IP Library Granted Patent US 9,843,602
Granted Patent B2
US 9,843,602 · App. 15/047,055 · Granted Dec 12, 2017

Login failure sequence for detecting phishing

Inventors: Wen-Kwang Tsao (Taipei, TW); Che-Fu Yeh (Taipei, TW); Hong-Che Lin (Taipei, TW)
Assignee: Trend Micro Incorporated
H04L63/1483H04L63/083
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,843,602
App. No.
15/047,055
Granted
Dec 12, 2017
Kind
B2
Abstract

A login page of an online service is received in a user computer. False credentials, such as a false user identifier (ID) and a false password, are entered into the login page to login to the online service. The login page is classified as phishing when the online service does not serve a legitimate login-fail page in response to the entry of the false credentials in the login page.

Claims (20)

1. A computer-implemented method comprising:

detecting, in a user computer, a login page of an online service;

sending a notification from the user computer to a backend system that the login page has been detected in the user computer;

receiving, by the backend system, the login page in the backend system using a network location identifier of the login page included in the notification;

entering, by the backend system, a false credential in the login page received in the backend system to login to the online service;

receiving a login-fail page in the backend system, the login-fail page indicating that the login to the online service using the false credential has failed;

determining, by the backend system, that the login-fail page is not a legitimate login-fail page by comparing the login-fail page to a database of legitimate login-fail pages; and

in response to determining that the login-fail page is not legitimate, preventing credentials from being entered into the login page.

2. The computer-implemented method of claim 1 , further comprising: informing the user computer that the login page received in the user computer is a phishing page in response to determining that the login-fail page is not legitimate.

3. The computer-implemented method of claim 1 , wherein the false credential comprises a false user identifier (ID).

4. The computer-implemented method of claim 1 , wherein the false credential comprises a false password.

5. The computer-implemented method of claim 1 , wherein the false credential is randomly generated.

6. The computer-implemented method of claim 1 , wherein the network location identifier of the login page included in the notification is a uniform resource locator (URL).

7. A system comprising:

a user computer that is configured to receive a login page of an online service and prevent a credential from being entered into the login page when the login page is classified as a phishing page; and

a backend system that is configured to receive from the user computer a notification regarding the login page, receive the login page in the backend system in response to receiving the notification, to login to the online service by entering a false credential in the login page received in the backend system, receive a login-fail page that indicates that the login to the online service has failed, evaluate whether or not the login-fail page is legitimate to determine if the login page received in the user computer is a phishing page, and classify the login page as a phishing page when the login-fail page is detected as not legitimate by comparing the login-fail page to a database of legitimate login-fail pages.

8. The system of claim 7 , wherein the user computer and the backend system communicate over the Internet.

9. The system of claim 7 , wherein the false credential is a false user identifier (ID).

10. The system of claim 7 , wherein the false credential is a false password.

11. The system of claim 7 , wherein the false credential is randomly generated.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 8, 2016
From: TSAO, WEN-KWANG; YEH, CHE-FU; LIN, HONG-CHE
To: TREND MICRO INCORPORATED
Reel/Frame 037920/0525 →
Continuity (1)
Related Publication 20170244755A1 · Aug 24, 2017