IP Library Granted Patent US 8,321,934
Granted Patent B1
US 8,321,934 · App. 12/115,352 · Granted Nov 27, 2012

Anti-phishing early warning system based on end user data submission statistics

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,321,934
App. No.
12/115,352
Granted
Nov 27, 2012
Kind
B1
Abstract

Websites used for phishing are detected by analyzing end user confidential data submission statistics. A central process receives data indicating confidential information submitted to websites from a plurality of user computers. The received data is aggregated and analyzed, for example through statistical profiling. Through the analysis of the aggregated data, anomalous behavior concerning submission of confidential information to websites is detected, such is an unexpected, rapid increase in the amount of confidential information submitted to a given website. Responsive to detecting the anomalous behavior, further action is taken to protect users from submitting confidential information to that website. For example, an alert can be sent, a protective measure against the site can be published, the site can be added to a blacklist or a procedure to have the site shut down can be initiated.

Claims (50)

1. A computer implemented method for detecting malicious websites based on end user data submission statistics, the method comprising the steps of:

receiving data from each of a plurality of user computers which has been marked by the user computers as confidential information;

aggregating data received from the plurality of user computers;

analyzing the aggregated data, comprising:

performing adaptive statistical anomaly detection, by applying statistical usage profiling to continuously modify a baseline;

measuring confidential information disclosure activity in relation to the baseline;

comparing the short-term profile to the long-term profile; and

detecting a statistically significant deviation between the two profiles, the deviation indicating a short term increase in submission of confidential information to a website;

based on the statistical analysis, detecting anomalous behavior concerning submission of aggregated confidential information received from the plurality of user computers to a website; and

responsive to detecting the anomalous behavior concerning submission of confidential information to a website, performing at least one additional step to protect users from submitting confidential information to that website.

2. The method of claim 1 wherein detecting anomalous behavior concerning submission of aggregated confidential information to a website further comprises:

detecting an increase in submission of confidential information to a website.

3. The method of claim 1 further comprising:

over a period of time, incorporating short-term observed usage into the long-term usage profile, to account for legitimate changes in website behaviors.

4. The method of claim 1 wherein performing at least one additional step to protect users from submitting confidential information to the website further comprises:

transmitting an alert to at least one destination from a group of destinations comprising: an automated computer security system, a technician, a system administrator and a user.

5. The method of claim 1 wherein performing at least one additional step to protect users from submitting confidential information to the website further comprises performing at least one step from a group of steps consisting of:

publishing a new rule to protect against submission of confidential information to the website;

adding the website to a list of known bad sites;

transmitting a warning concerning the site to at least one user; and

initiating a process to have the website shut down.

6. At least one non-transitory computer readable medium storing a computer program product for detecting malicious websites based on end user data submission statistics, the computer program product comprising:

program code for receiving data from each of a plurality of user computers which has been marked by the user computers as confidential information;

program code for aggregating data received from the plurality of user computers;

program code for analyzing the aggregated data, comprising:

performing adaptive statistical anomaly detection, by applying statistical usage profiling to continuously modify a baseline;

measuring confidential information disclosure activity in relation to the baseline;

comparing the short-term profile to the long-term profile; and

detecting a statistically significant deviation between the two profiles, the deviation indicating a short term increase in submission of confidential information to a website

based on the statistical analysis, program code for detecting anomalous behavior concerning submission of aggregated confidential information received from the plurality of user computers to a website; and

program code for responsive to detecting the anomalous behavior concerning submission of confidential information to a website, performing at least one additional step to protect users from submitting confidential information to that website.

7. The computer program product of claim 6 wherein the program code for detecting anomalous behavior concerning submission of aggregated confidential information to a website further comprises:

program code for detecting an increase in submission of confidential information to a website.

8. The computer program product of claim 6 further comprising:

program code for, over a period of time, incorporating short-term observed usage into the long-term usage profile, to account for legitimate changes in website behaviors.

9. The computer program product of claim 6 further comprising:

program code for, responsive to detecting the anomalous behavior concerning submission of confidential information to a website, determining the website is being used for phishing.

10. The computer program product of claim 6 wherein the program code for performing at least one additional step to protect users from submitting confidential information to the website further comprises:

program code for transmitting an alert to at least one destination from a group of destinations comprising:

an automated computer security system, a technician, a system administrator and a user.

11. The computer program product of claim 6 wherein the program code for performing at least one additional step to protect users from submitting confidential information to the website further comprises program code for performing at least one step from a group of steps consisting of:

publishing a new rule to protect against submission of confidential information to the website;

adding the website to a list of known bad sites;

transmitting a warning concerning the site to at least one user; and

initiating a process to have the website shut down.

12. A computer system for detecting malicious websites based on end user data submission statistics, the computer system comprising:

an interface to receive data from each of a plurality of user computers which has been marked by the user computers as confidential information;

a database to aggregate data received from the plurality of user computers;

an anomalous behavior ID component to analyze the aggregated data, and to detect anomalous behavior concerning submission of aggregated confidential information received from the plurality of user computers to a website, wherein analyzing the aggregated data comprises performing adaptive statistical anomaly detection, by applying statistical usage profiling to continuously modify a baseline, measuring confidential information disclosure activity in relation to the baseline, comparing the short-term profile to the long-term profile and detecting a statistically significant deviation between the two profiles, the deviation indicating a short term increase in submission of confidential information to a website; and

a reaction component to, responsive to detecting the anomalous behavior concerning submission of confidential information to a website from the statistical analysis, perform at least one additional step to protect users from submitting confidential information to that website.

Assignments (4)
NOTICE OF SUCCESSION OF AGENCY (REEL 050926 / FRAME 0560) Recorded Sep 13, 2022
From: JPMORGAN CHASE BANK, N.A.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 061422/0371 →
SECURITY AGREEMENT Recorded Sep 13, 2022
From: NORTONLIFELOCK INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062220/0001 →
CHANGE OF NAME Recorded Jun 18, 2020
From: SYMANTEC CORPORATION
To: NORTONLIFELOCK INC.
Reel/Frame 053306/0878 →
SECURITY AGREEMENT Recorded Nov 4, 2019
From: SYMANTEC CORPORATION; BLUE COAT LLC; LIFELOCK, INC,; SYMANTEC OPERATING CORPORATION
To: JPMORGAN, N.A.
Reel/Frame 050926/0560 →