IP Library Granted Patent US 12,470,596
Granted Patent B2
US 12,470,596 · App. 18/295,857 · Granted Nov 11, 2025

Model for detecting phishing URLS

Inventors: Yohan Guez (Tel Aviv, IL); Erez Harush (Tel Aviv, IL)
Assignee: Palo Alto Networks, Inc.
H04L63/1483G06V30/18143G06V2201/09
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,470,596
App. No.
18/295,857
Granted
Nov 11, 2025
Kind
B2
Abstract

Methods, storage systems and computer program products implement embodiments of the present invention for protecting a computing device. These embodiments include detecting that an email is received by the computing device, the email including a Uniform Resource Locator (URL) for a web page in a first domain. The web page is retrieved from the domain, and a set of keywords are extracted from the retrieved web page. A query included the set of keywords is submitted to a search engine, and a response to the query is received from the search engine, the response indicating a set of second domain. Finally, in response to detecting that the first domain does not match any of the second domains, an alert for a phishing attack is generated.

Claims (46)

1 . A method for protecting a computing device, comprising:

detecting an email received by the computing device and comprising a Uniform Resource Locator (URL) for a web page in a first domain;

retrieving the web page from the first domain;

determining a plurality of words that would be visible when the web page is rendered;

selecting, from the plurality of words, a set of words to be used as keywords;

submitting, to a search engine, a query comprising the set of keywords;

receiving, from the search engine, a response to the query, the response indicating a set of second domains and respective rankings for the second domains, where the ranking for a given second domain is provided by relative position of the given second domain in the set of second domains and is indicative of a quality of the second domain in relation to the keywords; and

generating an alert for a phishing attack responsively to detecting that either the first domain does not match any of the second domains or the first domain matches a second domain that has a ranking exceeding a specified ranking threshold.

2 . The method according to claim 1 , and further comprising retrieving Hypertext Markup Language (HTML) code associated with the web page, rendering the HTML code, and determining, based on the rendering, the words that would be visible.

3 . The method according to claim 1 , wherein selecting the set of keywords comprises applying a statistical model to the plurality of words so as to rank the words in order of importance, wherein the set of keywords comprises a specific number of the highest ranked words.

4 . The method according to claim 1 , wherein the web page comprises a first web page, wherein the first web page comprises a redirection to a second web page, and wherein selecting the set of keywords comprises determining the plurality of words that would be visible when the second web page is rendered and selecting, from the plurality of words, the set of words to be used as keywords.

5 . The method according to claim 4 , wherein the redirection comprises the first web page redirecting to the second web page within a specified amount of time.

6 . The method according to claim 1 , and further comprising identifying a first owner of the first domain, and identifying respective second owners for the second domains, and wherein detecting that the first domain does not match any of the second domains comprises detecting that the first owner does not match any of the second owners.

7 . The method according to claim 1 , and further comprising generating a screenshot of the retrieved web page, comparing the screenshot to logo images in a set of logo images, each logo image associated with a respective third domain, and generating the alert upon detecting a match between the screenshot and a given logo image in the set of logo images where the third domain associated with the given logo image does not match the first domain.

8 . The method according to claim 7 , wherein comparing the screenshot to the logo images comprises generating a first set of first keypoints for the screenshot, generating respective second sets of second keypoints for the logo images, and comparing the first set to the second sets.

9 . The method according to claim 8 , wherein detecting the match between the generated screenshot and the given logo image comprises detecting at least a specified number of matches between the first set of first keypoints and the second set of second keypoints for the given logo image.

10 . The method according to claim 8 , wherein comparing the first set to the second set comprises measuring respective scale-invariant feature transform (SIFT) distances between the first and the second sets.

11 . The method according to claim 1 , and further comprising generating the alert upon detecting a login form in the retrieved web page.

12 . The method according to claim 11 , wherein detecting the login form comprises rendering HTML code for the retrieved web page, extracting a set of words from the HTML code, comparing the extracted words to a set of login keywords, and detecting a match between a given extracted word and a given login keyword.

13 . The method according to claim 12 , wherein detecting the login form comprises rendering HTML code for the retrieved web page, extracting a set of HTML tags from the HTML code, comparing the extracted words to a set of login tags, and detecting a match between a given extracted word and a given login tag.

14 . The method according to claim 1 , and further comprising ascertaining an age of the first domain, and generating the alert upon detecting that the age exceeds a specified age threshold.

15 . The method according to claim 1 , and further comprising extracting a set of features from the URL, modeling the extracted features so as to classify the URL as either suspicious or unknown, and generating the alert upon classifying the URL as suspicious.

16 . The method according to claim 15 , wherein a given feature comprises a number of times any of one or more specified characters are in the URL.

17 . The method according to claim 15 , wherein a given feature comprises a number of times any of one or more specified words are in the URL.

18 . The method according to claim 15 , wherein a given feature comprises whether or not the web page is hosted by a free hosting service.

19 . The method according to claim 15 , wherein a given feature comprises whether or not the URL comprises an Internet Protocol (IP) address.

20 . The method according to claim 15 , wherein a given feature comprises a number of subdomains in the URL.

21 . The method according to claim 16 , wherein a given feature is selected from a group including a length of a path in the URL, a length of the URL and a length of the domain.

22 . A computing device, comprising:

a memory; and

a processor configured:

to detect an email received by the computing device and comprising a Uniform Resource Locator (URL) for a web page in a first domain,

to retrieve the web page from the first domain,

to determine a plurality of words that would be visible when the web page is rendered,

to select, from the plurality of words, a set of words to be used as keywords,

to submit, to a search engine, a query comprising the set of keywords,

to receive, from the search engine, a response to the query, the response indicating a set of second domains and respective rankings for the second domains, where the ranking for a given second domain is provided by relative position of the given second domain in the set of second domains and is indicative of a quality of the second domain in relation to the keywords, and

to generate an alert for a phishing attack responsive to detecting that either the first domain does not match any of the second domains or the first domain matches a second domain that has a ranking exceeding a specified ranking threshold.

23 . A computer software product for protecting a computing device, the computer software product comprising a non-transitory computer-readable medium, in which program instructions are stored, which instructions, when read by a computer, cause the computer:

to detect an email received by the computing device and comprising a Uniform Resource Locator (URL) for a web page in a first domain;

to retrieve the web page from the first domain;

to determine a plurality of words that would be visible when the web page is rendered;

to select, from the plurality of words, a set of words to be used as keywords;

to submit, to a search engine, a query comprising the set of keywords;

to receive, from the search engine, a response to the query, the response indicating a set of second domains and respective rankings for the second domains, where the ranking for a given second domain is provided by relative position of the given second domain in the set of second domains and is indicative of a quality of the second domain in relation to the keywords; and

to generate an alert for a phishing attack responsive to detecting that either the first domain does not match any of the second domains or the first domain matches a second domain that has a ranking exceeding a specified ranking threshold.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 3, 2024
From: PALO ALTO NETWORKS (ISRAEL ANALYTICS) LTD.
To: PALO ALTO NETWORKS INC.
Reel/Frame 068823/0886 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 5, 2023
From: GUEZ, YOHAN; HARUSH, EREZ
To: PALO ALTO NETWORKS (ISRAEL ANALYTICS) LTD.
Reel/Frame 063225/0171 →
Continuity (1)
Related Publication 20240340313A1 · Oct 10, 2024
References Cited (169)
US 8146146B1 · Coviello et al. · 2012 [cited by applicant]
US 8245304B1 · Chen et al. · 2012 [cited by applicant]
US 8285830B1 · Stout et al. · 2012 [cited by applicant]
US 8316440B1 · Hsieh et al. · 2012 [cited by applicant]
US 8555388B1 · Wang et al. · 2013 [cited by applicant]
US 8561188B1 · Wang et al. · 2013 [cited by applicant]
US 8677487B2 · Balupari et al. · 2014 [cited by applicant]
US 8713674B1 · Geide · 2014 [cited by applicant]
US 8826434B2 · Merza · 2014 [cited by examiner]
US 8893286B1 · Oliver · 2014 [cited by examiner]
US 8955114B2 · Dolan-Gavitt et al. · 2015 [cited by applicant]
US 8966625B1 · Zuk et al. · 2015 [cited by applicant]
US 9038178B1 · Lin et al. · 2015 [cited by applicant]
US 9130982B2 · Gottlieb et al. · 2015 [cited by applicant]
US 9147071B2 · Sallam · 2015 [cited by applicant]
US 9154516B1 · Vaystikh et al. · 2015 [cited by applicant]
US 9215239B1 · Wang et al. · 2015 [cited by applicant]
US 9342691B2 · Maestas · 2016 [cited by applicant]
US 9378361B1 · Yen et al. · 2016 [cited by applicant]
US 9386028B2 · Altman · 2016 [cited by applicant]
US 9462008B2 · Bartos et al. · 2016 [cited by applicant]
US 9998484B1 · Buyukkayhan et al. · 2018 [cited by applicant]
US 10148690B2 · Shen et al. · 2018 [cited by applicant]
US 10257295B1 · Alpert et al. · 2019 [cited by applicant]
US 10425436B2 · Firstenberg · 2019 [cited by examiner]
US 10574681B2 · Meshi et al. · 2020 [cited by applicant]
US 10587647B1 · Khalid et al. · 2020 [cited by applicant]
US 10601866B2 · Bartik · 2020 [cited by examiner]
US 10623446B1 · Stoler · 2020 [cited by applicant]
US 11457040B1 · Sole et al. · 2022 [cited by applicant]
US 11516232B1 · Sumpter et al. · 2022 [cited by applicant]
US 20030105980A1 · Challener et al. · 2003 [cited by applicant]
US 20030110379A1 · Ylonen et al. · 2003 [cited by applicant]
US 20060200487A1 · Adelman et al. · 2006 [cited by applicant]
US 20070064617A1 · Reves · 2007 [cited by applicant]
US 20070143852A1 · Keanini et al. · 2007 [cited by applicant]
US 20080034425A1 · Overcash et al. · 2008 [cited by applicant]
US 20080060054A1 · Srivastava · 2008 [cited by applicant]
US 20080082662A1 · Dandliker et al. · 2008 [cited by applicant]
US 20080256622A1 · Neystadt et al. · 2008 [cited by applicant]
US 20090119397A1 · Neerdaels · 2009 [cited by applicant]
US 20100042622A1 · Matkowsky · 2010 [cited by applicant]
US 20100235915A1 · Memon et al. · 2010 [cited by applicant]
US 20110016525A1 · Jeong et al. · 2011 [cited by applicant]
US 20110066624A1 · Turakhia · 2011 [cited by examiner]
US 20110185429A1 · Sallam · 2011 [cited by applicant]
US 20110239300A1 · Klein et al. · 2011 [cited by applicant]
US 20110283357A1 · Pandrangi et al. · 2011 [cited by applicant]
US 20110302656A1 · El-Moussa · 2011 [cited by applicant]
US 20120158626A1 · Zhu · 2012 [cited by examiner]
US 20130007233A1 · Lv et al. · 2013 [cited by applicant]
US 20130031625A1 · Lim · 2013 [cited by applicant]
US 20140007238A1 · Magee et al. · 2014 [cited by applicant]
US 20140165207A1 · Engel et al. · 2014 [cited by applicant]
US 20140181973A1 · Lee et al. · 2014 [cited by applicant]
US 20150128263A1 · Raugas et al. · 2015 [cited by applicant]
US 20150149530A1 · Maret et al. · 2015 [cited by applicant]
US 20150170072A1 · Grant et al. · 2015 [cited by applicant]
US 20150172300A1 · Cochenour · 2015 [cited by applicant]
US 20150195299A1 · Zoldi et al. · 2015 [cited by applicant]
US 20150358344A1 · Mumcuoglu et al. · 2015 [cited by applicant]
US 20150365437A1 · Bell, Jr. et al. · 2015 [cited by applicant]
US 20150373039A1 · Wang · 2015 [cited by applicant]
US 20150373043A1 · Wang et al. · 2015 [cited by applicant]
US 20160042287A1 · Eldardiry et al. · 2016 [cited by applicant]
US 20160057165A1 · Thakar et al. · 2016 [cited by applicant]
US 20160099852A1 · Cook et al. · 2016 [cited by applicant]
US 20160104203A1 · Roosenraad et al. · 2016 [cited by applicant]
US 20160134651A1 · Hu et al. · 2016 [cited by applicant]
US 20160150004A1 · Hentunen · 2016 [cited by applicant]
US 20160156655A1 · Lotem et al. · 2016 [cited by applicant]
US 20160234167A1 · Engel et al. · 2016 [cited by applicant]
US 20160294773A1 · Yu et al. · 2016 [cited by applicant]
US 20160352772A1 · O'Connor · 2016 [cited by examiner]
US 20160366159A1 · Chiba et al. · 2016 [cited by applicant]
US 20170026398A1 · Mumcuoglu et al. · 2017 [cited by applicant]
US 20170041333A1 · Mahjoub · 2017 [cited by examiner]
US 20170098086A1 · Hoernecke et al. · 2017 [cited by applicant]
US 20170123875A1 · Craik et al. · 2017 [cited by applicant]
US 20170126718A1 · Baradaran · 2017 [cited by examiner]
US 20170149807A1 · Schilling et al. · 2017 [cited by applicant]
US 20170244745A1 · Key et al. · 2017 [cited by applicant]
US 20170323548A1 · Glatfelter et al. · 2017 [cited by applicant]
US 20180013778A1 · Lim et al. · 2018 [cited by applicant]
US 20180054449A1 · Nandha et al. · 2018 [cited by applicant]
US 20180063174A1 · Grill et al. · 2018 [cited by applicant]
US 20180069884A1 · Firstenberg · 2018 [cited by examiner]
US 20180139224A1 · Amell et al. · 2018 [cited by applicant]
US 20180285567A1 · Raman · 2018 [cited by applicant]
US 20180288073A1 · Hopper · 2018 [cited by applicant]
US 20180351930A1 · Kim et al. · 2018 [cited by applicant]
US 20190007440A1 · Lavi et al. · 2019 [cited by applicant]
US 20190058724A1 · Kraning et al. · 2019 [cited by applicant]
US 20190068575A1 · Vongsouvanh et al. · 2019 [cited by applicant]
US 20190068624A1 · Compton · 2019 [cited by applicant]
US 20190068638A1 · Bartik · 2019 [cited by examiner]
US 20190081952A1 · Wood · 2019 [cited by applicant]
US 20190190931A1 · Levin et al. · 2019 [cited by applicant]
US 20190250911A1 · Lospinuso et al. · 2019 [cited by applicant]
US 20190297097A1 · Gong et al. · 2019 [cited by applicant]
US 20190319977A1 · Gottschlich et al. · 2019 [cited by applicant]
US 20190319981A1 · Meshi et al. · 2019 [cited by applicant]
US 20190372934A1 · Yehudai et al. · 2019 [cited by applicant]
US 20190387005A1 · Zawoad et al. · 2019 [cited by applicant]
US 20200007548A1 · Sanghavi et al. · 2020 [cited by applicant]
US 20200014714A1 · Mortensen et al. · 2020 [cited by applicant]
US 20200067913A1 · Kapoor et al. · 2020 [cited by applicant]
US 20200177625A1 · Rouvinen · 2020 [cited by applicant]
US 20200213333A1 · Deutschmann et al. · 2020 [cited by applicant]
US 20200233791A1 · Manzano et al. · 2020 [cited by applicant]
US 20200244658A1 · Meshi et al. · 2020 [cited by applicant]
US 20200364354A1 · Schwartz et al. · 2020 [cited by applicant]
US 20200412717A1 · Puertas Calvo et al. · 2020 [cited by applicant]
US 20210014198A1 · Amoudi et al. · 2021 [cited by applicant]
US 20210136037A1 · Balasubramaniam · 2021 [cited by applicant]
US 20210258325A1 · Meyer et al. · 2021 [cited by applicant]
US 20210266331A1 · Meshi et al. · 2021 [cited by applicant]
US 20210289371A1 · Bagwell · 2021 [cited by applicant]
US 20220006819A1 · Allon et al. · 2022 [cited by applicant]
US 20220070216A1 · Kohavi · 2022 [cited by examiner]
US 20220342976A1 · Stoyanov et al. · 2022 [cited by applicant]
US 20220353284A1 · Vörös · 2022 [cited by examiner]
US 20220385694A1 · Zverkov · 2022 [cited by examiner]
US 20230086281A1 · Kaidi · 2023 [cited by applicant]
US 20230118679A1 · Mayer · 2023 [cited by examiner]
US 20230403265A1 · Gaffney et al. · 2023 [cited by applicant]
US 20240015176A1 · Egbert · 2024 [cited by examiner]
CN 114077741A · 2022 [cited by applicant]
JP 2008243034A · 2008 [cited by applicant]
WO 2012167056A2 · 2012 [cited by applicant]
WO 2020148934A1 · 2020 [cited by applicant]
Yazan Ahmad Alsariera; AI Meta-Learners and Extra-Trees Algorithm for the Detection of Phishing Websites; IEEE:2020; pp. 142532-142542. [cited by examiner]
U.S. Appl. No. 18/353,115 Office Action dated May 1, 2024. [cited by applicant]
International Applicaton PCT/IB2023/056071 Search Report dated Sep. 22, 2023. [cited by applicant]
Alon, “Compromised Cloud Compute Credentials: Case Studies from the Wild,” Unit 42, Palo Alto Networks, Inc., pp. 1-14, Dec. 8, 2022, as downloaded from as downloaded from https://unit42.paloaltonetworks.com/compromised… [cited by applicant]
JP Application # 2024504256 Office Action dated Oct. 8, 2024. [cited by applicant]
U.S. Appl. No. 17/844,097 Office Action dated Nov. 19, 2024. [cited by applicant]
U.S. Appl. No. 18/591,004 Office Action dated Dec. 3, 2024. [cited by applicant]
Wei et al., “Identifying New Spam Domains by Hosting IPS: Improving Domain Blacklisting”, Dept. of Computer and Information Sciences, University of Alabama at Birmingham, pp. 1-8, Jan. 2010. [cited by applicant]
Iana., “Autonomous System (AS) Numbers”, 1 page, Jul. 29, 2016. [cited by applicant]
Gross et al., “FIRE: Finding Rogue nEtworks”, Annual Conference on Computer Security Applications, pp. 1-10, Dec. 7-11, 2009. [cited by applicant]
Frosch., “Mining DNS-related Data for Suspicious Features”, Ruhr Universitat Bochum, Master's Thesis, pp. 1-88, Dec. 23, 2011. [cited by applicant]
Bilge et at., “Disclosure: Detecting Botnet Command and Control Servers Through Large-Scale NetFlow Analysis”, Annual Conference on Computer Security Applications, pp. 1-10, Dec. 3-7, 2012. [cited by applicant]
Blum., “Combining Labeled and Unlabeled Data with Co-Training”, Carnegie Mellon University, Research Showcase @ CMU, Computer Science Department, pp. 1-11, Jul. 1998. [cited by applicant]
Felegyhazi et al., “On the Potential of Proactive Domain Blacklisting”, LEET'10 Proceedings of the 3rd USENIX Conference on Large-scale exploits and emergent threats, pp. 1-8, San Jose, USA, Apr. 27, 2010. [cited by applicant]
Konte et al., “ASwatch: An AS Reputation System to Expose Bulletproof Hosting ASes”, SIGCOMM , pp. 625-638, Aug. 17-21, 2015. [cited by applicant]
Markowitz, N., “Bullet Proof Hosting: A Theoretical Model”, Security Week, pp. 1-5 , Jun. 29, 2010, downloaded from http://www.infosecisland.com/blogview/4487-Bullet-Proof-Hosting-A-Theoretical-Model.html. [cited by applicant]
Markowitz, N., “Patterns of Use and Abuse with IP Addresses”, Security Week, pp. 1-4, Jul. 10, 2010, downloaded from http://infosecisland.com/blogview/5068-Patterns-of-Use-and-Abuse-with-IP-Addresses.html. [cited by applicant]
Goncharov, M., “Criminal Hideouts for Lease: Bulletproof Hosting Services”, Forward-Looking Threat Research (FTR) Team, A TrendLabsSM Research Paper, pp. 1-28, Jul. 3, 2015. [cited by applicant]
Bilge at al., “Exposure: Finding Malicious Domains Using Passive DNS Analysis ”, NDSS Symposium, pp. 1-17 Feb. 6-9, 2011. [cited by applicant]
Xu et al., “We know it before you do: Predicting Malicious Domains”, Virus Bulletin Conference, pp. 73-33, Sep. 2014. [cited by applicant]
Palo Alto Networks, “Cortex XDR”, p. 1-7, year 2020. [cited by applicant]
“GeoIP Databases & Services: Industry Leading IP Intelligence,” MaxMind, Inc., pp. 1-3, updated Jan. 14, 2022, as downloaded from https://www.maxmind.com/en/geoip2-services-and-databases. [cited by applicant]
Alon et al., U.S. Appl. No. 17/844,097, filed Jun. 20, 2022. [cited by applicant]
Mandiant, “Highly Evasive Attacker Leverages SolarWinds Supply Chain to Compromise Multiple Global Victims with SUNBURST Backdoor”, pp. 1-16, Dec. 13, 2020 downloaded from https://www.mandiant.com/resources/blog/evasive… [cited by applicant]
Zan et al., U.S. Appl. No. 17/857,196, filed Jul. 5, 2022. [cited by applicant]
U.S. Appl. No. 17/857,196 Office Action dated Dec. 7, 2023. [cited by applicant]
Palo Alto Networks, “Cortex Xsoar—Phishing Investigation—Generic v2,” pp. 1-6, year 2020, as downloaded from https://web.archive.org/web/20200927223050/https://xsoar.pan.dev/docs/reference/playbooks/phishing-investigati… [cited by applicant]
GitHub, cburgmer/rasterizeHTML.js, pp. 1-2, Jan. 19, 2020, as downloaded from https://web.archive.org/web/20200219074432/https://github.com/cburgmer/rasterizeHTML.js. [cited by applicant]
Refsnes Data, “W3Schools,—HTML <form> Tag,” pp. 1-10, years 1999-2023, as downloaded from https://www.w3schools.com/tags/tag_form.asp. [cited by applicant]
Refsnes Data, “W3Schools,—HTML <input> Tag,” pp. 1-11, years 1999-2023, as downloaded from https://www.w3schools.com/tags/tag_input.asp. [cited by applicant]
Microsoft 365, “Exchange—Work Smarter with Business-Class Email and Calendaring,” pp. 1-4, Aug. 15, 2020, as downloaded from https://web.archive.org/web/20200815211502/https://www.microsoft.com/en-ww/microsoft-365/excha… [cited by applicant]
Wikipedia, “Selenium (Software),” pp. 1-5, last edited Dec. 3, 2019, as downloaded from https://web.archive.org/web/20191218132058/https://en.wikipedia.org/wiki/Selenium_(software). [cited by applicant]
Wikipedia, “WHOIS,” pp. 1-16, last edited Dec. 23, 2019, as downloaded from https://web.archive.org/web/20200112181104/https://en.wikipedia.org/wiki/WHOIS. [cited by applicant]
“British National Corpus,” Oxford Text Archive, IT Services, University of Oxford, p. 1-1, year 2015, as downloaded from https://web.archive.org/web/20200128044646/http://www.natcorp.ox.ac.uk/. [cited by applicant]
JP Application # 2024504256 Office Action dated Jul. 2, 2024. [cited by applicant]
JP Application # 2024504256 Office Action dated Jan. 28, 2025. [cited by applicant]
U.S. Appl. No. 18/591,004 Office Action dated Apr. 7, 2025. [cited by applicant]
Final US Office Action # 18475266, dated Aug. 15, 2025. [cited by applicant]