US2020396252A1PendingUtilityA1

Systems and methods for identifying phishing websites

Assignee: SWISSCOM AGPriority: Jul 27, 2015Filed: Jul 6, 2020Published: Dec 17, 2020
Est. expiryJul 27, 2035(~9 yrs left)· nominal 20-yr term from priority
G06F 21/566H04L 63/1483H04L 63/1425
41
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Systems and methods are provided for automatically detecting phishing attacks. A sequence of network traffic events may be detecting within network traffic, the sequence including an initial communication from a network address to a first other network address, a first subsequent communication from the first other network address at a first time, and a second subsequent communication from the network address to a second other network address at a second time subsequent to the first time. The first other network address may be classified as a potential phishing website based on determining that the second other network address is not related to the first other network address, and that a time difference between the second time and the first time meets predefined criteria. Protective measures may be taken in response to the classifying, with the protective measures including at least blocking the first other network address.

Claims

exact text as granted — not AI-modified
1 - 20 . (canceled) 
     
     
         21 . A method for automatic detection of phishing websites, comprising:
 detecting within network traffic a sequence of network traffic events that comprises at least:
 an initial communication from a network address to a first other network address; 
 a first subsequent communication to the initial communication from the first other network address at a first time; and 
 a second subsequent communication from the network address to a second other network address at a second time subsequent to the first time; 
   classifying the first other network address as a potential phishing website; wherein the classifying comprises:
 determining that the second other network address is not related to the first other network address; and 
 determining that a time difference between the second time and the first time meets predefined criteria; and 
   taking one or more protective measures in response to the classifying, wherein the one or more protective measures comprise blocking the first other network address.   
     
     
         22 . The method of  claim 21 , comprising monitoring the network traffic using a log of network traffic events, and wherein the log has a machine readable log format, and comprises network addresses of requested and/or responding sites. 
     
     
         23 . The method of  claim 21 , wherein the second subsequent communication is within a limited number of network events relative to the first time; and comprising:
 classifying the first other network address as a potential phishing website based on a determination that the limited number of network events is smaller than a defined limit value.   
     
     
         24 . The method of  claim 24 , wherein the defined limit value is 5 or 3. 
     
     
         25 . The method of  claim 21 , wherein the pre-defined criteria comprise the time difference between the second time and the first time being smaller than a defined time value. 
     
     
         26 . The method of  claim 26 , wherein the defined time value is smaller than 1 second, and preferably smaller than 0.1 seconds. 
     
     
         27 . A method for protecting websites from phishing attacks, comprising:
 detecting within network traffic a communication from a network address to a target website;   evaluating network events involving the network address prior to the detected communication to detect a communication with the network address to a website not related to the target website, wherein the evaluating comprises obtaining time measurements that are independent of network latency;   classifying the prior website as potential phishing website; and   taking one or more protective measures in response to the classifying, wherein the one or more protective measures comprise blocking the prior website.   
     
     
         28 . The method of  claim 27 , comprising monitoring the network traffic using a log of network traffic events generated based on the network traffic. 
     
     
         29 . The method of  claim 28 , wherein the log is configured based on a machine readable log format, and comprises network addresses of requested and/or responding sites. 
     
     
         30 . The method of  claim 27 , wherein the evaluation is limited to network traffic events involving the network address within a limited number of network traffic events in a sequence of network traffic events. 
     
     
         31 . The method of claim  10 , wherein the limited number of network traffic events is 5 or 3. 
     
     
         32 . The method of claim  10 , wherein the time window is smaller than 1 second, and preferably smaller than 0.1 seconds. 
     
     
         33 . A system for the automated detection of phishing attacks, comprising:
 a network flow correlator configured to detect within network traffic a sequence of network traffic events, wherein such sequence comprises:
 an initial communication from a network address to a first other network address; 
 a first subsequent communication to the initial communication from the first other network address at a first time; and 
 a second subsequent communication from the network address to a second other network address at a second time subsequent to the first time; and 
   a website classifier configured to classify the first other network address as a potential phishing website; wherein the classifying comprises:
 a determination that the second other network address is not related to the first other network address, and 
 a determination that a time difference between the second time and the first time meets predefined criteria; and 
   wherein the system is configured to take one or more protective measures in response to the classifying, wherein the one or more protective measures comprise blocking the first other network address.   
     
     
         34 . The system of claim  13 , further comprising a network traffic monitor configured to monitor network traffic; and
 wherein the network traffic monitor is configured to generate a log of network traffic events for use during monitoring the network traffic.   
     
     
         35 . The system of claim  14 , wherein the log has a machine readable log format, and comprises network addresses of requested and/or responding sites. 
     
     
         36 . The system of claim  13 , further comprising an address collector configured to collect addresses corresponding to requested and/or responding sites from one or more different sources. 
     
     
         37 . The system of claim  13 , further comprising a pattern matching engine configured to identify potential phishing addresses based on analysis of addresses in plaintext logs. 
     
     
         38 . The system of claim  13 , further comprising a feature extractor configured to extract and analyze features of particular websites. 
     
     
         39 . The system of claim  18 , wherein the feature extractor is configured to compare extracted features for a particular website with pre-stored website features to identify the particular website. 
     
     
         40 . The system of claim  13 , wherein the second subsequent communication is within a limited number of network events relative to the first time; and
 wherein the website classifier is configured to classify the first other network address as a potential phishing website based on a determination that the limited number of network events is smaller than a defined limit value.

Join the waitlist — get patent alerts

Track US2020396252A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.