IP Library Granted Patent US 11,146,576
Granted Patent B1
US 11,146,576 · App. 16/580,530 · Granted Oct 12, 2021

Method and system for detecting credential stealing attacks

Inventor: Atif Mushtaq (San Ramon, CA)
Assignee: SLASHNEXT, INC.
H04L63/1416H04L63/1425G06F16/951G06N20/00
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,146,576
App. No.
16/580,530
Granted
Oct 12, 2021
Kind
B1
Abstract

An Active Vision detection method and system for detecting credential stealing attacks using an automated machine-learning page examination engine is provided that may be used to detect both brand-based and custom credential stealing attacks. The approach employs similarity analysis in a two-stage process that may be achieved through supervised or self-learning machine learning techniques and is comparable to human analysis. The Active Vision System is capable of self-learning; every new attack detected by the system becomes part of system's long-term memory making it incrementally more accurate in future predictions using its past experience.

Claims (29)

1. A method for detecting a credential stealing attack comprising:

a. loading a candidate web page into a browser memory;

b. interacting with the candidate web page by responding to one or more tests presented by the candidate web page;

c. collecting data related to a behavior of the candidate web page from the browser memory;

d. determining, using a trained machine learning algorithm, whether the candidate web page is a credential stealing page based on the collected data; and

e. displaying information regarding the candidate web page on a graphical user interface, wherein the displayed information comprises: (i) an identity of an infected machine on a network that has accessed the candidate web page if the candidate web page is determined to be a credential stealing page; and (ii) a feature of the infected machine, wherein the feature is selected from the group consisting of a machine location, a machine usage, a MAC ID, a type of machine, a machine operating system, and an identity of a machine user, and wherein the graphical user interface further allows a user to select the infected machine to view at least one of the following: nature or details regarding a specific machine-specific attack, a specific incident, a compiled set of attacks performed by a particular group, attacks on a particular day or time, and attacks that have occurred from a particular location or region.

2. The method of claim 1 , wherein collecting data in (b) further comprises extracting identity information and a plurality of features of the candidate web page from the browser memory and comparing the identity information and the plurality of features to a plurality of brand profiles.

3. The method of claim 2 , wherein extracting the plurality of features comprises extracting an image, written text, or source code of the candidate web page from the browser memory.

4. The method of claim 2 , further comprising determining that the candidate web page is not a credential stealing page when the candidate identity information matches a brand identity information from at least one of the pluralities of brand profiles.

5. The method of claim 2 , further comprising determining the candidate web page is a replica of a known brand page by: (a) generating a similarity feature set using the plurality of features and corresponding brand features and (b) analyzing the similarity feature set using a machine learning-based classifier.

6. The method of claim 5 , wherein the similarity feature set comprises at least one of: visual similarity features, natural language similarity features, and source code similarity features.

7. The method of claim 1 , wherein interacting with the candidate web page comprises entering an input with aid of a virtual keyboard or virtual mouse.

8. The method of claim 7 , wherein the input comprises a dummy credential.

9. A system for detecting a credential stealing attack comprising:

(i) a memory for storing a set of software instructions,

(ii) one or more processors configured to execute the set of software instructions to implement a page examination engine, wherein the page examination engine is configured to:

a. load a candidate web page into a browser memory;

b. interact with the candidate web page by responding to one or more tests presented by the candidate web page;

c. collect data related to a behavior of the candidate web page from the browser memory;

d. determine, using a trained machine learning algorithm, whether the candidate web page is a credential stealing page based on the collected data; and

e. displaying information regarding the candidate web page on a graphical user interface, wherein the displayed information comprises: (i) an identity of an infected machine on a network that has accessed the candidate web page if the candidate web page is determined to be a credential stealing page; and (ii) a feature of the infected machine, wherein the feature is selected from the group consisting of a machine location, a machine usage, a MAC ID, a type of machine, a machine operating system, and an identity of a machine user, and wherein the graphical user interface further allows a user to select the infected machine to view at least one of the following: nature or details regarding a specific machine-specific attack, a specific incident, a compiled set of attacks performed by a particular group, attacks on a particular day or time, and attacks that have occurred from a particular location or region.

10. The system of claim 9 , wherein collecting data in (b) further comprises extracting identity information and a plurality of features of the candidate web page from the browser memory and comparing the identity information and the plurality of features to a plurality of brand profiles.

11. The system of claim 10 , wherein extracting the plurality of features comprises extracting an image, written text, or source code of the candidate web page from the browser memory.

12. The system of claim 10 , wherein the page examination engine is configured to determine that the candidate web page is not a credential stealing page when the candidate identity information matches a brand identity information from at least one of the pluralities of brand profiles.

13. The system of claim 10 , wherein the page examination engine is configured to determine whether the candidate web page is a replica of a known brand page by: (a) generating a similarity feature set using the plurality of features and corresponding brand features and (b) analyzing the similarity feature set using a machine learning-based classifier.

14. The system of claim 13 , wherein the page examination engine comprises a machine learning-based classifier for determining whether the candidate web page is a replica of a known brand page.

15. The system of claim 14 , wherein an input to the machine learning-based classifier comprises a similarity feature set selected from the group consisting of: visual similarity features, natural language similarity features, and source code similarity features.

16. The system of claim 9 , wherein the page examination engine is configured to interact with the candidate web page by entering an input with aid of a virtual keyboard or virtual mouse.

17. The system of claim 16 , wherein the input comprises a dummy credential.

Assignments (3)
CHANGE OF NAME Recorded Apr 16, 2026
From: SLASHNEXT, INC.
To: SLASHNEXT, LLC
Reel/Frame 075409/0484 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 16, 2026
From: SLASHNEXT, LLC
To: VARONIS SYSTEMS, INC.
Reel/Frame 075409/0567 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 3, 2019
From: MUSHTAQ, ATIF
To: SLASHNEXT, INC.
Reel/Frame 050614/0642 →
Continuity (3)
Continuation In Part 16528356 · Jul 31, 2019
Continuation 15616061 · Jun 7, 2017
Provisional Application 62347514 · Jun 8, 2016
Cited By (9)
US 12,244,561 US 12,316,671 US 12,323,461 US 12,335,305 US 12,413,621 US 12,452,302 US 12,626,260 US 12,688,505 US 12,712,913