       11 . The method of  claim 6  wherein said subset of websites represents or more website identified to be most relevant. 
   
   
       12 . An article of manufacture having thereon computer storage medium and computer readable code configured for a phishing attempt by a given website, comprising:
 computer readable code for receiving a webpage from said given website, including computer-readable code for said webpage;   computer readable code for obtaining from said computer readable code a transaction destination URL, said transaction destination URL representing a destination URL for transaction information requested by said webpage;   computer readable code for ascertaining a set of hyperlink references in said computer-readable code, each hyperlink reference in said set of hyperlink references referencing at least a component of another webpage that is associated with given website or a website different from said given website;   performing transaction destination analysis on at least a subset of websites identified to be referenced by said set of hyperlink references, including ascertaining a first transaction destination URL specified by a transaction page in a first website that is associated with a webpage referenced by a first one of said set of hyperlink references, said first transaction destination URL representing a destination URL for transaction information requested by said transaction page in said first website; and   if said transaction destination URL obtained from said computer readable code for said webpage from said given website is different from said first transaction destination URL, performing anti-phishing measures with respect to said given website.   
   
   
       13 . The method of  claim 12  wherein said transaction information requested by said webpage pertains to at least one of user authentication information and user financial information. 
   
   
       14 . The method of  claim 12  wherein said first one of said set of hyperlink references has a first type, said first type being a member of a predefined set of triggering hyperlink reference types. 
   
   
       15 . The method of  claim 14  wherein said subset of websites represents websites associated with hyperlink references whose types belong to said predefined set of triggering hyperlink reference types, said performing said linking relationship analysis is performed only on said subset of websites. 
   
   
       16 . The method of  claim 15  wherein said predefined set of triggering hyperlink reference types includes an anchor hyperlink reference type. 
   
   
       17 . The method of  claim 12  wherein said subset of websites represents or more website identified to be most relevant.

Join the waitlist — get patent alerts

Track US2008163369A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.