IP Library Granted Patent US 12,418,549
Granted Patent B1
US 12,418,549 · App. 18/629,139 · Granted Sep 16, 2025

Method and system for detecting credential stealing attacks

Inventor: Atif Mushtaq (San Ramon, CA)
Assignee: Slash Next, Inc.
H04L63/1416H04L63/1425G06F16/951G06N20/00
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,418,549
App. No.
18/629,139
Granted
Sep 16, 2025
Kind
B1
Abstract

An Active Vision detection method and system for detecting credential stealing attacks using an automated machine-learning page examination engine is provided that may be used to detect both brand-based and custom credential stealing attacks. The approach employs similarity analysis in a two-stage process that may be achieved through supervised or self-learning machine learning techniques and is comparable to human analysis. The Active Vision System is capable of self-learning; every new attack detected by the system becomes part of system's long-term memory making it incrementally more accurate in future predictions using its past experience.

Claims (30)

1. A method for detecting a credential stealing attack comprising:

(a) loading a candidate web page into a browser memory;

(b) extracting different types of features from the candidate web page rendered in the browser memory;

(c) generating a similarity features set by comparing the different types of features extracted in (b) to corresponding custom features from a known custom credential stealing page fetched from a knowledge base storing a plurality of records of known custom credential stealing page;

(d) taking as input the similarity features set in (c), utilizing a trained binary classifier, to predict a binary result whether the candidate web page is the known custom credential stealing page; and

(e) upon determining the candidate web page is not the known custom credential stealing page, repeating (c)-(d) until the candidate web page is predicted to be a known custom credential stealing page or terminating the process by generating a verdict indicating the candidate web page is benign when all of the plurality of records are compared to the candidate web page.

2. The method of claim 1 , further comprising providing a graphical interface for displaying information regarding the candidate web page, the information comprising: (i) an identity of an infected machine on a network that has accessed the candidate web page if the candidate web page is predicted as a known custom credential stealing page and (ii) a feature of the infected machine, wherein the feature is selected from the group consisting of a machine location, a machine usage, a MAC ID, a type of machine, a machine operating system, and an identity of a machine user.

3. The method of claim 1 , further comprising providing a graphical interface for displaying information regarding a credential attack, the information comprising: a number of connection attempts made, a name of a Malware, a type of attack or attack category, a hacker group that performed the attack, a type of malware that was used, or a time of the attack.

4. The method of claim 1 , wherein the different types of features comprise at least two from the group consisting of visual features, natural language features and source code features.

5. The method of claim 1 , further comprising interacting with the candidate web page within the browser memory to collect forensics intelligence on the candidate web page's behavior.

6. The method of claim 1 , further comprising interacting with the candidate web page by establishing an out-of-band connection using an anonymous server to collect forensics intelligence on the candidate web page's behavior.

7. The method of claim 6 , wherein the anonymous server is a virtual private network or a proxy server.

8. The method of claim 6 , further comprising using a virtual mouse or virtual keyboard to interact with the candidate web page.

9. The method of claim 6 , wherein the candidate web page is predicted to be the known custom credential stealing page further based on the forensics intelligence on the candidate web page's behavior.

10. A system detecting a credential stealing attack comprising:

(i) a memory for storing a set of software instructions,

(ii) one or more processors configured to execute the set of software instructions to:

(a) load a candidate web page into a browser memory;

(b) extract different types of features from the candidate web page rendered in the browser memory;

(c) generate a similarity features set by comparing the different types of features extracted in (b) to corresponding custom features from a known custom credential stealing page fetched from a knowledge base storing a plurality of records of known custom credential stealing page;

(d) take as input the similarity features set in (c), utilizing a trained binary classifier, to predict a binary result whether the candidate web page is the known custom credential stealing page; and

(e) upon determining the candidate web page is not the known custom credential stealing page, repeat (c)-(d) until the candidate web page is predicted to be a known custom credential stealing page or terminate the process by generating a verdict indicating the candidate web page is benign when all of the plurality of records are compared to the candidate web page.

11. The system of claim 10 , wherein the one or more processors are further configured to provide a graphical interface for displaying information regarding the candidate web page, the information comprising: (i) an identity of an infected machine on a network that has accessed the candidate web page if the candidate web page is predicted as a known custom credential stealing page and (ii) a feature of the infected machine, wherein the feature is selected from the group consisting of a machine location, a machine usage, a MAC ID, a type of machine, a machine operating system, and an identity of a machine user.

12. The system of claim 10 , wherein the one or more processors are further configured to provide a graphical interface for displaying information regarding a credential attack, the information comprising: a number of connection attempts made, a name of a Malware, a type of attack or attack category, a hacker group that performed the attack, a type of malware that was used, or a time of the attack.

13. The system of claim 10 , wherein the different types of features comprise at least two from the group consisting of visual features, natural language features and source code features.

14. The system of claim 10 , wherein the one or more processors are further configured to interact with the candidate web page within the browser memory to collect forensics intelligence on the candidate web page's behavior.

15. The system of claim 10 , wherein the one or more processors are further configured to interact with the candidate web page by establishing an out-of-band connection using an anonymous server to collect forensics intelligence on the candidate web page's behavior.

16. The system of claim 15 , wherein the anonymous server is a virtual private network or a proxy server.

17. The system of claim 15 , wherein the one or more processors are further configured to use a virtual mouse or virtual keyboard to interact with the candidate web page.

18. The system of claim 15 , wherein the candidate web page is predicted to be the known custom credential stealing page further based on the forensics intelligence on the candidate web page's behavior.

Assignments (3)
CHANGE OF NAME Recorded Apr 16, 2026
From: SLASHNEXT, INC.
To: SLASHNEXT, LLC
Reel/Frame 075409/0484 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 16, 2026
From: SLASHNEXT, LLC
To: VARONIS SYSTEMS, INC.
Reel/Frame 075409/0567 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 10, 2024
From: MUSHTAQ, ATIF
To: SLASHNEXT, INC.
Reel/Frame 067055/0134 →
Continuity (5)
Continuation 17468592 · Sep 7, 2021
Continuation 16580530 · Sep 24, 2019
Continuation In Part 16528356 · Jul 31, 2019
Continuation 15616061 · Jun 7, 2017
Provisional Application 62347514 · Jun 8, 2016
References Cited (3)
US 9917852B1 · Xu · 2018 [cited by examiner]
US 20100186088A1 · Banerjee · 2010 [cited by examiner]
US 20120079566A1 · Barranco · 2012 [cited by examiner]