Systems and methods for identifying phishing websites
Abstract
Systems and methods are provided for automatically detecting phishing attacks. A sequence of network traffic events may be detecting within network traffic, the sequence including an initial communication from a network address to a first other network address, a first subsequent communication from the first other network address at a first time, and a second subsequent communication from the network address to a second other network address at a second time subsequent to the first time. The first other network address may be classified as a potential phishing website based on determining that the second other network address is not related to the first other network address, and that a time difference between the second time and the first time meets predefined criteria. Protective measures may be taken in response to the classifying, with the protective measures including at least blocking the first other network address.
Claims
exact text as granted — not AI-modified1 - 20 . (canceled)
21 . A method for automatic detection of phishing websites, comprising:
detecting within network traffic a sequence of network traffic events that comprises at least:
an initial communication from a network address to a first other network address;
a first subsequent communication to the initial communication from the first other network address at a first time; and
a second subsequent communication from the network address to a second other network address at a second time subsequent to the first time;
classifying the first other network address as a potential phishing website; wherein the classifying comprises:
determining that the second other network address is not related to the first other network address; and
determining that a time difference between the second time and the first time meets predefined criteria; and
taking one or more protective measures in response to the classifying, wherein the one or more protective measures comprise blocking the first other network address.
22 . The method of claim 21 , comprising monitoring the network traffic using a log of network traffic events, and wherein the log has a machine readable log format, and comprises network addresses of requested and/or responding sites.
23 . The method of claim 21 , wherein the second subsequent communication is within a limited number of network events relative to the first time; and comprising:
classifying the first other network address as a potential phishing website based on a determination that the limited number of network events is smaller than a defined limit value.
24 . The method of claim 24 , wherein the defined limit value is 5 or 3.
25 . The method of claim 21 , wherein the pre-defined criteria comprise the time difference between the second time and the first time being smaller than a defined time value.
26 . The method of claim 26 , wherein the defined time value is smaller than 1 second, and preferably smaller than 0.1 seconds.
27 . A method for protecting websites from phishing attacks, comprising:
detecting within network traffic a communication from a network address to a target website; evaluating network events involving the network address prior to the detected communication to detect a communication with the network address to a website not related to the target website, wherein the evaluating comprises obtaining time measurements that are independent of network latency; classifying the prior website as potential phishing website; and taking one or more protective measures in response to the classifying, wherein the one or more protective measures comprise blocking the prior website.
28 . The method of claim 27 , comprising monitoring the network traffic using a log of network traffic events generated based on the network traffic.
29 . The method of claim 28 , wherein the log is configured based on a machine readable log format, and comprises network addresses of requested and/or responding sites.
30 . The method of claim 27 , wherein the evaluation is limited to network traffic events involving the network address within a limited number of network traffic events in a sequence of network traffic events.
31 . The method of claim 10 , wherein the limited number of network traffic events is 5 or 3.
32 . The method of claim 10 , wherein the time window is smaller than 1 second, and preferably smaller than 0.1 seconds.
33 . A system for the automated detection of phishing attacks, comprising:
a network flow correlator configured to detect within network traffic a sequence of network traffic events, wherein such sequence comprises:
an initial communication from a network address to a first other network address;
a first subsequent communication to the initial communication from the first other network address at a first time; and
a second subsequent communication from the network address to a second other network address at a second time subsequent to the first time; and
a website classifier configured to classify the first other network address as a potential phishing website; wherein the classifying comprises:
a determination that the second other network address is not related to the first other network address, and
a determination that a time difference between the second time and the first time meets predefined criteria; and
wherein the system is configured to take one or more protective measures in response to the classifying, wherein the one or more protective measures comprise blocking the first other network address.
34 . The system of claim 13 , further comprising a network traffic monitor configured to monitor network traffic; and
wherein the network traffic monitor is configured to generate a log of network traffic events for use during monitoring the network traffic.
35 . The system of claim 14 , wherein the log has a machine readable log format, and comprises network addresses of requested and/or responding sites.
36 . The system of claim 13 , further comprising an address collector configured to collect addresses corresponding to requested and/or responding sites from one or more different sources.
37 . The system of claim 13 , further comprising a pattern matching engine configured to identify potential phishing addresses based on analysis of addresses in plaintext logs.
38 . The system of claim 13 , further comprising a feature extractor configured to extract and analyze features of particular websites.
39 . The system of claim 18 , wherein the feature extractor is configured to compare extracted features for a particular website with pre-stored website features to identify the particular website.
40 . The system of claim 13 , wherein the second subsequent communication is within a limited number of network events relative to the first time; and
wherein the website classifier is configured to classify the first other network address as a potential phishing website based on a determination that the limited number of network events is smaller than a defined limit value.Join the waitlist — get patent alerts
Track US2020396252A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.