IP Library Patent Application 18611937
Patent Application
App. No. 18/611,937

Systems and Methods for Detecting Phishing-Based Cybersecurity Threats

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
18/611,937
Filed
Mar 21, 2024
Art Unit
2424
USPC
726/23
Abstract

Systems, methods, and non-transitory computer readable media including instructions for implementing a runtime virtual barrier for fine grained execution control are disclose. Implementing the runtime virtual barrier for fine grained execution control includes receiving, by an application capable of JavaScript execution, an executable code including an API invocation; intercepting, by a virtual barrier, the API invocation; determining that the API invocation is an invocation for a native API configured for subsequent execution in response to a trigger event; based on the determination that the API invocation is an invocation for a native API configured for subsequent execution, recording an invocation source identifier; and upon occurrence of the trigger event: retrieving the invocation source identifier; and influencing execution of the native API based on the invocation source identifier.

Claims (45)

1 - 80 . (canceled)

81 . A non-transitory computer readable medium containing instructions that when executed by at least one processor cause the at least one processor to perform cybersecurity operations for detecting a phishing attempt, the operations comprising:

receiving a code for execution; and

injecting, into an execution environment associated with the code, at least one agent configured to:

collect execution data associated with rendering content based on the code;

analyze the execution data to detect at least one anomaly;

determine, based on runtime events resulting from executing the code in at least one execution context associated with the execution environment, whether functionality associated with the content is valid; and

implement a remedial action upon determining that the functionality associated with the content is not valid.

82 . The non-transitory computer readable medium of claim 81 , wherein the execution environment is associated with a web browser and the content includes web page content.

83 . The non-transitory computer readable medium of claim 81 , wherein the code is configured for execution by a JavaScript engine and the at least one agent includes a JavaScript agent.

84 . The non-transitory computer readable medium of claim 81 , wherein determining whether functionality associated with the content is valid includes:

executing the code in the at least one execution context in an isolated environment, and emulating at least one event in the isolated environment to identify a behavior of the code associated with the at least one event; and

wherein determining that the functionality associated with the content is not valid includes determining that the identified behavior diverges from an expected behavior.

85 . The non-transitory computer readable medium of claim 84 , wherein emulating at least one event in the isolated environment includes simulating following a link included in the content, monitoring a Document Object Model (DOM) structure associated with the content, and determining that the identified behavior diverges from the expected behavior when the DOM structure remains unchanged after simulation of following the link.

86 . The non-transitory computer readable medium of claim 84 , wherein emulating at least one event in the isolated environment includes submitting at least one value using a form of the content, and wherein identifying the behavior of the code includes determining a response to submitting the at least one value.

87 . The non-transitory computer readable medium of claim 86 , wherein the at least one value is arbitrary.

88 . The non-transitory computer readable medium of claim 87 , wherein the form is a login form, and wherein the at least one value corresponds to a login credential.

89 . The non-transitory computer readable medium of claim 88 , wherein the content is associated with a first web page, the expected behavior corresponds to an invalid credential warning, and the identified behavior includes redirecting a web browser to a second web page.

90 . The non-transitory computer readable medium of claim 81 , wherein the at least one anomaly includes a broken link.

91 . The non-transitory computer readable medium of claim 90 , wherein the broken link is an invalid link lacking an associated listener in a DOM structure associated with the content.

92 . The non-transitory computer readable medium of claim 81 , wherein the at least one anomaly includes a property violating a security rule.

93 . The non-transitory computer readable medium of claim 92 , wherein the property is associated with a root of a DOM structure associated with the content.

94 . The non-transitory computer readable medium of claim 92 , wherein the property includes a network request property.

95 . The non-transitory computer readable medium of claim 92 , wherein the property includes a DOM structure associated with the content.

96 . A method for performing cybersecurity operations for detecting a phishing attempt, the method comprising:

receiving a code for execution; and

injecting, into an execution environment associated with the code, at least one agent configured to:

collect execution data associated with a rendering content based on the code;

analyze the execution data to detect at least one anomaly;

determine, based on runtime events resulting from executing the code in at least one execution context associated with the execution environment, whether functionality associated with the content is valid; and

implement a remedial action upon determining that the functionality associated with the content is not valid.

97 . The method of claim 96 , wherein the execution environment is associated with a web browser and the content includes web page content.

98 . The method of claim 96 , wherein the code is configured for execution by a JavaScript engine and the at least one agent includes a JavaScript agent.

99 . The method of claim 96 , wherein determining whether functionality associated with the content is valid includes:

executing the code in the at least one execution context in an isolated environment, and emulating at least one event in the isolated environment to identify a behavior of the code associated with the at least one event; and

wherein the at least one agent is configured to determine whether functionality associated with the content is not valid by determining that the identified behavior diverges from an expected behavior.

100 . A system for performing cybersecurity operations for detecting a phishing attempt, the system comprising:

at least one processor configured to:

receive a code for execution;

inject, into an execution environment associated with the code, at least one agent configured to:

collect execution data associated with rendering content based on the code;

analyze the execution data to detect at least one anomaly;

determine, based on runtime events resulting from executing the code in at least one execution context associated with the execution environment, whether functionality associated with the content is valid; and

implement a remedial action upon determining that the functionality associated with the content is not valid.

101 - 159 . (canceled)

Assignments (3)
RELEASE OF SECURITY INTEREST Recorded Jun 25, 2026
From: HSBC BANK PLC
To: SERAPHIC ALGORITHMS LTD
Reel/Frame 075079/0275 →
SECURITY INTEREST Recorded May 12, 2025
From: SERAPHIC ALGORITHMS LTD
To: HSBC BANK PLC
Reel/Frame 071088/0637 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 21, 2024
From: COHEN, AVIHAY
To: SERAPHIC ALGORITHMS LTD.
Reel/Frame 066853/0755 →