US2013254888A1PendingUtilityA1

System and method for identifying security breach attempt of a website

Assignee: VERSAFE LTDPriority: Sep 23, 2009Filed: May 16, 2013Published: Sep 26, 2013
Est. expirySep 23, 2029(~3.2 yrs left)· nominal 20-yr term from priority
G06F 21/552G06F 21/57G06F 21/52H04L 63/1416G06F 2221/2119H04L 63/1483H04L 63/145
39
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

The present invention is a method, circuit and system for detecting, reporting and preventing an attempted security breach of a commercial website (for example a banking website), such as identity theft, website duplication (mirroring/Phishing), MITB (man in the browser) attacks, MITM (man in the middle) attacks and so on.

Claims

exact text as granted — not AI-modified
1 . A website security system for detecting security breach attempts associated with a phishing scheme, said system comprising: a code of a first website; a first software module, functionally associated with said code, and adapted to detect its own instancement on a server not associated with said first website; and a server associated with said first website and adapted to provide a client computer with said code and said first software module. 
     
     
         2 . The system according to  claim 1 , further comprising a file, stored on a server associated with said first website and not part of the code that is sent to a browser when it navigates to said first website; 
     
     
         3 . The system according to  claim 2 , wherein said first software module is further adapted to locate said file every time it is instanced and to determine that it has been instanced on a server, not associated with said first website, when it cannot locate said file. 
     
     
         4 . The system according to  claim 2 , wherein said file is an image. 
     
     
         5 . The system according to  claim 1 , wherein said first software module is further adapted, when it detects its own instancement on a server not associated with said first website, to perform one or more of the actions selected from the group of actions consisting of: (a) sending a warning to said first website proprietor, (b) sending a warning to the supplier of said software module, (c) sending a warning to an investigative body, (d) reporting the IP address of said unassociated server to said first website's proprietor (e) reporting the IP address of said unassociated server to the supplier of said software module, (f) reporting the IP address of said unassociated server to an investigative body, (g) reporting further details relating to said instancement to the supplier of said first software module, (h) reporting further details relating to said instancement to said first website's proprietor, and (i) reporting further details relating to said instancement to an investigative body. 
     
     
         6 . The system according to  claim 1 , further comprising a second software module, functionally associated with said first website and adapted to scan other websites and to report other websites containing graphics or text patterns similar to those contained in said first website. 
     
     
         7 . The system according to  claim 6 , wherein said second software module is further adapted to target for scanning, websites selected from the group of websites consisting of: (a) websites with new domain names, (b) websites with domain names that have recently changed ownership, and (c) websites with domain names similar to said first website's domain name. 
     
     
         8 . The system according to  claim 1 , further comprising a second software module, functionally associated with said first website and adapted to scan emails and to report emails masquerading as an email being sent by the proprietor of said first web site.

Join the waitlist — get patent alerts

Track US2013254888A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.