IP Library Granted Patent US 9,111,090
Granted Patent B2
US 9,111,090 · App. 13/437,122 · Granted Aug 18, 2015

Detection of phishing attempts

Inventors: Amit Klein (Herzliya, IL); Michael Boodaei (Givataim, IL)
Assignee: TRUSTEER, LTD.
G06F21/552G06F21/554H04L63/1483
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,111,090
App. No.
13/437,122
Granted
Aug 18, 2015
Kind
B2
Abstract

A method for alerting a service provider and/or a user of a web browser of a phishing attempt comprises providing on a page that it is desired to protect against phishing, a Javascript that when caused by a phishing page to run not in the context of the original page generates an indication that a phishing attempt may exist.

Claims (18)

1. An anti-phishing system comprising:

a non-transitory, computer-readable storage medium; and

a log-in webpage of a service provider, the log-in webpage stored on the computer-readable storage medium, the log-in webpage comprising Javascript code configured to

determine, when the Javascript code is running, that the Javascript code is running in the context of a phishing website,

add, in response to determining that the Javascript code is running in the context of the phishing website, an onSubmit event handler on the phishing website,

generate, in response to determining that the Javascript code is running in the context of the phishing website, an indication of a phishing attempt,

detect, using the onSubmit event handler, when a user submits credentials in the context of said phishing website,

recover said credentials using said onSubmit event handler, and

send said indication of a phishing attempt and said credentials to a server configured to protect an account of the user.

2. An anti-phishing method comprising:

configuring a log-in webpage stored on a non-transitory, computer-readable storage medium of a service provider, the log-in webpage comprising Javascript code configured to

determine, when the Javascript code is running, that the Javascript code is running in the context of a phishing website,

add, in response to determining that the Javascript code is running in the context of the phishing website, an onSubmit event handler on the phishing website,

generate, in response to determining that the Javascript code is running in the context of the phishing website, an indication of a phishing attempt

detect, using the onSubmit event handler, when a user submits credentials in the context of said phishing website,

recover said credentials using said onSubmit event handler, and

send said indication of a phishing attempt and said credentials to a server configured to protect an account of the user; and

providing access to the log-in web page.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 23, 2017
From: TRUSTEER, LTD.
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 041060/0411 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 7, 2012
From: KLEIN, AMIT; BOODAEI, MICHAEL
To: TRUSTEER LTD.
Reel/Frame 028336/0547 →
Continuity (1)
Related Publication 20130263264A1 · Oct 3, 2013