IP Library Granted Patent US 11,570,211
Granted Patent B1
US 11,570,211 · App. 17/157,968 · Granted Jan 31, 2023

Detection of phishing attacks using similarity analysis

Inventor: Rundong Liu (Santa Clara, CA)
Assignee: FireEye Security Holdings US LLC
H04L63/1483H04L9/3236
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,570,211
App. No.
17/157,968
Granted
Jan 31, 2023
Kind
B1
Abstract

A computerized system and method to detect phishing cyber-attacks is described. The approach entails analyzing one or more displayable images of a webpage referenced by a URL to ascertain whether the one or more displayable images, and thus the webpage and potentially an email including the URL, are part of a phishing cyber-attack.

Claims (42)

1. A computerized method for detecting a phishing cyber-attack, the method comprising:

generating one or more properties associated with each of a plurality of images, the plurality of images included as part of a webpage being an object under analysis;

determining an image score associated with each image of the plurality of images based on a correlation of the one or more properties associated with the image with one or more properties associated with known phishy images being images known to be part of or associated with the phishing cyber-attack; and

generating an object score by combining the image scores of the plurality of images associated with the object.

2. The computerized method of claim 1 further comprising:

generating an alert upon determining that the object, based on the object score, is associated with the phishing cyber-attack.

3. The computerized method of claim 1 , wherein prior to generating the one or more properties, the method further comprising:

analyzing the object to identify suspicious features associated with the plurality of images, the suspicious features being features that cannot be determined to be either benign or malicious based on features known to be benign or malicious.

4. The computerized method of claim 1 , wherein the one or more properties associated with an image of the plurality of images comprise a cryptographic hash of the image.

5. The computerized method of claim 1 , wherein the one or more properties associated with an image of the plurality of images comprise a perceptual hash of the image, the perceptual hash operates as a fingerprint of the image and is derived from features of the image.

6. The computerized method of claim 5 , wherein the perceptual hash is used in determining a similarity between the image and at least one of the known phishy images.

7. The computerized method of claim 1 , further comprising: providing a hash store identifying the one or more properties associated with the known phishy images.

8. The computerized method of claim 1 , wherein the plurality of images comprises two or more images visible to a user when the webpage is displayed.

9. The computerized method of claim 1 , wherein a property of the one or more properties associated with each of the plurality of images comprises a target entity for an email including a Uniform Resource Locator (URL) that is selected to reference the webpage being analyzed.

10. The computerized method of claim 1 , wherein the object score is generated based on a weighting of the image scores by a plurality of factors including (i) a ratio of displayable image area to the entire displayable area of the webpage or (ii) a quantity of phishy images relative to an entire number of images in the webpage.

11. A non-transitory persistent storage including logic, when executed by one or more processors, detect phishing cyber-attacks, comprising:

feature analyzer logic that, when in operation, receives a plurality of images extracted from a webpage being an object under analysis and generates properties associated with each of the plurality of extracted images;

classifier logic that, when in operation, (a) receives at least the properties associated with each of the plurality of extracted images, (b) determines an image score associated with each image of the plurality of extracted images based on a correlation between the properties associated with the image and properties associated with known phishy images being images known to be part of or associated with a phishing cyber-attack, (c) generates an object score by combining the image scores of the plurality of extracted images associated with the object, and (d) classifies the object as being associated with a phishing cyber-attack when the object score exceeds a threshold; and

a reporting engine that, when in operation, generates an alert upon determining, by the classifier logic, that the object is associated with the phishing cyber-attack.

12. The non-transitory persistent storage of claim 11 further comprising:

feature extractor logic that, when in operation, extracts the plurality of images associated with the webpage accessible through a Uniform Resource Locator (URL) and being content corresponding to the object.

13. The non-transitory persistent storage of claim 11 further comprising:

dynamic analysis logic that, when in operation, processes the object within an instrumented virtual machine.

14. The non-transitory persistent storage of claim 11 , wherein the one of the properties generated by the feature analyzer logic comprises a cryptographic hash of an image of the plurality of extracted images or a perceptual hash of the image operating as a fingerprint of the image and is derived from features of the image.

15. The non-transitory persistent storage of claim 14 , wherein the classifier logic uses the perceptual hash being one of the properties to determine a similarity between the image and at least one of the known phishy images.

16. The non-transitory persistent storage of claim 11 , wherein the plurality of extracted images provided to the feature analyzer correspond to images visible when the webpage is displayed to a user.

17. The non-transitory persistent storage of claim 11 , wherein the feature analyzer logic, prior to generating the one or more properties, analyzes the object to identify suspicious features associated with the plurality of images, the suspicious features being features that cannot be determined to be either benign or malicious based on features known to be malicious or benign.

18. The non-transitory persistent storage of claim 11 , wherein a property of the one or more properties associated with each of the plurality of images comprises a target entity for an email including a Uniform Resource Locator (URL) that is selected to reference the webpage being analyzed.

19. The non-transitory persistent storage of claim 11 , wherein the object score is generated based on a weighting of the image scores by a plurality of factors including (i) a ratio of displayable image area to the entire displayable area of the webpage or (ii) a quantity of phishy images relative to an entire number of images in the webpage.

20. A system for detecting a phishing cyber-attack, the system comprising:

a feature analyzer to generate one or more properties associated with each of a plurality of images, the plurality of images included as part of a webpage being an object under analysis;

an image classifier communicatively coupled to the feature analyzer, the image classifier to determine an image score associated with each image of the plurality of images based on a correlation of the one or more properties associated with the image with one or more properties associated with known phishy images being images known to be part of or associated with the phishing cyber-attack;

an object classifier communicatively coupled to the image classifier, the object classifier to generate an object score by combining the image scores of the plurality of images associated with the object; and

a reporting engine communicatively coupled to the object classifier, the reporting engine to generate an alert upon determining that the object is associated with the phishing cyber-attack.

21. The system of claim 20 further comprising:

feature extractor logic to extract the plurality of images associated with the webpage accessible through a Uniform Resource Locator (URL) and being content corresponding to the object.

22. The system of claim 20 further comprising:

dynamic analysis logic to process the object within an instrumented virtual machine.

23. The system of claim 20 , wherein the one of the properties generated by the feature analyzer logic comprises a cryptographic hash of an image of the plurality of extracted images or a perceptual hash of the image operating as a fingerprint of the image and is derived from features of the image.

24. The system of claim 20 , wherein the plurality of extracted images provided to the feature analyzer correspond to images visible when the webpage is displayed to a user.

25. The system of claim 20 , wherein the feature analyzer logic, prior to generating the one or more properties, analyzes the object to identify suspicious features associated with the plurality of images, the suspicious features being features that cannot be determined to be either benign or malicious based on features known to be malicious or benign.

26. The system of claim 20 , wherein the object score is generated based on a weighting of the image scores by a plurality of factors including (i) a ratio of displayable image area to the entire displayable area of the webpage or (ii) a quantity of phishy images relative to an entire number of images in the webpage.

Assignments (13)
RELEASE OF SECURITY INTEREST Recorded Aug 16, 2024
From: STG PARTNERS, LLC
To: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
Reel/Frame 068671/0435 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068656/0098 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068657/0843 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068657/0764 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY HOLDINGS LLC; SKYHIGH SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 068657/0666 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068656/0920 →
MERGER Recorded Aug 13, 2024
From: FIREEYE SECURITY HOLDINGS US LLC
To: MUSARUBRA US LLC
Reel/Frame 068581/0279 →
SECURITY INTEREST Recorded Aug 1, 2024
From: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
To: STG PARTNERS, LLC
Reel/Frame 068324/0731 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 21, 2022
From: MANDIANT, INC.
To: FIREEYE SECURITY HOLDINGS US LLC
Reel/Frame 061497/0825 →
CHANGE OF NAME Recorded Sep 21, 2022
From: FIREEYE, INC.
To: MANDIANT, INC.
Reel/Frame 061497/0822 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 11, 2021
From: FIREEYE SECURITY HOLDINGS US LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057772/0791 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Oct 11, 2021
From: FIREEYE SECURITY HOLDINGS US LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057772/0681 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 25, 2021
From: LIU, RUNDONG
To: FIREEYE, INC.
Reel/Frame 055025/0042 →
Cited By (2)
US 12,348,561 US 12,445,488