IP Library Granted Patent US 11,985,145
Granted Patent B1
US 11,985,145 · App. 17/468,592 · Granted May 14, 2024

Method and system for detecting credential stealing attacks

Inventor: Atif Mushtaq (San Ramon, CA)
Assignee: SLASHNEXT, INC.
H04L63/1416H04L63/1425G06F16/951G06N20/00
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,985,145
App. No.
17/468,592
Granted
May 14, 2024
Kind
B1
Abstract

An Active Vision detection method and system for detecting credential stealing attacks using an automated machine-learning page examination engine is provided that may be used to detect both brand-based and custom credential stealing attacks. The approach employs similarity analysis in a two-stage process that may be achieved through supervised or self-learning machine learning techniques and is comparable to human analysis. The Active Vision System is capable of self-learning; every new attack detected by the system becomes part of system's long-term memory making it incrementally more accurate in future predictions using its past experience.

Claims (28)

1. A method for detecting a credential stealing attack comprising:

(a) using a page rendering module to i) launch an invisible browser window to load and render a candidate web page into a browser memory by opening an URL of the candidate web page inside the invisible browser window, and ii) extract an artifact from the candidate web page rendered and stored in the browser memory, wherein the artifact comprises image and source code extracted from the browser memory;

(b) extracting, by a custom credential stealing feature extractor, different types of features (i) from the artifact of the candidate web page and (ii) from a known custom credential stealing page to generate a custom similarity feature set;

(c) processing the custom similarity feature set using a machine learning algorithm trained classifier to determine whether the candidate page matches the known custom credential stealing page; and

(d) providing a graphical interface for displaying information regarding the candidate web page, the information comprising: (i) an identity of an infected machine on a network that has accessed the candidate web page if the candidate page matches the known custom credential stealing page and (ii) a feature of the infected machine, wherein the feature is selected from the group consisting of a machine location, a machine usage, a MAC ID, a type of machine, a machine operating system, and an identity of a machine user.

2. The method of claim 1 , wherein the custom similarity feature set comprises visual similarity features and source code similarity feature.

3. The method of claim 1 , wherein the artifact further comprises written text from the candidate web page.

4. The method of claim 3 , wherein the custom similarity feature set comprises visual similarity features, natural language similarity features, and source code similarity feature.

5. The method of claim 2 , wherein the custom similarity feature set further comprises a brand logo similarity feature set.

6. The method of claim 5 , wherein the brand logo similarity feature set is generated based on a comparison of the different types of features extracted from the candidate web page and brand logo features extracted from one or more brand logo profiles stored in a brand logo knowledge base.

7. The method of claim 1 , wherein the known custom credential stealing page is retrieved from a custom credential stealing web sites knowledge base.

8. The method of claim 7 , further comprising, upon determining the candidate page matches the known custom credential stealing page, storing the candidate page to the custom credential stealing web sites knowledge base.

9. The method of claim 7 , further comprising, upon determining the candidate page does not match the known custom credential stealing page, retrieving another known custom credential stealing page from the custom credential stealing web sites knowledge base and repeating operations (b)-(c).

10. A system detecting a credential stealing attack comprising:

(i) a memory for storing a set of software instructions,

(ii) one or more processors configured to execute the set of software instructions to implement a page examination engine, wherein the page examination engine is configured to:

(a) use a page rendering module to i) launch an invisible browser window to load and render a candidate web page into a browser memory by opening an URL of the candidate web page inside the invisible browser window, and ii) extract an artifact from the candidate web page rendered and stored in the browser memory, wherein the artifact comprises image and source code extracted from the browser memory;

(b) extract different types of features (i) from the artifact of the candidate web page and (ii) from a known custom credential stealing page to generate a custom similarity feature set; and

(c) process the custom similarity feature set using a machine learning algorithm trained classifier to determine whether the candidate page matches the known custom credential stealing page; and

(iii) a graphical interface for displaying information regarding the candidate web page, the information comprising: (i) an identity of an infected machine on a network that has accessed the candidate web page if the candidate page matches the known custom credential stealing page and (ii) a feature of the infected machine, wherein the feature is selected from the group consisting of a machine location, a machine usage, a MAC ID, a type of machine, a machine operating system, and an identity of a machine user.

11. The system of claim 10 , wherein the custom similarity feature set comprises visual similarity features and source code similarity feature.

12. The system of claim 11 , wherein the artifact further comprises written text from the candidate web page.

13. The system of claim 12 , wherein the custom similarity feature set comprises visual similarity features, natural language similarity features, and source code similarity feature.

14. The system of claim 11 , wherein the custom similarity feature set further comprises a brand logo similarity feature set.

15. The system of claim 14 , wherein the brand logo similarity feature set is generated based on a comparison of the different types of features extracted from the candidate web page and brand logo features extracted from one or more brand logo profiles stored in a brand logo knowledge base.

16. The system of claim 10 , wherein the known custom credential stealing page is retrieved from a custom credential stealing web sites knowledge base.

17. The system of claim 16 , wherein the page examination engine is further configured to: upon determining the candidate page matches the known custom credential stealing page, store the candidate page to the custom credential stealing web sites knowledge base.

18. The system of claim 16 , wherein the page examination engine is further configured to: upon determining the candidate page does not match the known custom credential stealing page, retrieve another known custom credential stealing page from the custom credential stealing web sites knowledge base and repeating operations (b)-(c).

Assignments (3)
CHANGE OF NAME Recorded Apr 16, 2026
From: SLASHNEXT, INC.
To: SLASHNEXT, LLC
Reel/Frame 075409/0484 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 16, 2026
From: SLASHNEXT, LLC
To: VARONIS SYSTEMS, INC.
Reel/Frame 075409/0567 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 8, 2022
From: MUSHTAQ, ATIF
To: SLASHNEXT, INC.
Reel/Frame 059200/0729 →
Continuity (4)
Continuation 16580530 · Sep 24, 2019
Continuation In Part 16528356 · Jul 31, 2019
Continuation 15616061 · Jun 7, 2017
Provisional Application 62347514 · Jun 8, 2016
Cited By (1)
US 12,244,561