US2018115573A1PendingUtilityA1

Phishing detection with machine learning

Assignee: IBMPriority: Oct 26, 2016Filed: Dec 28, 2017Published: Apr 26, 2018
Est. expiryOct 26, 2036(~10.3 yrs left)· nominal 20-yr term from priority
H04L 63/1483H04L 63/101H04L 63/1408H04L 63/1416H04L 63/1425
45
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A system and method for identifying a phishing website is disclosed. Content associated with a website that a user is attempting to access is retrieved and translated into a format that a classifier can process. The classifier is trained to identify phishing attempts for a particular website or family of websites. The classifier processes the website to determine if the website is a phishing website. A scorer can determine the likelihood that the classifier classified the website correctly. If the website is determined to be a phishing website a protection component can deny access to the website. Otherwise the user can be permitted to access the website.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method comprising:
 retrieving content associated with a website:   performing a pre-analysis on the website where the reanalysis compares an address associated with the website to a whitelist of addresses associated with a single organization, and allows access to the website without processing the content through a classifier when the address is present in the whitelist and process the content through the classifier when the address is not present in the whitelist;   extracting features from the website; and   translating the extracted features into the format for the classifier to process, wherein extracting features extracts lexical features from the website, and extracts image sizes from the website.   translating the content into a format for the classifier to process;   processing the content and the extracted features through the classifier to determine if the website is a phishing website, wherein the classifier is trained to identify phishing websites for only a single organization;   granting access to the website when the website is determined not to be a phishing website; and   blocking access to the website when the website is determined to be a phishing website.

Join the waitlist — get patent alerts

Track US2018115573A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.