IP Library Patent Application 19542432
Patent Application
App. No. 19/542,432

CYBER SECURITY SYSTEMS AND METHODS

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
19/542,432
Abstract

A web browser prevents phishing attacks in-browser. The web browser, which is associated with an organization, monitors activity of a user performed via the web browser. The web browser detects interaction of the user with a first website. Based on loading the first website, the web browser determines a reputation of the first website maintained by the organization. Based on determining that the first website has a low reputation or no reputation maintained by the organization, the web browser indicates to the user that the first website has a low reputation or no reputation.

Claims (60)

1 - 9 . (canceled)

10 . A method comprising:

monitoring, by a web browser, activity of a first user performed via the web browser, wherein the web browser is associated with an organization; and

preventing phishing attacks affecting the first user, wherein preventing phishing attacks affecting the first user comprises, by the web browser,

detecting interaction of the first user with a first website of a plurality of websites;

based on loading the first website into the web browser, determining a reputation of the first website maintained by the organization; and

based on determining that the first website has a low reputation or no reputation maintained by the organization, indicating to the first user that the first website has a low reputation or no reputation.

11 . The method of claim 10 , further comprising, based on determining that the first website has a low reputation or no reputation maintained by the organization, blocking input by the first user into the first website.

12 . The method of claim 10 , further comprising at least one of terminating a browser session of the first user, preventing the first user from communicating with other users of the organization, and preventing the first user from interacting with one or more others of the plurality of websites based on determining that the interaction of the first user with the first website poses a phishing risk.

13 . The method of claim 10 , further comprising determining reputation rankings for the plurality of websites based on tracking access by users associated with the organization to the plurality of websites, wherein the plurality of websites includes the websites, wherein the reputation rankings for the plurality of websites are localized to the organization, wherein determining that the first website has a low reputation or no reputation is based on the determined reputation rankings.

14 . The method of claim 13 , further comprising, based on the web browser detecting interaction of the first user with a second website of the plurality of websites, increasing a reputation ranking of the second website maintained for the organization, wherein the interaction of the first user with the second website comprises consented user input by the first user into the second website.

15 . The method of claim 10 , further comprising:

prior to the web browser loading the first website, determining a probability that the first website is related to a phishing attack based on threat intelligence related to the first website; and

based on determining that the first website is related to a phishing attack, the web browser blocking loading of the first website or warning the first user that the first website is related to a phishing attack prior to loading the first website.

16 . The method of claim 10 , further comprising, by the web browser, based on determining from a document object model (DOM) of the first website that the first website does not comprise a login form or password field, determining if the first website comprises a login form or password field based on inspection of the first website with image recognition.

17 . The method of claim 10 , further comprising generating a graph comprising a plurality of nodes and a plurality of edges,

wherein the plurality of nodes represents a plurality of entities,

wherein the plurality of entities comprises users associated with the organization, resources of the organization, and the plurality of websites,

wherein the plurality of nodes is associated with a plurality of feature sets corresponding to the plurality of entities,

wherein the plurality of edges represents interactions among the plurality of entities.

18 . The method of claim 17 , further comprising:

based on the web browser detecting interaction of the first user with one or more entities of the plurality of entities, generating an activity group that indicates the first user, the one or more entities, and a subset of the plurality of feature sets corresponding to the first user and the one or more entities identified from the graph; and

determining a phishing risk posed by interaction of the first user with the one or more entities based on the activity group, wherein determining the phishing risk posed by interaction of the first user with the one or more entities based on the activity group comprises,

generating a feature vector representing the activity group; and

processing the feature vector with a neural network to determine a probability of phishing risk associated with activity of the first user represented by the activity group.

19 . The method of claim 10 , further comprising:

generating a phishing scenario and a plurality of possible actions to take for the phishing scenario; and

presenting the phishing scenario and the plurality of possible actions to the first user to measure proficiency of the first user in averting phishing attacks.

20 . One or more non-transitory machine-readable media having program code stored thereon, the program code comprising instructions to:

monitor, by a web browser, activity of a first user performed via the web browser, wherein the web browser is associated with an organization; and

prevent phishing attacks affecting the first user, wherein preventing phishing attacks affecting the first user comprises, by the web browser, detect interaction of the first user with a first website of a plurality of websites;

based on loading of the first website into the web browser, determine a reputation of the first website maintained by the organization;

based on a determination that the first website has a low reputation or no reputation maintained by the organization, indicate to the first user that the first website has a low reputation or no reputation; and

block input by the first user into the first website.

21 . The non-transitory machine-readable media of claim 20 , wherein the program code further comprises instructions to at least one of terminate a browser session of the first user, prevent the first user from communicating with other users of the organization, and prevent the first user from interacting with one or more others of the plurality of websites based on a determination that the interaction of the first user with the first website poses a phishing risk.

22 . The non-transitory machine-readable media of claim 20 , wherein the program code further comprises instructions to determine reputation rankings for the plurality of websites based on tracking access by users associated with the organization to the plurality of websites, wherein the plurality of websites includes the websites, wherein the reputation rankings for the plurality of websites are localized to the organization, wherein determining that the first website has a low reputation or no reputation is based on the determined reputation rankings.

23 . The non-transitory machine-readable media of claim 22 , wherein the program code further comprises instructions to, based on the web browser detecting interaction of the user with a second website of the plurality of websites, increase a reputation ranking of the second website maintained for the organization, wherein the interaction of the first user with the second website comprises consented user input by the first user into the second website.

24 . The non-transitory machine-readable media of claim 20 , wherein the program code further comprises instructions to:

prior to the web browser loading the first website, determine a probability that the first website is related to a phishing attack based on threat intelligence related to the first website; and

based on a determination that the first website is related to a phishing attack, by the web browser, block loading of the first website or warn the first user that the first website is related to a phishing attack prior to loading the first website.

25 . The non-transitory machine-readable media of claim 20 , wherein the program code further comprises instructions to, by the web browser, based on a determination from a document object model (DOM) of the first website that the first website does not comprise a login form or password field, determine whether the first website comprises a login form or password field based on inspection of the first website with image recognition.

26 . The non-transitory machine-readable media of claim 20 , wherein the program code further comprises instructions to:

generate a graph comprising a plurality of nodes and a plurality of edges,

wherein the plurality of nodes represents a plurality of entities,

wherein the plurality of entities comprises users associated with the organization, resources of the organization, and the plurality of websites,

wherein the plurality of nodes is associated with a plurality of feature sets corresponding to the plurality of entities,

wherein the plurality of edges represents interactions among the plurality of entities; and

based on the web browser detecting interaction of the first user with one or more entities of the plurality of entities, generate an activity group that indicates the first user, the one or more entities, and a subset of the plurality of feature sets corresponding to the first user and the one or more entities identified from the graph; and

determine a phishing risk posed by interaction of the first user with the one or more entities based on the activity group.

27 . An apparatus comprising:

a processor; and

a machine-readable medium having instructions stored thereon that are executable by the processor to cause the apparatus to,

monitor, by a web browser, activity of a first user performed via the web browser, wherein the web browser is associated with an organization; and

prevent phishing attacks affecting the first user, wherein the instructions executable by the processor to cause the apparatus to prevent phishing attacks affecting the first user comprise instructions executable by the processor to cause the apparatus to, by the web browser,

detect interaction of the first user with a first website of a plurality of websites;

based on loading of the first website into the web browser, determine a reputation of the first website maintained by the organization;

based on a determination that the first website has a low reputation or no reputation maintained by the organization, indicate to the first user that the first website has a low reputation or no reputation; and

block input by the first user into the first website.

28 . The apparatus of claim 27 , further comprising instructions executable by the processor to cause the apparatus to at least one of terminate a browser session of the first user, prevent the first user from communicating with other users of the organization, and prevent the first user from interacting with one or more others of the plurality of websites based on a determination that the interaction of the first user with the first website poses a phishing risk.

29 . The apparatus of claim 27 , further comprising instructions executable by the processor to cause the apparatus to determine reputation rankings for the plurality of websites based on tracking access by users associated with the organization to the plurality of websites, wherein the plurality of websites includes the websites, wherein the reputation rankings for the plurality of websites are localized to the organization, wherein determining that the first website has a low reputation or no reputation is based on the determined reputation rankings.

Assignments (2)
NUNC PRO TUNC ASSIGNMENT Recorded Jul 22, 2026
From: BEN-NOON, OFER; BOBROV, OHAD; SALOMON, IDO; ZRAHIA, SHLOMI; ENGLESMAN, YINON; SIKURIANSKY, ELIAZAR EDWARD; GOTLIB, YEHONATAN
To: TALON CYBER SECURITY LTD.
Reel/Frame 075355/0630 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2026
From: TALON CYBER SECURITY LTD.
To: PALO ALTO NETWORKS, INC.
Reel/Frame 075355/0800 →