IP Library Granted Patent US 10,200,381
Granted Patent B2
US 10,200,381 · App. 14/818,875 · Granted Feb 5, 2019

Systems and methods for phishing and brand protection

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,200,381
App. No.
14/818,875
Granted
Feb 5, 2019
Kind
B2
Abstract

This disclosure describes systems, methods, and computer-readable media related to phishing and brand protection via copycat detection. In some embodiments, a temporary page profile associated with a webpage may be generated. The temporary page profile may include an image component, a geometry component, a style component, and a link component. One or more baseline page profiles may be retrieved. The temporary page profile and the one or more baseline page profiles may be compared. It may be determined that the temporary page profile does not match the one or more baseline page profiles. An alert may be generated to display to a user indicating that fraud has been detected for the webpage.

Claims (38)

1. A storage disk or storage device comprising computer-executable instructions which, when executed by a processor, cause the processor to at least:

calculate a first hash of a first image in a webpage and a second hash of a second image in the webpage, the second image different from the first image, the first hash separate from the second hash;

generate an image component, a geometry component, a style component, and a link component of the webpage, the image component including the first hash and the second hash;

generate a temporary page profile associated with the webpage using the image component, the geometry component, the style component, and the link component;

retrieve one or more baseline page profiles;

compare the temporary page profile to the one or more baseline page profiles using a fuzzy matching MinHash algorithm;

determine that the temporary page profile does not match the one or more baseline page profiles; and

generate, based on the determination that the temporary page profile does not match the one or more baseline profiles, an alert to display to a user indicating that fraud has been detected for the webpage.

2. The storage disk or storage device comprising of claim 1 , wherein the instructions cause the processor to add the webpage to a white list in response to an input from the user.

3. The storage disk or storage device comprising of claim 1 , wherein the instructions cause the processor to generate the temporary page profile associated with the webpage in response to a triggering event indicating potential fraud associated with the webpage.

4. The storage disk or storage device comprising of claim 1 , wherein the instructions cause the processor to store the temporary page profile as one of the baseline page profiles.

5. The storage disk or storage device comprising of claim 1 , wherein the instructions cause the processor to initiate transmission of a report to a threat analyzer, the report indicating that the webpage is fraudulent, the report to include the temporary page profile and the baseline page profile.

6. A system comprising:

at least one memory including computer-executable instructions; and

at least one processor to access the at least one memory and to execute the computer-executable instructions to:

calculate a first hash of a first image in a webpage and a second hash of a second image in the webpage, the second image different from the first image, the first hash separate from the second hash;

generate an image component, a geometry component, a style component, and a link component of the webpage, the image component including;

generate a temporary page profile associated with the webpage using the image component, the geometry component, the style component, and the link component;

retrieve one or more baseline page profiles;

compare the temporary page profile to the one or more baseline page profiles using a fuzzy matching MinHash algorithm;

determine that the temporary page profile does not match the one or more baseline page profiles; and

generate, based on the determination that the temporary page profile does not match the one or more baseline profiles, an alert to display to a user indicating that fraud has been detected for the webpage.

7. The system of claim 6 , wherein the at least one processor is to add the webpage to a white list in response to an indication from the user.

8. The system of claim 6 , wherein the at least one processor is to generate the temporary page profile associated with the webpage in response to a triggering event indicating potential fraud associated with the webpage.

9. The system of claim 6 , wherein the at least one processor is to initiate storing the temporary page profile as one of the baseline page profiles.

10. The system of claim 6 , wherein the least one processor is to initiate transmission of a report to a threat analyzer, the report indicating that the webpage is fraudulent, the report to include the temporary page profile and the baseline page profile.

11. A method to identify a phishing attempt from a webpage, the method comprising:

calculating, by executing an instruction with a processor, a first hash of a first image in the webpage and a second hash of a second image in the webpage, the second image different from the first image, the first hash separate from the second hash;

generating, by executing an instruction with the processor, an image component, a geometry component, a style component, and a link component of the webpage, the image component including the first hash and the second hash;

generating, by executing an instruction with the processor, a temporary page profile associated with the webpage using the image component, the geometry component, the style component, and the link component;

retrieving one or more baseline page profiles;

comparing, by executing an instruction with the processor, the temporary page profile to the one or more baseline page profiles using a fuzzy matching MinHash algorithm;

determining, by executing an instruction with the processor, that the temporary page profile does not match the one or more baseline page profiles; and

generating, by executing an instruction with the processor, based on the determination that the temporary page profile does not match the one or more baseline profiles, an alert to display to a user indicating that fraud has been detected for the webpage.

12. The method of claim 11 , wherein the alert includes options displayed to the user and the method further includes adding the webpage to a whitelist in response to an input from the user.

13. The method of claim 11 , further including generating the temporary page profile associated with the webpage in response to a triggering event indicating potential fraud associated with the webpage.

14. The method of claim 11 , further including initiating storing the temporary page profile as one of the baseline page profiles.

15. The method of claim 11 , further including initiating transmission of a report to a threat analyzer, the report indicating that the webpage is fraudulent, the report to include the temporary page profile and the baseline page profile.

Assignments (11)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045056/0676 Recorded Mar 2, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 059354/0213 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →
CORRECTIVE ASSIGNMENT TO CORRECT THE SPELLING OF INVENTOR SAMBANDAM'S LAST NAME PREVIOUSLY RECORDED ON REEL 037102 FRAME 0690. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Mar 17, 2017
From: HUNT, SIMON; SAMBANDAM, VENKATA RAMANAN
To: MCAFFEE, INC.
Reel/Frame 042038/0281 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 20, 2015
From: HUNT, SIMON; SAMBANDANM, VENKATA RAMANAN
To: MCAFEE, INC.
Reel/Frame 037102/0690 →