IP Library › Granted Patent US 12,401,687
Granted Patent B2
US 12,401,687 · App. 18/140,956 · Granted Aug 26, 2025

Phishing detection via grammatical artifacts

Inventors: German Lancioni (San Jose, CA); Oliver G. Devane (Upton, GB)
Assignee: McAfee, LLC
H04L63/1483G06F40/205G06F40/232G06F40/242
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,401,687
App. No.
18/140,956
Granted
Aug 26, 2025
Kind
B2
Abstract

There is disclosed a method of mitigating phishing, including extracting text from a website under analysis; using a spell check algorithm to compare extracted words or phrases to a language dictionary of words or phrases selected from web pages known to be phishing targets, and using a spell counter to count misspell hits from the spell check algorithm; comparing the extracted words or phrases to a case-sensitive usage reference, and using a usage counter to count mismatched usage hits from the case-sensitive usage reference; combining the spell counter and the usage counter into a combined counter; and using the combined counter to identify the website under analysis as a suspected phishing website and taking a phishing mitigation action.

Claims (36)

1. A computer-implemented method of mitigating phishing, comprising:

extracting text from a website under analysis;

using a spell check algorithm to compare extracted words or phrases to a language dictionary of words or phrases selected from web pages known to be phishing targets, and using a spell counter to count misspell hits from the spell check algorithm;

comparing the extracted words or phrases to a case-sensitive usage reference, and using a usage counter to count mismatched usage hits from the case-sensitive usage reference;

combining the spell counter and the usage counter into a combined counter; and

using the combined counter to identify the website under analysis as a suspected phishing site and taking a phishing mitigation action.

2. The method of claim 1 , wherein the spell check algorithm is case insensitive.

3. The method of claim 1 , wherein the spell check algorithm comprises symmetric delete.

4. The method of claim 1 , wherein combining the spelling counter and the usage counter comprises a weighted sum.

5. The method of claim 1 , wherein combining the spelling counter and the usage counter comprises computing a normalized sum.

6. The method of claim 1 , wherein identifying the website under analysis as a suspected phishing site comprises using the combined counter as an input to a phishing analysis engine.

7. The method of claim 1 , wherein identifying the website under analysis as a suspected phishing site comprises using the combined counter as an input to an artificial intelligence algorithm.

8. The method of claim 1 , wherein identifying the website under analysis as a suspected phishing site comprises determining that the site includes two or more misspellings.

9. The method of claim 1 , wherein identifying the website under analysis as a suspected phishing site comprises determining that the website under analysis includes one or more misspellings, and two or more usage mismatches.

10. The method of claim 1 , wherein the phishing mitigation action comprises decorating the website under analysis for further human or machine analysis.

11. The method of claim 1 , wherein the phishing mitigation action comprises blocking the website under analysis.

12. The method of claim 1 , wherein the phishing mitigation action comprises sending a warning message a user.

13. The method of claim 1 , wherein the usage counter is weighted according to a number of case-sensitive variations of a word or phrase that appear in the case-sensitive usage reference.

14. One or more tangible, nontransitory computer-readable media having stored thereon executable instructions to instruct a processor to:

extract text from a website under analysis;

spell check the extracted text against a language dictionary of words or phrases selected from known non-phishing websites, and accumulate misspell hits into a spelling counter;

compare the spell-checked extracted text to a case-sensitive usage dictionary, and accumulate usage mismatches into a usage counter; and

based on a combination of the spelling counter and usage counter, identify the website under analysis as a suspected phishing website and take a phishing mitigation action.

15. The one or more tangible, nontransitory computer-readable media of claim 14 , wherein the instructions are further to perform a pre-analysis collection phase before extracting text from the website under analysis, comprising selecting a set of web pages known to be phishing targets, collecting common words and phrases from the set of web pages, and building the language dictionary and case-sensitive usage dictionary.

16. The one or more tangible, nontransitory computer-readable media of claim 15 , wherein building the language dictionary comprises building a histogram of most common words and phrases in the set of web pages.

17. The one or more tangible, nontransitory computer-readable media of claim 15 , wherein the set of web pages comprises web pages determined to be most popular as phishing targets.

18. The one or more tangible, nontransitory computer-readable media of claim 15 , wherein the set of web pages comprises pages from a domain that collect sensitive personal or financial data.

19. A computing ecosystem comprising one or more computing apparatus, comprising:

at least one processor circuit;

a memory; and

instructions stored within the memory to instruct the at least one processor circuit to:

collect text from a user input form a website under analysis;

spell check the collected text using a case-insensitive spell check algorithm with a language dictionary of words or phrases selected from user input forms of known non-phishing websites, and accumulate misspell hits into a spelling counter;

compare the spell-checked extracted text to a case-sensitive usage dictionary, and accumulate usage mismatches into a usage counter; and

combine the spelling counter and the usage counter into a combined counter, and based on the combined counter, identify the website under analysis as a suspected phishing website and take a phishing mitigation action.

20. The computing ecosystem of claim 19 , wherein combining the spelling counter and the usage counter comprises a weighted sum or normalized sum.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 28, 2023
From: LANCIONI, GERMAN; DEVANE, OLIVER G.
To: MCAFEE, LLC
Reel/Frame 063479/0801 →
Continuity (1)
Related Publication 20240364736A1 · Oct 31, 2024
References Cited (19)
US 8806622B2 · Waterson et al. · 2014 [cited by applicant]
US 10574696B2 · Celik · 2020 [cited by applicant]
US 10769370B2 · Zhu · 2020 [cited by examiner]
US 12041084B2 · Prakash · 2024 [cited by examiner]
US 20070294352A1 · Shraim et al. · 2007 [cited by applicant]
US 20150200963A1 · Geng · 2015 [cited by examiner]
US 20170075877A1 · Lepeltier · 2017 [cited by examiner]
US 20210021638A1 · Lancioni et al. · 2021 [cited by applicant]
US 20210105298A1 · Nagaraja · 2021 [cited by examiner]
US 20210144174A1 · N · 2021 [cited by applicant]
US 20210176272A1 · Maha et al. · 2021 [cited by applicant]
US 20210377300A1 · Devane et al. · 2021 [cited by applicant]
US 20220217154A1 · Song · 2022 [cited by examiner]
US 20230033134A1 · Kurrasch · 2023 [cited by examiner]
Conneau et al., “Unsupervised Cross-lingual Representation Learning at Scale,” Proceedings of the 58th Annual Meeting of the Association for Computational Linguistics, pp. 8440-8451, dated Jul. 5-10, 2020, 12 pages. [cited by applicant]
Devlin et al., “BERT: Pre-training of Deep Bidirectional Transformers for Language Understanding,” dated May 24, 2019, Proceedings of NAACL-HLT 2019, 16 pages. [cited by applicant]
Huang et al., “Methods and Apparatus to Implement Trusted Transfer Learning on Transformer-Based Phishing Detection,” U.S. Appl. No. 17/941,919, filed Sep. 9, 2022, McAfee, LLC, San Jose, CA, US, 106 pages. [cited by applicant]
Sun et al., “MobileBERT: a Compact Task-Agnostic BERT for Resource-Limited Devices,” arXiv:2004.02984 [cs.CL], submitted Apr. 6, 2020, retrieved from [https://arxiv.org/abs/2004.02984] on Jul. 21, 2022, 13 pages. [cited by applicant]
Van Der Maaten, “Visualizing Data using t-SNE,” dated Nov. 8, 2008, Journal of Machine Learning Research 9 (2008) 2579-2605, 27 pages. [cited by applicant]