US2015319191A1PendingUtilityA1

Anti-phishing domain advisor and method thereof

Assignee: VISICOM MEDIA INCPriority: Aug 1, 2011Filed: Jul 13, 2015Published: Nov 5, 2015
Est. expiryAug 1, 2031(~5 yrs left)· nominal 20-yr term from priority
Inventors:Milen Georgiev
H04L 61/1511H04L 63/1408H04L 63/1483H04L 61/4511H04L 63/101G06F 21/51H04L 63/1425
25
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A method of anti-phishing and domain name protection. The method comprises: capturing a system call; extracting a URL included in the captured system call; capturing a response to the system call; determining if the system call's response includes any one of a domain name system (DNS) error code and fake internet protocol (IP) address; checking the extracted URL against an anti-phishing blacklist to determine if the Internet resource is a malicious website; redirecting the application to an advisor server; marking a communication session between the application and the Internet resource as blocked; detecting a system call's response call that includes content received from the internet resource during the blocked session; modifying the system call's response by replacing the content with redirection information; and sending the modified system call's response to the application, thereby causing the application to access the advisor server.

Claims

exact text as granted — not AI-modified
What we claim is: 
     
         1 . An anti-phishing domain advisor, comprising:
 an interface configured to interface between an operating system of a client and at least one application executed over the client, wherein the interface is further configured to monitor and capture system calls sent by the at least one application to an operating system and responses to the system calls as generated by the operating system;   a memory configured to store at least an anti-phishing blacklist; and   a processor connected to the interface can configured to:
 determine if a system call's response generated in response to a system call's request of the at least one application to access an internet resource includes any one of a domain name system (DNS) error code and a fake IP address; 
 check a URL extracted from the system call's request against the anti-phishing blacklist to determine if the Internet resource is a malicious website; 
 perform a DNS error correction action if any one of the DNS error code and the fake IP address was detected; and 
 perform an anti-phishing protection action if the internet resource is determined to be a malicious website. 
   
     
     
         2 . The anti-phishing domain advisor of  claim 1 , wherein each of the DNS error correction action and the anti-phishing protection action causes redirection of the application to an advisor server. 
     
     
         3 . The anti-phishing domain advisor of  claim 1 , wherein the advisor server is further configured to generate a web page to be displayed by the application, the generated web page includes at least one hyperlink related to the extracted URL. 
     
     
         4 . The anti-phishing domain advisor of  claim 1 , wherein the web page generated by the advisor server includes a list of hyperlinks related to the extracted URL. 
     
     
         5 . The anti-phishing domain advisor of  claim 4 , wherein one or more of the hyperlinks are sponsored links. 
     
     
         6 . The anti-phishing domain advisor of  claim 1 , wherein the processor is further configured to:
 perform the anti-phishing protection action when both the DNS error code and the phishing attempt are detected.   
     
     
         7 . The anti-phishing domain advisor  1 , wherein the processor is further configured to detect the fake IP address generated by a DNS hijacker. 
     
     
         8 . The anti-phishing domain advisor  1 , wherein the system is further configured to:
 send through the interface a DNS resolution request to a DNS with a non-existing domain name;   flag a valid IP address returned in a response to the DNS resolution request as a IP address; and   compare the IP address included in the system call's response to the flagged IP address, and if a match exists the IP address in the system call's response is determined to be a fake IP address generated by a DNS hijacker.   
     
     
         9 . The anti-phishing domain advisor  claim 1 , wherein the anti-phishing blacklist is retrieved from a third-party anti-phishing server and updated periodically. 
     
     
         10 . The anti-phishing domain advisor of  claim 1 , wherein the interface is further configured to:
 hook to an application programming interface (API) of the operating system in order to capture the system calls.   
     
     
         11 . The anti-phishing domain advisor of  claim 1 , wherein the client is any one of: a personal computer, a mobile phone, a smartphone, and a tablet computer.

Join the waitlist — get patent alerts

Track US2015319191A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.