IP Library Granted Patent US 11,563,774
Granted Patent B2
US 11,563,774 · App. 17/118,112 · Granted Jan 24, 2023

Systems and methods for tracking and identifying phishing website authors

Inventor: Philippe Louis Yves Paquet (Beverly Hills, CA)
Assignee: Activision Publishing, Inc.
H04L63/1483G06F16/9574H04L61/5007H04L63/1466H04L2101/663H04L2463/146
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,563,774
App. No.
17/118,112
Granted
Jan 24, 2023
Kind
B2
Abstract

A method of tracking phishing activity is disclosed. A request to download a webpage hosted as part of a legitimate website on a server is initiated. The request includes identification data pertaining to at least one user computing device. The identification data is extracted from the request. A unique identifier corresponding to the extracted identification data is generated. Fingerprint data is generated using at least a subset of the extracted identification data. The unique identifier, the extracted identification data and the fingerprint data is stored. The fingerprint data is encoded into a program and/or data associated with the webpage to generate a modified webpage. The modified webpage is transmitted from the server to the user computing device in response to the request.

Claims (30)

1. A computer-implemented method of tracking phishing activity targeting a webpage that is part of a website which is hosted on at least one server, wherein the at least one server is in data communication with at least one user computing device over a network and wherein the at least one user computing device is configured to initiate a request to the at least one server to download the webpage, the method comprising:

receiving, at the at least one server, the request to download the webpage, wherein the request includes identification data pertaining to the at least one user computing device;

extracting, at the at least one server, one or more of the identification data from the request;

generating, at the at least one server, a unique identifier corresponding to the one or more of the identification data;

using, at the at least one server, at least a subset of the one or more of the identification data to generate fingerprint data wherein a size of the fingerprint data ranges from 64 bits to 256 bits;

storing, at the at least one server, the unique identifier, the one or more of the identification data, and the fingerprint data, wherein the unique identifier is stored in association with the one or more of the identification data and the fingerprint data;

encoding, at the at least one server, the fingerprint data into a program code and/or data associated with the webpage to generate a modified webpage, wherein the encoding comprises at least one of adding the fingerprint data to the program code and/or data or replacing a portion of the program code and/or data with the fingerprint data and wherein, after the encoding, the fingerprint data within the program code and/or data is visually undetectable by humans; and

transmitting the modified webpage with the fingerprint data from the at least one server to the user computing device in response to the request.

2. The computer-implemented method of claim 1 , wherein the one or more of the identification data comprises at least one of an IP address of the user computing device, an IP-based geo-location of the user computing device, TCP/IP fingerprint parameters, HTTP header fields or IP Address Whois data.

3. The computer-implemented method of claim 1 , further comprising:

downloading, at the at least one server, the modified webpage from a potentially phishing website;

decoding, at the at least one server, the modified webpage to retrieve the fingerprint data;

accessing, at the at least one server, the unique identifier associated with the retrieved fingerprint data;

accessing, at the at least one server, the one or more of the identification data using the accessed unique identifier; and

identifying the user computing device based on the accessed one or more of the identification data.

4. A computing system configured to track phishing activity targeting a webpage that is part of a website comprising:

at least one server, wherein the at least one server is in data communication with at least one remotely located user computing device over a network, wherein the at least one server is configured to receive a request from the at least one remotely located user computing device to acquire data indicative of the webpage, and wherein the at least one server comprises at least one hardware processor and programmatic instructions that, when executed by the at least one hardware processor:

receives the request to download the webpage, wherein the request includes identification data pertaining to the at least one user computing device;

extracts at least a portion of the identification data from the request;

generates a unique identifier corresponding to the portion of the identification data;

stores the unique identifier and the portion of the identification data, wherein the unique identifier bears an association with said one or more of the plurality of identification data and wherein a size of the unique identifier ranges from 64 bits to 256 bits;

encodes the unique identifier into a program code and/or data associated with the webpage by adding the unique identifier to the program code and/or data or replacing a portion of the program code and/or data with the unique identifier such that the unique identifier is visually undetectable by a human in the program code of the webpage or in the rendered version of webpage, thereby generating a modified webpage; and

transmits the modified webpage from the at least one server to the user computing device in response to the request.

5. The computing system of claim 4 , wherein the identification data comprises at least one of an IP address of the at least one user computing device, an IP-based geo-location of the at least one user computing device, TCP/IP fingerprint parameters indicative of the at least one user computing device, HTTP header fields indicative of the at least one user computing device and IP Address Whois data indicative of the at least one user computing device.

6. The computing system of claim 4 , wherein the programmatic instructions, when executed by the at least one hardware processor:

downloads the modified webpage from a potentially phishing website;

decodes the modified webpage to retrieve the fingerprint data;

accesses the unique identifier associated with the retrieved fingerprint data;

accesses the one or more of the identification data using the accessed unique identifier; and

identifies the user computing device based on the accessed one or more of the identification data.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 10, 2020
From: PAQUET, PHILIPPE LOUIS YVES
To: ACTIVISION PUBLISHING, INC.
Reel/Frame 054609/0783 →
Continuity (2)
Provisional Application 62954048 · Dec 27, 2019
Related Publication 20210203694A1 · Jul 1, 2021