IP Library Granted Patent US 12,712,913
Granted Patent B2
US 12,712,913 · App. 18/125,916 · Granted Aug 18, 2026

Machine learning for visual similarity-based phishing detection

Inventors: Haitao Li (Coquitlam, CA); Lisheng Ryan Sun (Burnaby, CA)
Assignee: Fortinet, Inc.
H04L63/1483
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,712,913
App. No.
18/125,916
Filed
Mar 24, 2023
Granted
Aug 18, 2026
Kind
B2
Examiner
DO, KHANG D
Art Unit
2492
USPC
726/23
Abstract

In one embodiment, a similarity index is calculated from characteristics of a suspected phishing web page to a database of known phishing web pages. The characteristics derive from both HTML tags of the suspected phishing web page and a screenshot of the suspected phishing web page. With machine learning using the similarity index as an input, a probability is estimated that the suspected web page comprises a known phishing web page from the database of known phishing web pages. A known phishing web page is selected from one or more candidates known phishing web pages, based on having a highest probability.

Claims (30)

1 . A computer-implemented method in a network device for web site phishing detection using machine learning of web site similarity without dependence on web site similarity thresholds, the method comprising:

calculating a similarity index from characteristics of a suspected phishing web page to a database of known phishing web pages, wherein the characteristics derive from both Hyper Text Markup Language (HTML) tags of the suspected phishing web page and a screenshot of the suspected phishing web page;

estimating, with machine learning using the similarity index as an input, a probability that the suspected web page comprises each of one or more candidate known phishing web pages from the database of known phishing web pages;

selecting a known phishing web page from the one or more candidate known phishing web pages, based on having a highest probability, among the one or more candidate known phishing web pages, that the suspected web page comprises the known phishing web page;

determining if the estimated probability of the selected phishing web page exceeds a probability threshold; and

responsive to exceeding the probability threshold, taking a security action to prevent actuation of the phishing web page.

2 . The method of claim 1 , wherein the estimated probability is from a Bayesian Classifier.

3 . The method of claim 1 , wherein the similarity index calculation is based at least in part on a Jaccard similarity coefficient.

4 . The method of claim 1 , wherein the estimated probability is based at least in part on a Hamming distance.

5 . A non-transitory computer-readable medium storing source code in a network device that, when executed by a processor, performs a method for web site phishing detection using machine learning of web site similarity without dependence on web site similarity thresholds, the method comprising:

calculating a similarity index from characteristics of a suspected phishing web page to a database of known phishing web pages, wherein the characteristics derive from both Hyper Text Markup Language (HTML) tags of the suspected phishing web page and a screenshot of the suspected phishing web page;

estimating, with machine learning using the similarity index as an input, a probability that the suspected web page comprises each of one or more candidate known phishing web pages from the database of known phishing web pages;

selecting a known phishing web page from the one or more candidate known phishing web pages, based on having a highest probability, among the one or more candidate known phishing web pages, that the suspected web page comprises the known phishing web page;

determining if the estimated probability of the selected phishing web page exceeds a probability threshold; and

responsive to exceeding the probability threshold, taking a security action to prevent actuation of the phishing web page.

6 . The method of claim 5 , wherein the estimated probability is from a Bayesian Classifier.

7 . The method of claim 5 , wherein the similarity index calculation is based at least in part on a Jaccard similarity coefficient.

8 . The method of claim 5 , wherein the estimated probability is based at least in part on a Hamming distance.

9 . A network device for web site phishing detection using machine learning of web site similarity without dependence on web site similarity thresholds, the network device comprising:

a processor;

a network interface communicatively coupled to the processor and to a Wireless Local Area Network (WLAN); and

a memory, communicatively coupled to the processor and storing:

a page similarity module to calculate a similarity index from characteristics of a suspected phishing web page to a database of known phishing web pages, wherein the characteristics derive from both Hyper Text Markup Language (HTML) tags of the suspected phishing web page and a screenshot of the suspected phishing web page;

a phishing probability module to estimate, with machine learning using the similarity index as an input, a probability that the suspected web page comprises each of one or more candidate known phishing web pages from the database of known phishing web pages;

a phishing page selection module to select a known phishing web page from the one or more candidate known phishing web pages, based on having a highest probability, among the one or more candidate known phishing web pages, that the suspected web page comprises the known phishing web page;

a probability threshold module to determine if the estimated probability of the selected phishing web page exceeds a probability threshold; and

a security action module to, responsive to exceeding the probability threshold, take a security action to prevent actuation of the web page.

10 . The network device of claim 9 , wherein the estimated probability is from a Bayesian Classifier.

11 . The network device of claim 9 , wherein the similarity index calculation is based at least in part on a Jaccard similarity coefficient.

12 . The network device of claim 9 , wherein the estimated probability is based at least in part on a Hamming distance.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 24, 2023
From: LI, HAITAO; SUN, LISHENG RYAN
To: FORTINET, INC.
Reel/Frame 063091/0521 →
Continuity (2)
Continuation In Part 16583707 · Sep 26, 2019
Related Publication 20230231879A1 · Jul 20, 2023
References Cited (41)
US 8495735B1 · Warner · 2013 [cited by examiner]
US 8984640B1 · Emigh · 2015 [cited by applicant]
US 9292493B2 · Chandramouli · 2016 [cited by examiner]
US 10129276B1 · Raviv · 2018 [cited by examiner]
US 10834128B1 · Rajagopalan · 2020 [cited by examiner]
US 10904286B1 · Liu · 2021 [cited by examiner]
US 11146576B1 · Mushtaq · 2021 [cited by examiner]
US 12021894B2 · Clausen · 2024 [cited by examiner]
US 12238138B2 · Zverkov · 2025 [cited by examiner]
US 20080172738A1 · Bates · 2008 [cited by examiner]
US 20080235103A1 · Baccas · 2008 [cited by examiner]
US 20110283361A1 · Perdisci · 2011 [cited by applicant]
US 20120227104A1 · Sinha · 2012 [cited by examiner]
US 20150067839A1 · Wardman · 2015 [cited by examiner]
US 20180063190A1 · Wright · 2018 [cited by examiner]
US 20180343283A1 · Goutal · 2018 [cited by applicant]
US 20200036751A1 · Kohavi · 2020 [cited by applicant]
US 20200226214A1 · Reddekopp · 2020 [cited by applicant]
US 20200311790A1 · Keren · 2020 [cited by applicant]
US 20200314122A1 · Jones · 2020 [cited by examiner]
US 20200366712A1 · Onut · 2020 [cited by examiner]
US 20200409988A1 · Singh · 2020 [cited by applicant]
US 20210099484A1 · Li · 2021 [cited by examiner]
US 20210176274A1 · Ben David · 2021 [cited by examiner]
US 20210203693A1 · Clausen · 2021 [cited by examiner]
US 20210248624A1 · Keren · 2021 [cited by examiner]
US 20220030029A1 · Kagan · 2022 [cited by examiner]
US 20220070216A1 · Kohavi · 2022 [cited by examiner]
US 20220385694A1 · Zverkov · 2022 [cited by examiner]
US 20230033134A1 · Kurrasch · 2023 [cited by examiner]
US 20230082481A1 · Azarafrooz · 2023 [cited by examiner]
US 20230231879A1 · Li · 2023 [cited by examiner]
US 20230262078A1 · Rozhnov · 2023 [cited by examiner]
US 20230344866A1 · Shao · 2023 [cited by examiner]
US 20230353595A1 · Hu · 2023 [cited by examiner]
US 20240114053A1 · Katz · 2024 [cited by examiner]
US 20240161038A1 · Sloane · 2024 [cited by examiner]
US 20240195836A1 · Gardezi · 2024 [cited by examiner]
US 20240202405A1 · Lang · 2024 [cited by examiner]
US 20240250987A1 · Annapureddy · 2024 [cited by examiner]
US 20250088535A1 · Li · 2025 [cited by examiner]